Secure Key Loading via Configuration Device in Wireless Mesh Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless mesh networks face challenges in securely loading cryptographic material, such as encryption keys, into devices during the joining process, as manual loading is prone to errors and wireless communication can be insecure, risking exposure to nearby devices.

Innovation Solution

A configuration device provides a secure communication path using a shielded antenna or temporary wired connection to load cryptographic material from a security manager to new devices, ensuring secure and error-free key loading.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic material is loaded manually into devices, then human error occurs and security is compromised, but automated wireless loading exposes keys to nearby devices

Engineering Contradiction:
ImprovesecurityVSAvoidkey exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A configuration device serves as an intermediary between the security manager and the wireless device during key loading. The configuration device establishes a secure communication path that prevents direct exposure of cryptographic material to nearby devices while enabling automated loading, thus resolving the contradiction between security reliability and key exposure risk

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key loading process is segmented into distinct phases: secure path establishment, authentication, and key transfer. This segmentation allows the system to maintain security controls at each stage while enabling automated operation, addressing both the reliability and security concerns

Inventive Principle:
Principle #1Segmentation

2Reliability

If a secure communication path is established using a configuration device, then key loading security is improved, but device complexity increases

Engineering Contradiction:
Improvekey loading securityVSAvoidconfiguration device requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The configuration device is designed to perform multiple functions: establishing secure communication paths, authenticating devices, and transferring cryptographic material. This multi-functionality reduces the need for separate specialized devices, thereby mitigating the increase in system complexity while maintaining high security standards

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated key loading is implemented, then productivity is improved, but security risks increase due to wireless exposure

Engineering Contradiction:
Improvekey loading efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The configuration device establishes a secure communication path and performs authentication before any cryptographic material is transferred. This preliminary action ensures that the automated process maintains security controls from the outset, enabling high productivity without compromising security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10153898B2Wireless mesh network with secure automatic key loads to wireless devices
Publication Date: 2018.12.11 ROSEMOUNT INC
  • US10153898B2 patent drawing
  • US10153898B2 patent drawing
  • US10153898B2 patent drawing

AI summary

A wireless mesh network provides secure communication by encrypting data using one or more encryption keys. A configuration device in communication with a security manager of the network provides a temporary secure communication path between the security manager and a new field device to be added to the mesh network. Cryptographic material and other configuration data can then be transferred between the security manager of the network and the new field device securely via the configuration device.