AP Node Token Management for Seamless Roaming Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication networks, especially in scenarios with large data volumes and ultra-low latency like AR/VR, the roaming process between Access Point (AP) nodes causes delays and security risks due to the need for reconnection and renegotiation of keys, which can lead to data leakage when attacked by sniffers, especially in devices not supporting standards like 802.11r or WPA3.
Innovation Solution
A new communication mechanism where multiple AP nodes share the same identification information, allowing seamless switching without re-establishing connections, thereby reducing latency and enhancing security by using a token-based system for authentication and key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional roaming mechanism is used where terminal device scans and dynamically selects AP nodes, then load balance can be achieved, but latency increases and communication security deteriorates due to reconnection and key renegotiation requirements
Solution Approach 1:
Multiple AP nodes are merged to share the same identification information (SSID, BSSID, AID) so that they appear as a single AP to the terminal device. This allows the terminal to switch between AP nodes without detecting any change in identity, thereby avoiding reconnection and key renegotiation, which resolves both latency and security issues simultaneously
Solution Approach 2:
The system performs preliminary key distribution to multiple AP nodes before the terminal device actually needs to switch. When a switch is required, the terminal can immediately use the pre-distributed keys to communicate with the new AP node without undergoing time-consuming key renegotiation, thus reducing latency while maintaining security
2Productivity
If AP nodes use different identification information, then each AP can be uniquely identified, but seamless switching cannot be achieved and reconnection delays occur
Solution Approach 1:
Multiple AP nodes are merged to share the same identification information (SSID, BSSID, AID) so that they appear as a single AP to the terminal device. This allows the terminal to switch between AP nodes without detecting any change in identity, thereby avoiding reconnection and key renegotiation, which resolves both latency and security issues simultaneously
Solution Approach 2:
A token-based system is introduced as an intermediary to manage the identification information. The token is distributed to multiple AP nodes and serves as a mediator that enables them to share the same identification information while maintaining unique functionality. This intermediary mechanism simplifies the overall system by providing a clear method for managing shared identifiers
3Reliability
If key renegotiation is performed during AP switching, then security is maintained, but data leakage risk increases when attacked by sniffers
Solution Approach 1:
The system performs preliminary key distribution to multiple AP nodes before the terminal device actually needs to switch. When a switch is required, the terminal can immediately use the pre-distributed keys to communicate with the new AP node without undergoing time-consuming key renegotiation, thus reducing latency while maintaining security
Solution Approach 2:
The patent applies the skipping principle by allowing the terminal device to skip the key renegotiation step during AP switching. Since keys are pre-distributed to multiple AP nodes, the terminal can directly use existing keys to communicate with the new AP node, rushing through the switching process without the vulnerable key renegotiation phase that would otherwise expose data to sniffers
Data Source
AI summary
A first device in a communication network receives from at least one second device in the communication network, a first request for acquiring a token, the token being permission for communicating with a third device. Based on the first request, a device from the at least one second device and the first device as a communication device is selected for providing a communication service to the third device in the communication network; and the token is transmitted to the communication device. The communication device receives the token for communicating with the third device. Other devices receive key information associated with communication of the third device from the first device, and monitor data associated with the communication of the third device.


