Mesh Authenticator Key Hierarchy for Ad Hoc Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ad hoc wireless networks face challenges in establishing secure associations between mesh nodes efficiently, as existing solutions require extensive authentication processes, leading to bottlenecks and prolonged connection times, especially in scenarios where multiple nodes need to establish secure links quickly.
Innovation Solution
The implementation of a mesh authenticator mechanism that supports efficient security association establishment through a mesh key hierarchy, allowing supplicant mesh points to reuse key material generated during initial contact to establish secure links with other mesh nodes, utilizing a Pre-Shared Key (PSK) or IEEE 802.1X authentication with an AAA server, and employing layer 2 protocols for key distribution and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication processes are used to establish security associations between mesh nodes, then security is ensured, but the authentication time is prolonged and connection establishment is slow
Solution Approach 1:
The patent applies preliminary action by pre-distributing key material (PMK-MKD) to mesh points during initial network setup or previous connections. This pre-established key material allows supplicant mesh points to quickly authenticate with mesh authenticators without performing full authentication procedures each time, thus reducing authentication time while maintaining security through pre-configured cryptographic keys
Solution Approach 2:
The patent uses copying by distributing copies of the master session key (PMK-MKD) to multiple mesh points and mesh authenticators. Instead of requiring each node to independently generate and verify security credentials through time-consuming authentication protocols, the system creates and distributes cryptographic key copies that enable rapid mutual authentication while preserving security associations
2Reliability
If full authentication with an online authentication server is performed for each node joining the network, then secure key hierarchy is established, but the process takes ten seconds or more causing bottlenecks
Solution Approach 1:
The system performs preliminary authentication and key distribution by pre-establishing the PMK-MKD in the network infrastructure before nodes need to join. Mesh authenticators and mesh points receive and store this key material in advance, so when a supplicant mesh point needs to join, it can quickly present its credentials against the pre-configured key hierarchy without initiating a full ten-second authentication sequence with an online server
Solution Approach 2:
The patent extracts the authentication server dependency by implementing a distributed key hierarchy where mesh authenticators locally verify supplicants using pre-distributed PMK-MKD values. This removes the bottleneck of centralized online authentication server communication, allowing nodes to join rapidly through local cryptographic verification while maintaining the integrity of the key hierarchy structure
3Reliability
If multiple mesh nodes establish secure links simultaneously, then comprehensive network security is achieved, but the extensive authentication processes create bottlenecks
Solution Approach 1:
The patent enables multiple simultaneous secure link establishments by distributing copies of the PMK-MKD to numerous mesh points and authenticators across the network. Each mesh point holds a copy of the master session key, allowing any supplicant to quickly authenticate with any mesh authenticator using locally-available cryptographic materials, thus supporting parallel connection establishment without centralized bottlenecks while maintaining comprehensive network security through consistent key hierarchy verification
Data Source
Figure 1~2
Figure 3~4B
Figure 5
AI summary
A method and apparatus for establishing security associations between nodes of an ad hoc wireless network includes two authentication steps: an initial first contact step (authentication, authorization, and accounting (AAA)-based authentication), and a "light-weight" step that reuses key material generated during first contact. A mesh authenticator within the network provides two roles. The first role is to implement an 802.1X port access entity (PAE), derive transient keys used for encryption with a supplicant mesh point via a four-way handshake and take care of back end communications with a key distributor. The second role is as a key distributor that implements a AAA-client and derives keys used to authenticate a mesh point during first contact or fast security association. The key distributor and the on-line authentication server can communicate to one another without these messages being transported over mesh links.