Wireless Router Security Handoff in Multi-Hop Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless multi-hop networks face delays in handoff processes due to the need for full authentication and key management protocols, especially in high-speed environments, which impact performance and security in mobile wireless networks.

Innovation Solution

A wireless router-assisted security handoff scheme that uses security context caching, where a wireless router vouches for the 'freshness' of an Anonce and combines re-association and four-way handshake messages into two messages, utilizing a pre-configured security context encryption key and generating a handoff PMK to facilitate fast and secure handoffs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full authentication and key management protocols are used during handoff, then security is maintained, but handoff delay increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidhandoff delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and key management actions in advance before the handoff occurs. The mobile station pre-authenticates with the target access point and pre-establishes security context, so that when handoff is needed, the authentication is already complete and only a quick key transition is required, eliminating the need for full authentication during the actual handoff moment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates and transfers a copy of the security context (including authentication credentials and key material) from the source access point to the target access point before handoff. This copied security context allows the mobile station to quickly establish security with the new access point without repeating the full authentication process, thus reducing handoff delay while maintaining security.

Inventive Principle:
Principle #26Copying

2Speed

If pre-authentication is performed before handoff, then handoff speed is improved, but the complexity of locating and authenticating with the correct new access point increases

Engineering Contradiction:
Improvehandoff speedVSAvoidhandoff process complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the mobile station monitors signal quality and handoff conditions, and only initiates pre-authentication when specific conditions are met (such as when the target access point's signal strength exceeds a threshold). This feedback-controlled approach prevents unnecessary pre-authentication attempts and simplifies the overall process by activating complexity only when beneficial.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary mechanism where the source access point assists in the pre-authentication process by providing information about suitable target access points and facilitating the security context transfer. This intermediary role simplifies the mobile station's task of locating and authenticating with the correct new access point, as the source AP guides the process rather than requiring the mobile station to independently discover and validate targets.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If security context is transferred between access points, then handoff delay is reduced, but memory and computation requirements increase

Engineering Contradiction:
Improvehandoff delayVSAvoidcomputation and memory requirements
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The patent extracts and transfers only the essential security context elements needed for fast handoff (such as the pairwise master key and authentication credentials) rather than transferring the entire security database. This selective extraction reduces the memory and computation burden on access points while still enabling rapid handoff through the transferred critical security information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local quality by having each access point store and process only the security context relevant to its local area and the mobile stations it serves, rather than maintaining global security information. The security context transfer is localized to specific handoff events between neighboring access points, reducing overall memory requirements and computation overhead in the network.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7483409B2Wireless router assisted security handoff (WRASH) in a multi-hop wireless network
Publication Date: 2009.01.27 ARRIS ENTERPRISES LLC
  • US7483409B2 patent drawing
  • US7483409B2 patent drawing
  • US7483409B2 patent drawing

AI summary

A wireless router assisted security handoff method (300) includes an efficient layer 2security handoff for an infrastructure-based mobile multi-hop wireless network. The handoff is assisted with a wireless router (311) which is the first hop from the mobile station (301) to the new access point (307). The security context from the old access point (303) is first delivered to the mobile station (301) in a secure manner. The first handoff message (309) from mobile station (301) to the new access point (307) has three roles namely, re-association request, security context delivery and new session key generation handshaking. The first hop wireless router (311) vouches the freshness of the message contents and tunnels the message securely to the new access point (307). The second message (315) from the new access point (307) to the mobile station (301) completes the handoff process.