Network Authentication Key for Secure Ad-hoc Device Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ad-hoc and mesh networks are difficult for technically unsophisticated users to administer and deploy securely, especially when adding new devices, due to concerns about security and administration complexity.

Innovation Solution

A system and method employing a key for authenticating new devices to an existing network, allowing users to validate new nodes with minimal technical expertise, using a key that can be inserted into or associated with new devices to confirm their approval for network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security authentication methods are used for adding new devices to ad-hoc networks, then network security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidease of deployment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A physical key serves as an intermediary authentication mechanism between the administrator and new devices. The key contains authentication credentials that simplify the enrollment process while maintaining security. The key acts as a trusted mediator that carries authentication information without requiring complex digital certificate management or cryptographic operations from end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical key insertion with wireless authentication methods. A wireless communication interface enables the key to communicate authentication credentials wirelessly to the network, eliminating the need for physical key insertion while maintaining the simplified user experience. This substitution modernizes the system while preserving the core benefit of easy authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional security authentication methods are used for adding new devices to ad-hoc networks, then network security is improved, but device complexity worsens

Engineering Contradiction:
Improvenetwork securityVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The physical key serves as a trusted intermediary that encapsulates authentication credentials. Instead of requiring administrators to manage complex digital certificates, cryptographic keys, or authentication protocols, the key provides a simple physical token that handles security operations internally. This reduces administrative complexity while maintaining strong security through the key's embedded authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key performs self-service authentication functions by automatically providing credentials to new devices without requiring administrator intervention for each authentication event. The key contains pre-configured authentication information that it can present autonomously, eliminating the need for administrators to manually configure security settings or manage authentication protocols for each device addition.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8037159B2System and method for effecting the secure deployment of networks
Publication Date: 2011.10.11 BISON PATENT LICENSING LLC
  • US8037159B2 patent drawing
  • US8037159B2 patent drawing
  • US8037159B2 patent drawing

AI summary

A system and method for allowing network users to securely administer and deploy network nodes (102). These networks (100) may comprise wired and/or wireless connections. Examples would include wired networks (104) with shared infrastructure in an office building, as well as ad-hoc multi-hopping peer-to-peer network applications for the home. The system and method provides a key (130) that allows new nodes (102) and thus new devices (124, 126, 132) to gain access to a network (100) via an existing node (122) of that network (100).