Wireless Mesh Data Transmission Without Intermediate Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless mesh networks face challenges in efficiently securing data transmissions as intermediate access points often decrypt and re-encrypt data packets, leading to increased latency and resource utilization, especially during roaming scenarios.
Innovation Solution
Implementing end-to-end encryption between a central access point and a station within a wireless mesh network, encapsulating data packets within multiple links, and assigning end-to-end packet numbers or sequence numbers to maintain encryption across multiple hops without intermediate decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If intermediate access points decrypt and re-encrypt data packets during transmission in a wireless mesh network, then data security is maintained at each hop, but communication latency increases and power consumption rises
Solution Approach 1:
The patent segments the encryption function by designating a specific central access point as the sole encryption/decryption node, while other intermediate access points function only as transparent relays. This segmentation eliminates redundant decryption/re-encryption operations at intermediate nodes, reducing latency while maintaining security through the centralized encryption architecture.
Solution Approach 2:
The patent introduces an intermediary role for the central access point that maintains encryption throughout the mesh network path. Instead of each intermediate access point performing decryption, the central access point acts as the intermediary that establishes and maintains the encrypted tunnel, allowing data to pass through intermediate nodes without decryption.
2Reliability
If intermediate access points decrypt and re-encrypt data packets, then security is ensured at each hop, but resource utilization and power consumption increase
Solution Approach 1:
The patent segments the computationally intensive encryption function from the relay function. Only the central access point performs encryption/decryption operations, while intermediate access points perform only simple packet forwarding. This segmentation dramatically reduces power consumption at intermediate nodes while maintaining end-to-end security through the centralized encryption approach.
3Area of stationary object
If data packets are transmitted through multiple access points in a mesh network, then coverage area is extended, but maintaining encryption across multiple hops becomes complex
Solution Approach 1:
The patent uses the central access point as an intermediary that establishes a single encryption context that spans multiple hops. Intermediate access points simply forward encrypted packets without needing to understand or participate in the encryption process, thereby extending coverage while keeping encryption complexity confined to the central node only.
Solution Approach 2:
The patent extracts the encryption functionality from the intermediate access points and concentrates it solely at the central access point. This extraction simplifies the overall system by removing encryption complexity from multiple nodes, leaving only simple packet forwarding at intermediate points while maintaining secure extended coverage.
Data Source
AI summary
This disclosure provides methods, components, devices and systems for end-to-end encrypted transmissions in a wireless mesh network. Some aspects more specifically relate to communications between one or more access points (APs) and one or more stations (STAs) in a wireless mesh network. In some examples, the wireless mesh network may include a central AP (CAP) that communicates with one or more other APs via one or more links. In the wireless mesh network, user data may be transmitted to a STA via data packets that are encrypted per link. In some implementations, the data packets may be end-to-end encrypted between the CAP and the STA and assigned end-to-end packet numbers and end-to-end sequence number. Thus, a first data packet may be encapsulated within one or more second data packets such that one or more intermediate APs may refrain from decrypting the first data packet.


