Dynamic Group Transient Key Management in Wireless LAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless LAN systems in mixed mode environments face challenges in determining the timing for generating a group transient key (GTK) due to unclear security states of mobile stations, leading to failed GTK exchanges and settings.

Innovation Solution

An apparatus and method for dynamically managing GTKs, which include a GTK generation timing deciding unit, a GTK generating unit, a GTK exchanging unit, and a GTK setting unit, that assess the security state of connected mobile stations to determine the appropriate timing for GTK generation and exchange, ensuring only authenticated stations participate in GTK exchanges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the AP includes all connected MSs on the GTK exchange target list, then the AP can attempt GTK exchange with more stations, but the AP cannot determine proper timing for GTK generation due to unclear security states, leading to failed GTK exchanges

Engineering Contradiction:
ImproveGTK exchange coverageVSAvoidGTK exchange success rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the MSs into different categories based on their security states (authenticated vs. unauthenticated, and their support for specific key exchange algorithms). This segmentation allows the AP to determine proper timing for GTK generation by first ensuring MSs are authenticated and then exchanging GTKs only with MSs that support the required algorithms, thereby resolving the contradiction between exchange coverage and success rate

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary authentication of MSs before including them in the GTK exchange process. The AP checks whether each MS is authenticated and whether it supports the necessary key exchange algorithms before initiating GTK exchange. This preliminary action ensures that GTK exchange timing is properly determined and that only suitable MSs participate, improving both the reliability and adaptability of the process

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If the AP uses conventional authentication methods without checking security states, then the authentication process is simpler, but the AP cannot determine when to generate GTKs, causing GTK setting failures

Engineering Contradiction:
Improveauthentication process complexityVSAvoidGTK setting success
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the AP continuously monitors the security state of connected MSs and uses this information to determine the appropriate timing for GTK generation and exchange. The AP checks authentication status and algorithm support feedback from MSs, adjusting the GTK exchange process accordingly. This feedback loop resolves the contradiction by adding necessary monitoring complexity to ensure reliable GTK setting success

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the AP exchanges GTK with all MSs regardless of authentication status, then more MSs can participate in GTK exchange, but unauthenticated MSs cause GTK exchange failures

Engineering Contradiction:
Improvenumber of participating MSsVSAvoidGTK exchange reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by treating different MSs differently based on their individual security states and algorithm support capabilities. The AP checks each MS's authentication status and key exchange algorithm support before including them in GTK exchange. This localized differentiation ensures that only authenticated MSs supporting the required algorithms participate, maintaining both adaptability to diverse MS types and reliability of the exchange process

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7477746B2Apparatus for dynamically managing group transient key in wireless local area network system and method thereof
Publication Date: 2009.01.13 ELECTRONICS & TELECOMM RES INST
  • US7477746B2 patent drawing
  • US7477746B2 patent drawing
  • US7477746B2 patent drawing

AI summary

An apparatus for dynamically managing a group transient key (GTK) and a method thereof in order to perform setting of a GTK successfully by an access point (AP). Wherein, the AP checks security state of a plurality of mobile stations (MS)s connecting to the AP, and exchanges and sets a GTK for authenticated MSs. The apparatus for managing a GTK in a wireless LAN system, the apparatus including: a GTK generation timing deciding unit for deciding timing to generate a GTK based on security state of an MS; a GTK generating unit for generating a GTK according to the GTK generation timing decided in the GTK generation timing deciding unit; a GTK exchanging unit for exchanging the GTK generated in the GTK generating unit based on the security state of the MS; and a GTK setting unit for setting the GTK based on the number of MSs exchanged the GTK.