Multi-band Hybrid Network Encryption via Channel Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hybrid wired/wireless networks face challenges in providing seamless communication and security due to mobility of access devices, interference issues, and limitations in channel assignment, especially in multi-band multi-protocol environments, where conventional switches struggle to manage network resources effectively and ensure security across changing traffic dynamics.
Innovation Solution
A method and system for multiple encryption in a multi-band multi-protocol hybrid wired/wireless network, where access points receive requests for communication sessions, authenticate devices, generate encryption keys based on traffic types, and establish virtual channels for secure communication across different PHY channels, utilizing authentication servers and encryption algorithms to ensure secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple PHY channels are used for communication sessions, authentication, and key distribution in a multi-band multi-protocol hybrid wired/wireless network, then communication flexibility and security are improved, but device complexity and management difficulty increase
Solution Approach 1:
The access point is designed to handle multiple communication sessions across different PHY channels (first PHY channel for communication, second PHY channel for authentication, third PHY channel for key distribution) using a unified processing architecture. The same access point performs diverse functions including session management, device authentication, and encryption key distribution, eliminating the need for separate dedicated devices for each function and thereby managing complexity while maintaining versatility.
2Reliability
If authentication and key distribution are performed on separate PHY channels from communication sessions, then security is improved, but channel management complexity increases
Solution Approach 1:
The system segments different communication functions across separate PHY channels: the first PHY channel handles data communication sessions, the second PHY channel handles device authentication, and the third PHY channel handles encryption key distribution. This segmentation isolates security-critical operations from data transmission, ensuring that compromise of one channel does not affect others, while the access point manages all channels through a centralized processing architecture.
3Reliability
If encryption keys are generated and distributed through multiple channels, then security against eavesdropping is improved, but the risk of key management errors increases
Solution Approach 1:
The access point implements a feedback mechanism where authentication information received on the second PHY channel is used to generate encryption keys that are then distributed on the third PHY channel. The system verifies authentication status and adjusts key distribution accordingly, ensuring that keys are only distributed to authenticated devices. This feedback loop maintains security while simplifying key management by automating the correlation between authentication and key distribution.
Data Source
AI summary
Multiple encryption in a multi-band multi-protocol hybrid wired/wireless network may include receiving on a first PHY channel of an access point, a request for initiation of a communication session from an originating access device. The received request may be acknowledged on the first PHY channel and the originating access device may be authenticated on a second PHY channel. One or more encryption/decryption keys may be provided for use during the communication session. A third PHY channel or the first or second PHY channels may host the communication session. The authentication information may be requested and delivered to the originating access device via a second PHY channel. The encryption key may be delivered to the originating access device via the first PHY channel or the second PHY channel. Additionally, information may be tunneled over a virtual channel established between the originating and a terminating access device.


