Wireless Authentication Information Elements in Management Frames
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication and association procedures in IEEE 802.11-compliant wireless networks, particularly for Directional Multigigabit (DMG) and Enhanced DMG devices, are time-consuming due to sequential handshake messages, which can be detrimental for applications requiring rapid network access, such as Ultra Short Range communications.
Innovation Solution
The method involves embedding authentication information elements within management frames or data frames, allowing for parallel authentication with other network operations, thereby reducing the time required to reach an authenticated and associated state without the need for separate dedicated frames.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sequential handshake messages are used for authentication and association, then security is maintained through proper verification steps, but the time required for network access increases significantly
Solution Approach 1:
The patent combines authentication information elements with management frames (such as beacon frames, probe response frames, and association response frames) that are already being exchanged during the network access process. This merging allows authentication to occur concurrently with existing protocol operations rather than as a separate sequential process, thereby reducing overall access time while maintaining security verification.
Solution Approach 2:
The patent enables authentication information to be embedded and processed in advance within management frames before the formal authentication handshake begins. By preparing authentication data structures and incorporating them into preliminary frame exchanges, the system reduces the time required for subsequent authentication steps while ensuring security requirements are met.
2Reliability
If multiple separate frames are used for authentication handshaking, then security verification is thorough, but the number of message exchanges increases
Solution Approach 1:
The patent merges authentication information elements into existing management frames that are already part of the wireless communication protocol. By combining multiple functions (authentication verification and network management) into single frame structures, the patent reduces the total number of message exchanges required while maintaining thorough security verification through the embedded authentication data.
3Device complexity
If dedicated authentication frames are transmitted separately, then authentication data is clearly structured, but the time and overhead for network access increases
Solution Approach 1:
The patent integrates authentication information elements within existing management frame structures rather than using separate dedicated frames. This approach maintains clear data structure organization while eliminating the time overhead associated with transmitting and processing separate authentication frames, as authentication data is carried along with routine management traffic.
Solution Approach 2:
The patent makes management frames multi-functional by enabling them to carry both their original management purposes and authentication verification functions simultaneously. This universality allows single frames to serve multiple roles, reducing the need for separate dedicated authentication frames and thereby decreasing overall processing time while maintaining structured data organization.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and apparatus for authenticating a directional multi gigabit device for communication in an IEEE 802.11-compliant wireless network are provided. Network association and authentication can be performed in parallel, with association and authentication information elements included in common frames. Authentication information elements are included in at least one and potentially a sequence of management frames transmitted between an access point of the wireless network and the device. The authentication information elements are thereby exchanged between the access point and the device. The exchanged authentication information elements are used to establish that both the access point and the device possess a common cryptographic key. The exchanged management frames can also facilitate network association. Authentication information elements can also be included in non-management frames. A format for the authentication information elements is presented.