Multihop Wireless Network Security via Segmented Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless multihopping communication networks are vulnerable to data interception due to the relay of traffic through intermediate nodes that may not be trusted, necessitating an end-to-end security scheme to protect data traffic from source to destination nodes.
Innovation Solution
A system and method providing end-to-end security through a peer-to-peer group authentication scheme and packet protection using authentication messages tunneled across intermediate nodes, employing Extensible Authentication Protocol Over LAN (EAPOL) and encryption with Counter-Mode-CBC-MAC Protocol (CCMP) or Advanced Encryption Standard (AES), ensuring secure communication between nodes in the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If traffic is relayed through intermediate nodes in a multihopping wireless network, then network coverage and connectivity are extended, but data security and confidentiality are compromised due to potential interception by untrusted nodes
Solution Approach 1:
The patent segments the data transmission process into authenticated hops between nodes. Each node performs authentication with its neighbor before relaying traffic, creating segmented security zones rather than a single vulnerable end-to-end path. This allows network coverage to extend through multiple nodes while maintaining security boundaries at each hop.
Solution Approach 2:
The patent introduces authentication protocols as intermediary mechanisms between source and destination nodes. These authentication intermediaries verify the legitimacy of each hop in the multihopping path, preventing untrusted nodes from intercepting data while still allowing trusted nodes to extend network coverage.
2Reliability
If end-to-end encryption is implemented to protect data traffic, then data security is improved, but complexity of the security scheme and processing overhead increase
Solution Approach 1:
The patent divides the encryption and authentication process into segments performed at each node hop rather than a single end-to-end operation. Each node performs localized authentication and encryption/decryption operations with its immediate neighbors, reducing the complexity burden on individual devices while maintaining overall data security.
Solution Approach 2:
The patent implements partial encryption at each hop rather than full end-to-end encryption. Each node encrypts only the portion of data relevant to its immediate transmission, reducing processing complexity while providing sufficient security for each segment of the journey.
3Reliability
If authentication protocols are implemented at each node, then security against untrusted intermediates is improved, but processing time and energy consumption increase
Solution Approach 1:
The patent performs authentication actions preliminarily at each node before data transmission begins. Nodes pre-authenticate with their neighbors and establish secure channels in advance, so that when data needs to be relayed, the authentication is already complete and no additional time is required during active transmission.
Solution Approach 2:
The patent maintains continuous authenticated sessions between nodes once established. Rather than performing full authentication protocols for every data packet, the system maintains continuous secure channels, performing authentication only when sessions need to be established or renewed, thereby reducing repeated authentication time overhead.
Data Source
AI summary
A system and method for providing secure communication between nodes (102, 106, 107) in a wireless multihopping communication network (100). The system and method achieve secure communication in a multihopping wireless network (100) by, for example, providing a transport medium for transmission of multihopping authentication messages (400) by the infrastructure devices, such as intelligent access points (106) or wireless routers (107), and user devices, such as mobile nodes (102). The authentication messages (400) are used to verify the identity of a node (102, 107) to thus permit the node (102, 107) to communicate within the network (100). The system and method further use, for example, encryption techniques for protecting the content data packet (1000) traffic being transmitted the nodes (102, 106, 107) within the wireless network (100).


