Sub-group Encryption Key Generation for Wireless Mesh Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless mesh networks do not facilitate secure messaging at the application-level between sub-groups of network nodes, leading to potential unauthorized access to intended communications.

Innovation Solution

A system that generates a sub-group encryption key unique to designated nodes within a wireless mesh network, allowing for secure peer-to-peer communication by encrypting application-layer messages within 'team packets' that can only be decrypted by nodes within the specified group, ensuring privacy and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless mesh networks enable network-level communication between all nodes, then network connectivity and information sharing are improved, but application-level security for sub-groups deteriorates as all nodes can read communications not intended for them

Engineering Contradiction:
Improvenetwork connectivityVSAvoidapplication-level security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the network communication into two distinct layers: network-level communication for general information sharing and application-level communication for secure sub-group messaging. This segmentation allows nodes to participate in network-wide communication while simultaneously maintaining private channels for specific sub-groups, resolving the contradiction between network connectivity and application-level security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different security characteristics to different communication layers. Network-level packets use encryption keys known to all nodes for broad accessibility, while application-level packets use separate encryption keys restricted to specific sub-groups. This allows each communication type to have optimized security properties appropriate to its purpose.

Inventive Principle:
Principle #3Local quality

2Reliability

If encryption is implemented at the network level for all nodes, then network communication security is improved, but application-level privacy for specific sub-groups deteriorates as it cannot provide targeted security

Engineering Contradiction:
Improvenetwork communication securityVSAvoidapplication-level privacy
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments encryption keys and security policies into network-level and application-level components. Network-level encryption provides baseline security for all communications, while application-level encryption with separate keys provides targeted privacy for specific sub-groups. This dual-layer segmentation resolves the contradiction by allowing both broad security and specific privacy simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds another dimension to security by implementing encryption at multiple layers (network level and application level) rather than relying on a single layer. This dimensional approach allows network-level encryption to provide general security while application-level encryption provides targeted privacy, resolving the contradiction between comprehensive security and specific adaptability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If secure group communication is implemented using existing solutions, then security policies are improved, but device complexity and implementation overhead deteriorate

Engineering Contradiction:
Improvesecurity policiesVSAvoidimplementation overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges secure group communication functionality directly into the existing wireless mesh network protocol stack. By integrating encryption and decryption operations at both network and application layers within the same device firmware, the solution eliminates the need for separate secure communication systems, reducing overall device complexity while maintaining strong security policies.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal security framework that handles both network-level and application-level communication security within the same device and protocol structure. This multi-functional approach allows a single device to provide both broad network security and specific application-level privacy without requiring additional specialized hardware or complex external systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3900288B1Secure peer-to-peer communication over wireless mesh networks
Publication Date: 2024.04.24 LANDIS GYR TECH INC
  • EP3900288B1 patent drawingFigure 1
  • EP3900288B1 patent drawingFigure 2
  • EP3900288B1 patent drawingFigure 3

AI summary

Systems and methods for secure team-based communication on existing wireless mesh networks are disclosed. In an example network with multiple network nods, a headend system designates a first network node and a second network node as a sub-group of nodes, generates a sub-group encryption key that is unique to the sub-group of nodes, and transmits the sub-group encryption key and the sub-group node list and to the first node and the second node. The first node encrypts an application layer message with the sub-group encryption key and sends the message to the second node. The second node decrypts the application layer message with the sub-group encryption key and performs an action based on the message.