Wireless Mesh Access Point Provisioning via Identity-Based Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The initial provision and configuration of mesh access points (APs) in wireless mesh networks are challenging due to the lack of a wired uplink and the need for secure communication channels, which are often time-consuming and insecure.

Innovation Solution

Implementing identity-based encryption (IBE) techniques allows for secure and zero-message-exchange provisioning of mesh APs, using a group encryption key to encrypt configuration messages that can be sent to multiple APs concurrently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional provisioning methods are used to establish secure communication channels between mesh APs and NMS, then security can be achieved, but the provisioning process becomes time-consuming and complex

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-distributing public keys to mesh APs during manufacturing before deployment. This allows the APs to immediately encrypt provisioning messages without requiring time-consuming key exchange protocols during the provisioning process, thus achieving both security and time efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a proxy device as an intermediary with a pre-established secure channel to the NMS. The proxy forwards provisioning messages to APs, eliminating the need for direct secure channel establishment between each AP and NMS, thereby reducing provisioning time while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If wired uplink is used for initial provisioning of mesh APs, then secure configuration can be achieved, but the process becomes cumbersome and difficult to deploy

Engineering Contradiction:
Improveconfiguration securityVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical wired connection system with a wireless communication system. By using pre-distributed public keys for message encryption, the system achieves secure configuration transmission over wireless channels without requiring physical cable connections, thus improving deployment ease while maintaining configuration security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If unsecure wireless channels are used for initial provisioning, then deployment ease is improved, but security risks increase

Engineering Contradiction:
Improvedeployment easeVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-distributing public keys to mesh APs during manufacturing before deployment. This allows the APs to immediately encrypt provisioning messages without requiring time-consuming key exchange protocols during the provisioning process, thus achieving both security and time efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical wired connection system with a wireless communication system. By using pre-distributed public keys for message encryption, the system achieves secure configuration transmission over wireless channels without requiring physical cable connections, thus improving deployment ease while maintaining configuration security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If individual key exchange is performed for each mesh AP, then security is maintained, but the provisioning process becomes complex and time-consuming

Engineering Contradiction:
Improvecommunication securityVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the key exchange process by pre-distributing public keys to all APs during manufacturing. This eliminates the need for individual key exchange protocols for each AP, reducing provisioning complexity while maintaining security through the use of these pre-established keys for message encryption

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The pre-distributed public keys serve multiple functions: they enable secure provisioning message encryption, facilitate authentication, and work across all APs in the network. This universal application of pre-distributed keys simplifies the overall provisioning system while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12323790B2Secure zero-exchange provision system for wireless mesh access points
Publication Date: 2025.06.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12323790B2 patent drawing
  • US12323790B2 patent drawing
  • US12323790B2 patent drawing

AI summary

One aspect provides a system and method for provisioning an access point (AP) in a wireless mesh network. During operation, a controller can obtain a set of published global encryption parameters comprising a master public key, apply an identity-based encryption (IBE) scheme to encrypt a configuration message based at least on the master public key, and transmit the encrypted configuration message to a proxy device, which forwards the encrypted configuration message to the AP. The proxy device is coupled to the controller via a previously established secure communication channel and coupled to the AP via an open communication channel. The AP can decrypt the encrypted configuration message using an AP-specific secret key generated based on a unique identifier of the AP and a master private key corresponding to the master public key, thereby facilitating provisioning of the AP based on the configuration message.