LiFi Handover Security via Pre-established Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In optical wireless networks, particularly Li-Fi systems, the small coverage area and limited overlapping zones of access points necessitate faster handovers, which introduces latency and security challenges during the handover process from one access point to another, especially when a device is in the middle of a communication session.
Innovation Solution
A subsystem that anticipates potential handovers by obtaining neighbor relationships among access points, selects a candidate access point, and informs the end device to pre-establish a new pairwise transient key before the handover, thereby reducing latency and ensuring a secure transition.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If fast handover is implemented in Li-Fi networks, then handover latency is reduced, but security risks increase during the transition process
Solution Approach 1:
The patent applies preliminary action by pre-establishing security keys and authentication credentials before the handover occurs. The network device prepares security parameters in advance during the initial connection phase, so that when handover is needed, the security framework is already in place and can be quickly activated without compromising security during the transition.
Solution Approach 2:
The patent implements preliminary anti-action by pre-configuring security measures and authentication mechanisms before potential security threats can arise during handover. The system proactively establishes security policies, credentials, and verification protocols in advance, preventing security vulnerabilities rather than reacting to them during the handover process.
2Reliability
If security protocols are established during handover, then security is maintained, but handover speed decreases
Solution Approach 1:
Security protocols, keys, and authentication credentials are established during the initial connection phase rather than during handover. This preliminary setup ensures that when handover occurs, the security framework is already in place and can be quickly activated without compromising security during the transition.
Solution Approach 2:
The patent uses an intermediary approach by implementing a security management entity that handles security protocol execution separately from the main handover data path. This intermediary structure allows security verification to occur in parallel or pre-configured, reducing the impact on handover speed while maintaining security requirements.
3Reliability
If pre-establishing security keys is implemented, then handover security is improved, but device complexity increases
Solution Approach 1:
The patent applies self-service by implementing automated key generation, management, and verification systems that operate without manual intervention. The network devices automatically handle security credential provisioning, storage, and validation during handover, reducing the perceived complexity for users while maintaining robust security protocols in the background.
Solution Approach 2:
The patent implements a universal security management architecture that handles multiple security functions (key generation, storage, verification, and rotation) through a single integrated system. This multi-functional approach consolidates what would otherwise be separate complex processes into a unified security framework that simplifies overall device complexity while maintaining comprehensive security coverage.
Data Source
AI summary
Because of the line-of-sight character of optical wireless communication and a limited field-of-view of optical receivers, the coverage of an access point (120) and the overlapping coverage area of adjacent access points (120) in an optical system are smaller as compared to a RF system. It turns more challenging to support an end point (110) to roam securely in an optical multi-cell wireless communication network (100). To address that problem, a subsystem is disclosed to select for the end point (110) a candidate access point out of the plurality of access points (120) in view of one or more neighbor relationships, and to inform the end point (110) about the candidate access point to trigger the end point (110) to start a procedure for pre-establishing a new pairwise transient key between the end point (110) and the candidate access point (120) for a secure handover.


