Wireless Authentication Interoperability via Fast BSS Transition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face performance overhead due to the implementation of robust security features like 4-Way handshake and RADIUS authentication, which impact network infrastructure and delay authentication processes, especially in scenarios with high user mobility and dense network loads.
Innovation Solution
The solution involves interoperability between different authentication methods, specifically using a hybrid approach that leverages existing network infrastructure by generating fast basic service set transition pairwise master keys based on reauthentication master session keys, allowing for quicker authentication and reduced load on authentication servers through efficient key management and message flows between access points and stations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If 4-Way handshake and RADIUS authentication are implemented for robust security, then security reliability is improved, but authentication time and network overhead increase
Solution Approach 1:
The patent implements Fast BSS Transition (FT) authentication that performs authentication actions in advance. When a station moves to a new access point, the authentication credentials and keys are pre-established through the mobility domain controller, allowing immediate authentication without waiting for the full 4-Way handshake to complete at the new access point. This preliminary action significantly reduces authentication time while maintaining security reliability.
Solution Approach 2:
The patent extracts the authentication functionality from the traditional RADIUS server-centric model and distributes it to mobility domain controllers that are closer to the access points. By taking out the authentication processing from the centralized RADIUS server and placing it at the edge (mobility domain controller), the system reduces authentication time and network overhead while maintaining security through the same EAP framework.
2Reliability
If RADIUS authentication is used for secure network access control, then security is improved, but network infrastructure overhead increases
Solution Approach 1:
The patent segments the authentication system into multiple components: EAP authentication for initial secure credential verification, Fast BSS Transition for subsequent rapid re-authentication, and mobility domain controllers that cache authentication credentials. This segmentation allows the heavy RADIUS authentication to occur only when necessary, while normal handovers use the lighter FT mechanism, reducing overall network infrastructure overhead while maintaining security.
Solution Approach 2:
The patent changes the authentication parameters by introducing a two-mode system: full EAP authentication (high security, high overhead) and Fast BSS Transition (lower overhead, sufficient security for handovers). The system dynamically selects between these modes based on whether it's an initial authentication or a handover scenario, optimizing the balance between security and infrastructure overhead.
3Reliability
If full EAP authentication is performed for every handover, then authentication security is improved, but handover speed decreases
Solution Approach 1:
The patent implements a dynamic authentication system that adapts its security level based on the handover context. For initial associations, full EAP authentication is performed. For subsequent handovers within the same mobility domain, the system dynamically switches to Fast BSS Transition using pre-cached credentials. This dynamic adjustment maintains authentication security when needed while maximizing handover speed during routine transitions.
Solution Approach 2:
The system performs preliminary EAP authentication and key establishment before handovers occur. The mobility domain controller caches authentication credentials in advance, so when a station needs to handover, the authentication is already complete and the station can immediately use the pre-established keys. This preliminary action eliminates the need for slow full EAP authentication during actual handovers.
4Adaptability or versatility
If traditional authentication protocols are used, then compatibility with existing systems is improved, but deployment of new security features is delayed
Solution Approach 1:
The patent creates a universal authentication framework that supports multiple authentication methods (EAP, Fast BSS Transition) within a single system. The mobility domain controller can handle both traditional RADIUS/EAP authentication and accelerated FT authentication, allowing networks to gradually adopt new security features while maintaining compatibility with existing systems. This multi-functionality enables phased deployment without requiring complete system replacement.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, methods, and computer readable mediums for authenticating a device perform a method of receiving, at a second device, a first authentication protocol reauthentication response for the device, the authentication response including a reauthentication master session key (rMSK), transmitting, at the second device, a second first authentication protocol reauthentication response to a first access point based on the reauthentication master session key, generating, at the second device, a first pairwise master key (PMK) based on the reauthentication master session key, generating, at the second device, a key message to include the first pairwise master key, and transmitting, at the second device, the key message to the second access point.