Cellular Network Handover Key Distribution via Encryption Tickets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current handover procedures in cellular networks, such as those in WiFi, GSM, or WiMax, face significant delays due to lengthy re-association times, which are incompatible with real-time services like voice over IP, and existing fast pre-authentication solutions have drawbacks such as non-compliance with IEEE802.11i standards and reliance on complex secure link configurations between access points.
Innovation Solution
A method for advance distribution of encrypted encryption keys to target attachment points, where an encryption ticket containing a key specific to the target attachment point is created and decrypted by the target point itself, ensuring secure communication without revealing private cryptographic information to intermediate points, and pre-identifying potential target attachment points reduces unnecessary information distribution and optimizes resource allocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the complete standardized IEEE802.11i procedure is used for handover, then security authentication is ensured, but re-association time becomes too long (order of a second) for real-time services
Solution Approach 1:
The patent performs preliminary authentication and key distribution before the actual handover occurs. The target access point receives and stores authentication keys and encryption tickets in advance through the current access point, so that when handover occurs, the terminal can quickly associate with the target point without undergoing the complete 4-way handshake, reducing re-association time to under 50ms while maintaining security
Solution Approach 2:
The current access point acts as an intermediary to transfer authentication keys and encryption tickets from the terminal to the target access point before handover. This intermediary mechanism enables pre-distribution of security credentials without requiring direct communication between terminal and target access point, facilitating fast authentication while preserving security protocols
2Loss of time
If pre-authentication is performed before handover to reduce re-association time, then handover speed improves, but strict conditions must be met to comply with IEEE802.11i standards
Solution Approach 1:
The patent segments the authentication process into two distinct phases: a preliminary phase where authentication keys and encryption tickets are distributed and stored at the target access point before handover, and a completion phase where the actual handover occurs with minimal authentication steps. This segmentation allows the system to meet IEEE802.11i security requirements while achieving fast handover performance
Solution Approach 2:
The patent changes the timing parameter of authentication operations, moving key distribution and authentication verification to occur before handover rather than during or after. This parameter change in the authentication timeline enables the system to satisfy security protocol requirements while reducing the critical handover time to under 50ms
3Loss of time
If encryption keys are distributed in advance to target access points, then handover speed improves, but private cryptographic information may be exposed to intermediate points
Solution Approach 1:
The current access point serves as a secure intermediary that receives encryption tickets from the terminal and forwards them to the target access point without exposing the cryptographic content. The intermediary only handles encrypted data and cannot decipher it, ensuring that private cryptographic information remains protected even during the pre-distribution phase while enabling fast handover
Solution Approach 2:
The patent uses encryption tickets as secure copies of authentication credentials that can be replicated and transmitted without exposing the original secret keys. The target access point receives encrypted copies of authentication information that it can use for verification without needing access to the terminal's private cryptographic material, thus preventing exposure while enabling fast authentication
Data Source
Figure 1A~1B
Figure 2
Figure 3~4
AI summary
The invention relates to a method of early distribution of at least one encryption key intended for securing a communication to be set up on the link layer of a cellular network formed of a plurality of cells each controlled by an attachment point, between a mobile terminal and a set of attachment points, termed the target attachment points. According to the invention, such a method comprises, for at least one target attachment point, the following steps: creation of an encryption ticket containing an encryption key, enciphered on the basis of at least one authentication key specific to this target attachment point; receipt of said enciphered encryption ticket, by way of a current attachment point to which said mobile terminal is connected; identification, of a means of deciphering said enciphered encryption ticket, with the aid of said at least one authentication key, making it possible to obtain said encryption key.