Multi-Hop Network Authentication Using Proxy Agent Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The authentication of newly joined nodes in large-scale wireless multi-hop networks becomes labor-intensive and potentially congestive due to the need for short-range wireless communication with provisioners, especially when nodes are located at distant locations.

Innovation Solution

Implementing a system where wireless communication devices other than the provisioner, referred to as agents, perform proxy authentication of newly joined nodes, allowing authentication to be conducted remotely and reducing the load on the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If provisioners perform authentication of newly joined nodes directly, then authentication security is maintained, but network congestion and labor intensity increase significantly in large-scale networks

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an agent as an intermediary component that performs authentication of newly joined nodes on behalf of the provisioner. The agent is equipped with authentication credentials and can independently authenticate nodes within its coverage area, eliminating the need for the provisioner to directly communicate with each joining node. This mediator approach maintains security while dramatically reducing the provisioner's workload and preventing network congestion.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent divides the authentication function into separate components: the provisioner retains credential management and node registration functions, while the agent handles the actual authentication process. This segmentation allows the authentication load to be distributed across multiple agents rather than concentrated on a single provisioner, improving overall system efficiency and scalability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If provisioners move closer to distant nodes for authentication, then authentication can be performed, but labor cost and time consumption increase

Engineering Contradiction:
Improveauthentication accessibilityVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent enables the authentication process to occur automatically without requiring physical movement of the provisioner. The agent, being stationary or mobile within the network, performs authentication locally when nodes join, eliminating the need for provisioner intervention in the physical authentication process. This self-service approach significantly reduces both labor cost and time consumption.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple nodes join the network simultaneously, then network scalability is improved, but authentication load becomes unmanageable

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidauthentication management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication management function by deploying multiple agents throughout the network, each responsible for a specific geographic area or group of nodes. When multiple nodes join simultaneously, different agents can handle their authentication in parallel, distributing the load and preventing any single point from becoming unmanageable. This segmentation maintains scalability while controlling complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent allows agents to perform authentication operations that would traditionally require provisioner involvement. By empowering agents with partial authentication capabilities, the system can handle excessive join requests without overloading the provisioner, as agents can independently process authentications within their capacity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20260032441A1Wireless communication system, wireless communication device, and method
Publication Date: 2026.01.29 KK TOSHIBA
  • US20260032441A1 patent drawing
  • US20260032441A1 patent drawing
  • US20260032441A1 patent drawing

AI summary

According to one embodiment, a wireless communication system includes a plurality of wireless communication devices. A first wireless communication device is configured to request a second wireless communication device to perform proxy of authentication of a third wireless communication device to be allowed to newly join a wireless multi-hop network. The second wireless communication device is configured to perform authentication communication with the third wireless communication device for performing authentication of the third wireless communication device. During the authentication communication, the first wireless communication device and the second wireless communication device are configured not to perform communication related to the authentication.