Wireless Network Security via Pre-Authentication Cluster Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless network systems experience prolonged hand-over times due to complex and unstandardized authentication processes, particularly with Wi-Fi Protected Access (WPA), leading to potential call disconnections and reduced mobility in Wi-Fi phone services.

Innovation Solution

A system utilizing a cluster function where access points store lists of candidate terminals, enabling authentication success messages to be sent without additional authentication, allowing terminals to hand-over quickly by using pre-authenticated encryption keys, and sharing updated lists among neighboring access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WPA security authentication is performed using 802.1x authentication, then security level is improved, but hand-over time is increased

Engineering Contradiction:
Improvesecurity levelVSAvoidhand-over time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The access point performs authentication in advance and stores the authenticated terminal information in a candidate terminal list before hand-over occurs. When hand-over is needed, the terminal can quickly switch to a new access point using the pre-stored authentication information, eliminating the need for repeated authentication and significantly reducing hand-over time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication result is cached locally in the access point's candidate terminal list rather than requiring centralized authentication server verification for every hand-over event. This local caching mechanism allows rapid authentication decisions at the access point level, reducing hand-over latency while preserving security through selective use of cached credentials

Inventive Principle:
Principle #3Local quality

2Loss of time

If Fast BSS Transition of IEEE802.11r is implemented, then hand-over time is reduced, but system complexity is increased

Engineering Contradiction:
Improvehand-over timeVSAvoidauthentication process complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The access point creates a simplified copy of the authentication result in the candidate terminal list, storing essential authentication data without implementing the full Fast BSS Transition protocol. This copying approach captures the essential benefit of fast authentication while avoiding the complexity of standardized fast transition mechanisms

Inventive Principle:
Principle #26Copying

Solution Approach 2:

Instead of implementing complex standardized fast transition protocols that require significant system modifications, the patent inverts the approach by using traditional authentication followed by result caching. This reversal achieves fast hand-over through a simpler, more straightforward mechanism that avoids the complexity of unstandardized fast transition schemes

Inventive Principle:
Principle #13The other way round (Inversion)

3Productivity

If cluster function is used to share candidate terminal lists among access points, then hand-over speed is improved, but security management complexity is increased

Engineering Contradiction:
Improvehand-over speedVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Multiple access points are merged into a cluster that shares a common candidate terminal list. When one access point authenticates a terminal, the authentication result is automatically shared with other cluster members, enabling any access point in the cluster to provide fast authentication to the terminal. This merging approach improves hand-over speed across the network while distributing security management responsibilities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The candidate terminal list serves multiple functions: it stores authenticated terminal information for fast authentication, acts as a security credential repository, and enables cross-access point hand-over without re-authentication. This multi-functionality reduces the need for separate security mechanisms at each access point, simplifying overall security management while improving hand-over performance

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8204478B2System for setting security in wireless network system using cluster function and method of controlling the same
Publication Date: 2012.06.19 HUAWEI TECH CO LTD
  • US8204478B2 patent drawing
  • US8204478B2 patent drawing
  • US8204478B2 patent drawing

AI summary

A system for setting security in a wireless network system using a cluster function. An access point stores a list of candidate terminals of each neighboring access point. When an arbitrary terminal sends an access request, the access point determines whether or not the terminal is authenticated using the stored list of candidate terminals, and transmits an authentication success message to the requesting terminal if the requesting terminal is authenticated. The terminal performs hand-over to the access point without performing authentication upon receiving the authentication success message from the access point in response to the access request. Thus, the hand-over time of a Wi-Fi phone is reduced in an environment based on Wi-Fi Protected Access (WPA) that is one of the strongest wireless LAN security policies, so that the safety and mobility of wireless LAN services can be improved at the same time.