Securing transmission paths in a mesh network
The present disclosure relates to securely setting up mesh networks in a secure manner that does not require a physical network cable being attached to a wireless device and that do not require transmitting unencrypted information wirelessly when a mesh network is setup. Methods and apparatus consistent with the present disclosure may use different communication interfaces and different types of channels to ensure that devices included in or being added to a wireless mesh network always communicate securely. Methods and apparatus consistent with the present disclosure may use a combination of conventional secure communication methods, such as secure hypertext transfer protocol (HTTPS) communications, low power signals that travel over short distances, and other types of communications to create a system that only uses secure communications when setting up or expanding a wireless mesh network.
1 . A method of securing transmission paths in a mesh network, the method comprising:
storing data in a database in memory regarding a wireless mesh network;
receiving, over a communication network, one or more settings via an interface of an onboarding device,
generating a custom profile for configuring a new wireless mesh node device to connect to the wireless mesh network, wherein the custom profile includes one or more security policies in accordance with the one or more settings received from the onboarding device; and
cross-referencing the custom profile to customer information and adding the new wireless mesh node device to the wireless mesh network in accordance with the custom profile and the cross-referenced customer information, wherein electronic packets routed through the new wireless mesh node device are secured in accordance with the one or more security policies associated with the custom profile.
2 . The method of claim 1 , wherein the one or more security policies limit a number of mesh portals with which the new wireless mesh node device is allowed to communicate.
3 . The method of claim 1 , wherein the one or more security policies limit the new wireless mesh node device to a location within a number of hops to a mesh portal.
4 . The method of claim 1 , wherein the one or more security policies specify one or more passcodes or passphrases assigned to the wireless mesh network.
5 . The method of claim 1 , wherein the one or more security policies specify how identifiers of one or more devices are used within the wireless mesh network.
6 . The method of claim 1 , wherein the new wireless mesh node device is one of a plurality of new wireless mesh node devices simultaneously added to the wireless mesh network, and wherein each of the plurality of new wireless mesh node devices is configured in accordance with the custom profile.
7 . The method of claim 6 , wherein the plurality of new wireless mesh node devices communicate in parallel or semi-parallel with the onboarding device using different wireless connections or interleaved communications.
8 . The method of claim 1 , further comprising: sending a unique session token to the onboarding device, and establishing a secure session with the onboarding device in accordance with the unique session token before adding the new wireless mesh node device to the wireless mesh network.
9 . The method of claim 1 , further comprising: receiving a code associated with information regarding the new wireless mesh node device via the onboarding device.
10 . A system of securing transmission paths in a mesh network, the system comprising:
memory that stores data in a database regarding a wireless mesh network;
a communication interface that communicates over a communication network with an onboarding device to receive one or more settings entered via an interface of the onboarding device; and
a processor that executes instructions stored in memory, wherein the processor executes the instructions to:
generate a custom profile for configuring a new wireless mesh node device to connect to the wireless mesh network, wherein the custom profile includes one or more security policies in accordance with the one or more settings received from the onboarding device; and
cross-reference the custom profile to customer information and add the new wireless mesh node device to the wireless mesh network in accordance with the custom profile and the cross-referenced customer information, wherein electronic packets routed through the new wireless mesh node device are secured in accordance with the one or more security policies associated with the custom profile.
11 . The system of claim 10 , wherein the one or more security policies limit a number of mesh portals with which the new wireless mesh node device is allowed to communicate.
12 . The system of claim 10 , wherein the one or more security policies limit the new wireless mesh node device to a location within a number of hops to a mesh portal.
13 . The system of claim 10 , wherein the one or more security policies specify one or more passcodes or passphrases assigned to the wireless mesh network.
14 . The system of claim 10 , wherein the one or more security policies specify how identifiers of one or more devices are used within the wireless mesh network.
15 . The system of claim 10 , wherein the new wireless mesh node device is one of a plurality of new wireless mesh node devices simultaneously added to the wireless mesh network, and wherein each of the plurality of new wireless mesh node devices is configured in accordance with the custom profile.
16 . The system of claim 15 , wherein the plurality of new wireless mesh node devices communicate in parallel or semi-parallel with the onboarding device using different wireless connections or interleaved communications.
17 . The system of claim 10 , wherein the communication interface further sends a unique session token to the onboarding device, and establishes a secure session with the onboarding device in accordance with the unique session token before adding the new wireless mesh node device to the wireless mesh network.
18 . The system of claim 10 , wherein the communication interface further receives a code associated with information regarding the new wireless mesh node device via the onboarding device.
19 . A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor to perform a method of securing transmission paths in a mesh network, the method comprising:
storing data in a database in memory regarding a wireless mesh network;
receiving, over a communication network, one or more settings via an interface of an onboarding device;
generating a custom profile for configuring a new wireless mesh node device to connect to the wireless mesh network, wherein the custom profile includes one or more security policies in accordance with the one or more settings received from the onboarding device; and
cross-referencing the custom profile to customer information and adding the new wireless mesh node device to the wireless mesh network in accordance with the custom profile and the cross-referenced customer information, wherein electronic packets routed through the new wireless mesh node device are secured in accordance with the one or more security policies associated with the custom profile.
20 . The non-transitory computer-readable storage medium of claim 19 , wherein the new wireless mesh node device is one of a plurality of new wireless mesh node devices simultaneously added to the wireless mesh network, and wherein each of the plurality of new wireless mesh node devices is configured in accordance with the custom profile, and wherein the plurality of new wireless mesh node devices communicate in parallel or semi-parallel with the onboarding device using different wireless connections or interleaved communications.