Authentication Server Key Distribution for Secure AP Fast Transition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing fast transitioning protocols in wireless networks, such as IEEE 802.11r, expose the first-level key (PMK-R0) and add complexity to access points (APs), compromising security and scalability.
Innovation Solution
An authentication server holds the first-level key (PMK-R0) and derives the second-level key (PMK-R1), distributing it securely to neighboring APs without exposing PMK-R0, thus maintaining security and reducing complexity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If existing fast transitioning protocols (IEEE 802.11r) are used, then fast transitioning between APs is enabled, but the first-level key (PMK-R0) is exposed and security is compromised
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the APs and the key management system. The server receives authentication requests from APs, verifies credentials against a centralized database, and manages key distribution without requiring APs to directly handle or expose the first-level key (PMK-R0). This mediator architecture enables fast transitioning while maintaining security by centralizing sensitive key management functions.
2Speed
If existing fast transitioning protocols are implemented in APs, then fast transitioning is achieved, but device complexity increases
Solution Approach 1:
The patent extracts complex key management functions from the APs and relocates them to a centralized authentication server. Specifically, the generation and secure storage of the first-level key (PMK-R0), credential verification, and key distribution logic are removed from APs and consolidated in the authentication server. This extraction reduces AP complexity while maintaining fast transitioning capability through simplified authentication procedures.
3Adaptability or versatility
If the first-level key is distributed to multiple APs, then fast transitioning is enabled, but security is compromised due to key exposure
Solution Approach 1:
The patent implements a selective key distribution mechanism where the authentication server generates and distributes only the necessary second-level keys (PMK-R1) to specific APs that have been authenticated and authorized. The first-level key (PMK-R0) remains securely stored only in the authentication server's centralized database. This copying approach enables roaming capability across multiple APs while minimizing key exposure risk by distributing only derived keys with limited scope.
Data Source
AI summary
In some examples, as part of an authentication process for an electronic device when connecting to a first access point (AP), an authentication server generates a first key of a hierarchy of keys. The authentication server receives a request from a second AP, and generates a second key based on the first key, the second key being part of the hierarchy of keys. In response to the request, the authentication server distributes the second key from the authentication server to the second AP for use in data protection for communications between the second AP and the electronic device after the electronic device has transitioned from the first AP to the second AP.


