Access Point Manager Roaming Token Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current WiFi 6 networks lack an efficient roaming solution for devices switching between access points, relying on traditional methods like Sticky Key Caching that require repeated authentication processes, leading to storage capacity limitations and inefficiencies.
Innovation Solution
A method where a single Pairwise Master Key (PMK) and Pairwise Master Key Identifier (PMKID) assigned to an endpoint for initial connection to a first access point can be used for subsequent connections to other access points, eliminating the need for repeated Simultaneous Authentication of Equals (SAE) or Opportunistic Wireless Encryption (OWE) processes by distributing an association identifier token across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional Sticky Key Caching is used for roaming, then authentication security is maintained, but storage capacity of network controllers is exceeded and roaming efficiency deteriorates
Solution Approach 1:
The patent extracts the authentication credentials (PMK and PMKID) from the network controller's storage and places them in a distributed cache across multiple access points. This removes the storage burden from the controller while maintaining authentication security, directly resolving the contradiction between security and storage capacity.
Solution Approach 2:
The patent introduces a distributed cache system as an intermediary between the network controller and access points. This intermediary stores authentication credentials locally at access points, eliminating the need for the controller to maintain large storage capacity while preserving security through controlled credential distribution.
2Reliability
If repeated authentication processes are performed for each access point, then security is maintained, but roaming time increases and user experience deteriorates
Solution Approach 1:
The patent performs preliminary authentication actions by distributing PMK and PMKID credentials to access points before roaming occurs. When a device roams, the authentication is already prepared at the target access point, eliminating the need for repeated authentication processes and reducing roaming time while maintaining security.
Solution Approach 2:
The patent creates copies of authentication credentials (PMK and PMKID) and distributes them to multiple access points. This allows a roaming device to use the same authentication credentials at different access points without repeating the full authentication process, significantly reducing roaming time while preserving security through controlled credential distribution.
3Adaptability or versatility
If multiple PMK/PMKID records are maintained for each access point, then roaming between access points is supported, but device complexity and storage requirements increase
Solution Approach 1:
The patent makes authentication credentials universal by distributing the same PMK and PMKID across multiple access points. A single set of credentials can be used at any access point in the network, eliminating the need for device-specific credential management and reducing complexity while maintaining full roaming capability.
Solution Approach 2:
The patent merges the authentication credential management function from individual access points into a centralized distribution system. Instead of each access point maintaining separate PMK/PMKID records, the system combines credentials into a single distributable set that works across all access points, reducing overall system complexity and storage requirements.
Data Source
AI summary
Systems, methods, and computer-readable media are provided for an efficient roaming management method using a single association identifier token for associating with different access points. In one aspect of the present disclosure, a network controller includes memory having computer-readable instructions stored therein and one or more processors. The one or more processors are configured to execute the computer-readable instructions to receive a request from an endpoint to connect to a first access point; generate association identification token (e.g., PMK and PMKID) for the endpoint to connect to the first access point; and distribute the association identification token to a second access point prior to the endpoint attempting to connect to the second access point, the association identification token being used by the second access point to validate a subsequent request by the endpoint to connect to the second access point.


