Wireless Network Switching Using Domain Key Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing wireless network transition process is cumbersome and inefficient due to the need to re-derive level-1 and level-2 keys during each transition, affecting the transition speed and efficiency.

Innovation Solution

A method where the requesting device and target access device verify an integrity code using a message integrity check key derived from a domain key, allowing them to directly generate a session key without re-deriving level-1 and level-2 keys, simplifying the transition process and improving efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the level-1 and level-2 keys are re-derived during each network transition, then the security authentication is maintained, but the transition process becomes cumbersome and transition efficiency decreases

Engineering Contradiction:
Improvesecurity authenticationVSAvoidtransition efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The domain key is pre-derived and stored in the requesting device during the initial association phase. When network transition occurs, this pre-derived domain key is directly utilized without needing to re-derive level-1 and level-2 keys, thus maintaining security authentication while significantly improving transition efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the essential authentication element (domain key) from the complex key derivation process (level-1 and level-2 keys). By separating the domain key derivation from the transition process and storing it in advance, the system eliminates the need for repeated complex key derivations during each transition, resolving the contradiction between security and efficiency

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the hierarchical key scheme with level-0, level-1 and level-2 keys is used, then the security mechanism is established, but the number of key derivation steps increases and the transition process becomes complex

Engineering Contradiction:
Improvesecurity mechanismVSAvoidkey derivation steps
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the domain key as a standalone authentication element from the hierarchical key structure. Instead of requiring all level-0, level-1 and level-2 keys to be re-derived during transition, the system uses only the pre-derived domain key for authentication, significantly reducing the number of key derivation steps while maintaining the security mechanism

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The domain key is pre-derived during the initial association phase and stored in the requesting device. This preliminary action eliminates the need for complex hierarchical key derivation during subsequent transitions, reducing process complexity while preserving security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12156028B2Wireless network switching method and device
Publication Date: 2024.11.26 CHINA IWNCOMM
  • US12156028B2 patent drawing
  • US12156028B2 patent drawing
  • US12156028B2 patent drawing

AI summary

A wireless network switching method. In the method, a station and a target access device directly generate a message integrity check key by means of a domain key, and verify an integrity code on the basis of the message integrity check key, so as to realize the authentication of two parties; and when the authentication of the opposite party is successful, session keys are generated by means of the domain key and in conjunction with random numbers of the two parties, thereby simplifying a switching process and realizing secure and efficient network switching. Further disclosed are a corresponding station and a corresponding access device.