Authentication Server Key Distribution for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure communication between nodes in a network requires extensive key sharing, leading to increased messaging, which is inefficient.

Innovation Solution

A method and apparatus for providing a pairwise transient key (PTK) and group transient key (GTK) for encryption, allowing nodes to authenticate and derive keys during the joining process, reducing the need for extensive messaging through a fast authentication handshake.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If extensive key sharing is performed between nodes to ensure secure communication, then security is improved, but the number of messages required increases

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of messages
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces an authentication server as an intermediary that centrally manages key distribution. Instead of nodes directly exchanging keys with each other (which requires extensive messaging), the authentication server acts as a mediator that distributes keys to nodes. This reduces the number of direct communication messages between nodes while maintaining security through centralized key management and verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional key distribution methods are used, then security is maintained, but communication efficiency decreases due to extensive messaging

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication and key distribution actions before actual data communication begins. Nodes perform authentication and receive keys in advance through the authentication server, so that when actual communication occurs, the key exchange is already complete. This preliminary action separates the security setup phase from the data transmission phase, improving overall communication efficiency.

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If nodes authenticate and derive keys during the joining process, then the number of messages is reduced, but the complexity of key derivation increases

Engineering Contradiction:
Improvenumber of messagesVSAvoidkey derivation complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent extracts the complex key derivation and authentication logic into a separate authentication server. Instead of each node implementing complex key derivation algorithms and performing mutual authentication with every other node, the authentication server centralizes this functionality. Nodes simply need to communicate with the authentication server, which handles the complex derivations and verifications, thereby reducing message overhead while managing complexity centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7461253B2Method and apparatus for providing a key for secure communications
Publication Date: 2008.12.02 ARRIS ENTERPRISES LLC
  • US7461253B2 patent drawing
  • US7461253B2 patent drawing
  • US7461253B2 patent drawing

AI summary

A method and apparatus for providing a key for secure communications is provided herein. During operation a node wishing to join a network, will authenticate with an authentication server and then derive a pairwise key (e.g., a Pair-wise Transient Key (PTK)) used for encryption of unicast traffic. The node will also create its own group transient key (GTK) for use in encrypting multicast or broadcast traffic. Once the GTK is generated, it will be provided to an authenticator as part of an association request message.