Wireless Instrumentation Network Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless instrumentation networks face challenges in reliability, scalability, low power consumption, security, auto-configuration, latency, maintenance, integration, and compatibility, particularly in industrial settings where wired solutions are costly and difficult to install.

Innovation Solution

A secure wireless infrastructure with a key server acting as a central key distribution center, using liaison devices to securely admit new nodes, deploy and update keys, and authorize communications sessions, ensuring secure communication through cryptographic key sharing and periodic key updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If wireless instrumentation networks are deployed in industrial settings, then installation cost and difficulty are reduced compared to wired solutions, but security vulnerabilities increase due to exposure to eavesdropping and spoofing attacks

Engineering Contradiction:
Improveinstallation cost and difficultyVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security actions by pre-distributing unique cryptographic keys to each wireless device before deployment. When devices join the network, they automatically authenticate using these pre-shared keys, establishing secure communication channels before any data transmission occurs. This preliminary key distribution and authentication mechanism prevents eavesdropping and spoofing attacks from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic key management as an intermediary layer between wireless devices and the network. A centralized key management system distributes and manages cryptographic keys, acting as a mediator that enables secure communication without requiring direct trusted connections between all devices. This intermediary key management infrastructure protects against security threats while maintaining wireless communication flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If cryptographic key management systems are implemented to secure wireless communications, then security against eavesdropping and spoofing is improved, but system complexity and key distribution overhead increase

Engineering Contradiction:
Improvesecurity against eavesdropping and spoofingVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The key management system is designed to be universal and multi-functional, serving multiple purposes: device authentication, secure key distribution, session management, and network access control. By consolidating these functions into a single cryptographic framework, the system achieves high security without proportionally increasing complexity, as the same infrastructure handles multiple security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Wireless devices automatically perform cryptographic operations and key management tasks without requiring manual intervention. Devices self-authenticate using pre-distributed keys, automatically establish secure communication channels, and manage their own cryptographic credentials. This self-service approach reduces operational complexity and eliminates the need for manual key distribution and configuration.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If secure authentication protocols are used during device joining, then network security is maintained, but device join time and network latency increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice join time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

Cryptographic authentication credentials are pre-distributed to devices during manufacturing or initial setup, before they need to join the network. When a device attempts to join, it immediately presents these pre-configured credentials for authentication, eliminating the need for time-consuming key exchange protocols or manual authentication procedures. This preliminary preparation significantly reduces device join time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7936878B2Secure wireless instrumentation network system
Publication Date: 2011.05.03 HONEYWELL INTERNATIONAL INC
  • US7936878B2 patent drawing
  • US7936878B2 patent drawing
  • US7936878B2 patent drawing

AI summary

The present system having a secure wireless infrastructure with a key server acting as a key distribution center. The key server may be the core of the network, securely admitting new nodes or devices, deploying and updating keys and authorizing secure communications sessions. The system may also share secure keying information with a new device not already a member of a secure wireless network. The keying information may be used for authentication or encryption or both, and may be provided to the new device in a manner or mode which is not susceptible to exposure outside of the secure network. The keying information shared with the new device may be regarded as a birth key. Then the new device may send a birth key encrypted request to join the secure network via an exposed communication mode. The key server may respond with a birth key encrypted key encryption key.