Secure Switching System for Wireless Roaming Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless clients experience significant authentication delays and connectivity gaps when roaming between access points in wireless networks, leading to interruptions in ongoing applications due to the need for repeated authentication processes.

Innovation Solution

Implementing a system where access points share and reuse authentication information within a predetermined expiration period, allowing seamless switching between access points without the need for repeated authentication, and periodic re-authentication to ensure security and network integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a client performs authentication with each new access point when roaming, then security is maintained, but authentication delays and connectivity gaps occur

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by having the authentication server pre-authenticate access points and establish security contexts before the client actually roams. The target access point receives and stores authentication information in advance, so when the client connects, the authentication process is already complete or near-complete, eliminating delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an authentication server as an intermediary that manages authentication information and security contexts. The server acts as a mediator between clients and access points, pre-establishing trust relationships and enabling fast roaming without requiring traditional authentication handshakes at each access point transition.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If authentication information is shared across access points, then roaming speed improves, but security risks increase

Engineering Contradiction:
Improveroaming speedVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system changes the parameter of authentication information validity by introducing expiration times and scope limitations. Authentication information is valid only for specific time periods and specific access points, transforming it from a permanent universal credential to a temporary context-specific credential, thereby reducing security risks while enabling fast roaming.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The invention segments authentication information into access-point-specific contexts rather than using a single universal credential. Each access point receives authentication information tailored to it, and the system segments the validity period into controlled time windows. This segmentation allows secure information sharing across multiple access points while maintaining granular control over security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the access point treats each client as a new arrival, then security is ensured, but ongoing applications experience interruptions

Engineering Contradiction:
ImprovesecurityVSAvoidapplication continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system ensures continuity of useful action by maintaining authentication contexts across access point transitions. The authentication server preserves security contexts and authentication states, allowing client sessions and applications to continue uninterrupted as the client roams between access points, eliminating the need for applications to restart or re-authenticate.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP1864442B1Secure switching system for networks and method for secure switching
Publication Date: 2022.05.04 EXTREME NETWORKS INC
  • EP1864442B1 patent drawingFigure 1
  • EP1864442B1 patent drawingFigure 2

AI summary

Methods and systems are provided for secure switching of a roaming wireless terminal. The system includes a network having a first access point for communicating with the wireless terminal, and a second access point for communicating. The first access point also generates a first authentication information with the wireless terminal and connects the wireless terminal with the network upon authentication of the wireless terminal based on the first authentication information. The first access point also transmits the first authentication information to the second access point via the network upon authentication of the wireless terminal. The second access point also connects the wireless terminal with the network using the first authentication information.