Wireless Mesh Access Point Provisioning via Identity-Based Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The initial provision and configuration of mesh access points (APs) in wireless mesh networks are challenging due to the lack of a wired uplink and the need for secure communication channels, which are often time-consuming and insecure.
Innovation Solution
Implementing identity-based encryption (IBE) techniques allows for secure and zero-message-exchange provisioning of mesh APs, using a group encryption key to encrypt configuration messages that can be sent to multiple APs concurrently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional provisioning methods are used to establish secure communication channels between mesh APs and NMS, then security can be achieved, but the provisioning process becomes time-consuming and complex
Solution Approach 1:
The patent applies preliminary action by pre-distributing public keys to mesh APs during manufacturing before deployment. This allows the APs to immediately encrypt provisioning messages without requiring time-consuming key exchange protocols during the provisioning process, thus achieving both security and time efficiency
Solution Approach 2:
The patent uses a proxy device as an intermediary with a pre-established secure channel to the NMS. The proxy forwards provisioning messages to APs, eliminating the need for direct secure channel establishment between each AP and NMS, thereby reducing provisioning time while maintaining security
2Reliability
If wired uplink is used for initial provisioning of mesh APs, then secure configuration can be achieved, but the process becomes cumbersome and difficult to deploy
Solution Approach 1:
The patent replaces the mechanical wired connection system with a wireless communication system. By using pre-distributed public keys for message encryption, the system achieves secure configuration transmission over wireless channels without requiring physical cable connections, thus improving deployment ease while maintaining configuration security
3Ease of operation
If unsecure wireless channels are used for initial provisioning, then deployment ease is improved, but security risks increase
Solution Approach 1:
The patent applies preliminary action by pre-distributing public keys to mesh APs during manufacturing before deployment. This allows the APs to immediately encrypt provisioning messages without requiring time-consuming key exchange protocols during the provisioning process, thus achieving both security and time efficiency
Solution Approach 2:
The patent replaces the mechanical wired connection system with a wireless communication system. By using pre-distributed public keys for message encryption, the system achieves secure configuration transmission over wireless channels without requiring physical cable connections, thus improving deployment ease while maintaining configuration security
4Reliability
If individual key exchange is performed for each mesh AP, then security is maintained, but the provisioning process becomes complex and time-consuming
Solution Approach 1:
The patent merges the key exchange process by pre-distributing public keys to all APs during manufacturing. This eliminates the need for individual key exchange protocols for each AP, reducing provisioning complexity while maintaining security through the use of these pre-established keys for message encryption
Solution Approach 2:
The pre-distributed public keys serve multiple functions: they enable secure provisioning message encryption, facilitate authentication, and work across all APs in the network. This universal application of pre-distributed keys simplifies the overall provisioning system while maintaining security
Data Source
AI summary
One aspect provides a system and method for provisioning an access point (AP) in a wireless mesh network. During operation, a controller can obtain a set of published global encryption parameters comprising a master public key, apply an identity-based encryption (IBE) scheme to encrypt a configuration message based at least on the master public key, and transmit the encrypted configuration message to a proxy device, which forwards the encrypted configuration message to the AP. The proxy device is coupled to the controller via a previously established secure communication channel and coupled to the AP via an open communication channel. The AP can decrypt the encrypted configuration message using an AP-specific secret key generated based on a unique identifier of the AP and a master private key corresponding to the master public key, thereby facilitating provisioning of the AP based on the configuration message.


