Mesh Network Personal Pre-Shared Keys for Stranded Device Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless mesh networks, updating the pre-shared key (PSK) can lead to electronic devices being stranded if they do not receive the updated key due to issues like power failures, interference, or hacker attacks, resulting in communication disruptions and increased operational costs.

Innovation Solution

Electronic devices establish personal pre-shared keys (PPSKs) with each other, allowing them to maintain encrypted communication using a backup key if the primary PSK fails, ensuring continuous connectivity and improving network reliability and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single pre-shared key (PSK) is used for encrypted communication in a mesh network, then network security is maintained through centralized key management, but communication reliability deteriorates when devices fail to receive updated keys due to power failures, interference, or attacks

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the single network PSK into multiple device-specific PPSKs. Each electronic device generates its own unique PPSK that is shared only with its communication partner, rather than relying on a single centralized PSK. This segmentation allows individual devices to maintain communication independently if the centralized key distribution fails, thereby improving reliability without significantly increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by having electronic devices exchange and store PPSKs in advance during the provisioning phase, before actual communication begins. This pre-exchange ensures that devices have backup authentication credentials ready, so if centralized PSK updates fail, devices can immediately fall back to using their pre-established PPSKs without interruption to communication reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If centralized PSK updates are implemented in a mesh network, then network security is improved through key rotation, but operational costs increase due to site visits required when devices become stranded with outdated keys

Engineering Contradiction:
Improvenetwork uptimeVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service by allowing electronic devices to autonomously establish encrypted communication using their device-specific PPSKs without requiring centralized key distribution or manual intervention. When devices need to communicate, they independently authenticate using their pre-shared PPSKs, eliminating the need for operator site visits to recover stranded devices and reducing operational costs while maintaining high network uptime.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by pre-configuring devices with PPSKs during provisioning, so that devices have backup authentication credentials ready before communication begins. This pre-preparedness ensures that if centralized PSK updates fail or devices become stranded, they can immediately fall back to PPSK-based authentication without requiring operator intervention, thereby maintaining network uptime and reducing operational costs.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If device-specific personal pre-shared keys (PPSKs) are exchanged between pairs of electronic devices, then communication reliability is improved through backup authentication, but the provisioning process becomes more complex

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach where a controller or access point facilitates the PPSK exchange between device pairs during provisioning. The intermediary generates or distributes PPSKs to appropriate devices and coordinates the key exchange process, simplifying the provisioning complexity while still enabling reliable backup authentication. This intermediary management prevents devices from having to independently manage complex key exchange protocols, thereby reducing provisioning complexity while maintaining communication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9774580B2Mesh network with personal pre-shared keys
Publication Date: 2017.09.26 RUCKUS IP HOLDINGS LLC
  • US9774580B2 patent drawing
  • US9774580B2 patent drawing
  • US9774580B2 patent drawing

AI summary

A mesh network with a network-wide pre-shared key (PSK) that can be updated is described. The PSK can be used to establish secure communication between arbitrary electronic devices in the mesh network. In order to prevent electronic devices from being inadvertently ‘stranded,’ i.e., unable to securely communicate with other electronic devices in the mesh network when the PSK is updated, pairs of electronic devices in the mesh network establish personal PSKs (PPSKs). In particular, after securely associating with each other, a given pair of electronic devices may have used the current PSK to authenticate and encrypt their communication. Then, the given pair of electronic devices may define a PPSK, e.g., by exchanging one or more random numbers. If a subsequent attempt at establishing secure or encrypted communication between the given pair of electronic devices fails, these electronic devices may use the PPSK as a backup to establish the encrypted communication.