Provisioner Node Pre-Encryption for Mesh Network Friendship Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless mesh networks, the establishment of secure connections between nodes is compromised by the risk of 'false friend' nodes intercepting and relaying messages, leading to power consumption issues and potential node malfunction due to unauthorized control.

Innovation Solution

A method involving a provisioner node generating a random value encrypted with device-specific keys for each node, used to create a friendship-specific encryption key, ensuring only authorized nodes can communicate securely and preventing false friend scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If nodes in a wireless mesh network establish connections using traditional friendship key generation, then network connectivity is achieved, but security is compromised due to false friend nodes intercepting and relaying messages

Engineering Contradiction:
Improveconnection securityVSAvoidfalse friend attack
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by having the provisioner node pre-generate and distribute encrypted friendship key material to nodes before actual communication occurs. The provisioner encrypts the friendship key with each node's device-specific encryption key and stores it securely. When nodes need to establish a connection, they already possess the encrypted key material, eliminating the need for insecure key exchange during runtime and preventing false friend attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the provisioner node as an intermediary to securely distribute friendship keys. Instead of nodes directly exchanging key material (which would be vulnerable to interception), the provisioner acts as a trusted mediator that encrypts and distributes the friendship key to each node individually using their device-specific encryption keys. This intermediary approach ensures that only the intended nodes can decrypt and use the friendship key.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If nodes continuously monitor and verify connection authenticity, then security against false friends is improved, but power consumption increases

Engineering Contradiction:
Improveconnection authenticityVSAvoidnode power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs the security verification action in advance by having the provisioner node pre-encrypt and distribute the friendship key to nodes during the provisioning phase. Once nodes have the encrypted friendship key stored securely, they can immediately use it for encrypted communication without needing to perform continuous verification operations. This preliminary setup eliminates ongoing power-consuming monitoring while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If device-specific encryption keys are used for friendship key generation, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improveencryption securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses the provisioner node as an intermediary to manage the complexity of device-specific encryption keys. The provisioner handles the generation and distribution of encrypted friendship keys to each node, abstracting away the complex key management operations from the end nodes. Nodes simply receive and store the pre-encrypted friendship key material, significantly reducing their operational complexity while still benefiting from strong security based on device-specific encryption keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11166156B2Secure friendship establishment in a mesh network
Publication Date: 2021.11.02 QUALCOMM INC
  • US11166156B2 patent drawing
  • US11166156B2 patent drawing
  • US11166156B2 patent drawing

AI summary

Disclosed are techniques for establishing an encrypted connection between a first node and a second node in a wireless mesh network. In an aspect, the first node receives, from a provisioner node in the wireless mesh network, a first value encrypted with a device-specific encryption key known only to the first node and the provisioner node, wherein the second node receives, from the provisioner node, the first value encrypted with a second device-specific encryption key, generates a friendship-specific encryption key based on the first value, an identifier of the first node, and an identifier of the second node, wherein the second node generates the friendship-specific encryption key, sends, to the second node, a first message encrypted with the friendship-specific encryption key, and receives, from the second node, a second message encrypted with the friendship-specific encryption key.