Wireless Mesh Node Authentication via Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless mesh networks, new nodes setting up links with neighbors initially lack connectivity to an infrastructure network and authentication servers, leading to increased load on the authentication server and inefficiencies in authentication processes.

Innovation Solution

A method where a first communications device acts as an authenticator to communicate with an AAA server for a second device, generating basic encryption information, allowing subsequent EAP procedures to occur without initial AAA server connection, using derived encryption keys for secure communication and policy implementation within the mesh network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If new nodes perform authentication with AAA server before setting up mesh links, then authentication security is ensured, but network setup complexity increases and server load increases

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork setup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the first node perform authentication with the AAA server before establishing mesh links with other nodes. This ensures that authentication security is established in advance, allowing subsequent EAP procedures to occur without requiring prior security material configuration on nodes without AAA server connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach where the first node acts as a mediator between the AAA server and other mesh nodes. The first node receives encryption information from the AAA server and facilitates subsequent authentication procedures with other nodes, reducing the need for direct AAA server connections from all nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If AAA server is replicated on each node for independent authentication, then authentication independence is improved, but server load increases and scalability decreases

Engineering Contradiction:
Improveauthentication independenceVSAvoidserver load and scalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies segmentation by dividing the authentication function into two parts: centralized authentication with the AAA server for security management, and localized EAP procedures for actual authentication. This allows authentication independence at the node level while maintaining centralized control, thereby reducing server load and improving scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service by enabling nodes to perform authentication procedures independently using encryption information received from the AAA server. Nodes can authenticate with each other without requiring continuous AAA server connection, making the system more scalable and reducing server load.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If security material is configured on nodes without AAA server connections, then mesh network flexibility is improved, but authentication reliability decreases

Engineering Contradiction:
Improvemesh network flexibilityVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by having nodes receive and store encryption information from the AAA server before establishing mesh links. This preliminary configuration of security material allows nodes to perform authentication independently while maintaining authentication reliability through the use of securely obtained encryption keys.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8495360B2Method and arrangement for providing a wireless mesh network
Publication Date: 2013.07.23 UNIFY BETEILIGUNGSVERWALTUNG GMBH & CO KG
  • US8495360B2 patent drawing
  • US8495360B2 patent drawing
  • US8495360B2 patent drawing

AI summary

A method and an arrangement are provided wherein a newly added mesh node does not require a link to the AAA server for the purpose of authentication. Authentication is carried out using a node which is already present in the mesh network and which has a link to the AAA server.