Salted Key Refresh for Wireless Network Secrecy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network systems face security threats from unauthorized nodes that can compromise data security by obtaining and refreshing network keys, compromising forward and backward secrecy.
Innovation Solution
Introduce a salt value as an additional input to the key derivation function, encrypted and shared only with authenticated nodes, ensuring that unauthorized entities cannot compute new network keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network keys are shared and refreshed among secondary nodes, then communication security is improved, but unauthorized nodes can also compute and use the refreshed keys, compromising forward and backward secrecy
Solution Approach 1:
A salt value is introduced as an intermediary element in the key derivation process. The salt is encrypted and shared separately from the key derivation function (KDF) inputs, acting as a mediator that enables authorized nodes to derive new keys while preventing unauthorized nodes from computing them, thus resolving the security contradiction
Solution Approach 2:
The key refresh mechanism is segmented into multiple components: the KDF inputs (current key and session number) and the salt value. This segmentation allows the system to distribute different elements through different channels, with the salt being encrypted and transmitted separately, preventing unauthorized nodes from obtaining all necessary components to derive new keys
2Reliability
If a salt value is introduced for key derivation, then forward and backward secrecy are improved, but the complexity of the key management system increases
Solution Approach 1:
The salt value is generated and encrypted in advance before the key refresh operation. This preliminary action allows the salt to be prepared and securely distributed ahead of time, reducing the computational complexity during the actual key refresh process and simplifying the overall key management workflow
Data Source
AI summary
A method for key refreshment in a wireless network system using a salt. The method includes receiving, from each of a plurality of secondary nodes communicably coupled to a primary node, a current session number. The current session numbers are compared to a session number at the primary node to identify a mismatch, and a salt is generated responsive to identifying the mismatch. The method further includes sending the salt to each of the plurality of secondary nodes having a current session number matching the session number at the primary node.


