Multi-Hop Network Authentication Using Proxy Agent Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The authentication of newly joined nodes in large-scale wireless multi-hop networks becomes labor-intensive and potentially congestive due to the need for short-range wireless communication with provisioners, especially when nodes are located at distant locations.
Innovation Solution
Implementing a system where wireless communication devices other than the provisioner, referred to as agents, perform proxy authentication of newly joined nodes, allowing authentication to be conducted remotely and reducing the load on the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If provisioners perform authentication of newly joined nodes directly, then authentication security is maintained, but network congestion and labor intensity increase significantly in large-scale networks
Solution Approach 1:
The patent introduces an agent as an intermediary component that performs authentication of newly joined nodes on behalf of the provisioner. The agent is equipped with authentication credentials and can independently authenticate nodes within its coverage area, eliminating the need for the provisioner to directly communicate with each joining node. This mediator approach maintains security while dramatically reducing the provisioner's workload and preventing network congestion.
Solution Approach 2:
The patent divides the authentication function into separate components: the provisioner retains credential management and node registration functions, while the agent handles the actual authentication process. This segmentation allows the authentication load to be distributed across multiple agents rather than concentrated on a single provisioner, improving overall system efficiency and scalability.
2Ease of operation
If provisioners move closer to distant nodes for authentication, then authentication can be performed, but labor cost and time consumption increase
Solution Approach 1:
The patent enables the authentication process to occur automatically without requiring physical movement of the provisioner. The agent, being stationary or mobile within the network, performs authentication locally when nodes join, eliminating the need for provisioner intervention in the physical authentication process. This self-service approach significantly reduces both labor cost and time consumption.
3Adaptability or versatility
If multiple nodes join the network simultaneously, then network scalability is improved, but authentication load becomes unmanageable
Solution Approach 1:
The patent segments the authentication management function by deploying multiple agents throughout the network, each responsible for a specific geographic area or group of nodes. When multiple nodes join simultaneously, different agents can handle their authentication in parallel, distributing the load and preventing any single point from becoming unmanageable. This segmentation maintains scalability while controlling complexity.
Solution Approach 2:
The patent allows agents to perform authentication operations that would traditionally require provisioner involvement. By empowering agents with partial authentication capabilities, the system can handle excessive join requests without overloading the provisioner, as agents can independently process authentications within their capacity.
Data Source
AI summary
According to one embodiment, a wireless communication system includes a plurality of wireless communication devices. A first wireless communication device is configured to request a second wireless communication device to perform proxy of authentication of a third wireless communication device to be allowed to newly join a wireless multi-hop network. The second wireless communication device is configured to perform authentication communication with the third wireless communication device for performing authentication of the third wireless communication device. During the authentication communication, the first wireless communication device and the second wireless communication device are configured not to perform communication related to the authentication.


