Sub-group Encryption for Wireless Mesh Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless mesh networks do not facilitate secure messaging at the application-level between sub-groups of network nodes, leading to potential unauthorized access to intended communications.

Innovation Solution

A network system that generates a unique sub-group encryption key for designated nodes, allowing secure application-layer communication by encrypting messages within 'team packets' with identifiers for the sub-group, ensuring only authorized nodes can decrypt and process the messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If wireless mesh networks are used for network-level communication, then secure communication between all nodes is enabled, but application-level secure messaging between sub-groups of nodes is not facilitated

Engineering Contradiction:
Improvesecure communicationVSAvoidapplication-level messaging capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network communication into two distinct layers: network-level communication for general node-to-node messaging and application-level communication for secure sub-group messaging. This segmentation allows the system to maintain the existing wireless mesh network's secure communication capabilities while adding a new layer of application-specific secure messaging with sub-group encryption keys, thereby resolving the contradiction between maintaining network-level security and enabling application-level versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to the communication system by introducing application-level encryption that operates independently from the network-level encryption. This dimensional addition allows messages to be encrypted at multiple levels simultaneously, enabling both network-level secure communication and application-level sub-group messaging without interfering with each other, thus resolving the contradiction between security reliability and communication versatility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If sub-group encryption is implemented for application-level communication, then secure messaging between specific nodes is achieved, but additional encryption key management is required

Engineering Contradiction:
Improvemessage confidentialityVSAvoidencryption key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a message broker as an intermediary component that automatically manages the generation, distribution, and rotation of sub-group encryption keys. This intermediary handles the complex key management tasks transparently, allowing application nodes to focus on messaging while the broker ensures secure key distribution and rotation, thereby achieving message confidentiality without significantly increasing device complexity at the node level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service mechanisms where the message broker automatically generates encryption keys, distributes them to relevant sub-groups, and rotates keys without manual intervention. This automated self-service approach to key management reduces the operational burden and complexity that would otherwise be associated with manual key management, while maintaining strong message confidentiality through consistent encryption practices.

Inventive Principle:
Principle #25Self-service

3Reliability

If team packets with sub-group identifiers are used, then secure delivery to specific nodes is ensured, but packet structure complexity increases

Engineering Contradiction:
Improvesecure deliveryVSAvoidpacket structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested packet structure where the application-level message with sub-group encryption is nested within the standard wireless mesh network packet. The outer packet maintains the network-level addressing and routing information, while the inner packet contains the application-level message encrypted with sub-group keys. This nesting approach allows secure delivery to specific nodes through layered encryption without significantly increasing overall packet structure complexity, as each layer independently handles its own security requirements.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11212673B2Secure peer-to-peer communication over wireless mesh networks
Publication Date: 2021.12.28 LANDIS GYR TECH INC
  • US11212673B2 patent drawing
  • US11212673B2 patent drawing
  • US11212673B2 patent drawing

AI summary

Techniques for secure team-based communication on existing wireless mesh networks are disclosed. In an example, a first network node receives a network encryption key from a headend system. The first network node receives a sub-group encryption key that is unique to a sub-group of nodes, a sub-group identifier, and a sub-group node list that lists the sub-group of nodes associated with the sub-group identifier. The first network node generates an application layer message for a second node of the sub-group of nodes at an application layer. The first network node encrypts the application layer message using the sub-group encryption key. The first network node generates a team packet that is addressed to a selected node and includes the encrypted application layer message and the sub-group identifier. The first network node encrypts the team packet using the network encryption key and transmits the encrypted team packet to the selected node.