Roaming Between Wi-Fi Generations Using Dynamic Security Protocols

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of Wi-Fi 7/8 technology with legacy Wi-Fi 5/6 systems faces challenges due to differences in security protocols, specifically the mandatory support of WPA-3 in Wi-Fi 7/8 access points, which breaks seamless roaming as legacy AKMs and ciphers are invalid, leading to disassociation and lengthy network delays during key re-establishment.

Innovation Solution

The solution enables efficient re-association of Stations (STAs) between Wi-Fi 7/8 and Wi-Fi 5/6 access points by facilitating seamless roaming through the use of WPA-2 and WPA-3 security protocols, allowing STAs to derive new keys and transition quickly between access points using different key exchange mechanisms without initiating a full key exchange protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Wi-Fi 7/8 access points mandate WPA-3 security protocol, then security is improved, but compatibility with legacy Wi-Fi 5/6 systems deteriorates, breaking seamless roaming

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the security protocol parameter dynamically based on the target access point's capabilities. The station supports both WPA-2 and WPA-3 protocols and selects the appropriate protocol when roaming, allowing seamless transition between legacy and modern access points without breaking compatibility while maintaining security.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If full key exchange protocol is initiated during roaming between different security protocols, then security is re-established, but network delay increases significantly

Engineering Contradiction:
Improvesecurity re-establishmentVSAvoidnetwork delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The station performs preliminary actions by maintaining support for both WPA-2 and WPA-3 protocols simultaneously and pre-configuring itself to handle protocol transitions. This preliminary preparation allows the station to switch protocols during roaming without initiating a complete key exchange, significantly reducing the time penalty while still establishing secure connections.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If legacy AKMs and ciphers are used for compatibility, then roaming between legacy access points is maintained, but security is weakened when connecting to modern Wi-Fi 7/8 access points

Engineering Contradiction:
Improveroaming compatibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security protocol selection is made dynamic rather than static. The station adapts its security protocol choice based on the target access point's capabilities - using WPA-2 with legacy AKMs when connecting to legacy access points for compatibility, and switching to WPA-3 with modern AKMs when connecting to Wi-Fi 7/8 access points for enhanced security. This dynamic adaptation resolves the contradiction between compatibility and security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240381188A1Roaming between generations access points utilizes different security protocols
Publication Date: 2024.11.14 CISCO TECHNOLOGY INC
  • US20240381188A1 patent drawing
  • US20240381188A1 patent drawing
  • US20240381188A1 patent drawing

AI summary

The present technology provides for efficient re-association of a STA from a first Wi-Fi AP to a second Wi-Fi AP where the respective Wi-Fi APs utilize different security protocols. Since the association and key management (AKM) protocols are different and the cipher suites between generations of Wi-Fi technology, a STA normally would not be able to take advantage of the fast transition process. However, since the present technology allows the STA to derive the security keys in advance, the STA can perform the fast transition and efficiently roam to the Wi-Fi AP that utilizes a different association and key management (AKM) version.