Wireless Mesh Node Onboarding Using Certificate Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing process for adding nodes to a wireless mesh network is cumbersome and insecure, often requiring backhaul communication and manual configuration, which complicates the addition of new nodes and exposes the network to security risks.
Innovation Solution
A certificate-based onboarding method is employed, where new nodes are authenticated using device certificates issued by a common Certificate Authority (CA) of the mesh service provider, allowing secure connection establishment without backhaul communication, and configuration information is transmitted via a secure connection from a cloud service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication is used for node addition, then security is improved, but device complexity increases due to certificate management requirements
Solution Approach 1:
Device certificates are pre-installed on nodes before they are added to the mesh network. The certificates are provisioned in advance during manufacturing or initial setup, eliminating the need for complex real-time certificate issuance and management during node addition operations.
Solution Approach 2:
A cloud service acts as an intermediary to facilitate secure node addition. The cloud service receives node identification information, performs certificate-based authentication, and communicates with the main node to complete the addition process, thereby simplifying the authentication mechanism for end users.
2Ease of operation
If backhaul communication is required for node addition, then centralized control is maintained, but the addition process becomes cumbersome and time-consuming
Solution Approach 1:
The cloud service serves as a mediator that enables direct authentication between the new node and the mesh network without requiring lengthy backhaul communication sequences. The cloud service handles the authentication protocol and configuration transmission, significantly reducing the time and steps required for node addition.
Solution Approach 2:
Authentication credentials and network configuration information are prepared in advance by the cloud service before the actual node addition occurs. This preliminary preparation eliminates the need for real-time configuration exchanges and reduces the overall addition time.
3Ease of operation
If manual configuration is required for node addition, then network control is maintained, but the process becomes cumbersome and user-unfriendly
Solution Approach 1:
The node addition process is designed to be self-service oriented. The new node automatically performs authentication using its pre-installed certificate, and the cloud service automatically provisions the necessary configuration information. Users only need to initiate the process by scanning a QR code or entering a simple identifier, eliminating the need for manual configuration steps.
Solution Approach 2:
The cloud service acts as an automated intermediary that handles all complex configuration tasks. It receives minimal input from the user, performs certificate-based authentication, retrieves network configuration from the main node, and pushes settings to the new node automatically, thereby simplifying the user experience while maintaining network control.
Data Source
AI summary
A node being added to a wireless mesh network (“network”) identifies an available wireless network(s) for which WPA-Enterprise is deployed that is advertised by a “gateway node,” such as the network's main node. The new and main node have installed digital certificates that were issued by the mesh service provider. The node attempts to connect to the wireless network(s) using 802.1X authentication with its certificate. On successful network connection establishment, the node establishes a secure connection with an external service offered by the mesh service provider. Meanwhile, a user associated with the network scans a code attached to the node to initiate registration of the node for the user and network. The external service receives the encoded information, registers the node in association with the user and the network, and communicates a network configuration to the node over the secure connection. The node installs the configuration and is incorporated in the network as a satellite node.


