BRAS-AC Key Notification via CAPWAP Handshake Trigger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In WLAN networks where the Broadband Remote Access Server (BRAS) is separate from the Access Controller (AC), there is a lack of internal communication mechanism for the BRAS to notify the AC of the master key, preventing the AC from initiating a 4-way handshake with the WLAN station to agree on a transient key.

Innovation Solution

The BRAS sends a CAPWAP message carrying the master key and a 4-way handshake triggering bit to the AC, allowing the AC to perform the handshake with the WLAN station, ensuring secure encryption of data transmitted over the wireless link using the WPA2 standard.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the BRAS and AC are integrated as a single device, then internal communication mechanisms can be used to notify the AC of the master key, but the system architecture becomes less flexible and harder to deploy in distributed networks

Engineering Contradiction:
Improvekey notification reliabilityVSAvoidsystem architecture flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system is segmented into separate BRAS and AC devices that communicate through standardized CAPWAP protocols. The BRAS handles authentication and key generation, while the AC handles wireless access management. This segmentation allows independent deployment and scaling of each component while maintaining reliable key notification through the defined protocol interface.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CAPWAP protocol acts as an intermediary mechanism between the BRAS and AC. It provides a standardized interface for key notification, allowing secure key transmission without requiring direct internal communication or integration. The protocol includes specific message types for key delivery and handshake triggering, ensuring reliable communication between separate devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the BRAS sends the master key to the AC through external communication, then system flexibility is improved, but the key transmission security and timing coordination become more complex

Engineering Contradiction:
Improvesystem architecture flexibilityVSAvoidcommunication protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The CAPWAP protocol is designed to handle multiple functions within a unified framework: authentication, key transmission, handshake triggering, and wireless access management. By using this universal protocol, the system avoids creating separate complex communication mechanisms for each function, reducing overall complexity while maintaining flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The protocol uses parameter changes in message fields to control the state transitions of the key management process. Specific bits and fields in CAPWAP messages indicate key types, transmission modes, and handshake requirements, allowing the system to adapt to different scenarios through parameter variation rather than structural complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the AC performs the 4-way handshake immediately upon receiving the master key, then security is improved, but the timing coordination and message synchronization become more critical

Engineering Contradiction:
Improveencryption securityVSAvoidhandshake timing coordination
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The BRAS performs preliminary actions by generating and securely transmitting the master key to the AC before the actual wireless authentication occurs. The AC is pre-configured with the key material needed to initiate the 4-way handshake, allowing immediate security establishment once the handshake is triggered without delays in key preparation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The protocol implements feedback mechanisms where the AC confirms receipt of the master key and readiness to perform the handshake. The BRAS sends triggering messages that include timing and synchronization information, and the AC provides feedback on its state, allowing coordinated execution of the security handshake without timing conflicts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8842830B2Method and apparatus for sending a key on a wireless local area network
Publication Date: 2014.09.23 HUAWEI TECH CO LTD
  • US8842830B2 patent drawing
  • US8842830B2 patent drawing
  • US8842830B2 patent drawing

AI summary

A method and an apparatus for sending a key on a Wireless Local Area Network (WLAN) is provided. In a scenario where an Access Server is separate from an Access Controller, the Access Controller may send a master key of a specified WLAN station to the AC and trigger the AC to agree with the station on a transient key. The method includes: when receiving the master key of the WLAN station sent from an AAA server, searching a station information table for an IP address of an AC associated with the station; sending a message to the AC to instruct the AC to perform a 4-way handshake with the station to agree on a transient key, where the third message carries the master key of the station, a 4-way handshake triggering bit, and a MAC address of the WLAN station.