Wireless Mesh Network Security via Type of Protection Values

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security mechanisms in wireless mesh networks are inadequate for protecting against internal attacks and data manipulation, particularly in multi-hop environments, as they rely on complex and costly key management systems that fail to prevent selective forwarding and routing disruptions.

Innovation Solution

The implementation of differentiated confidence levels, denoted by Type of Protection (ToP) values, which are embedded in data packets and used to control routing, ensuring that only nodes with matching or higher confidence levels can process and forward data, thereby reducing internal attacks and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If group keys are used for encrypting data traffic between nodes, then protection against eavesdropping is improved, but protection against data alteration by internal attackers deteriorates due to multi-hop data forwarding

Engineering Contradiction:
Improveprotection against eavesdroppingVSAvoidprotection against data alteration
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent segments the security protection into two independent layers: group keys for encrypting data traffic to prevent eavesdropping, and individual cryptographic signatures for each data packet to prevent alteration. This segmentation allows each mechanism to address its specific security concern without compromising the other, resolving the contradiction between eavesdropping protection and data integrity in multi-hop environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite security mechanism by combining group key encryption with individual digital signatures. The group key provides confidentiality for multi-hop transmission, while the digital signature provides integrity verification at each hop. This composite approach leverages the strengths of both mechanisms to simultaneously achieve both protection goals.

Inventive Principle:
Principle #40Composite materials

2Reliability

If different keys in pairs are used for security, then protection against internal attackers is improved, but device complexity and cost increase significantly

Engineering Contradiction:
Improveprotection against internal attackersVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the integrity verification function from the key management system and implements it through digital signatures attached to individual data packets. This extraction eliminates the need for complex pairwise key management between nodes, as each node only needs its own private key and the public keys of other nodes for verification, significantly simplifying the key management infrastructure while maintaining protection against internal attackers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Each node generates and manages its own cryptographic key pair independently, and includes its own digital signature on each data packet it forwards. This self-service approach eliminates the need for a centralized key distribution system or complex pairwise key negotiation, reducing overall system complexity while ensuring each node can verify the authenticity of packets it receives.

Inventive Principle:
Principle #25Self-service

3Reliability

If existing security mechanisms are implemented in mesh networks, then authentication is improved, but protection against routing disruptions and selective forwarding deteriorates

Engineering Contradiction:
ImproveauthenticationVSAvoidprotection against routing disruptions
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by including a digital signature from the original source node on each data packet that travels through the mesh network. Each intermediate node can verify this signature to confirm the packet's authenticity and intended routing. If a node attempts selective forwarding or routing disruption, the verification fails and the packet is rejected, providing continuous feedback that prevents such attacks while maintaining authentication.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The source node performs preliminary action by digitally signing the data packet before it enters the mesh network. This pre-established authentication marker travels with the packet through all intermediate nodes, enabling them to verify the packet's legitimacy and intended routing path without requiring complex real-time authentication negotiations, thus preventing routing disruptions before they can occur.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8473736B2Method for making security mechanisms available in wireless mesh networks
Publication Date: 2013.06.25 UNIFY BETEILIGUNGSVERWALTUNG GMBH & CO KG
  • US8473736B2 patent drawing
  • US8473736B2 patent drawing
  • US8473736B2 patent drawing

AI summary

A method for making safety mechanisms available in wireless mesh networks which have a plurality of nodes that are interconnected by multi-hop communication in a wireless network meshed by mesh routing in the MAC layer, every node being active as a router to forward the data traffic of the other nodes. At least two differentiated levels of confidence are defined by a type of protection (ToP) the value of which represents a specific level of confidence for the nodes and data packets, the data packets being labeled with a ToP value in the mesh header, and at least one ToP value being allocated to the participating nodes, the nodes forwarding the data packet in the mesh network using the ToP values of the node and of the data packet if this ToP value combination is admissible in the node.