LiFi Handover Security via Pre-established Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In optical wireless networks, particularly Li-Fi systems, the small coverage area and limited overlapping zones of access points necessitate faster handovers, which introduces latency and security challenges during the handover process from one access point to another, especially when a device is in the middle of a communication session.

Innovation Solution

A subsystem that anticipates potential handovers by obtaining neighbor relationships among access points, selects a candidate access point, and informs the end device to pre-establish a new pairwise transient key before the handover, thereby reducing latency and ensuring a secure transition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If fast handover is implemented in Li-Fi networks, then handover latency is reduced, but security risks increase during the transition process

Engineering Contradiction:
Improvehandover latencyVSAvoidhandover security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-establishing security keys and authentication credentials before the handover occurs. The network device prepares security parameters in advance during the initial connection phase, so that when handover is needed, the security framework is already in place and can be quickly activated without compromising security during the transition.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements preliminary anti-action by pre-configuring security measures and authentication mechanisms before potential security threats can arise during handover. The system proactively establishes security policies, credentials, and verification protocols in advance, preventing security vulnerabilities rather than reacting to them during the handover process.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If security protocols are established during handover, then security is maintained, but handover speed decreases

Engineering Contradiction:
Improvehandover securityVSAvoidhandover speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Security protocols, keys, and authentication credentials are established during the initial connection phase rather than during handover. This preliminary setup ensures that when handover occurs, the security framework is already in place and can be quickly activated without compromising security during the transition.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by implementing a security management entity that handles security protocol execution separately from the main handover data path. This intermediary structure allows security verification to occur in parallel or pre-configured, reducing the impact on handover speed while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If pre-establishing security keys is implemented, then handover security is improved, but device complexity increases

Engineering Contradiction:
Improvehandover securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by implementing automated key generation, management, and verification systems that operate without manual intervention. The network devices automatically handle security credential provisioning, storage, and validation during handover, reducing the perceived complexity for users while maintaining robust security protocols in the background.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a universal security management architecture that handles multiple security functions (key generation, storage, verification, and rotation) through a single integrated system. This multi-functional approach consolidates what would otherwise be separate complex processes into a unified security framework that simplifies overall device complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12192834B2Secure handover in a LiFi network
Publication Date: 2025.01.07 SIGNIFY HOLDING BV
  • US12192834B2 patent drawing
  • US12192834B2 patent drawing
  • US12192834B2 patent drawing

AI summary

Because of the line-of-sight character of optical wireless communication and a limited field-of-view of optical receivers, the coverage of an access point (120) and the overlapping coverage area of adjacent access points (120) in an optical system are smaller as compared to a RF system. It turns more challenging to support an end point (110) to roam securely in an optical multi-cell wireless communication network (100). To address that problem, a subsystem is disclosed to select for the end point (110) a candidate access point out of the plurality of access points (120) in view of one or more neighbor relationships, and to inform the end point (110) about the candidate access point to trigger the end point (110) to start a procedure for pre-establishing a new pairwise transient key between the end point (110) and the candidate access point (120) for a secure handover.