Mesh Access Point Profile for Secure Network Joining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless mesh networks, there is a need to uniquely identify and authenticate mesh access points across different administrative domains to prevent unauthorized access and ensure secure service provisioning, particularly in scenarios where child mesh APs need to distinguish between networks and link with parent APs that support appropriate security services.
Innovation Solution
A mesh access point with an access point profile that stores parameters for selecting and authenticating with a wireless mesh network, including security information and policies for mutual authentication, allowing the access point to join appropriate networks and filter potential parent mesh access points based on their capabilities and requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If child mesh APs are allowed to join any nearby mesh network, then network connectivity and coverage are improved, but security risks increase due to potential connection to unauthorized or insecure networks
Solution Approach 1:
The access point profile is pre-configured with authentication credentials and security policies before the mesh AP joins the network. This preliminary preparation enables the mesh AP to perform mutual authentication and enforce security requirements before actual network connection, preventing connection to unauthorized networks while maintaining joining flexibility
Solution Approach 2:
The access point profile acts as an intermediary mechanism between the child mesh AP and the parent mesh network. It contains authentication credentials and security policies that mediate the connection process, allowing the mesh AP to verify network legitimacy and enforce security requirements without compromising connection flexibility
2Reliability
If mutual authentication is implemented between child mesh AP and parent mesh AP, then network security is improved, but authentication complexity and time requirements increase
Solution Approach 1:
Authentication credentials are pre-stored in the access point profile before the authentication process begins. This eliminates the need for real-time credential exchange and complex authentication protocols, reducing authentication time and complexity while maintaining strong security through pre-verified credentials
Solution Approach 2:
The mesh AP uses its own pre-configured authentication credentials to perform mutual authentication automatically. The system serves itself by using stored credentials rather than requiring complex interactive authentication processes, reducing complexity while maintaining security
3Reliability
If access point profiles are pre-configured with security policies, then service quality and security requirements are ensured, but device configuration complexity increases
Solution Approach 1:
Security policies and service quality parameters are pre-configured in the access point profile before deployment. This preliminary configuration ensures that when the mesh AP joins a network, it automatically enforces required services and security measures without requiring complex real-time configuration, thus ensuring service quality while reducing operational complexity
Solution Approach 2:
The mesh AP automatically uses its pre-configured access point profile to enforce service requirements and security policies without requiring manual intervention or complex configuration processes. The system self-configures based on stored policies, reducing configuration complexity while maintaining service quality assurance
Data Source
AI summary
A mesh access point that includes an access point profile storing one ore more parameters in non-volatile memory, and a method of using the mesh access point having the access point profile to select and carry out mutual authentication on a wireless mesh network to establish itself to the mesh network using information in the access point profile, and further to provide services to wireless clients according to information in the access point profile. Access point profiles can be pre-configured/configured/updated suitably in order to adapt the mesh access point in a mesh network according to its capabilities and requirements.


