Wireless Handoff Authentication via Pre-shared Secret Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for speeding up handoff procedures in wireless communications networks, such as those compliant with IEEE 802.11i, are not satisfactory as they compromise security, incur significant delays, and resource wastage, especially when access points are compromised or when handoffs do not occur within a defined time frame.
Innovation Solution
A short authentication method is introduced, where a shared secret is used to generate authentication tokens between the supplicant and authentication server, allowing for faster key generation and secure communication without involving all access points in the authentication process, thus minimizing computational burden and maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current handoff procedures in IEEE 802.11i networks are used, then security is maintained through full authentication, but handoff latency increases and computational burden rises
Solution Approach 1:
The patent applies preliminary action by pre-establishing a shared secret between the supplicant and authentication server before handoff occurs. During handoff, the supplicant generates an authentication token using this pre-shared secret, allowing the authentication server to quickly verify authenticity without performing a full authentication exchange, thus reducing handoff latency while maintaining security
Solution Approach 2:
The patent segments the authentication process into two phases: a preliminary key establishment phase where a shared secret is created, and a rapid handoff phase where only token verification is needed. This segmentation allows the computationally intensive key generation to occur once, while handoffs use lightweight token verification, reducing both latency and computational burden during actual handoff events
2Reliability
If all access points are involved in authentication verification, then security is enhanced, but device complexity and computational burden increase
Solution Approach 1:
The patent extracts the authentication verification function from all access points and concentrates it solely in the authentication server. The supplicant generates an authentication token that is forwarded directly to the authentication server for verification, bypassing the need for other access points to participate in verification. This reduces device complexity at access points while maintaining centralized security verification
Solution Approach 2:
The authentication server acts as an intermediary that receives and verifies authentication tokens from supplicants during handoff. Instead of having all access points perform verification, the authentication server mediates the authentication process by validating tokens against the shared secret, simplifying the overall system architecture while maintaining security
3Ease of operation
If shared secrets are distributed to all access points for verification, then authentication can be distributed, but security risk increases if access points are compromised
Solution Approach 1:
The patent extracts the shared secret from the access points entirely and stores it only in the authentication server. During handoff, the supplicant uses the shared secret to generate a token that is verified by the authentication server. This extraction eliminates the security risk of compromised access points while maintaining distributed authentication capability, as the secret never resides in access points
Solution Approach 2:
The patent uses cryptographic copying where the supplicant creates a derived authentication token from the shared secret without exposing the secret itself. The token is a cryptographic copy that contains sufficient information for verification but cannot be used to derive the original secret, allowing distributed authentication while protecting the security of the shared secret stored only in the authentication server
Data Source
AI summary
In a wireless communications network including at least one authenticator and at least one authentication server, wherein the authenticator is adapted to interact with the authentication server for authenticating supplicants in order to conditionally grant thereto access to the wireless communications network, a short authentication method for authenticating a supplicant, the method including: providing a shared secret, shared by and available at the supplicant and the authentication server; having the supplicant provide to the authenticator an authentication token, wherein the authentication token is based on the shared secret available thereat; having the authenticator forward the authentication token to the authentication server; having the authentication server ascertain an authenticity of the received authentication token based on the shared secret available thereat; in case the authenticity of the authentication token is ascertained, having the authentication server generate a first authentication key based on the shared secret available thereat, and provide the generated authentication key to the authenticator; having the supplicant generate a second authentication key based on the shared secret; and having the supplicant and the authenticator exploit the generated first and the second keys for communicating with each other. The short authentication method is particularly useful in situations of handoff of the supplicant from an authenticator to another.


