Wireless Controller Encryption Offload for Access Point Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional implementations of wireless LAN security protocols, such as WEP, WPA, and WPA2, only encrypt data between wireless clients and access points, leaving data transfers between access points and switches insecure and susceptible to attacks, while also increasing the cost, complexity, and power requirements of access points by performing cryptographic operations.

Innovation Solution

Offloading encryption and decryption from access points to network switches, which handle wire-speed encryption and manage per-client or broadcast/multicast encryption, ensuring secure data transfer between access points and switches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic operations are performed on the access point, then wireless data security is improved, but the cost, complexity, and power requirements of the access point increase

Engineering Contradiction:
Improvedata securityVSAvoidaccess point complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic processing functions from the access point and relocates them to the wireless controller. The access point only performs encapsulation and forwarding, while the wireless controller handles all encryption/decryption operations, thereby reducing access point complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary encapsulation mechanism where data is wrapped in a tunnel protocol format between the access point and wireless controller. This intermediary structure allows the access point to forward encrypted data without performing cryptographic operations, reducing its complexity while maintaining end-to-end security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic operations are performed on the access point, then wireless data security is improved, but the power requirements of the access point increase

Engineering Contradiction:
Improvedata securityVSAvoidaccess point power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts power-intensive cryptographic operations from the access point and concentrates them in the wireless controller, which has superior processing capabilities. This reduces the access point's power consumption while maintaining the same security level through centralized encryption/decryption.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If per client key management is performed on the access point, then wireless security is improved, but client roaming time increases

Engineering Contradiction:
Improvewireless securityVSAvoidclient roaming time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts key management functions from the access point and centralizes them in the wireless controller. During roaming, the controller handles key distribution and re-keying operations, allowing the access point to quickly forward frames without waiting for key management operations, thereby reducing roaming time while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If data is transmitted through a shared tunnel between access point and wireless controller, then network flexibility is improved, but data security between access point and switch deteriorates

Engineering Contradiction:
Improvenetwork flexibilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the data transmission path into two distinct security zones: an encrypted wireless segment from client to access point, and an encrypted wired segment from access point to wireless controller using tunnel encapsulation. This segmentation allows the wired portion to be protected through protocol-level encryption while maintaining network flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses composite encapsulation where the original data packet is wrapped in a tunnel protocol format with additional security headers. This composite structure provides both the flexibility of standard IP routing and the security of encrypted transport, combining the benefits of both approaches.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS8320567B2Efficient data path encapsulation between access point and access switch
Publication Date: 2012.11.27 CISCO TECHNOLOGY INC
  • US8320567B2 patent drawing
  • US8320567B2 patent drawing
  • US8320567B2 patent drawing

AI summary

In one embodiment, a method for processing encrypted wireless station data at a network device includes receiving from an access point, one or more frames comprising wireless station data fragmented into a plurality of encrypted protocol data units. The frames are configured to identify the encrypted protocol units associated with the wireless station data. The method further includes decrypting the encrypted protocol data units and forwarding the wireless station data. An apparatus for processing encrypted wireless station data, a method for transmitting encrypted multicast data for a wireless client, and a method for processing encrypted wireless station data at an access point are also disclosed.