Authentication Server Key Distribution for Secure AP Fast Transition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing fast transitioning protocols in wireless networks, such as IEEE 802.11r, expose the first-level key (PMK-R0) and add complexity to access points (APs), compromising security and scalability.

Innovation Solution

An authentication server holds the first-level key (PMK-R0) and derives the second-level key (PMK-R1), distributing it securely to neighboring APs without exposing PMK-R0, thus maintaining security and reducing complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If existing fast transitioning protocols (IEEE 802.11r) are used, then fast transitioning between APs is enabled, but the first-level key (PMK-R0) is exposed and security is compromised

Engineering Contradiction:
Improvetransitioning speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the APs and the key management system. The server receives authentication requests from APs, verifies credentials against a centralized database, and manages key distribution without requiring APs to directly handle or expose the first-level key (PMK-R0). This mediator architecture enables fast transitioning while maintaining security by centralizing sensitive key management functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If existing fast transitioning protocols are implemented in APs, then fast transitioning is achieved, but device complexity increases

Engineering Contradiction:
Improvetransitioning speedVSAvoidAP complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent extracts complex key management functions from the APs and relocates them to a centralized authentication server. Specifically, the generation and secure storage of the first-level key (PMK-R0), credential verification, and key distribution logic are removed from APs and consolidated in the authentication server. This extraction reduces AP complexity while maintaining fast transitioning capability through simplified authentication procedures.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If the first-level key is distributed to multiple APs, then fast transitioning is enabled, but security is compromised due to key exposure

Engineering Contradiction:
Improveroaming capabilityVSAvoidkey exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a selective key distribution mechanism where the authentication server generates and distributes only the necessary second-level keys (PMK-R1) to specific APs that have been authenticated and authorized. The first-level key (PMK-R0) remains securely stored only in the authentication server's centralized database. This copying approach enables roaming capability across multiple APs while minimizing key exposure risk by distributing only derived keys with limited scope.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12520144B2Key distribution from an authentication server
Publication Date: 2026.01.06 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12520144B2 patent drawing
  • US12520144B2 patent drawing
  • US12520144B2 patent drawing

AI summary

In some examples, as part of an authentication process for an electronic device when connecting to a first access point (AP), an authentication server generates a first key of a hierarchy of keys. The authentication server receives a request from a second AP, and generates a second key based on the first key, the second key being part of the hierarchy of keys. In response to the request, the authentication server distributes the second key from the authentication server to the second AP for use in data protection for communications between the second AP and the electronic device after the electronic device has transitioned from the first AP to the second AP.