Multihop Wireless Network Security via Segmented Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless multihopping communication networks are vulnerable to data interception due to the relay of traffic through intermediate nodes that may not be trusted, necessitating an end-to-end security scheme to protect data traffic from source to destination nodes.

Innovation Solution

A system and method providing end-to-end security through a peer-to-peer group authentication scheme and packet protection using authentication messages tunneled across intermediate nodes, employing Extensible Authentication Protocol Over LAN (EAPOL) and encryption with Counter-Mode-CBC-MAC Protocol (CCMP) or Advanced Encryption Standard (AES), ensuring secure communication between nodes in the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If traffic is relayed through intermediate nodes in a multihopping wireless network, then network coverage and connectivity are extended, but data security and confidentiality are compromised due to potential interception by untrusted nodes

Engineering Contradiction:
Improvenetwork coverageVSAvoiddata interception
Core Design Contradiction:
Area of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data transmission process into authenticated hops between nodes. Each node performs authentication with its neighbor before relaying traffic, creating segmented security zones rather than a single vulnerable end-to-end path. This allows network coverage to extend through multiple nodes while maintaining security boundaries at each hop.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authentication protocols as intermediary mechanisms between source and destination nodes. These authentication intermediaries verify the legitimacy of each hop in the multihopping path, preventing untrusted nodes from intercepting data while still allowing trusted nodes to extend network coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end encryption is implemented to protect data traffic, then data security is improved, but complexity of the security scheme and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsecurity scheme complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the encryption and authentication process into segments performed at each node hop rather than a single end-to-end operation. Each node performs localized authentication and encryption/decryption operations with its immediate neighbors, reducing the complexity burden on individual devices while maintaining overall data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial encryption at each hop rather than full end-to-end encryption. Each node encrypts only the portion of data relevant to its immediate transmission, reducing processing complexity while providing sufficient security for each segment of the journey.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If authentication protocols are implemented at each node, then security against untrusted intermediates is improved, but processing time and energy consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication actions preliminarily at each node before data transmission begins. Nodes pre-authenticate with their neighbors and establish secure channels in advance, so that when data needs to be relayed, the authentication is already complete and no additional time is required during active transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous authenticated sessions between nodes once established. Rather than performing full authentication protocols for every data packet, the system maintains continuous secure channels, performing authentication only when sessions need to be established or renewed, thereby reducing repeated authentication time overhead.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS7904945B2System and method for providing security for a wireless network
Publication Date: 2011.03.08 ARRIS ENTERPRISES LLC
  • US7904945B2 patent drawing
  • US7904945B2 patent drawing
  • US7904945B2 patent drawing

AI summary

A system and method for providing secure communication between nodes (102, 106, 107) in a wireless multihopping communication network (100). The system and method achieve secure communication in a multihopping wireless network (100) by, for example, providing a transport medium for transmission of multihopping authentication messages (400) by the infrastructure devices, such as intelligent access points (106) or wireless routers (107), and user devices, such as mobile nodes (102). The authentication messages (400) are used to verify the identity of a node (102, 107) to thus permit the node (102, 107) to communicate within the network (100). The system and method further use, for example, encryption techniques for protecting the content data packet (1000) traffic being transmitted the nodes (102, 106, 107) within the wireless network (100).