Relay Packet Forwarding Without Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing packet processing method in IEEE 802.11 ah standard, where a relay device decrypts and then encrypts packets between a station and an access point, results in reduced channel utilization and increased power consumption.

Innovation Solution

The method involves generating additional authentication data based on packet header address information using specific rules, allowing the relay device to forward encrypted packets without decryption, thereby optimizing processing time and power usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the relay device decrypts and then encrypts packets when forwarding between station and access point, then packet security is maintained, but channel utilization is reduced and power consumption increases

Engineering Contradiction:
Improvepacket securityVSAvoidchannel utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the decryption operation from the relay device's processing workflow. By having the access point perform decryption directly on packets received from the station (bypassing the relay), the relay device is freed from the decryption/encryption burden, thereby improving channel utilization while maintaining security through the access point's direct decryption capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a new intermediary role for the access point in the decryption process. Instead of the relay device performing decryption and re-encryption, the access point acts as an intermediary that directly decrypts packets from the station, eliminating the need for the relay to perform these operations and thus improving overall system efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the relay device decrypts and then encrypts packets when forwarding between station and access point, then packet security is maintained, but power consumption increases

Engineering Contradiction:
Improvepacket securityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the power-intensive decryption operation from the relay device. By having the access point perform decryption directly, the relay device no longer needs to consume power for both decryption and re-encryption operations, thereby reducing overall system power consumption while maintaining security through the access point's direct decryption capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access point serves as an intermediary that handles the power-consuming decryption task directly. This intermediary approach eliminates the need for the relay device to perform both decryption and re-encryption, significantly reducing the computational load and power consumption of the relay device while preserving packet security

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9872175B2Packet processing method, apparatus, and system
Publication Date: 2018.01.16 HUAWEI DEVICE CO LTD
  • US9872175B2 patent drawing
  • US9872175B2 patent drawing
  • US9872175B2 patent drawing

AI summary

A packet processing method, apparatus, and system. A first node receives a first packet sent by a relay device, where the first packet includes data in a second packet sent by a second node to the relay device, the data in the second packet is encrypted by using second additional authentication data and a session key between the first node and the second node, and the second additional authentication data is generated by the second node according to at least address information in a packet header of the second packet by using a second rule; the first node generates first additional authentication data according to address information in a packet header of the first packet by using a first rule, and decrypts the data in the first packet by using the first additional authentication data and the session key.