PAN Router Re-Encryption for Secure Legacy Device Rejoin
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The legacy Zigbee home automation specification allows devices to rejoin a network using a well-known encryption key, making it insecure and vulnerable to eavesdropping, which the Connectivity Standards Alliance aims to address by banning this method in new device certifications.
Innovation Solution
A method and router are introduced to allow devices with outdated network keys to rejoin the PAN using a proxy connection with a unique third network key, ensuring the active network key remains secure by re-encrypting messages through a router.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a well-known encryption key (ZBA09) is used to allow devices to rejoin the PAN, then legacy devices can reconnect to the network, but the network key becomes vulnerable to eavesdropping and security is compromised
Solution Approach 1:
The patent introduces a router as an intermediary device between the PAN and legacy joiner devices. The router receives join requests encrypted with the well-known ZBA09 key, establishes a secure connection, and then relays communication between the joiner device and the PAN using this secure channel. This mediator approach allows legacy devices to use outdated encryption methods while the router ensures current security standards are maintained for actual PAN communication.
Solution Approach 2:
The patent segments the communication path into two distinct encrypted channels: one channel between the router and the PAN using current security standards, and another channel between the router and legacy joiner devices using the well-known key. This segmentation isolates the security vulnerability to a controlled interface while protecting the core PAN communication with modern encryption.
2Ease of operation
If the rejoin process uses only the well-known encryption key, then the process is simple and straightforward, but it becomes easy for eavesdroppers to obtain the active network key
Solution Approach 1:
The router acts as a secure intermediary that handles the complex key management and encryption transitions. Joiner devices can use the simple well-known key to initiate connection, but the router mediates the establishment of secure encrypted channels for actual data communication, thus maintaining both simplicity for end devices and security for network communication.
Solution Approach 2:
The patent creates a copy of the secure communication channel through the router. The router receives encrypted messages from the PAN, re-encrypts them with the well-known key for transmission to legacy devices, and vice versa. This copying mechanism with different encryption layers allows simple client-side operations while maintaining secure server-side communication.
3Reliability
If the router re-encrypts messages between the first network key and third network key, then the active network key is protected from being leaked, but the device complexity increases
Solution Approach 1:
The router as intermediary bears the complexity burden of dual encryption operations. It maintains both the current PAN encryption key and the well-known legacy key, performing real-time encryption and decryption transformations. This concentrates the complexity in a single device that can be upgraded or replaced without affecting legacy joiner devices, isolating the complexity management.
Solution Approach 2:
The router performs multiple functions: it acts as a standard PAN member device for communication with the network, simultaneously serves as a secure gateway for legacy devices, and performs key transformation operations. This multi-functionality consolidates the complexity handling capability in a device already designed for versatile network operations.
Data Source
AI summary
A wireless personal area network (PAN) includes a plurality of devices configured to communicate messages encrypted with a first network key across the PAN, and the plurality of devices includes a router. The router receives from the joiner device a join request message encrypted by a second network key and sends to the joiner device a join confirmation message that contains a third network key. The router receives subsequent incoming messages from the joiner device encrypted by the third network key, re-encrypts each subsequent incoming message with the first network key, and transmits the re-encrypted subsequent incoming messages to other devices in the PAN. The router receives, from other devices in the PAN, subsequent outgoing messages for the joiner device encrypted by the first network key, re-encrypts the subsequent outgoing messages with the third network key, and sends the re-encrypted subsequent outgoing messages to the joiner device.


