Precaching Roaming Keys to Reduce Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional client device roaming across different subnets in networks often results in latency and interruptions due to the need for deauthentication and reauthentication at new access points, which involves complex key computations and IP address renewals, leading to inefficiencies and resource consumption.
Innovation Solution
A computing system that proactively caches precursor keys at clusters with a high probability of being roamed to, allowing seamless roaming by eliminating the need for authentication at new access points and retaining the original IP address, thereby reducing latency and conserving resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If client device performs deauthentication and reauthentication at new access points during roaming, then security is maintained, but latency and service interruption occur
Solution Approach 1:
The system performs preliminary authentication by caching precursor keys (PMK-R0, PMK-R1) at the home cluster before roaming occurs. When a client device roams to a foreign cluster, the authentication is already complete, eliminating the time-consuming deauthentication and reauthentication process while maintaining security. The precursor keys are valid for a predetermined time period, enabling seamless roaming without service interruption.
2Reliability
If client device reauthenticates at new access points during roaming, then access security is ensured, but resource consumption increases
Solution Approach 1:
The home cluster pre-computes and caches precursor keys (PMK-R0, PMK-R1) before roaming occurs. When the client device roams to a foreign cluster within the roaming domain, these pre-computed keys are used for authentication, eliminating the need for resource-intensive reauthentication processes at the new access point. This significantly reduces computational overhead and energy consumption while maintaining access security.
3Reliability
If client device performs IP address renewal during roaming, then network connectivity is maintained, but latency and service interruption occur
Solution Approach 1:
The system performs preliminary IP address allocation by assigning a home cluster IP address to the client device before roaming occurs. The home cluster acts as an anchor point, maintaining the IP address assignment even when the device roams to foreign clusters. This eliminates the need for IP address renewal during roaming, preventing service interruption and maintaining continuous network connectivity.
4Reliability
If traditional roaming authentication process is used, then security is maintained, but device complexity and processing overhead increase
Solution Approach 1:
The home cluster performs preliminary authentication and key derivation, caching the precursor keys (PMK-R0, PMK-R1) before roaming occurs. When the client device roams to a foreign cluster, the authentication process is significantly simplified because the precursor keys are already available. This reduces the processing overhead and complexity at both the client device and foreign cluster while maintaining security through the use of WPA3-SAE authentication.
Data Source
AI summary
Examples relate to seamless roaming across subnets. In an example, a system receives an indication that a client device has been authenticated at a first network device of a network. The system receives precursor keys and identification information of the client device, as generated from the authentication of the client device. The system determines second clusters, which are within a roaming domain of the cluster or the client device. The system receives one or more second precursor keys corresponding to the second clusters and distributes the second precursor keys to the corresponding second clusters. The system determines to create one or more tunnels among the second clusters and the cluster and provisions the tunnels to transmit data through the tunnels.


