Wireless Handoff Authentication via Pre-shared Secret Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for speeding up handoff procedures in wireless communications networks, such as those compliant with IEEE 802.11i, are not satisfactory as they compromise security, incur significant delays, and resource wastage, especially when access points are compromised or when handoffs do not occur within a defined time frame.

Innovation Solution

A short authentication method is introduced, where a shared secret is used to generate authentication tokens between the supplicant and authentication server, allowing for faster key generation and secure communication without involving all access points in the authentication process, thus minimizing computational burden and maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current handoff procedures in IEEE 802.11i networks are used, then security is maintained through full authentication, but handoff latency increases and computational burden rises

Engineering Contradiction:
ImprovesecurityVSAvoidhandoff latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing a shared secret between the supplicant and authentication server before handoff occurs. During handoff, the supplicant generates an authentication token using this pre-shared secret, allowing the authentication server to quickly verify authenticity without performing a full authentication exchange, thus reducing handoff latency while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication process into two phases: a preliminary key establishment phase where a shared secret is created, and a rapid handoff phase where only token verification is needed. This segmentation allows the computationally intensive key generation to occur once, while handoffs use lightweight token verification, reducing both latency and computational burden during actual handoff events

Inventive Principle:
Principle #1Segmentation

2Reliability

If all access points are involved in authentication verification, then security is enhanced, but device complexity and computational burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication verification function from all access points and concentrates it solely in the authentication server. The supplicant generates an authentication token that is forwarded directly to the authentication server for verification, bypassing the need for other access points to participate in verification. This reduces device complexity at access points while maintaining centralized security verification

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication server acts as an intermediary that receives and verifies authentication tokens from supplicants during handoff. Instead of having all access points perform verification, the authentication server mediates the authentication process by validating tokens against the shared secret, simplifying the overall system architecture while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If shared secrets are distributed to all access points for verification, then authentication can be distributed, but security risk increases if access points are compromised

Engineering Contradiction:
Improvedistributed authenticationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the shared secret from the access points entirely and stores it only in the authentication server. During handoff, the supplicant uses the shared secret to generate a token that is verified by the authentication server. This extraction eliminates the security risk of compromised access points while maintaining distributed authentication capability, as the secret never resides in access points

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses cryptographic copying where the supplicant creates a derived authentication token from the shared secret without exposing the secret itself. The token is a cryptographic copy that contains sufficient information for verification but cannot be used to derive the original secret, allowing distributed authentication while protecting the security of the shared secret stored only in the authentication server

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8621201B2Short authentication procedure in wireless data communications networks
Publication Date: 2013.12.31 TELECOM ITALIA SPA
  • US8621201B2 patent drawing
  • US8621201B2 patent drawing
  • US8621201B2 patent drawing

AI summary

In a wireless communications network including at least one authenticator and at least one authentication server, wherein the authenticator is adapted to interact with the authentication server for authenticating supplicants in order to conditionally grant thereto access to the wireless communications network, a short authentication method for authenticating a supplicant, the method including: providing a shared secret, shared by and available at the supplicant and the authentication server; having the supplicant provide to the authenticator an authentication token, wherein the authentication token is based on the shared secret available thereat; having the authenticator forward the authentication token to the authentication server; having the authentication server ascertain an authenticity of the received authentication token based on the shared secret available thereat; in case the authenticity of the authentication token is ascertained, having the authentication server generate a first authentication key based on the shared secret available thereat, and provide the generated authentication key to the authenticator; having the supplicant generate a second authentication key based on the shared secret; and having the supplicant and the authenticator exploit the generated first and the second keys for communicating with each other. The short authentication method is particularly useful in situations of handoff of the supplicant from an authenticator to another.