Root LLN Device Strips Redundant Certificates from Authentication Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large-scale wireless mesh networks with thousands of low-power and lossy network devices face substantial traffic burdens and delays due to the large size of authentication messages containing certificates, which are an order of magnitude larger than non-authentication messages, causing significant congestion and delaying convergence in the network.
Innovation Solution
A root network device removes redundant certificates from authentication messages destined for constrained network devices, generating a modified message without the certificate, which is then restored by intermediate devices that have cached the certificate, thereby reducing unnecessary traffic and message size.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication messages containing certificates are sent to each LLN device, then secure authentication is achieved, but network traffic burden increases substantially
Solution Approach 1:
The root LLN device performs preliminary actions by removing certificates from authentication messages before forwarding them to intermediate LLN devices. The certificates are transmitted only once to the root device, which then strips them before relay, eliminating redundant certificate transmissions through the network while maintaining authentication security at the destination device.
Solution Approach 2:
The patent extracts the certificate data from authentication messages at the root LLN device before forwarding to intermediate devices. The certificate is taken out from the message body, allowing the message to be transmitted without the bulky certificate payload, and only the essential authentication data is propagated through the network.
2Reliability
If certificates are included in authentication messages, then authentication integrity is maintained, but message size increases by an order of magnitude
Solution Approach 1:
The root LLN device extracts and removes the certificate from the authentication message before forwarding to intermediate devices. This extraction reduces message size from approximately 4KB to 100-200 bytes while preserving the essential authentication information needed for integrity verification at the destination.
Solution Approach 2:
The certificate is transmitted to the root LLN device in advance, allowing the root device to remove it before relaying the authentication message. This preliminary transmission ensures the root device has the certificate for verification purposes without including it in subsequent relayed messages.
3Reliability
If full authentication messages are transmitted through the network, then authentication completeness is ensured, but network convergence is delayed by over one month
Solution Approach 1:
By extracting and removing certificates from authentication messages at the root LLN device before network transmission, the patent reduces message size and transmission time. This extraction eliminates redundant data propagation through thousands of LLN devices, reducing convergence time from over one month to a manageable duration.
Solution Approach 2:
The root LLN device performs preliminary certificate removal before forwarding authentication messages to intermediate devices. This preliminary action prevents the propagation of large authentication messages through the entire network, thereby avoiding the extended convergence delays that would otherwise occur.
4Adaptability or versatility
If certificates are transmitted to each LLN device, then authentication capability is provided to all devices, but network congestion increases
Solution Approach 1:
The root LLN device extracts and removes certificates from authentication messages before relaying them to intermediate LLN devices. This extraction eliminates the source of network congestion caused by redundant certificate transmissions while preserving the authentication capability at the destination device through the use of cached certificates or alternative authentication mechanisms.
Solution Approach 2:
The root LLN device performs preliminary certificate removal before forwarding authentication messages through the network. This preliminary action prevents network congestion by eliminating bulky certificate data from repeated transmissions, while the destination device maintains authentication capability through previously cached certificate information.
Data Source
AI summary
In one embodiment, a method comprises: forwarding, by a root network device in a low power and lossy network, an authentication message to a constrained child network device having attached to the root network device, the authentication message generated by an authenticator device and specifying a certificate associated with the authenticator device; receiving a second authentication message destined for a second constrained network device via the constrained child network device; removing, from the second authentication message, the certificate; and outputting, by the root network device, the modified second authentication message that does not include the certificate toward the second constrained network device via the constrained child network device, the modified second authentication message causing the constrained child network device to restore the second authentication message for delivery to the second constrained network device, based on insertion of the certificate back into the modified second authentication message.


