Method, Apparatus, and Device for Managing Authentication Data of STA
US-2017063828-A1 · Mar 2, 2017 · US
US2018317089A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2018317089-A1 |
| Application number | US-201815963055-A |
| Country | US |
| Kind code | A1 |
| Filing date | Apr 25, 2018 |
| Priority date | May 1, 2017 |
| Publication date | Nov 1, 2018 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
In a wireless mesh network having multiple network managers, the network managers maintain network security through the use of encryption keys and packet counters. To ensure that each network manager can authenticate communications with any node of the network, the authentication data is replicated in a disjoint manner in all network managers. Advantageously, network reliability is assured by providing redundant managers that can seamlessly maintain network operation even if multiple network managers fail; newly joining managers can obtain full authentication data for the network upon joining; and network throughput is increased by ensuring that any of the multiple managers can authenticate the communications of any network node. The disjoint replication of the authentication data across all network managers is performed with low data-rate manager-to-manager packets propagated through the network. The disjoint security methods and systems can advantageously be used in wireless battery monitoring systems, for example.
Opening claim text (preview).
What is claimed is: 1 . A method for coordinating authentication between network manager devices, the method comprising: receiving, in a first network manager device, from a wireless network node via a first wireless mesh network access point of the wireless mesh network, a join request to join the wireless network node with the wireless mesh network; generating, in response to receiving the join request, authentication data to authenticate subsequent communications passing through the first network manager device between the joined wireless network node and a host application external to the wireless mesh network; storing the authentication data at the first network manager device; and transmitting, by the first network manager device, the authentication data to a second network manager device of the wireless mesh network for storage and use by the second network manager device to authenticate subsequent communications passing through the second network manager device and between the joined wireless network node and the host application. 2 . The method of claim 1 , wherein the authentication data comprises an encryption key associated with the wireless network node, and the first network manager device uses the encryption key to encrypt or decrypt subsequent communications passing through the first network manager device between the host application and the wireless network node. 3 . The method of claim 2 , wherein the encryption key is a unicast encryption key specific to the wireless network node, and the first network manager device stores a different unicast encryption key associated with each different wireless network node of the wireless mesh network. 4 . The method of claim 2 , wherein the encryption key is a broadcast encryption key used to encrypt broadcast packets transmitted to all wireless network nodes of the wireless mesh network. 5 . The method of claim 1 , wherein at least one of the subsequent communications is received from a second wireless mesh network access point of the wireless mesh network, remote from the first wireless mesh network access point, and the authentication data is wirelessly transmitted from the first network manager device to the second network manager device. 6 . The method of claim 5 , wherein the authentication data is transmitted via the first wireless mesh network access point, one or more wireless network nodes of the wireless mesh network, and the second wireless mesh network access point from the first network manager device to the second network manager device. 7 . The method of claim 1 , wherein the authentication data comprises, for each node of the wireless mesh network, a count of communications sent to or received from the node, and wherein the method further comprises: authenticating, by the first network manager device, a respective communication passing through the first network manager device and between a respective node and the host application based on the count of the authentication data for the respective node. 8 . The method of claim 7 , further comprising: resetting, by the first network manager device, a first counter based on receiving the join request from the wireless network node seeking to join the wireless mesh network; incrementing, following resetting of the first counter, the first counter for each packet received by the first network manager device from the wireless network node; and transmitting, by the first network manager device, a respective increment by which the first counter has been incremented to the second network manager device for use by the second network manager device in maintaining a second counter associated with the wireless network node that is synchronized with the first counter. 9 . The method of claim 8 , wherein the reset and incremented first counter is an upstream counter, the method further comprising: setting a downstream counter associated with the wireless network node in response to receiving the join request from the wireless network node; incrementing the downstream counter for each packet transmitted from the first network manager device to the wireless network node; following incrementing the downstream counter, transmitting a count value of the downstream counter to the second network manager device associated with a second wireless mesh network access point; and authenticating, in the wireless network node, a respective communication received from the first network manager device based on a count of the downstream counter included in the respective communication. 10 . The method of claim 1 , further comprising: receiving, by the first network manager device via the first wireless mesh network access point, from a new network manager device seeking to join the wireless mesh network, a join request to join the new network manager device with the wireless mesh network; in response to receiving the join request to join the new network manager device: joining the new network manager device with the wireless mesh network, and transmitting, by the first network manager device to the new network manager device, authentication data stored by the first network manager device for all wireless network nodes of the wireless mesh network. 11 . A network manager device comprising: a communication interface for establishing a communication link, via a first wireless mesh network access point, with a wireless mesh network; a processor communicatively connected to the communication interface; and a non-transitory memory device storing program instructions which, when executed by the processor, cause the network manager device to: receive, from a wireless network node via the first wireless mesh network access point, a join request to join the wireless network node with the wireless mesh network; generate, in response to receiving the join request, authentication data to authenticate subsequent communications passing through the network manager device between the joined wireless network node and a host application external to the wireless mesh network; store the authentication data at the network manager device; and transmit the authentication data to another network manager device of the wireless mesh network for storage and use by the other network manager device to authenticate subsequent communications passing through the other network manager device and between the joined wireless network node and the host application. 12 . The network manager device of claim 11 , wherein the authentication data comprises an encryption key associated with the wireless network node, and the network manager device is configured to use the encryption key to encrypt or decrypt subsequent communications passing through the network manager device between the host application and the wireless network node. 13 . The network manager device of claim 12 , wherein the encryption key is a unicast encryption key specific to the wireless network node, and the network manager device stores a different unicast encryption key associated with each different wireless network node of the wireless mesh network. 14 . The network manager device of claim 12 , wherein the encryption key is a broadcast encryption key used to encrypt broadcast packets transmitted to all wireless network nodes of the wireless mesh network. 15 . The network manager device of claim 11 , wherein at least one of the subsequent communications is received from a second wireless mesh network access point of the wireless mesh network, remote from the first wireless mesh network access point, and the authentication data is wireless
using selective relaying for reaching a BTS [Base Transceiver Station] or an access point · CPC title
Self-organising networks, e.g. ad-hoc networks or sensor networks · CPC title
Wireless · CPC title
Hierarchical topologies · CPC title
Access security · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.