Wireless Access Point Link Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless mesh networks face security risks due to widespread sharing of encryption keys, leading to potential network shutdowns when a single access point's key is compromised, and inconvenience during maintenance or repair.

Innovation Solution

Implementing a system where each access point in a wireless mesh network uses a separate encryption key for each link, with a supplicant and authenticator processing unit that manages authentication and key distribution independently, preventing key sharing and allowing localized security breaches without network-wide shutdowns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If all access points share a single group key distributed from a master access point, then key management is simplified, but network security is compromised because a single key compromise endangers the entire network

Engineering Contradiction:
Improvekey management complexityVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single group key into multiple individual link keys, where each access point has a unique key for each wireless link it establishes. This segmentation isolates security breaches to individual links rather than compromising the entire network, while the authentication server automates key distribution to maintain manageable complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication server acts as an intermediary that automatically generates, distributes, and manages individual link keys between access points. This intermediary eliminates the need for manual key distribution while implementing fine-grained key isolation, thereby maintaining simplicity through automation while achieving enhanced security through key segmentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a group key is compromised or an access point is removed for servicing, then security must be maintained, but the entire network must be shut down to change the group key

Engineering Contradiction:
Improvesecurity integrityVSAvoidnetwork availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting security into individual link keys rather than a single group key, the patent enables localized security management. When one access point's key is compromised or the access point needs maintenance, only that specific link key needs to be changed, not all keys in the network. This allows other parts of the network to continue operating normally, maintaining productivity while ensuring security integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different security keying to different wireless links. Each link has its own key, allowing security changes to be applied locally at the affected link or access point rather than globally across the entire network. This enables maintenance and security updates without network-wide shutdowns.

Inventive Principle:
Principle #3Local quality

3Reliability

If access points use separate encryption keys for each link, then network security is improved against key compromise, but key management complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server provides self-service key management by automatically generating individual link keys and distributing them to the appropriate access points without requiring manual intervention. Each access point receives its unique link keys automatically, and the system handles key updates and rotations autonomously, thereby achieving fine-grained security without proportionally increasing operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication server serves as an intermediary that manages the complexity of individual link key distribution. Rather than requiring each access point to manually manage keys for every link, the intermediary automatically handles key generation, distribution, and updates, thereby achieving enhanced security through individual link keys while keeping management complexity manageable through automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7596368B2Wireless access point apparatus and method of establishing secure wireless links
Publication Date: 2009.09.29 OKI ELECTRIC INDUSTRY CO LTD
  • US7596368B2 patent drawing
  • US7596368B2 patent drawing
  • US7596368B2 patent drawing

AI summary

A wireless network is connectable to an authentication server. Each access point in the wireless network includes a supplicant processing unit, an authenticator processing unit, and a function selector. When an access point is detected within communication range, the function selector selects either the supplicant processing unit or the authenticator processing unit. The selected unit operates to carry out or mediate an authentication protocol and establish a secure wireless link, protected by a pairwise encryption key, between the two access points. Because every access point can operate as either an authenticator or a supplicant, it is not necessary to invoke the services of a master authenticator. If an encryption key is compromised, the effect is limited and does not force the entire network to be shut down.