Wireless Network Switching Using Domain Key Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing wireless network transition process is cumbersome and inefficient due to the need to re-derive level-1 and level-2 keys during each transition, affecting the transition speed and efficiency.
Innovation Solution
A method where the requesting device and target access device verify an integrity code using a message integrity check key derived from a domain key, allowing them to directly generate a session key without re-deriving level-1 and level-2 keys, simplifying the transition process and improving efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the level-1 and level-2 keys are re-derived during each network transition, then the security authentication is maintained, but the transition process becomes cumbersome and transition efficiency decreases
Solution Approach 1:
The domain key is pre-derived and stored in the requesting device during the initial association phase. When network transition occurs, this pre-derived domain key is directly utilized without needing to re-derive level-1 and level-2 keys, thus maintaining security authentication while significantly improving transition efficiency
Solution Approach 2:
The patent extracts the essential authentication element (domain key) from the complex key derivation process (level-1 and level-2 keys). By separating the domain key derivation from the transition process and storing it in advance, the system eliminates the need for repeated complex key derivations during each transition, resolving the contradiction between security and efficiency
2Reliability
If the hierarchical key scheme with level-0, level-1 and level-2 keys is used, then the security mechanism is established, but the number of key derivation steps increases and the transition process becomes complex
Solution Approach 1:
The patent extracts the domain key as a standalone authentication element from the hierarchical key structure. Instead of requiring all level-0, level-1 and level-2 keys to be re-derived during transition, the system uses only the pre-derived domain key for authentication, significantly reducing the number of key derivation steps while maintaining the security mechanism
Solution Approach 2:
The domain key is pre-derived during the initial association phase and stored in the requesting device. This preliminary action eliminates the need for complex hierarchical key derivation during subsequent transitions, reducing process complexity while preserving security
Data Source
AI summary
A wireless network switching method. In the method, a station and a target access device directly generate a message integrity check key by means of a domain key, and verify an integrity code on the basis of the message integrity check key, so as to realize the authentication of two parties; and when the authentication of the opposite party is successful, session keys are generated by means of the domain key and in conjunction with random numbers of the two parties, thereby simplifying a switching process and realizing secure and efficient network switching. Further disclosed are a corresponding station and a corresponding access device.


