Unified Authentication Key Management for Heterogeneous Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In heterogeneous home networks, the different authentication and key management processes for various MAC layer technologies lead to resource wastage during the authentication process, as each technology requires separate authentication and key negotiation procedures, resulting in inefficient security management.
Innovation Solution
A unified authentication and key management method that generates a Network Key (NK) for network equipment, allowing it to perform a single authentication protocol interaction to calculate a Basic Session Key (BSK), which is then used to derive link Encryption Keys (EKs) for multiple MAC and PHY layers, ensuring seamless encryption and decryption across various access technologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication and key negotiation processes are performed for each MAC layer technology, then security authentication can be completed for each interface, but calculation resources are wasted due to redundant authentication operations
Solution Approach 1:
The patent merges multiple separate authentication and key negotiation processes into a single unified authentication process. The authentication management module performs one authentication operation that generates a master key, from which all necessary link encryption keys for different MAC layer technologies (PLC, MoCA, WiFi) are derived through key derivation functions, eliminating redundant authentication calculations while maintaining security for each interface
Solution Approach 2:
The patent creates a universal authentication mechanism where a single authentication process produces a master key that serves multiple functions. This master key can derive link encryption keys for various MAC layer technologies through key derivation, making the authentication system multi-functional and applicable to heterogeneous network interfaces without requiring separate authentication for each
2Adaptability or versatility
If different authentication and key management methods are applied for various MAC layer technologies, then each technology can use its specified authentication process, but the authentication process becomes complex and requires multiple separate procedures
Solution Approach 1:
The patent segments the key management function from the authentication function. The authentication management module handles authentication and generates a master key, while separate key derivation modules derive specific link encryption keys for each MAC layer technology (PLC, MoCA, WiFi) from this master key. This segmentation allows a single authentication process to support multiple technologies without increasing overall system complexity
3Reliability
If multiple authentication protocol interactions are performed for multiple MAC layer technologies, then security can be ensured for each link, but the authentication time increases
Solution Approach 1:
The patent performs preliminary authentication at the authentication management module before data transmission begins. The master key is generated in advance through a single authentication protocol interaction, and all link encryption keys for different MAC layer technologies are derived from this pre-generated master key. This preliminary action eliminates the need for repeated authentication interactions during subsequent data transmission across multiple interfaces
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
Provided is a network equipment and an authentication and key management method for the same. The network equipment generates a Network Key (NK); the network equipment performs authentication protocol interaction with opposite communication equipment, and calculates a Basic Session Key (BSK) according to parameters for the authentication protocol interaction and the NK; and the network equipment calculates link Encryption Keys (EKs) used respectively for Media Access Control (MAC) and Physical (PHY) layers using various access technologies according to the BSK, and provides the EKs for respective MAC and PHY layer function modules. With the disclosure, the legality of the equipment is verified by performing an authentication process on the heterogeneous network equipments in one pass, and keys in various MAC layer technologies are managed in a unified way.