Segment Controller Secure Protocol Execution in Wireless Mesh Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless mesh networks face challenges in securing protocol execution, particularly in outdoor lighting control systems, where intermediate devices like segment controllers may act as man-in-the-middle threats, requiring secure configuration and software updates while minimizing backend connectivity and data traffic.

Innovation Solution

A system where a controlling device, acting as an intermediate entity, performs protocols with network nodes by requiring predetermined response messages, ensuring correct protocol execution without extensive data traffic, and utilizing cryptographic methods like HASH-chains for authentication and encryption to prevent manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional end-to-end security protocols are used between service center and nodes, then high security authentication is achieved, but severe requirements on backend connectivity, bandwidth and operations are imposed

Engineering Contradiction:
Improvesecurity authenticationVSAvoidbackend connectivity requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a segment controller as an intermediary device between the service center and network nodes. The segment controller receives protocol information from the service center and executes the protocol locally with multiple nodes, eliminating the need for continuous direct connections between the service center and each node. This mediator approach maintains security authentication while significantly reducing backend connectivity requirements and data traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If segment controller is not fully trusted and may act as man-in-the-middle, then operational flexibility is improved, but security of protocol execution deteriorates

Engineering Contradiction:
Improveoperational flexibilityVSAvoidprotocol execution security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where nodes send predetermined response messages to the segment controller during protocol execution. The segment controller must collect these response messages and forward them to the service center for verification. This feedback loop ensures that even if the segment controller is not fully trusted, it cannot manipulate protocol execution without detection, as the service center can verify whether the controller actually received and processed the nodes' responses correctly.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The service center provides the segment controller with encrypted protocol information in advance, including authentication data and instructions for executing the protocol with specific nodes. The segment controller cannot decode or properly execute the protocol without the predetermined response messages from the nodes. This preliminary action of providing encrypted instructions ensures that the segment controller cannot act as an unauthorized man-in-the-middle while maintaining operational flexibility.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If continuous connection with backend is maintained for security protocols, then authentication reliability is improved, but data traffic and bandwidth requirements increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddata traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of maintaining continuous connections between the service center and nodes for security protocols, the patent implements periodic action where the segment controller executes the protocol locally with nodes using pre-provided encrypted information. The segment controller periodically reports status and collected response messages to the service center only when needed for verification. This periodic interaction maintains authentication reliability while dramatically reducing data traffic and bandwidth requirements compared to continuous connections.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP2719115B1Secure protocol execution in a network
Publication Date: 2021.08.11 SIGNIFY HOLDING BV
  • EP2719115B1 patent drawingFigure 1
  • EP2719115B1 patent drawingFigure 2
  • EP2719115B1 patent drawingFigure 3

AI summary

For secure configuration of network nodes from a backend with low connectivity requirements and workload at the backend and reduced communication overhead, a system, a control unit for a segment controller and a method for secure protocol execution in a network are provided, wherein protocol information is provided to a segment controller (60) for controlling a node (10) and a protocol is performed based on the protocol information to control the node (10), at least one response message of the node (10) being required at the segment controller (60) for performing one or more steps of the protocol.