Temporary Master Key Generation for Wireless Handoff Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication systems face challenges in maintaining secure and low-latency handoffs between access terminals and access points, as current solutions either introduce security risks by sharing master keys or increase latency through repeated authentication processes.
Innovation Solution
A distributive and centralized key management scheme is implemented, where temporary master keys are generated and shared between access points and access terminals, allowing secure communication without exposing the master key, and enabling low-latency handoffs by pre-establishing security associations with multiple access points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the authentication process is repeated at each handoff, then security is maintained, but latency increases to an unacceptable level
Solution Approach 1:
The system performs preliminary authentication during the initial network attachment phase, establishing a master key before handoff occurs. This preliminary action eliminates the need for repeated authentication during handoff, reducing latency while maintaining security through pre-established credentials.
Solution Approach 2:
A key distribution center acts as an intermediary to manage and distribute temporary session keys to access points. This mediator enables fast handoff by providing pre-authenticated credentials without requiring the mobile device to re-authenticate, thus reducing latency while maintaining security through centralized key management.
2Loss of time
If the master key is shared among access points to reduce latency, then handoff speed improves, but security is compromised if an access point is breached
Solution Approach 1:
The master key is segmented into multiple temporary session keys, each specific to a particular access point and time period. This segmentation ensures that if one access point is compromised, the breach is isolated to that specific session key and does not affect the master key or other access points, maintaining security while enabling fast handoff.
Solution Approach 2:
The system uses disposable temporary session keys that have limited validity periods and are discarded after use. These short-lived keys enable rapid handoff without compromising long-term security, as each key is replaced after a single use or expiration, preventing persistent access even if a key is compromised.
3Loss of time
If temporary master keys are generated and distributed to multiple access points, then handoff latency is reduced, but key management complexity increases
Solution Approach 1:
A key distribution center serves as a centralized intermediary that automatically generates, manages, and distributes temporary session keys to multiple access points. This centralized mediation simplifies the overall system architecture by consolidating key management functions, reducing the complexity burden on individual access points while enabling fast handoff through efficient key distribution.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A novel key management approach is provided for securing communication handoffs between an access terminal (118) and two access points (110,112). This approach provides for securely handing off communications between an access terminal and access point without risking exposure a master key for the access terminal. Temporary master keys (I-MK) are derived for low latency handoffs and secure authentication between a new access point (112) and the access terminal! In one aspect, a distributive key management scheme is provided in which a current access point (110) generates a new security key (based on its own security key) that is used by the next access point with which an access terminal communicates. In another aspect, a centralized key management scheme is provided in which a central authenticator (120) maintains, generates, and distributes new security keys (based on a master security key associated with the access terminal) to access points.