Pair-Wise Security Material Generation in PBSS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Emerging network topologies like piconet basic service set (PBSS) face challenges in efficient key generation and distribution for secure, direct station-to-station and station-to-group communications, particularly due to the complexity of managing multiple broadcast keys and pair-wise keys without a central actor.

Innovation Solution

The method involves computing pair-wise and group-wise security materials as functions of shared secrets and unique data associated with stations, allowing direct secure communications within a PBSS without transit through a central control point, using techniques like EAPoL four-way handshakes for secure communication and minimizing overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If distributed techniques are used in mesh topology for key generation, then central actor dependency is eliminated, but computational intensity and communication overhead increase to O(N^2)

Engineering Contradiction:
Improvetopology flexibilityVSAvoidkey distribution complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a central secret holder/provider (PCP) as an intermediary that generates and distributes group keys to all stations. This mediator approach allows mesh topology flexibility while reducing key distribution complexity from O(N^2) to O(N), as the PCP centrally manages key generation and distribution rather than requiring pairwise key establishment between all station pairs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple broadcast keys are required in PBSS for secure station-to-station communications, then security is improved, but key generation and distribution complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple key management functions into a single group key mechanism. Instead of managing separate pairwise keys for each station pair, the system uses a single group key generated by the PCP that all stations can use for secure communications. This combining approach maintains security while significantly reducing key management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The group key serves multiple functions simultaneously: it enables secure unicast communications between any pair of stations, supports broadcast communications, and eliminates the need for separate key management protocols. This multi-functional key approach reduces overall key management complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If direct station-to-station communications occur without transiting through PCP, then communication efficiency improves, but pair-wise key generation and distribution becomes more complex

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidpair-wise key management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent uses a copying approach where the PCP generates a master group key and distributes copies to all stations. Each station then has an identical copy of the group key, enabling direct communications without requiring complex pairwise key generation. This copying mechanism simplifies key management while supporting efficient direct station-to-station communications.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8813201B2Generating security material
Publication Date: 2014.08.19 MARVELL ASIA PTE LTD
  • US8813201B2 patent drawing
  • US8813201B2 patent drawing
  • US8813201B2 patent drawing

AI summary

An apparatus and method establish a secure, direct, station-to-station communication between a first station and a second station in a topology (e.g., PBSS) having a central secret holder/provider that allows secure, direct, station-to-station communications and that allows secure station-to-station broadcast communications. The first station and the second station will have previously established a security association (SA) with a topology control point (PCP). The method includes creating pair-wise unique material for the first station. The pair-wise unique material is computed as a function of (i) a known shared secret associated with the PCP, (ii) a first piece of unique data associated with the first station, and (iii) a second piece of unique data associated with the second station. The method includes securely communicating the pair-wise unique material from the first station to the second station.