EP3146751B1

Securing a wireless mesh network via a chain of trust

Abstract

This record has no abstract on file.

EP3146751B1, drawing sheet 1
Sheet 1 of 11

Term

Projected expiry 29 April 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Projected expiry

14 claims: 3 independent, 11 dependent

  1. 1
    A computer-implemented method for securing a wireless mesh network of beacon devices, comprising:receiving, by a master beacon device (130) and from a plurality of servant beacon devices (110a, 110b) in a mesh network, survey data comprising, for each of the servant beacon devices (110), a beacon device identifier and a measure to estimate a distance between proximate servant beacon devices (110) detected by each servant beacon device (110), wherein the measure comprises path loss information, a received signal strength indicator, a received channel power indicator, a time of arrival, or a round trip time of proximate servant beacon devices, detected by each servant beacon device;constructing, by the master beacon device (130), a first virtual map of the mesh network based on the received survey, the first virtual map comprising a list of beacon devices in the mesh network identified by the beacon device identifiers and the measure detected by servant beacon devices (110);transmitting, by the master beacon device (130) and to each of the plurality of servant beacon devices (110a, 110b), enrollment data comprising beacon device identifiers and corresponding measure values of proximate beacon devices to servant beacon devices (110), wherein the enrollment data is based on the first virtual map data and wherein the enrollment data may be retransmitted by servant beacon devices (110) within the mesh network to reach other recipient servant beacon devices (110);receiving, by the master beacon device (130), authentication data from a plurality of servant beacon devices (110a, 110b), the authentication data comprising beacon device identifiers for servant beacon devices (110) and the measure detected by servant beacon devices (110) of proximate servant beacon devices;constructing, by the master beacon device (130), a second virtual map of the mesh network based on the received authentication data, the second virtual map comprising a list of all known beacon devices in the mesh network identified by the beacon device identifiers and the measure detected by servant beacon devices (110);comparing, by the master beacon device (130), the first virtual map to the second virtual map;and determining, by the master beacon device (130), that the mesh network is insecure based on identified differences between the first virtual map and the second virtual map.
  2. 8
    A computer program product, comprising:a non-transitory computer-readable medium having computer-readable program instructions embodied thereon that when executed by a computer cause the computer to secure a wireless mesh network of beacon devices, the computer readable instructions comprising: computer-readable program instructions for receiving, by a master beacon device (130) and from a plurality of servant beacon devices (110a, 110b) in a mesh network, survey data comprising, for each of the servant beacon devices (110), a beacon device identifier and a measure to estimate a distance between proximate servant beacon devices (110) detected by each servant beacon device (110), wherein the measure comprises path loss information, a received signal strength indicator, a received channel power indicator, a time of arrival, or a round trip time of proximate servant beacon devices, detected by each servant beacon device;computer-readable program instructions for transmitting to each of the plurality of servant beacon devices (110a, 110b), enrollment data comprising beacon device identifiers and corresponding received measure values of proximate beacon devices to servant beacon devices (110), wherein the enrollment data is based on a first virtual map of the mesh network based on the received survey, and wherein the enrollment data may be retransmitted by servant beacon devices (110) within the mesh network to reach other recipient servant beacon devices (110), the first virtual map data comprising a list of beacon devices (110) in the mesh network identified by the beacon device identifiers and the measure detected by servant beacon devices;computer-readable program instructions for receiving authentication data from a plurality of servant beacon devices (110), the authentication data comprising beacon device identifiers for servant beacon devices (110) and the measure detected by servant beacon devices (110) of proximate servant beacon devices (110);computer-readable program instructions for constructing a second virtual map of the mesh network based on the received authentication data, the second virtual map comprising a list of all known beacon devices in the mesh network identified by the beacon device identifiers and the measure detected by servant beacon devices (110);and computer-readable program instructions for comparing the first virtual map to the second virtual map to identify differences between the first virtual map and the second virtual map;computer-readable program instructions for determining that the mesh network is insecure based on identified differences between the first virtual map and the second virtual map.
  3. 13
    A system for securing a wireless mesh network of beacon devices, comprising:a storage device;and a processor communicatively coupled to the storage device, wherein the processor executes application code instructions that are stored in the storage device to cause the system to: receive, from a plurality of servant beacon devices (110a, 110b) in a mesh network, survey data comprising, for each of the servant beacon devices (110), a beacon device identifier and a measure to estimate a distance between proximate servant beacon devices (110) detected by each servant beacon device (110), wherein the measure comprises path loss information, a received signal strength indicator, a received channel power indicator, a time of arrival, or a round trip time of proximate servant beacon devices, detected by each servant beacon device;construct a first virtual map of the mesh network based on the received survey, the first virtual map comprising a list of beacon devices in the mesh network identified by the beacon device identifiers and the measure detected by servant beacon devices (110);transmit, to each of the plurality of servant beacon devices (110a, 110b), enrollment data comprising beacon device identifiers and corresponding measure values of proximate beacon devices (110) to servant beacon devices (110), wherein the enrollment data is based on the received survey data and wherein the enrollment data may be retransmitted by servant beacon devices (110) within the mesh network to reach other recipient servant beacon devices (110);receive authentication data from a plurality of servant beacon devices (110) in a mesh network, the authentication data comprising beacon device identifiers for servant beacon devices (110) and the measure detected by servant beacon devices (110) of proximate servant beacon devices (110);construct a second virtual map of the mesh network based on the received authentication data, the second virtual map comprising a list of all known beacon devices in the mesh network identified by the beacon device identifiers and the measure detected by servant beacon devices (110);compare the first virtual map to the second virtual map;and determine that the mesh network is insecure based on identified differences between the first virtual map and the second virtual map.