Wireless Mesh Node Onboarding Using Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing process for adding nodes to a wireless mesh network is cumbersome and insecure, often requiring backhaul communication and manual configuration, which complicates the addition of new nodes and exposes the network to security risks.

Innovation Solution

A certificate-based onboarding method is employed, where new nodes are authenticated using device certificates issued by a common Certificate Authority (CA) of the mesh service provider, allowing secure connection establishment without backhaul communication, and configuration information is transmitted via a secure connection from a cloud service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication is used for node addition, then security is improved, but device complexity increases due to certificate management requirements

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Device certificates are pre-installed on nodes before they are added to the mesh network. The certificates are provisioned in advance during manufacturing or initial setup, eliminating the need for complex real-time certificate issuance and management during node addition operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A cloud service acts as an intermediary to facilitate secure node addition. The cloud service receives node identification information, performs certificate-based authentication, and communicates with the main node to complete the addition process, thereby simplifying the authentication mechanism for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If backhaul communication is required for node addition, then centralized control is maintained, but the addition process becomes cumbersome and time-consuming

Engineering Contradiction:
Improvenode addition processVSAvoidnode addition time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The cloud service serves as a mediator that enables direct authentication between the new node and the mesh network without requiring lengthy backhaul communication sequences. The cloud service handles the authentication protocol and configuration transmission, significantly reducing the time and steps required for node addition.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Authentication credentials and network configuration information are prepared in advance by the cloud service before the actual node addition occurs. This preliminary preparation eliminates the need for real-time configuration exchanges and reduces the overall addition time.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If manual configuration is required for node addition, then network control is maintained, but the process becomes cumbersome and user-unfriendly

Engineering Contradiction:
Improvenode addition simplicityVSAvoidconfiguration process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The node addition process is designed to be self-service oriented. The new node automatically performs authentication using its pre-installed certificate, and the cloud service automatically provisions the necessary configuration information. Users only need to initiate the process by scanning a QR code or entering a simple identifier, eliminating the need for manual configuration steps.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cloud service acts as an automated intermediary that handles all complex configuration tasks. It receives minimal input from the user, performs certificate-based authentication, retrieves network configuration from the main node, and pushes settings to the new node automatically, thereby simplifying the user experience while maintaining network control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12526853B2Certificate-based addition of nodes to a wireless mesh network
Publication Date: 2026.01.13 PALO ALTO NETWORKS INC
  • US12526853B2 patent drawing
  • US12526853B2 patent drawing
  • US12526853B2 patent drawing

AI summary

A node being added to a wireless mesh network (“network”) identifies an available wireless network(s) for which WPA-Enterprise is deployed that is advertised by a “gateway node,” such as the network's main node. The new and main node have installed digital certificates that were issued by the mesh service provider. The node attempts to connect to the wireless network(s) using 802.1X authentication with its certificate. On successful network connection establishment, the node establishes a secure connection with an external service offered by the mesh service provider. Meanwhile, a user associated with the network scans a code attached to the node to initiate registration of the node for the user and network. The external service receives the encoded information, registers the node in association with the user and the network, and communicates a network configuration to the node over the secure connection. The node installs the configuration and is incorporated in the network as a satellite node.