Precaching Roaming Keys to Reduce Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional client device roaming across different subnets in networks often results in latency and interruptions due to the need for deauthentication and reauthentication at new access points, which involves complex key computations and IP address renewals, leading to inefficiencies and resource consumption.

Innovation Solution

A computing system that proactively caches precursor keys at clusters with a high probability of being roamed to, allowing seamless roaming by eliminating the need for authentication at new access points and retaining the original IP address, thereby reducing latency and conserving resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If client device performs deauthentication and reauthentication at new access points during roaming, then security is maintained, but latency and service interruption occur

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by caching precursor keys (PMK-R0, PMK-R1) at the home cluster before roaming occurs. When a client device roams to a foreign cluster, the authentication is already complete, eliminating the time-consuming deauthentication and reauthentication process while maintaining security. The precursor keys are valid for a predetermined time period, enabling seamless roaming without service interruption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If client device reauthenticates at new access points during roaming, then access security is ensured, but resource consumption increases

Engineering Contradiction:
Improveaccess securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The home cluster pre-computes and caches precursor keys (PMK-R0, PMK-R1) before roaming occurs. When the client device roams to a foreign cluster within the roaming domain, these pre-computed keys are used for authentication, eliminating the need for resource-intensive reauthentication processes at the new access point. This significantly reduces computational overhead and energy consumption while maintaining access security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If client device performs IP address renewal during roaming, then network connectivity is maintained, but latency and service interruption occur

Engineering Contradiction:
Improvenetwork connectivityVSAvoidservice interruption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary IP address allocation by assigning a home cluster IP address to the client device before roaming occurs. The home cluster acts as an anchor point, maintaining the IP address assignment even when the device roams to foreign clusters. This eliminates the need for IP address renewal during roaming, preventing service interruption and maintaining continuous network connectivity.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If traditional roaming authentication process is used, then security is maintained, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The home cluster performs preliminary authentication and key derivation, caching the precursor keys (PMK-R0, PMK-R1) before roaming occurs. When the client device roams to a foreign cluster, the authentication process is significantly simplified because the precursor keys are already available. This reduces the processing overhead and complexity at both the client device and foreign cluster while maintaining security through the use of WPA3-SAE authentication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11778467B2Precaching precursor keys within a roaming domain of client devices
Publication Date: 2023.10.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11778467B2 patent drawing
  • US11778467B2 patent drawing
  • US11778467B2 patent drawing

AI summary

Examples relate to seamless roaming across subnets. In an example, a system receives an indication that a client device has been authenticated at a first network device of a network. The system receives precursor keys and identification information of the client device, as generated from the authentication of the client device. The system determines second clusters, which are within a roaming domain of the cluster or the client device. The system receives one or more second precursor keys corresponding to the second clusters and distributes the second precursor keys to the corresponding second clusters. The system determines to create one or more tunnels among the second clusters and the cluster and provisions the tunnels to transmit data through the tunnels.