Root LLN Device Strips Redundant Certificates from Authentication Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale wireless mesh networks with thousands of low-power and lossy network devices face substantial traffic burdens and delays due to the large size of authentication messages containing certificates, which are an order of magnitude larger than non-authentication messages, causing significant congestion and delaying convergence in the network.

Innovation Solution

A root network device removes redundant certificates from authentication messages destined for constrained network devices, generating a modified message without the certificate, which is then restored by intermediate devices that have cached the certificate, thereby reducing unnecessary traffic and message size.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication messages containing certificates are sent to each LLN device, then secure authentication is achieved, but network traffic burden increases substantially

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork traffic volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The root LLN device performs preliminary actions by removing certificates from authentication messages before forwarding them to intermediate LLN devices. The certificates are transmitted only once to the root device, which then strips them before relay, eliminating redundant certificate transmissions through the network while maintaining authentication security at the destination device.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the certificate data from authentication messages at the root LLN device before forwarding to intermediate devices. The certificate is taken out from the message body, allowing the message to be transmitted without the bulky certificate payload, and only the essential authentication data is propagated through the network.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If certificates are included in authentication messages, then authentication integrity is maintained, but message size increases by an order of magnitude

Engineering Contradiction:
Improveauthentication integrityVSAvoidmessage size
Core Design Contradiction:
ReliabilityVSLength of stationary object

Solution Approach 1:

The root LLN device extracts and removes the certificate from the authentication message before forwarding to intermediate devices. This extraction reduces message size from approximately 4KB to 100-200 bytes while preserving the essential authentication information needed for integrity verification at the destination.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The certificate is transmitted to the root LLN device in advance, allowing the root device to remove it before relaying the authentication message. This preliminary transmission ensures the root device has the certificate for verification purposes without including it in subsequent relayed messages.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If full authentication messages are transmitted through the network, then authentication completeness is ensured, but network convergence is delayed by over one month

Engineering Contradiction:
Improveauthentication completenessVSAvoidconvergence time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By extracting and removing certificates from authentication messages at the root LLN device before network transmission, the patent reduces message size and transmission time. This extraction eliminates redundant data propagation through thousands of LLN devices, reducing convergence time from over one month to a manageable duration.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The root LLN device performs preliminary certificate removal before forwarding authentication messages to intermediate devices. This preliminary action prevents the propagation of large authentication messages through the entire network, thereby avoiding the extended convergence delays that would otherwise occur.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If certificates are transmitted to each LLN device, then authentication capability is provided to all devices, but network congestion increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidnetwork congestion
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The root LLN device extracts and removes certificates from authentication messages before relaying them to intermediate LLN devices. This extraction eliminates the source of network congestion caused by redundant certificate transmissions while preserving the authentication capability at the destination device through the use of cached certificates or alternative authentication mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The root LLN device performs preliminary certificate removal before forwarding authentication messages through the network. This preliminary action prevents network congestion by eliminating bulky certificate data from repeated transmissions, while the destination device maintains authentication capability through previously cached certificate information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20200396634A1Reducing traffic in a low power and lossy network based on removing redundant certificate from authentication message destined for constrained wireless device via authenticated wireless device
Publication Date: 2020.12.17 CISCO TECHNOLOGY INC
  • US20200396634A1 patent drawing
  • US20200396634A1 patent drawing
  • US20200396634A1 patent drawing

AI summary

In one embodiment, a method comprises: forwarding, by a root network device in a low power and lossy network, an authentication message to a constrained child network device having attached to the root network device, the authentication message generated by an authenticator device and specifying a certificate associated with the authenticator device; receiving a second authentication message destined for a second constrained network device via the constrained child network device; removing, from the second authentication message, the certificate; and outputting, by the root network device, the modified second authentication message that does not include the certificate toward the second constrained network device via the constrained child network device, the modified second authentication message causing the constrained child network device to restore the second authentication message for delivery to the second constrained network device, based on insertion of the certificate back into the modified second authentication message.