Multi-Hop Wireless Node Registration via Encrypted Matrix Barcode

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-hop wireless networks lack secure registration and ignition processes, making them vulnerable to unauthorized access, as they do not have built-in security features like trusted platform modules (TPMs), allowing malicious actors to pose as authorized nodes and potentially disrupt the network.

Innovation Solution

A secure registration and ignition process using a matrix barcode label with encrypted registration information, where the network node's MAC address, serial number, and firmware hash are encrypted with a public key, allowing only authorized nodes to join the network by decrypting the information with a private key stored in the network management system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If no security features like TPMs are implemented in network nodes, then device complexity and cost are reduced, but the network becomes vulnerable to unauthorized access and malicious actors can pose as authorized nodes

Engineering Contradiction:
Improvenetwork securityVSAvoidnode security features
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a matrix barcode as an intermediary carrier that holds encrypted registration information. Instead of embedding security features directly in the network node, the security credentials are externalized into a scannable barcode label that can be read during registration, thus providing security without adding complex hardware to the node itself

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses encrypted registration information (MAC address, serial number, firmware hash) stored in a matrix barcode as a secure copy of the node's identity credentials. This allows the node to prove its authenticity without having to physically contain all security verification mechanisms, as the verified copy resides in the barcode and is validated by the network management system

Inventive Principle:
Principle #26Copying

2Reliability

If a secure registration process with encrypted information is implemented, then unauthorized access is prevented, but the registration and ignition processes become more complex

Engineering Contradiction:
Improveaccess securityVSAvoidregistration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual or complex physical security verification processes with optical scanning of a matrix barcode. Instead of manual entry or complex hardware handshaking, the registration information is optically captured via barcode scanning, significantly simplifying the user interface and process flow while maintaining cryptographic security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent performs encryption of registration information in advance during node manufacturing, storing the encrypted data in a matrix barcode before deployment. This preliminary encryption action ensures that when the node is registered in the field, the security verification is already prepared and只需 requires scanning and decryption, rather than performing complex cryptographic operations in real-time during registration

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10320762B2Secure registration and ignition of network nodes on a multi-hop wireless network
Publication Date: 2019.06.11 META PLATFORMS INC
  • US10320762B2 patent drawing
  • US10320762B2 patent drawing
  • US10320762B2 patent drawing

AI summary

In one embodiment, a method includes receiving from a requesting network node identifying information, and accessing registration information of previously registered network nodes of a multi-hop wireless network. The registration information includes a firmware hash or a serial number of the previously registered network node. The registration information may have been extracted from the previously registered network node and communicated to the network-management system as cipher text encoded with a public key and decoded at the network-management system with a private key. The method may further include comparing the identifying information of the requesting network node with the registration information of the previously registered network nodes to determine whether the requesting network node is one of the previously registered network nodes. If, based on the comparison, the requesting network node is one of the previously registered network nodes, then the requesting node may be permitted to join the network.