Dynamic Mesh SSID Authentication for Secure AP Links
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mesh networks, the use of a static mesh service set identifier (SSID) exposes the network to security risks as the SSID can be sniffed by third parties, compromising the security of the entire mesh cluster.
Innovation Solution
Implementing a dynamic SSID mechanism where each mesh link establishment generates a unique SSID for authentication using a random number and a predefined key, ensuring each pair of mesh APs has a distinct identifier for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a static mesh SSID is used for authentication in mesh networks, then the authentication process is simple and consistent across all mesh APs, but the network security is compromised as the SSID can be sniffed by third parties
Solution Approach 1:
The patent transforms the static mesh SSID into a dynamic identifier that changes for each link establishment. Each mesh AP generates a unique dynamic SSID based on its identifier and a random number, so the SSID is no longer fixed but varies per connection attempt, preventing sniffing while maintaining authentication functionality
Solution Approach 2:
The patent applies different SSID values to different local contexts (individual link establishments) rather than using a single global SSID. Each mesh AP uses its own identifier combined with a random number to generate a locally unique SSID for each authentication attempt, ensuring security at the local link level
2Object-affected harmful factors
If a dynamic SSID is generated for each mesh link using random numbers and predefined keys, then network security is enhanced, but the device complexity increases
Solution Approach 1:
The patent changes the parameters used in SSID generation from a static configuration to dynamic parameters including the mesh AP's own identifier and a randomly generated number. This parameter change approach allows security enhancement through variability while keeping the generation mechanism relatively simple
Solution Approach 2:
Each mesh AP autonomously generates its own dynamic SSID using its predefined identifier and a random number it creates itself. This self-service approach eliminates the need for a centralized authority to manage complex authentication, distributing the complexity across individual devices rather than concentrating it in one system
Data Source
AI summary
Implementations of the present disclosure relate to dynamic mesh service set identifiers (SSIDs). In the implementations, a first AP broadcasts a probe request including a first identifier and a first random number. The first AP receives a probe response including a second identifier and a second random number from a second AP. The first AP generates a first SSID based on the first identifier, the first random number, the second identifier and the second random number. The first AP transmits an authentication request including the first SSID to the second AP. The first AP receives an authentication response to the authentication request from the second AP. In this way, the mesh SSIDs associated with different mesh links are different so that other mesh APs would not be attacked even if a mesh SSID of one mesh AP in the same mesh cluster is exposed.


