Self-Organizing Mesh Network Authentication for Mobile Peers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional RFID-based physical security access management systems are vulnerable to attacks like piggybacking and tailgating due to non-private and static ID numbers, which can be spoofed, and social engineering techniques can bypass security checks at fixed points of entry.

Innovation Solution

A self-organizing mobile peer-to-peer mesh network authentication system where authentication devices form a network that challenges peers for identity and permissions, using wireless communication and cryptographic methods to maintain robust security and prevent single-point failures, allowing for mobile and dispersed checkpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional RFID badges with static ID numbers are used for access control, then the system is simple to operate and implement, but the security is weak because ID numbers can be spoofed and the system is vulnerable to piggybacking and tailgating attacks

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static RFID ID numbers into dynamic cryptographic credentials that change with each authentication event. The authentication devices perform cryptographic challenges and responses, generating unique proof tokens for each access attempt, making credential theft and spoofing ineffective.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces cryptographic protocols as intermediaries between the authentication device and the access control system. Instead of directly transmitting static ID numbers, the system uses cryptographic challenge-response mechanisms that mediate the authentication process, preventing direct credential capture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If fixed point of entry checkpoints are used for authentication, then the authentication process is centralized and simple to manage, but the system is vulnerable to social engineering attacks and attackers can bypass security at unmonitored points

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized authentication system into distributed peer-to-peer authentication nodes. Each authentication device becomes an independent security checkpoint that can verify credentials locally, eliminating single points of failure and enabling security coverage at multiple locations simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a spatial dimension to authentication by enabling mobile, dispersed checkpoints rather than fixed locations. Authentication devices can move freely and create security perimeters dynamically, adding the dimension of mobility and spatial flexibility to the authentication architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If RFID badges use non-private ID numbers for identification, then the authentication process is fast and simple, but the system allows attackers to listen in and capture ID numbers for spoofing

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic cryptographic challenges where authentication devices exchange time-sensitive tokens rather than static IDs. Each authentication requires a fresh cryptographic proof generated at the moment of authentication, preventing replay attacks while maintaining speed through optimized cryptographic operations.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11025439B2Self-organizing mobile peer-to-peer mesh network authentication
Publication Date: 2021.06.01 RAYTHEON CO
  • US11025439B2 patent drawing
  • US11025439B2 patent drawing
  • US11025439B2 patent drawing

AI summary

A plurality of authentication devices form and manage a self-organizing mobile peer-to-peer mesh network to provide robust authentication of mobile peers, humans and or mobile devices such as drones, cars, satellites, robots etc. The mesh network may supplement traditional fixed point of entry authentication to combat social engineering penetrations or be used in situations where fixed-point authentication is not viable. Network efficiency can be enhanced by using two-level encryption, a first level of encryption based on permissions to join a mesh network and a simpler second level of encryption based on knowledge shared with members of the network for communication. Making the permissions a function of location can make the network more robust. Re-authenticating member peers based on the occurrence of defined events can further enhance security.