Multi-Link Radio Authentication Using Reusable PMKs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-link communication systems face inefficiencies due to the overhead of exchanging EAP messages during link establishment, leading to prolonged connection times and reduced throughput.

Innovation Solution

A communication apparatus that generates a Pairwise Master Key (PMK) for the first radio link and reuses this key for subsequent links, thereby omitting the need for EAP authentication in each link establishment, allowing efficient establishment of multiple radio links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAP authentication is executed for each radio link establishment, then security authentication is ensured, but connection time increases and throughput decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidconnection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs EAP authentication and generates the PMK in advance during the initial link establishment. This preliminary action allows the authentication result to be reused for subsequent link establishments, eliminating the need to repeat the time-consuming EAP message exchanges and thereby reducing connection time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent makes the PMK generated in one link universally applicable to multiple other links. Instead of generating separate authentication keys for each link, the same PMK is reused across multiple radio links, reducing the overhead of repeated authentication processes while ensuring consistent security across all links

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If EAP authentication is executed for each radio link establishment, then secure connection is ensured, but message exchange overhead increases

Engineering Contradiction:
Improveconnection securityVSAvoidmessage exchange overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex EAP authentication process and message exchanges are performed once in advance during initial link establishment. The authentication result (PMK) is then cached and reused for subsequent links, eliminating the need to repeat the complex message exchange protocol and thereby reducing overhead while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the PMK generated during initial authentication and reuses this key copy for subsequent link establishments. This copying approach avoids repeating the entire EAP authentication message exchange process, reducing the complexity and overhead of multiple link establishments while maintaining security through key reuse

Inventive Principle:
Principle #26Copying

3Reliability

If PMK generation is executed for each radio link, then key freshness is ensured, but processing time increases

Engineering Contradiction:
Improveencryption key freshnessVSAvoidlink establishment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The PMK is generated in advance during the initial link establishment rather than being regenerated for each subsequent link. This preliminary key generation approach maintains encryption security while eliminating repeated processing time, thereby improving link establishment speed without sacrificing key security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The PMK generated for one link is made universally applicable to multiple other links. This multi-functional use of a single PMK avoids the need to regenerate encryption keys for each link, maintaining cryptographic security while significantly improving link establishment productivity by eliminating redundant key generation processes

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12463809B2Communication apparatus, control method, and computer-readable storage medium
Publication Date: 2025.11.04 CANON KK
  • US12463809B2 patent drawing
  • US12463809B2 patent drawing
  • US12463809B2 patent drawing

AI summary

A communication apparatus establishes, in a case where a second radio link is established with a partner apparatus in communication in addition to an already established first radio link, the second radio link using information obtained by authentication processing executed at the time of establishing the first radio link.