Wireless Network Key Distribution for Roaming Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing 802.11i specification for wireless local area networks (WLANs) requires clients to re-authenticate with each access point during handoff, leading to significant latency, which is detrimental for real-time data transfers such as voice communications.

Innovation Solution

The solution involves allowing clients to maintain the same encryption key (SEK) when transitioning between access points coupled to the same authentication server, using a four-way handshake and a trusted third party (the server) to securely distribute and manage the encryption key, eliminating the need for repeated authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If clients re-authenticate with each access point during handoff according to 802.11i specification, then security is maintained, but latency increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidlatency during handoff
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication server pre-distributes the Pairwise Master Key (PMK) to multiple access points before handoff occurs. When a client roams between APs within the same authentication domain, the SEK is already cached at the target AP, eliminating the need for real-time re-authentication and reducing handoff latency while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An authentication server acts as a trusted intermediary that manages key distribution across multiple access points. The server mediates between the client and multiple APs by caching SEKs at APs and verifying handoff requests, enabling seamless roaming without direct client-reauthentication with each AP while preserving security through centralized control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If clients maintain the same encryption key when roaming between access points, then handoff latency is reduced, but key distribution complexity increases

Engineering Contradiction:
Improvehandoff latencyVSAvoidkey distribution system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The authentication server serves as a trusted intermediary that simplifies key distribution by centrally managing SEK caching at multiple access points. This intermediary approach reduces distribution complexity compared to peer-to-peer key management, as the server handles key generation, caching, and verification across the authentication domain

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server performs multiple functions: it authenticates clients, distributes PMKs to APs, caches SEKs at APs for rapid handoff, and verifies handoff requests. This multi-functionality consolidates key management operations into a single trusted entity, reducing overall system complexity while enabling fast roaming

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7529925B2System and method for distributing keys in a wireless network
Publication Date: 2009.05.05 TRAPEZE NETWORKS INC
  • US7529925B2 patent drawing
  • US7529925B2 patent drawing
  • US7529925B2 patent drawing

AI summary

A technique for improving authentication speed when a client roams from a first authentication domain to a second authentication domain involves coupling authenticators associated with the first and second authentication domains to an authentication server. A system according to the technique may include, for example, a first authenticator using an encryption key to ensure secure network communication, a second authenticator using the same encryption key to ensure secure network communication, and a server coupled to the first authenticator and the second authenticator wherein the server distributes, to the first authenticator and the second authenticator, information to extract the encryption key from messages that a client sends to the first authenticator and the second authenticator.