Wireless Authentication Interoperability via Fast BSS Transition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face performance overhead due to the implementation of robust security features like 4-Way handshake and RADIUS authentication, which impact network infrastructure and delay authentication processes, especially in scenarios with high user mobility and dense network loads.

Innovation Solution

The solution involves interoperability between different authentication methods, specifically using a hybrid approach that leverages existing network infrastructure by generating fast basic service set transition pairwise master keys based on reauthentication master session keys, allowing for quicker authentication and reduced load on authentication servers through efficient key management and message flows between access points and stations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 4-Way handshake and RADIUS authentication are implemented for robust security, then security reliability is improved, but authentication time and network overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements Fast BSS Transition (FT) authentication that performs authentication actions in advance. When a station moves to a new access point, the authentication credentials and keys are pre-established through the mobility domain controller, allowing immediate authentication without waiting for the full 4-Way handshake to complete at the new access point. This preliminary action significantly reduces authentication time while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the authentication functionality from the traditional RADIUS server-centric model and distributes it to mobility domain controllers that are closer to the access points. By taking out the authentication processing from the centralized RADIUS server and placing it at the edge (mobility domain controller), the system reduces authentication time and network overhead while maintaining security through the same EAP framework.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If RADIUS authentication is used for secure network access control, then security is improved, but network infrastructure overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork infrastructure overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into multiple components: EAP authentication for initial secure credential verification, Fast BSS Transition for subsequent rapid re-authentication, and mobility domain controllers that cache authentication credentials. This segmentation allows the heavy RADIUS authentication to occur only when necessary, while normal handovers use the lighter FT mechanism, reducing overall network infrastructure overhead while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the authentication parameters by introducing a two-mode system: full EAP authentication (high security, high overhead) and Fast BSS Transition (lower overhead, sufficient security for handovers). The system dynamically selects between these modes based on whether it's an initial authentication or a handover scenario, optimizing the balance between security and infrastructure overhead.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If full EAP authentication is performed for every handover, then authentication security is improved, but handover speed decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidhandover speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements a dynamic authentication system that adapts its security level based on the handover context. For initial associations, full EAP authentication is performed. For subsequent handovers within the same mobility domain, the system dynamically switches to Fast BSS Transition using pre-cached credentials. This dynamic adjustment maintains authentication security when needed while maximizing handover speed during routine transitions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary EAP authentication and key establishment before handovers occur. The mobility domain controller caches authentication credentials in advance, so when a station needs to handover, the authentication is already complete and the station can immediately use the pre-established keys. This preliminary action eliminates the need for slow full EAP authentication during actual handovers.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If traditional authentication protocols are used, then compatibility with existing systems is improved, but deployment of new security features is delayed

Engineering Contradiction:
ImprovecompatibilityVSAvoiddeployment speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent creates a universal authentication framework that supports multiple authentication methods (EAP, Fast BSS Transition) within a single system. The mobility domain controller can handle both traditional RADIUS/EAP authentication and accelerated FT authentication, allowing networks to gradually adopt new security features while maintaining compatibility with existing systems. This multi-functionality enables phased deployment without requiring complete system replacement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3210404B1Authentication interoperability in a wireless communication system
Publication Date: 2020.01.01 QUALCOMM INC
  • EP3210404B1 patent drawingFigure 1
  • EP3210404B1 patent drawingFigure 2
  • EP3210404B1 patent drawingFigure 3

AI summary

Systems, methods, and computer readable mediums for authenticating a device perform a method of receiving, at a second device, a first authentication protocol reauthentication response for the device, the authentication response including a reauthentication master session key (rMSK), transmitting, at the second device, a second first authentication protocol reauthentication response to a first access point based on the reauthentication master session key, generating, at the second device, a first pairwise master key (PMK) based on the reauthentication master session key, generating, at the second device, a key message to include the first pairwise master key, and transmitting, at the second device, the key message to the second access point.