Authentication Resumption for Wireless Roaming Handoffs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless communication methods require full authentication with a new service provider's authentication server when switching from one wireless access point to another, leading to lengthy handoff times and inefficient network connectivity.

Innovation Solution

Implementing authentication resumption by storing and reusing security association information from a previous service provider to establish a new wireless connection with a different service provider's network, allowing for quicker handoffs and reduced authentication time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full authentication with a new service provider's authentication server is performed when switching wireless access points, then network security is maintained, but handoff time increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidhandoff time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by storing security association information (SAI) including authentication credentials during the initial connection to the first service provider. When roaming to a second service provider, this pre-stored SAI is reused to bypass full authentication, thus maintaining security while reducing handoff time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the security association information from the first service provider and uses this copy to establish connection with the second service provider. This copying mechanism allows the device to leverage prior authentication credentials without performing complete authentication again, resolving the contradiction between security and speed.

Inventive Principle:
Principle #26Copying

2Speed

If security association information is stored and reused from a previous service provider, then handoff speed improves, but authentication security may be compromised

Engineering Contradiction:
Improvehandoff speedVSAvoidauthentication security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system introduces a roaming authentication server as an intermediary between the wireless device and the second service provider's authentication server. This intermediary validates the reused security association information and coordinates with both service providers to ensure that security requirements are met while enabling fast handoff through credential reuse.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If conventional authentication protocols are used for each wireless access point connection, then authentication thoroughness is ensured, but network connectivity efficiency decreases

Engineering Contradiction:
Improveauthentication thoroughnessVSAvoidnetwork connectivity efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication process is segmented into two phases: initial comprehensive authentication with the first service provider where full security checks are performed, and subsequent streamlined authentication with the second service provider using pre-stored security association information. This segmentation allows thorough authentication when needed while enabling efficient connectivity during roaming.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11706823B2Communication management and wireless roaming support
Publication Date: 2023.07.18 TIME WARNER CABLE ENTERPRISES LLC
  • US11706823B2 patent drawing
  • US11706823B2 patent drawing
  • US11706823B2 patent drawing

AI summary

A user-operated communication device stores security association information that is initially used to wirelessly connect the user-operated communication device to a first wireless access point made available by a first private wireless network service provider. Assume that the user-operated communication device roams out of a first wireless coverage region supported by the first wireless access point into wireless range of a second wireless access point operated by a second private wireless network service provider. Instead of performing full authentication to establish a wireless communication link with the second wireless access point, the user-operated communication device requests authentication resumption and utilizes the stored security association information (provided by the first service provider) to more quickly, wirelessly connect the communication device to the second wireless access point. Accordingly, techniques herein support authentication resumption across different service providers' wireless networks.