Wireless Network Configuration via Self-Certifying Node Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In dynamic wireless networks, the reliability of neighboring nodes is unknown, leading to issues with secure information routing, as existing ad hoc routing algorithms lack secure authentication and may cause network overload and resource misuse, particularly for wireless devices with battery constraints.

Innovation Solution

An apparatus and method utilizing self-certifying identifiers and the Host Identity Protocol (HIP) for secure network configuration and route discovery, ensuring only trustworthy nodes participate in routing, thereby establishing secure IPsec tunnels and reducing network load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If free routing is allowed for all nodes in a wireless network, then network connectivity and communication capability are improved, but network security deteriorates and resource usage becomes uncontrolled

Engineering Contradiction:
Improvenetwork connectivityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing authentication of neighboring nodes before allowing routing operations. The apparatus authenticates nodes using cryptographic methods (public key infrastructure, digital signatures) in advance, storing authentication results and node identities. This preliminary authentication ensures that only verified nodes can participate in routing, preventing security issues before they occur while maintaining network connectivity.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If routing is performed for all transmitted traffic, then network communication capability is improved, but power consumption increases significantly for battery-powered devices

Engineering Contradiction:
Improvecommunication capabilityVSAvoidbattery power consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-authenticating nodes and storing authentication results before routing operations. The apparatus maintains a cache of authenticated node identities and authentication outcomes, allowing rapid verification without repeated cryptographic computations during routing. This reduces processing overhead and power consumption while maintaining communication capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by performing full authentication only for neighboring nodes that need to participate in routing, rather than continuously authenticating all network traffic. The apparatus selectively authenticates nodes based on routing needs, storing results for future use. This partial authentication approach reduces overall power consumption while maintaining necessary communication capabilities.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If existing ad hoc routing algorithms are used, then routing functionality is provided, but secure authentication of nodes is not achieved and third party servers are required

Engineering Contradiction:
Improverouting functionalityVSAvoidauthentication infrastructure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies the extraction principle by removing the dependency on third-party certification servers from the authentication process. The apparatus implements distributed authentication where each node independently verifies others using public key infrastructure and digital signatures. The authentication logic and cryptographic verification capabilities are extracted from centralized servers and embedded directly in the wireless communication apparatus, eliminating the need for external infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies self-service by enabling nodes to perform their own authentication and verification operations without external assistance. The apparatus includes cryptographic processing capabilities to generate, store, and verify digital signatures independently. Each node serves its own authentication needs and can verify the authenticity of routing information from other nodes autonomously, reducing system complexity.

Inventive Principle:
Principle #25Self-service

4Productivity

If malicious nodes are allowed to transmit traffic, then network traffic flow is maintained, but network operation is disrupted through overload and resource misuse

Engineering Contradiction:
Improvetraffic flowVSAvoidnetwork disruption
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary action by authenticating nodes before allowing them to transmit or forward traffic. The apparatus verifies the identity and authorization of neighboring nodes using cryptographic methods, storing authentication results in advance. This preliminary verification ensures that only authenticated nodes can participate in routing operations, preventing malicious nodes from disrupting network operation while maintaining traffic flow from legitimate sources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potential harm of allowing unrestricted traffic into a benefit by using cryptographic authentication to identify and filter malicious traffic. The authentication mechanism transforms the problem of unknown node reliability into a solution where verified nodes are positively identified. By requiring digital signatures and verification, the system benefits from the ability to distinguish legitimate traffic sources, converting the challenge of open network access into enhanced security through cryptographic proof of identity.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP1983715B1Wireless network configuration
Publication Date: 2010.05.19 VALTION TEKNILLINEN TUTKIMUSKESKUS
  • EP1983715B1 patent drawingFigure 1~2
  • EP1983715B1 patent drawingFigure 3~4
  • EP1983715B1 patent drawingFigure 5~8

AI summary

Apparatus, computer program and a method for wireless network configuration are disclosed. In the method, a self-certifying identifier of the apparatus is inputted (802) into the apparatus. Next, the apparatus performs (804) an authentication process utilizing the self-certifying identifier of the apparatus with other apparatuses within wireless communication range of the apparatus. Finally, routes to such other apparatuses that passed the authentication process are added (806) to a routing table.