Proactive PMK Sharing for Fast WLAN Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network roaming techniques require each neighbor access point to obtain a unique pairwise master key (PMK), leading to network congestion, processing delays, and potential connection disruptions, especially during voice calls, due to the complexity and inefficiency of authenticating each neighbor AP with the AAA server.

Innovation Solution

A service controller manages neighbor graph generation and PMK notifications, sharing a single PMK among access points and eliminating the need for each neighbor AP to regenerate a new PMK upon roaming, with implicit updates to the neighbor graph through notifications, reducing the load on the authentication server and minimizing inter-AP dialogs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each neighbor AP obtains a unique PMK through authentication with the AAA server, then security between the STA and each AP is ensured, but network congestion increases dramatically and processing delays occur

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having the serving AP obtain and distribute PMKs to neighbor APs in advance, before the STA actually roams. This proactive key distribution eliminates the need for neighbor APs to authenticate with the AAA server at the moment of roaming, thus preventing network congestion and processing delays while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The serving AP acts as an intermediary by obtaining PMKs from the AAA server on behalf of neighbor APs and distributing them proactively. This intermediary role eliminates the need for multiple direct authentication transactions between neighbor APs and the AAA server, reducing network congestion and processing delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If each neighbor AP authenticates with the AAA server to obtain a unique PMK, then secure connection is established, but processing delays of 2-5 seconds occur causing connection disruptions

Engineering Contradiction:
Improveconnection stabilityVSAvoidroaming time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by distributing PMKs to neighbor APs before the STA roams. This eliminates the 2-5 second authentication delay that would occur if neighbor APs authenticated with the AAA server at the moment of roaming, thereby preventing connection disruptions and reducing roaming time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies beforehand cushioning by pre-distributing PMKs to neighbor APs, creating a buffer that ensures keys are already available when the STA roams. This prevents connection disruptions that would occur due to authentication delays, effectively cushioning against potential service interruptions.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If unique PMKs are generated for each neighbor AP, then security is maintained, but the complexity of key management and inter-AP dialogs increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies merging by having the serving AP consolidate the role of obtaining and distributing PMKs to multiple neighbor APs. Instead of each neighbor AP independently authenticating with the AAA server, the serving AP performs this function centrally, reducing key management complexity and the number of inter-AP dialogs required.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The serving AP performs multiple functions: it acts as the STA's security endpoint, manages key distribution to neighbor APs, and updates the neighbor graph. This multi-functionality reduces overall system complexity by consolidating key management responsibilities in a single entity rather than requiring complex coordination among multiple APs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If the STA regenerates a new PMK for each neighbor AP, then security is ensured, but additional processing delays occur

Engineering Contradiction:
ImprovesecurityVSAvoidPMK generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having neighbor APs receive PMKs in advance through proactive distribution from the serving AP. This eliminates the need for the STA to regenerate PMKs when roaming to neighbor APs, removing additional processing delays while maintaining security through the pre-distributed keys.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7873352B2Fast roaming in a wireless network using per-STA pairwise master keys shared across participating access points
Publication Date: 2011.01.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7873352B2 patent drawing
  • US7873352B2 patent drawing
  • US7873352B2 patent drawing

AI summary

A fast roaming (handoff) service is provided for a WLAN infrastructure. A given mobile station (STA) obtains a pairwise master key (PMK) when it associates with an access point (AP) in the infrastructure. A neighbor graph identifies prospective APs to which the STA may then roam. At initialization, preferably the neighbor graph is fully-connected (i.e., each AP is assumed to be connected to every other AP). The PMK (obtained by the STA initially) is shared proactively with the neighbor APs as indicated in the neighbor graph. Thus, when the STA roams to a neighbor AP, because the PMK is already available, there is no requirement that the STA initiate a real-time request to an authentication server to re-associate to the new AP. Further, the new AP causes an update to the neighbor graph information implicitly by simply issuing a notification that it is now handling the STA that arrived from the prior AP; in this manner, the prior AP is confirmed as a neighbor, but there is no requirement for any inter-AP dialog before a given neighbor graph is updated. As roaming occurs the neighbor graph is pruned down (to reflect the actual neighbor AP connections) using the implicit notification data.