Segment Controller Secure Protocol Execution in Wireless Mesh Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless mesh networks face challenges in securing protocol execution, particularly in outdoor lighting control systems, where intermediate devices like segment controllers may act as man-in-the-middle threats, requiring secure configuration and software updates while minimizing backend connectivity and data traffic.
Innovation Solution
A system where a controlling device, acting as an intermediate entity, performs protocols with network nodes by requiring predetermined response messages, ensuring correct protocol execution without extensive data traffic, and utilizing cryptographic methods like HASH-chains for authentication and encryption to prevent manipulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional end-to-end security protocols are used between service center and nodes, then high security authentication is achieved, but severe requirements on backend connectivity, bandwidth and operations are imposed
Solution Approach 1:
The patent introduces a segment controller as an intermediary device between the service center and network nodes. The segment controller receives protocol information from the service center and executes the protocol locally with multiple nodes, eliminating the need for continuous direct connections between the service center and each node. This mediator approach maintains security authentication while significantly reducing backend connectivity requirements and data traffic.
2Adaptability or versatility
If segment controller is not fully trusted and may act as man-in-the-middle, then operational flexibility is improved, but security of protocol execution deteriorates
Solution Approach 1:
The patent implements a feedback mechanism where nodes send predetermined response messages to the segment controller during protocol execution. The segment controller must collect these response messages and forward them to the service center for verification. This feedback loop ensures that even if the segment controller is not fully trusted, it cannot manipulate protocol execution without detection, as the service center can verify whether the controller actually received and processed the nodes' responses correctly.
Solution Approach 2:
The service center provides the segment controller with encrypted protocol information in advance, including authentication data and instructions for executing the protocol with specific nodes. The segment controller cannot decode or properly execute the protocol without the predetermined response messages from the nodes. This preliminary action of providing encrypted instructions ensures that the segment controller cannot act as an unauthorized man-in-the-middle while maintaining operational flexibility.
3Reliability
If continuous connection with backend is maintained for security protocols, then authentication reliability is improved, but data traffic and bandwidth requirements increase
Solution Approach 1:
Instead of maintaining continuous connections between the service center and nodes for security protocols, the patent implements periodic action where the segment controller executes the protocol locally with nodes using pre-provided encrypted information. The segment controller periodically reports status and collected response messages to the service center only when needed for verification. This periodic interaction maintains authentication reliability while dramatically reducing data traffic and bandwidth requirements compared to continuous connections.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
For secure configuration of network nodes from a backend with low connectivity requirements and workload at the backend and reduced communication overhead, a system, a control unit for a segment controller and a method for secure protocol execution in a network are provided, wherein protocol information is provided to a segment controller (60) for controlling a node (10) and a protocol is performed based on the protocol information to control the node (10), at least one response message of the node (10) being required at the segment controller (60) for performing one or more steps of the protocol.