Wireless Controller Encryption Offload for Access Point Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional implementations of wireless LAN security protocols, such as WEP, WPA, and WPA2, only encrypt data between wireless clients and access points, leaving data transfers between access points and switches insecure and susceptible to attacks, while also increasing the cost, complexity, and power requirements of access points by performing cryptographic operations.
Innovation Solution
Offloading encryption and decryption from access points to network switches, which handle wire-speed encryption and manage per-client or broadcast/multicast encryption, ensuring secure data transfer between access points and switches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic operations are performed on the access point, then wireless data security is improved, but the cost, complexity, and power requirements of the access point increase
Solution Approach 1:
The patent extracts the cryptographic processing functions from the access point and relocates them to the wireless controller. The access point only performs encapsulation and forwarding, while the wireless controller handles all encryption/decryption operations, thereby reducing access point complexity while maintaining security.
Solution Approach 2:
The patent introduces an intermediary encapsulation mechanism where data is wrapped in a tunnel protocol format between the access point and wireless controller. This intermediary structure allows the access point to forward encrypted data without performing cryptographic operations, reducing its complexity while maintaining end-to-end security.
2Reliability
If cryptographic operations are performed on the access point, then wireless data security is improved, but the power requirements of the access point increase
Solution Approach 1:
The patent extracts power-intensive cryptographic operations from the access point and concentrates them in the wireless controller, which has superior processing capabilities. This reduces the access point's power consumption while maintaining the same security level through centralized encryption/decryption.
3Reliability
If per client key management is performed on the access point, then wireless security is improved, but client roaming time increases
Solution Approach 1:
The patent extracts key management functions from the access point and centralizes them in the wireless controller. During roaming, the controller handles key distribution and re-keying operations, allowing the access point to quickly forward frames without waiting for key management operations, thereby reducing roaming time while maintaining security.
4Adaptability or versatility
If data is transmitted through a shared tunnel between access point and wireless controller, then network flexibility is improved, but data security between access point and switch deteriorates
Solution Approach 1:
The patent segments the data transmission path into two distinct security zones: an encrypted wireless segment from client to access point, and an encrypted wired segment from access point to wireless controller using tunnel encapsulation. This segmentation allows the wired portion to be protected through protocol-level encryption while maintaining network flexibility.
Solution Approach 2:
The patent uses composite encapsulation where the original data packet is wrapped in a tunnel protocol format with additional security headers. This composite structure provides both the flexibility of standard IP routing and the security of encrypted transport, combining the benefits of both approaches.
Data Source
AI summary
In one embodiment, a method for processing encrypted wireless station data at a network device includes receiving from an access point, one or more frames comprising wireless station data fragmented into a plurality of encrypted protocol data units. The frames are configured to identify the encrypted protocol units associated with the wireless station data. The method further includes decrypting the encrypted protocol data units and forwarding the wireless station data. An apparatus for processing encrypted wireless station data, a method for transmitting encrypted multicast data for a wireless client, and a method for processing encrypted wireless station data at an access point are also disclosed.


