SIM-Based Authentication for Fast WLAN Inter-AP Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SIM-based authentication methods for WLANs face security vulnerabilities and delays due to the separation of authentication systems between cellular networks and WLANs, leading to potential unauthorized data access and increased re-authentication times during inter-AP handovers.

Innovation Solution

An SIM-based authentication method that integrates network and mobile node authentication using a cellular network authentication center, enabling pre-distribution of temporal keys for secure packet transmission and reducing re-authentication requirements through aggressive key pre-distribution and passive key queries, ensuring secure and efficient inter-AP handovers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM-based authentication is integrated into WLANs, then security is improved, but authentication time increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-distributing temporal keys to multiple access points before handover occurs. The authentication server distributes these keys in advance to neighboring APs, so when a mobile node hands over, the new AP already possesses the necessary key for immediate secure communication, eliminating the need for re-authentication and reducing authentication time while maintaining security

Inventive Principle:
Principle #10Preliminary action

2Reliability

If re-authentication is performed during inter-AP handover, then security is maintained, but handover time increases

Engineering Contradiction:
ImprovesecurityVSAvoidhandover time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary key distribution to neighboring access points before handover occurs. When a mobile node moves to a new AP, that AP already has the temporal key pre-distributed, allowing immediate secure communication without re-authentication delays

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server creates and distributes copies of temporal keys to multiple access points simultaneously. These key copies are stored at neighboring APs in advance, enabling fast handover when the mobile node transitions between cells without requiring real-time key generation or authentication

Inventive Principle:
Principle #26Copying

3Speed

If temporal keys are pre-distributed to multiple access points, then handover speed is improved, but key management complexity increases

Engineering Contradiction:
Improvehandover speedVSAvoidkey management complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent extracts the key management complexity from the access points and centralizes it in the authentication server. The server handles key generation, distribution, and revocation, while access points simply store and use the pre-distributed temporal keys. This separation reduces the computational burden on APs and simplifies overall key management despite the distributed nature of the system

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7624267B2SIM-based authentication method capable of supporting inter-AP fast handover
Publication Date: 2009.11.24 IND TECH RES INST
  • US7624267B2 patent drawing
  • US7624267B2 patent drawing
  • US7624267B2 patent drawing

AI summary

The invention relates to a SIM-based authentication method capable of supporting inter-AP fast handover, which can decrease the number of authentication procedures without negatively influencing the security of the wireless LAN by establishing an encrypted channel for each mobile node and using method 1: an aggressive key pre-distribution and method 2: probe request triggering passive key pre-query technique, thereby reducing the time of inter-AP handover for the mobile node. Furthermore, a re-authentication procedure is started to update the key after the key is used for a long time so as to ensure that the key is safe, thereby effectively achieving a fast and safe wireless LAN environment.