Scalable Ethernet Mesh Key Distribution via Segmented Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mesh networks, governed by IEEE 802.1X-2010, are limited to no more than 30 nodes, restricting the scalability of Ethernet-based mesh networks and limiting their ability to support large-scale peer devices for secure communication and authentication.

Innovation Solution

A large-scale Ethernet mesh network is developed, utilizing an authenticator module to authenticate and distribute a shared group encryption key to over 100 supplicant nodes, implementing modified protocols such as IEEE 802.1X-2010 control port state machine, MACsec Key Agreement, and a peer management module to enable secure key agreements and data exchange among a large number of peer devices, supporting jumbo frames for increased payload capacity and dynamic authentication timing adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional IEEE 802.1X-2010 mesh network protocol is used, then authentication and key distribution can be implemented, but the network is limited to no more than 30 nodes

Engineering Contradiction:
Improvenumber of nodesVSAvoidprotocol complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the key management function by introducing a dedicated key server that handles key generation and distribution separately from the authenticator that handles authentication. This separation allows the network to scale beyond 30 nodes by distributing key management responsibilities across multiple key servers, eliminating the node limit imposed by conventional protocols

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key server as an intermediary component between supplicants and the authentication system. This intermediary handles the complex key generation and distribution tasks, allowing the authenticator to focus solely on authentication. The key server mediates key agreements between multiple nodes without requiring direct peer-to-peer key exchange, enabling scalable mesh networks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If a single shared group encryption key is used for all supplicants, then secure communication can be established, but scalability is limited to 30 nodes

Engineering Contradiction:
Improvenumber of authenticated supplicantsVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent applies local quality by providing different cryptographic materials to different nodes based on their specific needs and roles. Each supplicant receives a unique cryptographic identity and can establish individual key agreements with the key server, while still participating in group communication. This localized key management maintains security for each node while enabling scalable network growth

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the cryptographic parameters by transitioning from a single shared group key to a hierarchical key structure where each node has unique cryptographic credentials. The system supports both group-wide key distribution and individual key agreements, dynamically adjusting key parameters based on communication requirements. This parameter flexibility enables secure communication among over 30 nodes

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If mesh networks dynamically self-organize and self-configure, then installation overhead is reduced and fault-tolerance is improved, but key management becomes more complex

Engineering Contradiction:
Improveinstallation overheadVSAvoidkey management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling supplicants to autonomously discover key servers and initiators through broadcast messages and automatic connection establishment. Nodes automatically perform key agreement protocols and configure their cryptographic settings without manual intervention. This self-configuration capability reduces installation overhead while the structured key server architecture manages the underlying complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by having key servers pre-generate and store cryptographic identities for supplicants before they join the network. When a supplicant connects, the key server already has the necessary cryptographic materials ready for immediate key agreement. This preliminary preparation eliminates complex real-time key generation and simplifies the join process, enabling dynamic network formation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11153078B2Extensible system for authenticated and protected key agreement in large mesh layer 2 ethernet networks
Publication Date: 2021.10.19 RAYTHEON CO
  • US11153078B2 patent drawing
  • US11153078B2 patent drawing
  • US11153078B2 patent drawing

AI summary

A large-scale Ethernet mesh network is provided, which includes a group connectivity association (CA) including at least thirty-one authenticated supplicant nodes. An authenticator module authenticates each of the authenticated supplicant nodes, and distributes a shared group encryption key to each of the authenticated supplicant nodes. Each of the authenticated supplicant nodes encrypt data using the shared group encryption key, and exchange the encrypted data with any other remaining authenticated supplicant node.