Cascaded Layer 2 Authentication for Home Network Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing home network traffic isolation methods face challenges in efficiently managing layer 2 authentication and encryption across multiple hops, leading to increased network latency and complexity, especially in community Wi-Fi networks where seamless access is required.

Innovation Solution

The implementation of cascaded layer 2 authentication using Extensible Authentication Protocol (EAP) over LAN (EAPoL) and the derivation of pairwise temporary keys (PTK) between Wi-Fi extenders and residential gateways, allowing for end-to-end encryption without the need for joint key establishment, thereby simplifying traffic isolation and reducing latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional home network traffic isolation methods are used, then traffic separation is achieved, but network latency increases and complexity increases

Engineering Contradiction:
Improvetraffic isolationVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs layer 2 authentication and key derivation in advance before data traffic needs to be isolated. By pre-establishing pairwise temporary keys (PTK) between Wi-Fi extenders and residential gateways, the system eliminates the need for real-time authentication during data transmission, thereby reducing network latency while maintaining secure traffic isolation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces Wi-Fi extenders as intermediary devices that facilitate authentication and key management between end devices and residential gateways. These intermediaries handle the complex authentication processes and key derivation, simplifying the overall system architecture and reducing the computational burden on end devices while maintaining secure traffic isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional home network traffic isolation methods are used, then traffic separation is achieved, but device complexity increases

Engineering Contradiction:
Improvetraffic isolationVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication and encryption functions into a unified cascaded layer 2 authentication framework. By merging the authentication process with the key derivation process and integrating these functions across Wi-Fi extenders and residential gateways, the system reduces overall device complexity while maintaining secure traffic isolation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the authentication and key management functions across different network components. Wi-Fi extenders perform local authentication and key derivation, while residential gateways manage overall network security. This segmentation distributes complexity across multiple devices rather than concentrating it in a single point, making the system more manageable and scalable.

Inventive Principle:
Principle #1Segmentation

3Reliability

If joint key establishment is used, then security is maintained, but authentication process becomes more complex

Engineering Contradiction:
Improveencryption securityVSAvoidkey establishment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key establishment process from the traditional joint authentication model and implements it as a cascaded process where keys are derived sequentially through Wi-Fi extenders to residential gateways. This extraction simplifies the authentication protocol by eliminating the need for complex mutual authentication between all parties, while still ensuring secure end-to-end encryption through derived pairwise temporary keys.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10791093B2Home network traffic isolation
Publication Date: 2020.09.29 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US10791093B2 patent drawing
  • US10791093B2 patent drawing
  • US10791093B2 patent drawing

AI summary

Implementations provide for extending an authentication protocol to dynamically create a per user end to end encryption over a multi-hop path for data traffic, which provides an automatic triggering of authentication on each hop of a path when a client joins the network. A device includes a processor that is configured to, in response to receipt of a request for authentication from an end device, perform an authentication protocol to authenticate with an authentication server via an authenticator device. When the authentication protocol is successfully performed, the processor is configured to receive a message indicating that the device was successfully authenticated by the authentication server. The processor is configured to create a pairwise master key (PMK) from the parameters, and derive a pairwise temporary key (PTK) from a key derivation function seeded by the PMK. The processor is configured to encrypt, using the PTK, a message from the end device.