Caching PMKID for WLAN Reconnection Without EAP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network authentication protocols require re-authentication when a WLAN connection is dropped and re-established, leading to unnecessary resource consumption and transmission of EAP messages.
Innovation Solution
Implementing a method where a client device caches a pairwise master key identifier (PMKID) upon connection drop, allowing for secure reconnection without EAP re-authentication by providing the PMKID to the WLAN access point, which verifies its validity and permits network access without re-authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP re-authentication is performed when WLAN connection is dropped and re-established, then security is maintained, but computing resources and network resources are unnecessarily consumed
Solution Approach 1:
The patent applies preliminary action by caching the pairwise master key (PMK) and its identifier (PMKID) before the connection is actually dropped. When the connection drops and the device re-establishes connection to the same access point, the cached PMKID is reused to avoid re-authentication. This preliminary caching enables fast reconnection while maintaining security, as the authenticated session information is preserved and can be quickly validated without full EAP re-authentication.
2Reliability
If EAP re-authentication is performed when WLAN connection is dropped and re-established, then authentication security is ensured, but transmission of EAP messages increases network traffic
Solution Approach 1:
The patent extracts the essential authentication element (PMKID) from the full EAP authentication process. Instead of transmitting complete EAP messages during reconnection, only the compact PMKID is transmitted and verified. This extraction allows the system to maintain authentication security while dramatically reducing network traffic, as the PMKID serves as a succinct representation of the authenticated session.
3Reliability
If full EAP authentication is performed on reconnection, then security is maintained, but connection establishment time increases
Solution Approach 1:
The patent applies preliminary action by pre-computing and caching the pairwise master key (PMK) and its identifier (PMKID) during the initial authentication process. When the device reconnects to the same access point, the cached PMKID is immediately available for verification, eliminating the need for time-consuming full EAP authentication. This preliminary preparation enables rapid reconnection while maintaining security through the validated cached credentials.
Data Source
AI summary
A device may determine that a first wireless local area network (WLAN) connection, established with a first WLAN access point using an extensible authentication protocol, has been dropped. The device may store a pairwise master key identifier, associated with the first WLAN access point, based on determining that the first WLAN connection has been dropped. The device may detect a WLAN signal, associated with the first WLAN access point or a second WLAN access point, after determining that the first WLAN connection has been dropped. The device may provide the pairwise master key identifier to the first WLAN access point or the second WLAN access point based on detecting the WLAN signal. The device may establish a second WLAN connection with the first WLAN access point or the second WLAN access point based on providing the pairwise master key identifier and without re-authenticating using the extensible authentication protocol.


