Distributed R0KH Handoff in Wireless Mesh Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless mesh network standards, such as IEEE 802.11i and IEEE 802.11r, are limited in scope to indoor enterprise architecture and have drawbacks in high availability and fast handoff capabilities, particularly due to a single point of failure in the key hierarchy and diminished ROKH handoff when the R0KH is outside the radio access network.
Innovation Solution
The implementation of multiple ROKHs (first level key holders) within a wireless mesh network, where each mesh access point takes the role of a second level key holder (RIKH) and propagates the identity of ROKHs and mobility domain identifiers, enabling fast secure handoffs without relying on a centralized key hierarchy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized key hierarchy with a single R0KH is used to manage security in a mobility domain, then security management is simplified and centralized control is achieved, but the system becomes vulnerable to single point of failure and handoff availability is reduced
Solution Approach 1:
The patent divides the centralized key hierarchy into multiple distributed R0KH instances across different access points. Instead of relying on a single R0KH, the system segments the key management function across multiple nodes, allowing mobile devices to handoff to alternative R0KHs when the primary one is unavailable, thus eliminating the single point of failure while maintaining security management functionality.
2Adaptability or versatility
If the R0KH is located outside the radio access network to provide centralized security services, then network architecture flexibility is improved, but ROKH handoff capability is significantly diminished
Solution Approach 1:
The patent distributes R0KH instances across multiple access points within the radio access network, adding a spatial dimension to key holder placement. This allows mobile devices to perform fast handoffs by switching between co-located R0KHs at different access points without requiring long-distance communication with an external R0KH, thus maintaining both architectural flexibility and handoff speed.
3Reliability
If IEEE 802.11i and IEEE 802.11r standards are applied to indoor enterprise architecture, then secure handoff is achieved within that scope, but the solution is not adaptable to wide area mesh networks with mobile nodes
Solution Approach 1:
The patent extends the IEEE 802.11r fast BSS transition mechanism to wide area mesh networks by making access points universal nodes that can simultaneously function as mesh routers and security domain controllers. Each access point with an embedded R0KH can serve multiple functions: providing mesh routing, maintaining security associations, and enabling fast handoffs, thus making the solution universally applicable to both indoor enterprise and wide area mesh networks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed is a method for providing fast secure handoff in a wireless mesh network. The method comprises configuring multiple first level key holders (R0KHs) within a radio access network to which supplicants within the multi-hop wireless mesh network are capable of establishing a security association, configuring a common mobility domain identifier within the first level key holders of a mobility domain, and propagating identity of a first level key holder and the mobility domain identifier through the wireless mesh network to enable the supplicants within the mobility domain to perform fast secure handoff.