Distributed R0KH Handoff in Wireless Mesh Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless mesh network standards, such as IEEE 802.11i and IEEE 802.11r, are limited in scope to indoor enterprise architecture and have drawbacks in high availability and fast handoff capabilities, particularly due to a single point of failure in the key hierarchy and diminished ROKH handoff when the R0KH is outside the radio access network.

Innovation Solution

The implementation of multiple ROKHs (first level key holders) within a wireless mesh network, where each mesh access point takes the role of a second level key holder (RIKH) and propagates the identity of ROKHs and mobility domain identifiers, enabling fast secure handoffs without relying on a centralized key hierarchy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a centralized key hierarchy with a single R0KH is used to manage security in a mobility domain, then security management is simplified and centralized control is achieved, but the system becomes vulnerable to single point of failure and handoff availability is reduced

Engineering Contradiction:
Improvekey hierarchy managementVSAvoidhandoff availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the centralized key hierarchy into multiple distributed R0KH instances across different access points. Instead of relying on a single R0KH, the system segments the key management function across multiple nodes, allowing mobile devices to handoff to alternative R0KHs when the primary one is unavailable, thus eliminating the single point of failure while maintaining security management functionality.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the R0KH is located outside the radio access network to provide centralized security services, then network architecture flexibility is improved, but ROKH handoff capability is significantly diminished

Engineering Contradiction:
Improvenetwork architecture flexibilityVSAvoidROKH handoff speed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent distributes R0KH instances across multiple access points within the radio access network, adding a spatial dimension to key holder placement. This allows mobile devices to perform fast handoffs by switching between co-located R0KHs at different access points without requiring long-distance communication with an external R0KH, thus maintaining both architectural flexibility and handoff speed.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If IEEE 802.11i and IEEE 802.11r standards are applied to indoor enterprise architecture, then secure handoff is achieved within that scope, but the solution is not adaptable to wide area mesh networks with mobile nodes

Engineering Contradiction:
Improvesecure handoffVSAvoidnetwork scope applicability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends the IEEE 802.11r fast BSS transition mechanism to wide area mesh networks by making access points universal nodes that can simultaneously function as mesh routers and security domain controllers. Each access point with an embedded R0KH can serve multiple functions: providing mesh routing, maintaining security associations, and enabling fast handoffs, thus making the solution universally applicable to both indoor enterprise and wide area mesh networks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2210438B1Method for providing fast secure handoff in a wireless mesh network
Publication Date: 2018.12.26 ARRIS ENTERPRISES LLC
  • EP2210438B1 patent drawingFigure 1
  • EP2210438B1 patent drawingFigure 2
  • EP2210438B1 patent drawingFigure 3

AI summary

Disclosed is a method for providing fast secure handoff in a wireless mesh network. The method comprises configuring multiple first level key holders (R0KHs) within a radio access network to which supplicants within the multi-hop wireless mesh network are capable of establishing a security association, configuring a common mobility domain identifier within the first level key holders of a mobility domain, and propagating identity of a first level key holder and the mobility domain identifier through the wireless mesh network to enable the supplicants within the mobility domain to perform fast secure handoff.