Disjoint security in wireless networks with multiple managers or access points

US2018317089A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2018317089-A1
Application numberUS-201815963055-A
CountryUS
Kind codeA1
Filing dateApr 25, 2018
Priority dateMay 1, 2017
Publication dateNov 1, 2018
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In a wireless mesh network having multiple network managers, the network managers maintain network security through the use of encryption keys and packet counters. To ensure that each network manager can authenticate communications with any node of the network, the authentication data is replicated in a disjoint manner in all network managers. Advantageously, network reliability is assured by providing redundant managers that can seamlessly maintain network operation even if multiple network managers fail; newly joining managers can obtain full authentication data for the network upon joining; and network throughput is increased by ensuring that any of the multiple managers can authenticate the communications of any network node. The disjoint replication of the authentication data across all network managers is performed with low data-rate manager-to-manager packets propagated through the network. The disjoint security methods and systems can advantageously be used in wireless battery monitoring systems, for example.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for coordinating authentication between network manager devices, the method comprising: receiving, in a first network manager device, from a wireless network node via a first wireless mesh network access point of the wireless mesh network, a join request to join the wireless network node with the wireless mesh network; generating, in response to receiving the join request, authentication data to authenticate subsequent communications passing through the first network manager device between the joined wireless network node and a host application external to the wireless mesh network; storing the authentication data at the first network manager device; and transmitting, by the first network manager device, the authentication data to a second network manager device of the wireless mesh network for storage and use by the second network manager device to authenticate subsequent communications passing through the second network manager device and between the joined wireless network node and the host application. 2 . The method of claim 1 , wherein the authentication data comprises an encryption key associated with the wireless network node, and the first network manager device uses the encryption key to encrypt or decrypt subsequent communications passing through the first network manager device between the host application and the wireless network node. 3 . The method of claim 2 , wherein the encryption key is a unicast encryption key specific to the wireless network node, and the first network manager device stores a different unicast encryption key associated with each different wireless network node of the wireless mesh network. 4 . The method of claim 2 , wherein the encryption key is a broadcast encryption key used to encrypt broadcast packets transmitted to all wireless network nodes of the wireless mesh network. 5 . The method of claim 1 , wherein at least one of the subsequent communications is received from a second wireless mesh network access point of the wireless mesh network, remote from the first wireless mesh network access point, and the authentication data is wirelessly transmitted from the first network manager device to the second network manager device. 6 . The method of claim 5 , wherein the authentication data is transmitted via the first wireless mesh network access point, one or more wireless network nodes of the wireless mesh network, and the second wireless mesh network access point from the first network manager device to the second network manager device. 7 . The method of claim 1 , wherein the authentication data comprises, for each node of the wireless mesh network, a count of communications sent to or received from the node, and wherein the method further comprises: authenticating, by the first network manager device, a respective communication passing through the first network manager device and between a respective node and the host application based on the count of the authentication data for the respective node. 8 . The method of claim 7 , further comprising: resetting, by the first network manager device, a first counter based on receiving the join request from the wireless network node seeking to join the wireless mesh network; incrementing, following resetting of the first counter, the first counter for each packet received by the first network manager device from the wireless network node; and transmitting, by the first network manager device, a respective increment by which the first counter has been incremented to the second network manager device for use by the second network manager device in maintaining a second counter associated with the wireless network node that is synchronized with the first counter. 9 . The method of claim 8 , wherein the reset and incremented first counter is an upstream counter, the method further comprising: setting a downstream counter associated with the wireless network node in response to receiving the join request from the wireless network node; incrementing the downstream counter for each packet transmitted from the first network manager device to the wireless network node; following incrementing the downstream counter, transmitting a count value of the downstream counter to the second network manager device associated with a second wireless mesh network access point; and authenticating, in the wireless network node, a respective communication received from the first network manager device based on a count of the downstream counter included in the respective communication. 10 . The method of claim 1 , further comprising: receiving, by the first network manager device via the first wireless mesh network access point, from a new network manager device seeking to join the wireless mesh network, a join request to join the new network manager device with the wireless mesh network; in response to receiving the join request to join the new network manager device: joining the new network manager device with the wireless mesh network, and transmitting, by the first network manager device to the new network manager device, authentication data stored by the first network manager device for all wireless network nodes of the wireless mesh network. 11 . A network manager device comprising: a communication interface for establishing a communication link, via a first wireless mesh network access point, with a wireless mesh network; a processor communicatively connected to the communication interface; and a non-transitory memory device storing program instructions which, when executed by the processor, cause the network manager device to: receive, from a wireless network node via the first wireless mesh network access point, a join request to join the wireless network node with the wireless mesh network; generate, in response to receiving the join request, authentication data to authenticate subsequent communications passing through the network manager device between the joined wireless network node and a host application external to the wireless mesh network; store the authentication data at the network manager device; and transmit the authentication data to another network manager device of the wireless mesh network for storage and use by the other network manager device to authenticate subsequent communications passing through the other network manager device and between the joined wireless network node and the host application. 12 . The network manager device of claim 11 , wherein the authentication data comprises an encryption key associated with the wireless network node, and the network manager device is configured to use the encryption key to encrypt or decrypt subsequent communications passing through the network manager device between the host application and the wireless network node. 13 . The network manager device of claim 12 , wherein the encryption key is a unicast encryption key specific to the wireless network node, and the network manager device stores a different unicast encryption key associated with each different wireless network node of the wireless mesh network. 14 . The network manager device of claim 12 , wherein the encryption key is a broadcast encryption key used to encrypt broadcast packets transmitted to all wireless network nodes of the wireless mesh network. 15 . The network manager device of claim 11 , wherein at least one of the subsequent communications is received from a second wireless mesh network access point of the wireless mesh network, remote from the first wireless mesh network access point, and the authentication data is wireless

Assignees

Inventors

Classifications

  • using selective relaying for reaching a BTS [Base Transceiver Station] or an access point · CPC title

  • Self-organising networks, e.g. ad-hoc networks or sensor networks · CPC title

  • Wireless · CPC title

  • Hierarchical topologies · CPC title

  • Access security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2018317089A1 cover?
In a wireless mesh network having multiple network managers, the network managers maintain network security through the use of encryption keys and packet counters. To ensure that each network manager can authenticate communications with any node of the network, the authentication data is replicated in a disjoint manner in all network managers. Advantageously, network reliability is assured by p…
Who is the assignee on this patent?
Linear Tech Corp
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Nov 01 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).