Split Supplicant Handover for Secure Optical Wireless Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of achieving fast and secure handovers in optical wireless networks, such as Li-Fi, is exacerbated by the small coverage areas and limited field-of-view of optical access points, leading to increased latency during transitions between cells.
Innovation Solution
An end point subsystem with a host processor acting as a first supplicant and a controller acting as a second supplicant is employed to establish initial and new pairwise transient keys, respectively, using a split supplicant approach to expedite the handover process, reducing latency and ensuring secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user equipment performs measurements on multiple target cells during handover, then handover reliability is improved, but handover time and latency increase
Solution Approach 1:
The network side pre-configures measurement configurations, reporting configurations, and admission control configurations for multiple potential target cells before handover is needed. This preliminary setup allows the user equipment to immediately execute handover measurements and procedures without delay, achieving both high reliability and low latency.
Solution Approach 2:
The handover process is segmented into independent configurable components (measurement configurations, reporting configurations, admission control configurations) that can be prepared in advance for multiple target cells. This segmentation allows parallel preparation of handover parameters for different cells, reducing overall handover time while maintaining multiple measurement options for reliability.
2Speed
If measurement configurations are pre-configured for multiple target cells, then handover speed is improved, but network signaling overhead increases
Solution Approach 1:
A single measurement configuration can be designed to serve multiple target cells simultaneously. The network configures universal measurement parameters that apply across multiple cells, reducing redundant signaling while enabling fast handover execution to any of the pre-configured target cells.
3Reliability
If multiple target cells are pre-configured with measurement and reporting parameters, then handover reliability is improved, but device complexity increases
Solution Approach 1:
Measurement configurations, reporting configurations, and admission control configurations for multiple target cells are merged into unified pre-configured parameter sets. The user equipment maintains a single consolidated configuration structure that covers multiple cells, reducing the complexity burden compared to managing separate configurations for each cell.
4Reliability
If the network configures multiple target cells with detailed measurement parameters, then handover reliability is improved, but network processing load increases
Solution Approach 1:
The network performs the complex task of configuring multiple target cells with detailed measurement parameters in advance, during periods of lower load. This preliminary configuration work is done once and stored, eliminating the need to perform this computationally intensive task repeatedly during actual handover events, thus reducing real-time network processing load while maintaining high handover reliability.
Data Source
Figure 1~2
Figure 3~5
Figure 6~7
AI summary
Because of the line-of-sight character of optical wireless communication and a limited field-of-view of optical receivers, the coverage of an access point and the overlapping coverage area of adjacent access points in an optical system are smaller as compared to a RF system. It turns more challenging to support an end point (110) to roam securely in an optical multi-cell wireless communication network. To speed up the derivation of a new pairwise transient key with a new access point during a handover procedure, the end point of this invention comprises a controller (118) that is configured to act as a second supplicant (1181), on behalf of a first supplicant (1186) comprised in a host processor (1185), to communicate with an authenticator to establish a new pairwise transient key for the end point (110) and a candidate access point, and an active pairwise transient key with the currently associated access point is used to secure the communication for new key derivation.