Authentication Resumption for Wireless Roaming Handoffs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless communication methods require full authentication with a new service provider's authentication server when switching from one wireless access point to another, leading to lengthy handoff times and inefficient network connectivity.
Innovation Solution
Implementing authentication resumption by storing and reusing security association information from a previous service provider to establish a new wireless connection with a different service provider's network, allowing for quicker handoffs and reduced authentication time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full authentication with a new service provider's authentication server is performed when switching wireless access points, then network security is maintained, but handoff time increases significantly
Solution Approach 1:
The system performs preliminary actions by storing security association information (SAI) including authentication credentials during the initial connection to the first service provider. When roaming to a second service provider, this pre-stored SAI is reused to bypass full authentication, thus maintaining security while reducing handoff time.
Solution Approach 2:
The system creates a copy of the security association information from the first service provider and uses this copy to establish connection with the second service provider. This copying mechanism allows the device to leverage prior authentication credentials without performing complete authentication again, resolving the contradiction between security and speed.
2Speed
If security association information is stored and reused from a previous service provider, then handoff speed improves, but authentication security may be compromised
Solution Approach 1:
The system introduces a roaming authentication server as an intermediary between the wireless device and the second service provider's authentication server. This intermediary validates the reused security association information and coordinates with both service providers to ensure that security requirements are met while enabling fast handoff through credential reuse.
3Reliability
If conventional authentication protocols are used for each wireless access point connection, then authentication thoroughness is ensured, but network connectivity efficiency decreases
Solution Approach 1:
The authentication process is segmented into two phases: initial comprehensive authentication with the first service provider where full security checks are performed, and subsequent streamlined authentication with the second service provider using pre-stored security association information. This segmentation allows thorough authentication when needed while enabling efficient connectivity during roaming.
Data Source
AI summary
A user-operated communication device stores security association information that is initially used to wirelessly connect the user-operated communication device to a first wireless access point made available by a first private wireless network service provider. Assume that the user-operated communication device roams out of a first wireless coverage region supported by the first wireless access point into wireless range of a second wireless access point operated by a second private wireless network service provider. Instead of performing full authentication to establish a wireless communication link with the second wireless access point, the user-operated communication device requests authentication resumption and utilizes the stored security association information (provided by the first service provider) to more quickly, wirelessly connect the communication device to the second wireless access point. Accordingly, techniques herein support authentication resumption across different service providers' wireless networks.


