Wireless Roaming Group Segmentation for Access Controller Key Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current WLAN roaming techniques face challenges in seamless mobility between access controllers (ACs), particularly in efficiently managing key synchronization and system resource utilization during roaming, which affects the performance and scalability of wireless networks.

Innovation Solution

The implementation of parallel roaming groups using Key Cache for intra-group roaming and EAP reauthentication for inter-group roaming, where ACs are divided into groups based on network segment, STA and AP management, reducing the need for extensive key synchronization and resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If Key Cache is used for roaming between different ACs, then fast roaming is achieved, but extensive key synchronization is required which increases system complexity and resource consumption

Engineering Contradiction:
Improveroaming speedVSAvoidkey synchronization complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent divides ACs into multiple roaming groups (first roaming group, second roaming group, etc.) based on network segments. Each group manages key synchronization independently, reducing the scope of key distribution. This segmentation allows fast roaming within groups while limiting the complexity of inter-group key management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a roaming group manager as an intermediary component that coordinates between different roaming groups. This mediator handles the complexity of inter-group roaming decisions and key management, allowing ACs within groups to perform fast local key synchronization without needing to coordinate with all other ACs in the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all ACs synchronize key information, then seamless roaming is achieved, but system resource occupation increases

Engineering Contradiction:
Improveseamless roamingVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

By segmenting ACs into multiple roaming groups, the patent reduces the quantity of key information that needs to be synchronized at any given time. Each group maintains keys only for its member ACs, significantly reducing the total key storage requirements compared to a single large synchronization network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of requiring all ACs to synchronize with all other ACs (excessive action), the patent implements partial synchronization where each AC only synchronizes keys with ACs within its own roaming group. This partial action is sufficient for achieving seamless roaming within the constrained scope of each group.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If extensive information interaction occurs during roaming, then authentication is thorough, but roaming efficiency decreases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidroaming efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments authentication into two stages: first within roaming groups using cached keys (efficient), and only between groups when necessary (thorough). This segmentation allows most roaming operations to proceed with minimal information interaction while maintaining authentication reliability through the hierarchical group structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key synchronization and caching within roaming groups before actual roaming occurs. This preliminary action ensures that when a user roams within a group, authentication can proceed quickly using pre-shared keys, reducing the need for extensive real-time information interaction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9173083B2Wireless roaming method and access controller
Publication Date: 2015.10.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9173083B2 patent drawing
  • US9173083B2 patent drawing
  • US9173083B2 patent drawing

AI summary

According to an example, a reauthentication or reassociation message carrying a roaming group information may be received from a wireless client (STA) by an AC when the STA is roaming. In addition, the AC may determine, according to the roaming group information and the received reauthentication or reassociation message, whether the STA is roaming between roaming groups or within a roaming group. In response to a determination that the roaming is between roaming groups, an extension authentication protocol (EAP) reauthentication process may be initiated and in response to a determination that the roaming is within a roaming group, a Key Cache method may be adopted to authenticate the STA.