Neighbor Key Cache Servers for Fast Roaming in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key caching mechanisms in large wireless local area networks (WLANs) face challenges in efficiently managing key caching across a large number of access points (APs) and client devices, leading to increased latency and user experience issues during client mobility and roaming.

Innovation Solution

The implementation of Neighbor Key Cache Servers (NKCSs) that store and manage client device or session key data across overlapping wireless networks, enabling fast reauthentication between access points of the same or different WLAN operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If key caching is implemented using centralized controller-based solutions, then reauthentication speed is improved, but system resource requirements and device complexity increase significantly

Engineering Contradiction:
Improvereauthentication latencyVSAvoidsystem resource requirements
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent segments the centralized key cache into distributed key caches located at individual access points and regional key caches. This segmentation allows key caching functionality to be distributed across multiple nodes rather than concentrated in a single centralized controller, reducing the resource burden on any single device while maintaining fast reauthentication capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to key cache architecture by adding regional key caches that serve multiple access points. This creates a multi-level cache structure (access point level, regional level, and network level) that distributes the caching burden across different spatial and organizational dimensions, reducing complexity at any single point.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If key caching is restricted to specific groups of APs, then system resource requirements are reduced, but roaming reliability deteriorates due to failed key cache usage

Engineering Contradiction:
Improvesystem resource requirementsVSAvoidroaming reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces regional key caches as intermediary entities between access points and the network. These regional caches act as mediators that store key information for multiple access points within a region, allowing clients to perform fast reauthentication when moving between access points in the same region without requiring full authentication, thereby improving roaming reliability while distributing the caching burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple access points into regional groups managed by shared regional key caches. By combining the key caching functionality for multiple access points into regional units, the system reduces overall resource requirements compared to having separate caches at each access point, while still maintaining reliable fast roaming within each regional group.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If full authentication exchanges are performed during roaming, then security is maintained, but user experience deteriorates due to service interruption

Engineering Contradiction:
ImprovesecurityVSAvoidservice interruption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary key caching during initial authentication, where key information is pre-stored in access point caches and regional key caches before roaming occurs. When a client needs to roam, the pre-cached keys enable fast reauthentication without requiring full authentication exchanges, thus maintaining security while eliminating service interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the authentication parameter from full authentication (requiring complete credential verification) to fast reauthentication (using pre-shared keys). This parameter change allows the system to maintain security requirements while dramatically reducing the time and resources needed for the authentication process during roaming events.

Inventive Principle:
Principle #35Parameter changes

4Loss of time

If neighbor reports are generated based on SSID or ESSID match criteria, then roaming speed is improved, but adaptability deteriorates for large scale deployments with multiple operators

Engineering Contradiction:
Improveroaming speedVSAvoidmulti-operator compatibility
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The patent enhances neighbor report functionality to serve multiple purposes: it not only provides SSID/ESSID matching for fast roaming within the same network but also includes information about neighboring access points from different operators and regions. This universal neighbor report mechanism supports both intra-operator and inter-operator roaming scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent makes the neighbor report mechanism dynamic by allowing it to adapt to different deployment scenarios. The reports can include various types of information depending on the context: SSID-based information for same-network roaming, regional boundary information for inter-region roaming, and multi-operator information for partner network roaming, making the system adaptable to large-scale multi-operator deployments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250175794A1Dynamic key caching for fast roaming in secured wireless networks
Publication Date: 2025.05.29 CHARTER COMM OPERATING LLC
  • US20250175794A1 patent drawing
  • US20250175794A1 patent drawing
  • US20250175794A1 patent drawing

AI summary

Various embodiments comprise systems, methods, architectures, mechanisms and apparatus for caching and sharing client/device keys, session keys, and so on between APs of overlapping wireless networks operated by same or different wireless local areal network (WLAN) operators via one or more Neighbor Key Cache Servers (NKCSs) configured to store client device or session key data for client devices overlapping network boundaries so as to facilitate fast reauthentication between presently serving and target access points (APs) of the same or different WLAN operators. Neighbor reports data may comprise data based on WLAN/SSID from APs associated with each of a plurality of AP home regions and/or realm/Network Access Identifiers from APs associated with an overlapping network of a different WLAN operator.