Mesh Network Security Threat Detection via Monitoring Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless mesh networks are vulnerable to security threats such as Man-in-the-Middle attacks and data corruption due to the lack of robust security measures, particularly during the provisioning process and within the network, which can compromise the network key and lead to denial of service or unauthorized access.

Innovation Solution

A monitoring device is introduced into the mesh network to continuously monitor and analyze traffic, detect corrupted messages, and identify security threats by sniffing all messages and analyzing patterns, allowing for real-time threat detection and mitigation, including the removal of attacker nodes and key refresh procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a mesh network is implemented to extend communication range and provide multiple routing paths, then network reliability and coverage are improved, but security vulnerability increases due to the distributed nature of the network

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A monitoring device is introduced as an intermediary component within the mesh network that specifically monitors communication between nodes. This device collects information from messages passing through it and analyzes patterns to detect security threats such as man-in-the-middle attacks and data corruption, thereby addressing the security vulnerability while preserving the network's distributed reliability benefits

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring device implements continuous monitoring and analysis of network traffic patterns, providing feedback about security threats to the network. When corrupted messages or suspicious patterns are detected, the system can respond by alerting administrators or taking mitigation actions, creating a feedback loop that enhances security without compromising the mesh network's inherent reliability

Inventive Principle:
Principle #23Feedback

2Difficulty of detecting and measuring

If continuous monitoring and analysis of network traffic is performed to detect security threats, then security detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidmonitoring device complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The monitoring function is extracted as a separate, dedicated component within the mesh network. Rather than requiring every node to perform complex analysis, the monitoring device is isolated to perform these functions centrally, collecting information from messages and analyzing patterns without adding complexity to each individual network node

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The monitoring device creates a copy of network traffic information for analysis purposes. By collecting and analyzing copies of messages rather than intercepting and modifying actual communication, the system achieves enhanced detection capability while maintaining network operation simplicity and avoiding excessive complexity in the monitoring infrastructure

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3888317B1Detection of security threats in a mesh network
Publication Date: 2024.05.01 QUALCOMM INC
  • EP3888317B1 patent drawingFigure 1
  • EP3888317B1 patent drawingFigure 2
  • EP3888317B1 patent drawingFigure 3

AI summary

Disclosed are techniques for detecting a security threat in a wireless mesh network. In an aspect, a monitoring device in the wireless mesh network detects a first message transmitted by a source node in the wireless mesh network to a destination node in the wireless mesh network via at least one relay node in the wireless mesh network, collects information from the first message as it is transmitted in the wireless mesh network, determines that the first message has been corrupted based on analysis of the information from the first message, and detects the security threat in the wireless mesh network based on the first message being corrupted.