Wireless Mesh Node Authentication via Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless mesh networks, new nodes setting up links with neighbors initially lack connectivity to an infrastructure network and authentication servers, leading to increased load on the authentication server and inefficiencies in authentication processes.
Innovation Solution
A method where a first communications device acts as an authenticator to communicate with an AAA server for a second device, generating basic encryption information, allowing subsequent EAP procedures to occur without initial AAA server connection, using derived encryption keys for secure communication and policy implementation within the mesh network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If new nodes perform authentication with AAA server before setting up mesh links, then authentication security is ensured, but network setup complexity increases and server load increases
Solution Approach 1:
The patent applies preliminary action by having the first node perform authentication with the AAA server before establishing mesh links with other nodes. This ensures that authentication security is established in advance, allowing subsequent EAP procedures to occur without requiring prior security material configuration on nodes without AAA server connections.
Solution Approach 2:
The patent uses an intermediary approach where the first node acts as a mediator between the AAA server and other mesh nodes. The first node receives encryption information from the AAA server and facilitates subsequent authentication procedures with other nodes, reducing the need for direct AAA server connections from all nodes.
2Adaptability or versatility
If AAA server is replicated on each node for independent authentication, then authentication independence is improved, but server load increases and scalability decreases
Solution Approach 1:
The patent applies segmentation by dividing the authentication function into two parts: centralized authentication with the AAA server for security management, and localized EAP procedures for actual authentication. This allows authentication independence at the node level while maintaining centralized control, thereby reducing server load and improving scalability.
Solution Approach 2:
The patent implements self-service by enabling nodes to perform authentication procedures independently using encryption information received from the AAA server. Nodes can authenticate with each other without requiring continuous AAA server connection, making the system more scalable and reducing server load.
3Adaptability or versatility
If security material is configured on nodes without AAA server connections, then mesh network flexibility is improved, but authentication reliability decreases
Solution Approach 1:
The patent applies preliminary action by having nodes receive and store encryption information from the AAA server before establishing mesh links. This preliminary configuration of security material allows nodes to perform authentication independently while maintaining authentication reliability through the use of securely obtained encryption keys.
Data Source
AI summary
A method and an arrangement are provided wherein a newly added mesh node does not require a link to the AAA server for the purpose of authentication. Authentication is carried out using a node which is already present in the mesh network and which has a link to the AAA server.


