Multi-AP Security Key Synchronization via Mobility Anchor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless LAN systems face challenges in efficiently transmitting and receiving security key-related information across multiple access points (APs), which hinders the speed and efficiency of station (STA) movement between APs.

Innovation Solution

A method and device for generating and transmitting security keys based on association information between STAs, using a security parameter element (SPE) that includes BSSID or STA address, allowing APs in a multi-AP set to obtain the same security key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security key-related information is transmitted between multiple APs in a WLAN system, then the speed and efficiency of STA movement between multi-APs is improved, but the complexity of key management and synchronization increases

Engineering Contradiction:
ImproveSTA movement speedVSAvoidkey management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a mobility anchor point (MAP) as an intermediary entity that centralizes security key management. The MAP receives security key-related information from the source AP and distributes it to target APs, eliminating the need for direct peer-to-peer key exchange between multiple APs. This mediator approach simplifies the overall key management architecture while enabling fast STA movement between multi-APs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a security key copying mechanism where the MAP receives security key-related information (including PMK, PTK, or GTK) from the source AP and distributes copies to target APs. This allows target APs to obtain the same security keys without requiring new authentication procedures, enabling seamless STA movement while maintaining security.

Inventive Principle:
Principle #26Copying

2Reliability

If security keys are synchronized across multi-APs using traditional methods, then security is maintained, but the latency and overhead of STA handover increases

Engineering Contradiction:
ImprovesecurityVSAvoidhandover latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the mobility anchor point pre-obtain and store security key-related information from the source AP before the STA actually moves to the target AP. When handover occurs, the target AP already possesses the necessary security keys, eliminating the need for time-consuming re-authentication and key exchange procedures during the actual handover process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuity of security action by maintaining valid security keys across AP transitions. The MAP continuously manages key distribution to ensure that target APs have the same security keys as the source AP, allowing uninterrupted secure communication during STA movement without requiring security procedures to restart.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If each AP generates independent security keys for STAs, then security isolation is maintained, but STA mobility between APs becomes inefficient

Engineering Contradiction:
Improvesecurity isolationVSAvoidSTA mobility efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges security key management across multiple APs through a central mobility anchor point. Instead of each AP independently managing separate security keys, the MAP consolidates key management functions and distributes unified security keys to multiple APs. This merging approach maintains security isolation (each AP still has controlled access to keys) while enabling efficient STA mobility across the multi-AP network.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4645749A1Method and apparatus for transmitting or receiving security key-related information on basis of operation of multiple access points in wireless LAN system
Publication Date: 2025.11.05 LG ELECTRONICS INC
  • EP4645749A1 patent drawingFigure 1
  • EP4645749A1 patent drawingFigure 2~3
  • EP4645749A1 patent drawingFigure 4~5

AI summary

Disclosed are a method and apparatus for transmitting or receiving security key-related information on the basis of the operation of multiple access points (APs) in a wireless LAN system. The method performed by a first station (STA) in a wireless LAN system, according to one embodiment of the present disclosure, may include the steps of: generating a security key for a second STA on the basis of linkage with the second STA; and transmitting, to a third STA, a first message including information related to the security key for the second STA. The first message may include a security parameter element (SPE) including at least one of a basic service set identifier (BSSID) of the first STA or an address of the second STA.