Ad-hoc Network Encryption Key Sharing via 4-Way Handshake

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In ad-hoc wireless LAN environments, managing and distributing encryption keys for secure communication is challenging, especially when new terminals join the network, as there is no central management mechanism and the 4-way handshake process is unclear, making it difficult to share and update encryption keys among multiple terminals.

Innovation Solution

A communication apparatus and method that includes sharing means to distribute encryption keys, determination means to assess key possession, and control means to initiate key sharing processes, allowing new terminals to join the network securely by executing 4-way and group key handshakes, ensuring all terminals share a consistent encryption key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a common encryption key is used for all terminals in an ad-hoc network, then key management complexity for each terminal is reduced, but it becomes difficult to assign the same encryption key to new terminals joining the network

Engineering Contradiction:
Improvekey management complexityVSAvoidability to assign key to new terminals
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by having existing terminals store the public keys of other terminals in advance. When a new terminal joins, the existing terminals already have the necessary public key information to initiate key sharing through the 4-way handshake process, eliminating the need for manual key distribution to new terminals.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses public keys as an intermediary mechanism. Instead of directly sharing secret encryption keys between all terminals, the system uses public keys that can be freely distributed as a mediator. The 4-way handshake then uses these public keys to securely derive and share session-specific encryption keys, solving the problem of key distribution to new terminals.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If each terminal possesses the encryption key of every other terminal, then secure direct communication between any terminals is enabled, but the more terminals there are, the more difficult key management becomes

Engineering Contradiction:
Improvesecurity of direct communicationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management process into two distinct parts: public keys that are freely distributed and stored by all terminals, and session-specific encryption keys that are derived through the 4-way handshake process. This segmentation allows terminals to have the necessary information for secure communication without needing to store all other terminals' secret keys, reducing key management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces public keys as an intermediary that enables secure communication without requiring terminals to possess each other's secret encryption keys. The 4-way handshake acts as a mediator that uses exchanged public keys to derive shared session keys, maintaining security while simplifying key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If a new terminal initiates the 4-way handshake to join the network, then the new terminal can obtain a group key, but the group key that was being utilized on the network thus far cannot be distributed to new terminals

Engineering Contradiction:
Improveability of new terminal to join networkVSAvoidconsistency of group key across network
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies dynamics by making the 4-way handshake process bidirectional - either the new terminal or an existing terminal can initiate the handshake. The system dynamically determines which terminal acts as the authenticator and which acts as the supplicant based on who initiates the connection, allowing flexible key distribution while maintaining group key consistency through the standardized handshake protocol.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If the terminal that initiates 4-way handshake is undetermined in ad-hoc mode, then terminals can freely join the network, but there is no mechanism to manage which terminals exist on the network centrally

Engineering Contradiction:
Improvefreedom of terminal joiningVSAvoidability to find and initiate handshake with target terminal
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by having terminals store public key information in advance. This pre-stored information enables terminals to identify and initiate handshakes with target terminals without requiring centralized management or real-time discovery mechanisms, maintaining network freedom while improving operational ease.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9021576B2Apparatus and method for sharing of an encryption key in an ad-hoc network
Publication Date: 2015.04.28 CANON KK
  • US9021576B2 patent drawing
  • US9021576B2 patent drawing
  • US9021576B2 patent drawing

AI summary

It is so arranged that an encryption key can be shared with a communication apparatus that participates in a network anew, even in an ad-hoc-mode type of environment. In order to achieve this, a communication apparatus determines whether it possesses an encryption key shared with another communication apparatus and, in accordance with the result of the determination, initiates sharing process for sharing the encryption key with a first communication apparatus from the communication apparatus after the sharing process for sharing the encryption key has been initiated from the first communication apparatus.