WPA3 Cloud-based Network Access and Provisioning

By using WPA3 protocol and device provisioning protocol (DPP) in cloud provisioning systems, the weaknesses of existing Wi-Fi security protocols in the face of attacks and IoT device security authentication difficulties are solved, achieving higher wireless network security and simplified device management.

JP2025514620APending Publication Date: 2025-05-09DISH NETWORK LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024557448
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-03-29
Filing Date
2023-03-29
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Existing Wi-Fi security protocols such as WPA and WPA2 have weaknesses in the face of attacks, especially when using pre-shared keys (PSKs), and some devices such as IoT devices lack a user interface and are difficult to perform secure authentication.

Method used

Using WPA3-based authentication process, a wireless network access profile with user identification is created through the cloud provisioning system to realize the secure authentication of the device, and the device provisioning protocol (DPP) is used to exchange secure network credentials, avoiding dependence on PSK.

Benefits of technology

Improves the security of wireless networks, enhances resistance to brute-force attacks, and simplifies security authentication and network access management for interfaceless devices such as IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025514620000001_ABST
    Figure 2025514620000001_ABST
Patent Text Reader

Abstract

Systems, methods, and non-transitory machine-readable media may facilitate wireless network provisioning. In one example, a method for provisioning wireless network access for a wireless device includes creating a wireless network access profile in a cloud-based provisioning system including a user identifier associated with the wireless device, receiving an authentication request at an access point transmitted from the wireless device, identifying, by the cloud-based provisioning system, the wireless device based on the user identifier associated with the wireless device, performing, on the cloud-based provisioning system, a WPA3-based authentication to authenticate the wireless device, and providing, by the access point, network access to the wireless device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Provisional Patent Application No. 63 / 325,017, filed March 29, 2022, the disclosure of which is incorporated by reference in its entirety for all purposes. [Background technology]

[0002] Wireless networks are susceptible to attacks such as eavesdropping, packet sniffing, and data theft. Enabling wireless devices for wireless network access may present challenges. Traditional security protocols such as WPA2, WPA, or older versions may help prevent attacks by providing secure encryption methods for wireless connections and communications between wireless devices and wireless networks. For example, WPA2 may include features such as key management, authentication, and data integrity checks to further enhance security. While WPA and WPA2 are effective in improving wireless network security, challenges still exist. For example, both WPA and WPA2 use pre-shared keys (PSKs) for authentication, which may be susceptible to brute force attacks if the PSKs are not properly managed and used. If an attacker can obtain the PSK, the attacker may be able to decrypt all network traffic. In addition, WPA and WPA2 may be of limited use if the wireless device attempting to connect to the wireless network does not have a user interface that can be used to present such requests and gather user credentials. For example, many Internet of Things (IoT) devices, such as sensor devices, may not have a user interface that is sufficient for a user to efficiently enter such credentials. Summary of the Invention

[0003] According to some embodiments of the present disclosure, a method is provided. In one example, the method includes creating, in a cloud-based provisioning system, a wireless network access profile including a user identifier associated with a wireless device, receiving, at an access point, an authentication request transmitted from the wireless device, identifying, by the cloud-based provisioning system, the wireless device based on the user identifier associated with the wireless device, performing, on the cloud-based provisioning system, a WPA3-based authentication to authenticate the wireless device, and providing wireless network access to the wireless device via the access point.

[0004] In some embodiments, the method further includes receiving, by the cloud-based provisioning system, an authentication request generated by the wireless device from the wireless device via the access point, the authentication request including a user-provided PSK and a user-provided password identifier, comparing the user-provided password identifier with a provided password identifier in the wireless network access profile to identify a match, and providing network access to the wireless device in response to the identified match.

[0005] In some embodiments, the method further includes generating, by the wireless device, a public-private key pair including a public key and a private key; receiving, on the cloud-based provisioning system, the public key sent from the wireless device; sending a verification request to the wireless device; receiving, on the cloud-based provisioning system, a response message sent from the wireless device, the response message including a signature value signed by the private key; and verifying, by the cloud-based provisioning system, the signature value using the public key.

[0006] In some embodiments, the method further includes generating, on the wireless device, a first group element and a first scalar value using an agreed-upon algorithm between the wireless device and the authentication system; receiving, on the cloud based provisioning system, a commit message sent from the wireless device via the AP, the commit message including the first group element; generating, on the cloud based provisioning system, a second group element and a second scalar value using the agreed-upon algorithm; transmitting the second group element to the wireless device; generating, on the wireless device, a first shared secret key based on the first scalar value and the second group element using the agreed-upon algorithm; generating, on the authentication system, a second shared secret key based on the second scalar value and the first group element using the agreed-upon algorithm; and identifying a match of the first shared secret key and the second shared secret key by the authentication system.

[0007] In another example, a method includes creating a wireless network access profile for a wireless device, the wireless network access profile storing a pre-shared key (PSK) associated with the wireless device, a password identifier corresponding to the PSK, and a user identifier associated with the PSK and the password identifier; receiving an authentication request transmitted from the wireless device, the authentication request including a user-provided PSK and a user-provided password identifier; performing a WPA3 based authentication by comparing the user-provided PSK and the user-provided password identifier with a stored PSK and a stored password identifier, respectively, in the wireless network access profile; identifying a match between the user-provided PSK and the stored PSK and between the user-provided password identifier and the stored password identifier; and providing network access to the wireless device in response to the identified match.

[0008] According to some embodiments of the present disclosure, a cloud-based provisioning system is provided. In one example, the cloud-based provisioning system includes one or more processors and a computer-readable storage medium storing computer-executable instructions, which, when executed by the one or more processors, cause the cloud-based provisioning system to: create a wireless network access profile for a wireless device, the wireless network access profile storing a pre-shared key (PSK) associated with the wireless device, a password identifier corresponding to the PSK, and a user identifier associated with the PSK and the password identifier; receive an authentication request transmitted from the wireless device, the authentication request including a user-provided PSK and a user-provided password identifier; perform a WPA3-based authentication by comparing the user-provided PSK and the user-provided password identifier with a stored PSK and a stored password identifier in the wireless network access profile, respectively; identify a match between the user-provided PSK and the stored PSK, and between the user-provided password identifier and the stored password identifier; and provide network access to the wireless device in response to the identified match.

[0009] According to some embodiments of the present disclosure, a non-transitory processor-readable medium is described that may include processor-readable instructions configured to cause one or more processors to perform any of the methods or operations described herein.

[0010] Further understanding of the nature and advantages of various embodiments may be realized with reference to the following figures. In the accompanying figures, similar components or features may have the same reference label. Furthermore, various components of the same type may be distinguished by following the reference label with a dash symbol and a second label that distinguishes the similar components. When only a first reference label is used in this specification, the description is applicable to any one of the similar components having the same first reference label, regardless of the second reference label. [Brief description of the drawings]

[0011] [Figure 1] 1 is a schematic diagram illustrating an example of a communication system, in accordance with various embodiments. [Diagram 2] 1 is a schematic diagram illustrating another example of a communication system, in accordance with various embodiments. [Diagram 3] FIG. 1 is a flow diagram illustrating an example method for wireless network provisioning use, according to various embodiments. [Figure 4] 1 is a flow diagram illustrating an example method for wireless device authentication use, according to various embodiments. [Diagram 5] 4 is a flow diagram illustrating another example method for wireless device authentication use, according to various embodiments. [Figure 6] 4 is a flow diagram illustrating a further example method for wireless device authentication use, according to various embodiments. [Figure 7] FIG. 1 is a schematic diagram illustrating an embodiment of a computer system, in accordance with various embodiments. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0012] overview This disclosure provides techniques for authenticating devices and provisioning network services or resources to wireless-enabled devices using WPA3-based authentication protocols.

[0013] One insight provided in this disclosure is that the method described herein utilizes a Wi-Fi Protected Access 3 (WPA3) based authentication process to authenticate wireless-enabled devices. WPA3 is the latest version of the Wi-Fi security protocol used to secure wireless networks. WPA3 offers several improvements over previous versions of the WPA protocol, such as WPA and WPA2, including stronger encryption and more robust protection against attacks. WPA3 also adds new features such as Simultaneous Authentication of Equals (SAE), which enhances security and privacy for users. Notably, one of the main improvements of WPA3 is the use of a key exchange process with 256-bit encryption, which provides stronger protection against brute force attacks. WPA3 also introduces the use of forward secrecy, which ensures that even if an attacker manages to obtain a Wi-Fi network password, the attacker cannot decrypt previously captured data. WPA3 includes new security features that make it more difficult for an attacker to guess a password and gain unauthorized access to wireless network services or resources. WPA3 also allows for a simplified configuration and a simplified data exchange process between wireless devices and access points during authentication.

[0014] Another insight provided in this disclosure is that the methods described herein can use Device Provisioning Protocol (DPP) to facilitate WPA3-based authentication and network service provisioning. DPP is a novel feature of the WPA3 protocol that allows wireless-enabled devices to securely exchange network credentials without the need for pre-shared keys or manual configuration. In some embodiments according to the present disclosure, DPP can use a secure public key infrastructure (PKI) to allow devices to authenticate and securely exchange network credentials. This eliminates the need for users to manually enter wireless network passwords, which can be time-consuming and possibly insecure. For example, the DPP protocol can be used to support multiple deployment models, including QR code scanning, Near-Field Communication (NFC), and Bluetooth Low Energy (BLE). DPP also provides several benefits for wireless network administrators and users by simplifying the process of adding new devices to the network and reducing the risk of unauthorized access or password sharing. DPP also supports secure network onboarding for devices that do not have a user interface, such as IoT sensors and smart home devices.

[0015] A further insight provided in this disclosure is that the method described herein utilizes common data storage technology coupled with standards-based communication protocols to create a process of securely authenticating wireless-enabled devices and provisioning wireless network services or resources to authenticated devices. According to some embodiments, the method provides a means for creating a profile that associates a unique and verified user identifier (such as an email address, a customer loyalty number, an apartment number, or a patient record identifier) ​​with a WPA3 pre-shared key and password identifier for the wireless-enabled device. In addition, the method provides a means for restricting, granting, or controlling access to any number of these wireless-enabled devices to any number of managed networks based on the associated WPA3 pre-shared key, password identifier, and a set of applied logical rules. By moving this novel method to a globally available cloud, authentication and provisioning can be performed on any network around the world that utilizes the same pre-shared key and password identifier. Finally, the method allows authenticated devices to be automatically provisioned onto managed networks and gain access to global Internet or IP resources according to a set of applied logical rules.

[0016] EXEMPLARY SYSTEMS AND METHODS 1 is a schematic diagram illustrating an example of a communication system 100, according to various embodiments. In the illustrated example, the communication system 100 includes, among other components, a cloud-based provisioning system 110, a database 112, a registration system 120, Internet 130, an access point (AP) 140, and a wireless-enabled device (hereinafter, "wireless device") 150.

[0017] The registration system 120 may include one or more computing devices or systems (e.g., an example shown in FIG. 7) and may be operated or configured by an administrator tasked with managing access to the wireless network hosted by the AP. When one or more of a user's wireless devices are to be provided with access to the wireless network, the registration system 120 may be used to generate a unique pre-shared key (PSK). Similar to a traditional Wi-Fi network, a user may select a wireless network based on the wireless network's Service Set Identifier (SSID) and enter a PSK. In the embodiments detailed herein, the PSK may be specific to a user (or group of users) and may have been provided to the user separately (e.g., in a registration email, by text message, verbally, on paper, etc.).

[0018] In some embodiments, a user may be permitted to define their own PSK or a portion of the PSK (the registration system 120 defines the rest). The unique PSK may be required to be unique compared to other PSKs used by the cloud-based provisioning system 110. The PSK may be provided only to the user or a small group of related users (e.g., residents of a particular apartment building, members of a particular travel group). The registration system 120 may be used to transmit a message to the user indicating the unique PSK, the SSID of the wireless network, a unique user identifier associated with the user (e.g., username, email address, customer loyalty number, apartment number, hotel room number, patient record identifier, MAC address of a wireless device, employee ID, home address, date of birth, membership number, biometric data (e.g., fingerprint or facial recognition), reservation number, social security number, user-created password, etc.), and / or other details and / or rules that may be associated with the user, such as the times and dates the user is authorized to access the wireless network, the bandwidth allocated to the user, access and / or creation of personal networks (PANs), and access to virtual local area networks (VLANs), etc.

[0019] The registration system 120 may transmit the message to the user in many forms: for example, an email may be transmitted to an email address on record for the user, a text message may be sent to the user's mobile phone number, a letter may be addressed and mailed to the user (e.g., as part of a hotel reservation or welcome package), a representative or automated system may call (or separately speak with) the user (e.g., upon hotel check-in), a message may be presented on a display screen for the user to read, a code may be presented to the user to capture on their device, NFC, Bluetooth, or other short-range data transfer may be implemented.

[0020] The enrollment system 120 may be in direct communication with the cloud-based provisioning system 110 or may communicate with the cloud-based provisioning system 110 over a network such as the Internet 130. Alternatively, the enrollment system 120 and the cloud-based provisioning system 110 may function as components of a software implementation of the same server system. In some embodiments, the enrollment system 120 may have direct access to the database 112.

[0021] The database 112 may include, among other components, a PSK database, a profile database, and a rules database. The PSK database may be used to store PSKs associated with wireless devices. The profile database may be used to store wireless access profiles associated with wireless data sets. The rules database may be used to store predefined rules for wireless access.

[0022] In addition to being provided with a unique PSK for the user, a wireless network access profile may be created in the profile database based on data obtained from the registration system 120 into the profile database. The wireless network access profile may include the unique PSK, the SSID of the wireless network, a unique user identifier associated with the user. The rules database may include rules associated with the user (e.g., times and dates when access to the wireless network is permitted via the wireless network access profile, amount of allocated bandwidth, access to the PAN, access to VLANs), and data regarding use of the wireless network access profile (e.g., whether the unique PSK has been used previously for wireless network access).

[0023] AP 140 may represent a device that creates or functions as part of a wireless network through which one or more wireless devices, if properly authenticated, can access the Internet and / or some other public or private network. In the embodiment shown, there is a single AP. AP 140 uses a WPA3-based protocol as a security protocol for protecting network communications. It should be understood that the embodiments detailed herein may be adapted to and used with other communication and security protocols.

[0024] A wireless device, such as wireless device 150, may generally be any form of computerized device capable of communicating with a wireless network. Examples of wireless devices include, but are not limited to, smartphones, tablets, laptops, smart home devices, and Internet of Things (IoT) devices. In some embodiments, one or more wired network devices may also be present. For example, a wired network device may be directly connected to AP 140 using a cable (e.g., an Ethernet cable). Once access is granted for a wireless device, such as wireless device 150, to a wireless network, the wireless device may also be able to communicate with some or all of the wired devices connected to the network.

[0025] In the example of an IoT device (e.g., a sensor device, a home automation device), there may be no user interface or there may be a limited user interface. The IoT device may require or benefit from network connectivity, but it may be difficult or impossible for a user to perform any form of network authentication for the IoT device. In some embodiments, an application may run on another device, such as the wireless device 150, to configure the IoT device. Through such a device, the user may be able to provide credentials that the IoT device can use to perform authentication with the AP 140.

[0026] Wireless device 150 may include a smartphone, a tablet computer, a laptop computer, a desktop computer, a gaming device, a smart television, a home assistant device, a smart doorbell, a smart smoke detector, a smart carbon monoxide detector, a streaming video camera, a set-top box (STB), etc. When a user desires a wireless device, such as wireless device 150 in this example, to initially communicate with a wireless network, the user may enter or select the correct SSID, as provided by registration system 120, and enter a unique PSK into wireless device 150.

[0027] The wireless device 150 may perform an initial pairing procedure, for example, to determine whether a unique PSK grants access to the wireless network created by the AP 140. The wireless device 150 may also generate a commit message to be used in the key exchange process based on the Simultaneous Authentication of Equal (SAE) protocol specific to the WPA3-based authentication process. Note that the SAE process may use a more secure authentication method that prevents an attacker from using an offline dictionary attack to discover the Wi-Fi password. The SAE process may use a unique password (e.g., derived from the commit message) for each connection, which is generated by the wireless device 150 and the AP 140 during the authentication process. In some embodiments, after the SAE is performed, a handshake procedure may be performed, such as a WPA3 4-way handshake.

[0028] The AP 140 may transmit the message received from the wireless device, along with any other required data such as the EAPoL frame, the AP MAC address, and the MAC address of the wireless device, to the cloud-based provisioning system 110 via the Internet 130 (or additionally or alternatively via some other public and / or private network, or directly). In some embodiments, when the SAE protocol is used in the authentication process, the AP 140 may communicate with the wireless device 150 by transmitting a challenge message in response to a request sent from the wireless device 150. The AP 140 may further transmit a hash value generated by the wireless device 150 to the cloud-based provisioning system 110 for verifying the hash value.

[0029] The cloud-based provisioning system 110 includes a WPA3-based authentication system 115. The cloud-based provisioning system 110 and the WPA3-based authentication system 115 may include one or more computer server systems in communication with one or more databases 112 that are stored using a non-transitory processor-readable medium.

[0030] The profile database stores wireless network access profiles, which may include, for example, an allowed time range for access, an allowed date range for access, whitelisted and / or blacklisted MAC addresses, an amount of bandwidth, a total amount of uplink and / or downlink data allowed within a given time period (e.g., one month), allowed or disallowed usage (e.g., no video streaming), whether further authentication is required, a level of access the network is allowed to be accessed, etc.

[0031] In some embodiments, data from the wireless network access profile is transmitted over the Internet 130 (or some other network) to the AP 140 and / or other components of the network. In such embodiments, the AP 140 may analyze the contents of the wireless network access profile to determine whether the wireless device 150 should be provided network access. In other embodiments, the determination of whether access is allowed is performed by the WPA3-based authentication system 115 or the cloud-based provisioning system 110. The advantage of transmitting the PMK is that an encryption algorithm may not need to be applied by the AP 140. The AP 140 may use the received PSK with the wireless device 150 to complete the handshake procedure and initiate communication. Such an arrangement results in the PSK never being transmitted between the wireless device 150 and the AP 140 in either encrypted or unencrypted form.

[0032] In some embodiments, the data stored as part of the wireless network access profile in the profile database may be dynamic. For example, when a PSK associated with the wireless network access profile is used by the wireless device to connect with any AP for a first time, one or more additional steps may be required to be performed. The data in the wireless network access profile may indicate whether the PSK has been previously used to connect with an AP for which the cloud-based provisioning system 110 manages access. For example, after communication between the wireless device 150 and the AP 140 is established using the PSK, but before the AP 140 grants network access (access to the Internet 130), terms of use may be transmitted to the wireless device 150 for presentation to and acceptance by a user of the wireless device 150. Once the terms of use are accepted and an indication of such is received by the AP 140, the AP 140 may transmit such an indication to the cloud-based provisioning system 110 to modify the wireless network access profile associated with the PSK to indicate that the terms of use have been agreed to and do not need to be presented again. In other embodiments, the terms of use may be provided at a different step in the provisioning process. For example, in some embodiments, in order to receive the PSK and / or SSID, a user may first be required to accept terms of use.

[0033] In some embodiments, in response to the wireless device being successfully granted access to the wireless network, the MAC address (or some other form of identifier for the wireless device) may be stored and associated with the wireless network access profile, or the PSK stored in the wireless network access profile. If the device attempts to reconnect to the wireless network in the future, a MAC address match may be identified rather than repeating the entire provisioning process.

[0034] In some embodiments, additional security beyond the wireless device being used to supply a valid PSK may be desired by an administrator operating the registration system 120. As previously noted, additional information such as a unique user identifier (e.g., email address, password) may be stored as part of the wireless network access profile in the profile database. After the PSK is verified, the AP may request that the wireless device supply additional information. For example, the AP 140 may request an email address, loyalty identifier / number, apartment number, patient record identifier, or some other form of unique and verified user identifier from the wireless device 150. The user may then supply the email address (or other form of unique user identifier) ​​provided to the registration system 120 during the registration process. Either the AP 140 or the WPA3-based authentication system 115 or the cloud-based provisioning system 110 may verify whether the provided unique user identifier matches a stored unique user identifier in the wireless network access profile. If there is a match, network access may be provided. If there is no match, network access may not be provided and / or the wireless network access profile may be disabled. Depending on the desires of the administrator of the registration system 120, such additional security steps may be performed only once for a given wireless network access profile, may be performed each time a wireless device connects to a new AP, and / or may be performed for each new wireless device that uses a PSK to connect with an AP whose access is controlled via the cloud-based provisioning system 110.

[0035] The WPA3-based authentication system 115 may also be capable of and operable to perform a key exchange process following an SAE-based or DPP-based protocol. In some embodiments, a PSK is not generated and used in the key exchange process. Further examples of SAE-based or DPP-based protocols for authentication are described below with reference to Figures 5-6.

[0036] In the illustrated embodiment of FIG. 1, there may be a single database 112 that stores wireless network access profiles. Alternatively, the PMK database and the profile database may exist as separate databases. In some embodiments, the stored data may be stored across a greater number of databases or other forms of data storage arrangements (e.g., tables). Additionally, although FIGS. 1 and 2 depict the cloud-based provisioning system 110 as being located remotely from the APs 140 and 142, in some embodiments, the cloud-based provisioning system 110 may be co-located with one or more APs and communicate without using the Internet. For example, a wired local area network connection may be used.

[0037] 2 illustrates another example of a communication system 200. The communication system 200 can function similarly to the system 100 of FIG. 1. However, the system 200 can include multiple APs, such as AP 140 and AP 142. The APs 140 and AP 142 can be located in different geographic locations or can be nearly co-located. Co-located can refer to APs located in the same building, facility, campus, etc. Different locations can refer to different buildings, different hotels, different facilities, etc. For example, a business may want to provide users with access to APs across business offices spread across a city, state, country, continent, or the world.

[0038] If the APs are co-located, as the wireless device moves a relatively short distance, such as within a building, the wireless device may switch which AP it communicates with, but access may remain authorized due to access being managed for both APs by cloud-based provisioning system 110. Similarly, if APs 140 and 142 are installed in different geographic locations, network access may still be managed centrally by cloud-based provisioning system 110. For example, an entity such as a property rental company may be able to centrally manage guest access across many properties via cloud-based provisioning system 110.

[0039] In some embodiments, AP 140 and AP 142 may represent different base stations of a cellular network. Full or partial access may be granted to the cellular network in a manner similar to that of a wireless local area network.

[0040] If the initial registration process is performed with a first AP, such as when the wireless device 150 previously communicated with the AP 140, the data stored in the profile database may indicate that the wireless device is authorized for access. Thus, when the wireless device 150 accesses the AP 142, the back-end process for the AP 142 to acquire the correct authentication information (e.g., PSK, CE, hash value, etc.) may need to be repeated, but the terms of use (or some other one-time event) may not need to be presented or repeated by the wireless device 150 again by virtue of the wireless network access profile stored in the profile database indicating that the event has already occurred. Similarly, if the user (or an associated user) reuses the authentication information on another device, the terms of use may not need to be presented or accepted because the same wireless network access profile is used.

[0041] Various methods may be implemented using the detailed systems of Figures 1 and 2. Figure 3 shows an example method 300 for wireless network provisioning. Method 300 may be implemented using system 100, system 200, or some other form of system that enables wireless network provisioning using WPA3-based authentication. Depending on the implementation, method 300 may include additional, fewer, or alternative steps performed in various orders or in parallel.

[0042] At 302, a wireless network access profile is created. As noted above, the wireless network access profile may include a PSK, a password identifier, a unique and verified user identifier associated with the PSK, a user identifier including user credentials and device information, or other information associated with the user and / or wireless device. Other information or data may also be included in the WPA3 wireless network access profile, such as a primary connection location, a device access MAC address, acceptance of acceptable use policies, etc. This data may be organized into predefined data structures and stored as one or more data tables in some type of relational database system, such as Microsoft SQL Server or Microsoft Access, and may follow common rules of normalization.

[0043] In some embodiments, the wireless network access profile is created directly by a user of the wireless device. As an example, the user of the wireless device may manually enter profile information (e.g., a user identifier, user credentials, and device information associated with the wireless device information, etc.) into a user interface, such as a web page. The profile information is captured and further organized and stored in a profile database. The user interface may be exposed to an integratable system, such as an asset management system. Once the integratable system creates the requested data, it transmits the requested data to a data repository, such as a profile database connected to a cloud-based provisioning system. In another embodiment, the wireless network access profile is created by an authorized representative. A predefined manual data entry process may be utilized by the authorized representative to assist the user in identifying and entering the correct information and storing the information in the profile database.

[0044] At 304, an authentication request is sent to an AP that supports WPA3 authentication. The authentication request may indicate an attempt to access a network service or resource (i.e., the Internet) through the AP and may include user credentials and information provided or entered by the user (e.g., a user-provided PSK, a user-provided password identifier, a user-provided user identifier, etc.). Once the authentication request is received by the AP, the AP may transmit all or selected data included in the authentication request to a cloud-based provisioning system.

[0045] At 306, the wireless device is identified by the authentication system based on a wireless network access profile associated with the wireless device. A search may be performed to locate the wireless network access profile in a profile database connected to the cloud-based provisioning system. Information such as a user identifier, user credentials, and device information of the wireless network access profile may be obtained and compared with user-provided information included in the authentication request sent from the wireless device to confirm an identity match of the wireless device.

[0046] At 308, WPA3 authentication is performed by an authentication system of the cloud-based provisioning system to authenticate the wireless device based on the wireless network access profile. Typically, data or information provided by the user or transmitted from the wireless device is compared to wireless network access profiles previously registered with the cloud-based provisioning system and stored in a database to identify a match. If a match is identified, the wireless device is authenticated. To enable the wireless device for access to network services or resources, the data or information provided by the user must be presented in a predefined manner to allow the authentication system to properly utilize the data information. Such presentation may include, but is not limited to, moving the data to a temporary data table in a database management system, setting an option field in an existing data table to identify that network access is being requested, providing a data field join to present the data to the authentication system. WPA3 authentication may be performed using a PSK. Alternatively, a key exchange approach may also be used. Further examples of the WPA3 authentication process are described with reference to Figures 4-6.

[0047] At 310, once the wireless device is authenticated, access to the network service or resource is granted and the network access is provisioned by the AP according to predefined logical rules. As mentioned above, the predefined logical rules may be stored in a rules database connected to the cloud-based provisioning system. The rules are related to the user and the wireless device associated with the user, including, but not limited to, the time and date when access to the wireless network is granted via the wireless network access profile, the amount of allocated bandwidth, access to the PAN, access to the VLAN, and data regarding the use of the wireless network access profile (e.g., whether a unique PSK was previously used for wireless network access). The rules may be triggered by an external event. Examples of external events may include, but are not limited to, a hotel guest reserving a room, a patient visiting a doctor's office, an airline passenger purchasing an airline ticket, a renter or resident signing a rental agreement, etc. Once an event triggers this process, access to the network service or resource is granted according to the predefined rules.

[0048] In some embodiments, additional actions may be performed by the authentication system, which may include, but are not limited to, sending commands to any and all network equipment responsible for providing network services or resources, sending billing information to a billing authority, logging the transaction in a database management system associated with the network, etc.

[0049] 4 illustrates an example method 400 for wireless network provisioning using a PSK. Method 400 may be implemented using system 100, system 200, or some other form of system that enables wireless network provisioning using WPA3-based authentication. Depending on the implementation, method 400 may include additional, fewer, or alternative steps performed in various orders or in parallel. Method 400, or any operations thereof, may be combined with other methods described herein in any suitable manner.

[0050] At 402, the unique PSK and SSID of the wireless network access profile are provided to a wireless device that intends to access a network service or resource. In some embodiments, the unique PSK may be randomly generated and checked to ensure that it does not match any other PSK associated with the wireless network access profile. The unique PSK may be created using the cloud-based provisioning system 110, the registration system 120, or some other computerized component that has access to the profile database 114. The unique PSK may be created and stored in the profile database of the cloud-based provisioning system. The unique PSK, possibly along with other relevant information (e.g., the network SSID), may be provided to the user via any of the previously disclosed arrangements so that the user can enter the unique PSK to connect with the wireless network.

[0051] In some embodiments, a user may be permitted to create their own PSK and provide it to the cloud-based provisioning system for storage in the profile database. For example, a user may access the cloud-based provisioning system via a user interface and be provided with the opportunity to enter a desired PSK. In such embodiments, the PSK created by the user may be checked against other PSKs in the profile database to ensure there is no match with other PSKs assigned to other users. If there is a match, the user may be required to create a different PSK, or both the user and other users who were already mapped with the matching PSK may be required to each create a new PSK before being allowed to access the network. In some embodiments, the cloud-based provisioning system may define a portion of the PSK and the user may define a portion of the PSK. By the cloud-based provisioning system defining a portion of the PSK, any matches with other PSKs in the profile database may be prevented. For example, the cloud-based provisioning system may specify a unique preamble portion of the PSK (ensuring there is no match with other PSKs in the profile database) and the user is permitted to define a later portion of the PSK.

[0052] In some embodiments, the unique PSK, possibly along with other information, may be provided to a wireless device intending to access the wireless network. A user may access a network configuration interface and select or enter the correct SSID. The user may then be prompted to enter the PSK and password identifier. If the wireless device was an IoT device that does not have a user interface that allows direct entry of data, the user may run an application on another computerized device or perform some other action to enter data on behalf of the IoT device. Such other computerized device may forward the SSID and PSK to the IoT device for use in connecting with the AP.

[0053] In some embodiments, a QR code is generated to make it easier for a user to connect to a network without having to manually enter an SSID and password identifier. The QR code may store data such as a PSK, a password identifier, a unique and verified user identifier associated with the user and the wireless device. The QR code may be included in a wireless network access profile associated with the wireless device. When a user scans the QR code using a wireless device, the wireless device automatically transmits the data and information contained in the QR code to the AP.

[0054] At 404, the wireless device may attempt to connect with an AP of the wireless network. An authentication request may be generated by the wireless device and transmitted to the AP. The authentication request may include data provided by the user, such as a user-entered PSK, a user-entered password identifier, or additional data (e.g., a MAC address, a commit message, a calculated scalar value, a calculated element value, etc.). In some embodiments, a PTK may also be generated based on the PSK, and the PTK may be included in the authentication request. At 406, upon receiving the authentication request, the AP may forward the authentication request to a cloud-based provisioning system along with all or selected data provided or entered by the user.

[0055] At 408, the cloud-based provisioning system may search a profile database coupled to the cloud-based provisioning system and locate a wireless network access profile associated with the user or wireless device from the profile database based on the user-provided data included in the authentication request (e.g., the user-entered PSK and the user-entered password identifier). In some embodiments, the cloud-based provisioning system may obtain additional data from the wireless network access profile and perform further comparisons.

[0056] A match may be identified at 410. A match is determined to exist when user-provided data included in the authentication request matches data included in a wireless network access profile associated with a user of the wireless device that has been previously registered in a database connected to the cloud-based provisioning system. In some embodiments, a match is identified when a password identifier included in the authentication request matches a password identifier included in the previously registered wireless network access profile.

[0057] At 412, if the data included in the authentication request and the data provided by the previously registered wireless network access profile match, a response indicating that the wireless device is authenticated is sent from the cloud-based provisioning system to the AP to grant the wireless device access to the wireless network. In some embodiments, the response may include only the PSK associated with the password identifier. In some embodiments, the response may include additional data, such as fully computed and calculated scalars and elements. In some embodiments, a PMK is generated based on the PSK and the associated password identifier, and the PMK is also included in the response. In some embodiments, the additional data may be collected from the wireless device based on data stored in the previously registered wireless network access profile before access is granted. For example, the user may be required to provide a user identifier (e.g., username, email address, loyalty number) that matches a stored identifier in the previously registered wireless network access profile, and / or the user may be required to accept a set of terms of use that are provided to the wireless device (or that are provided to associated wireless devices). In some embodiments, the wireless network access profile may be updated to include data regarding wireless devices that have successfully connected (e.g., the wireless device has accepted the terms of use, the MAC address of the wireless device, etc.).

[0058] In some embodiments, the AP may establish an encrypted communications session with the wireless device and grant network (e.g., Internet) access to the wireless device. In some embodiments, data stored in a wireless network access profile may be mapped to a PSK and used to further define the scope of network access or add additional conditions, such as whether additional layers of security, such as the need to agree to terms of use, the amount of bandwidth provided, the total amount of data allowed to be uploaded or downloaded, temporal restrictions, and / or matching of the user's unique user identifier, must be in place before network access is granted via the AP and / or other devices used to prepare the connection and / or grant access.

[0059] At 414, the provisioning process may be completed and network access based at least in part on the unique PSK may be provided to the wireless device. For example, the network access may be used to access the Internet. In other embodiments, the access may be used to grant access to another network, such as an intranet, a corporate LAN, etc. In some embodiments, the provisioning process may be used to restrict access to the network. For example, for a particular device or type of device (mapped to a particular PSK), the level of access granted to the wireless network may be limited according to predetermined rules. For example, a device may be granted intranet access but not allowed to access the Internet via the intranet.

[0060] In some embodiments according to the present disclosure, the method 400 does not involve the use of a Message Integrity Code (MIC) commonly used in WPA2-based security protocols.

[0061] 5 illustrates an example method 500 for wireless network provisioning using the DPP protocol. Method 500 may be alternative or additional to method 400. Method 500 may be implemented using system 100, system 200, or some other form of system that enables wireless network provisioning using WPA3-based authentication. Depending on the implementation, method 500 may include additional, fewer, or alternative steps implemented in various orders or in parallel. Method 500, or any operations thereof, may be combined with other methods described herein in any suitable manner.

[0062] At 502, a request is sent from a wireless device to an AP to initiate a DPP process. The request may include a message containing information about the device, such as its capabilities and supported protocols. A response message may be sent from the AP to the wireless device. The response message may confirm that the wireless network supports the DPP protocol and may include information about the network name, security settings, a URL to a DPP configuration file, etc. Such information may be used to initiate a WPA3 authentication process.

[0063] At 504, a DPP Initiation frame is transmitted to the AP. The DPP Initiation frame may be generated by the wireless device based on user information, a wireless device identifier (e.g., MAC address), a network identifier (e.g., SSID), security settings (e.g., WPA3-Personal or WPA3-Enterprise), a nonce for the wireless device, a DPP configuration file, a unique and verified identifier associated with the user, additional credentials, and other information obtained from the response message sent from the AP. In some embodiments, a public-private key pair is generated by the wireless device at 506. Unlike a PSK, a public-private key pair includes both a public key shared by the wireless device and the AP and a private key known only to the wireless device. The public key is used to identify the wireless device to the network. The public key is shared with the network during the DPP Initiation frame and is used by the network to securely provision the device onto the network. The public key may be generated using asymmetric cryptography and is mathematically related to the private key. Meanwhile, the private key is kept secret by the wireless device and is used to sign messages sent to the network to provide integrity protection. Only the wireless device that generated the public-private key pair has access to the private key. The private key may also be generated using asymmetric cryptography and is mathematically related to the public key. The public key is included in the DPP Initiation frame sent to the AP. In some embodiments, the public key may be included in the wireless network access profile, but the private key is not included in the wireless network access profile.

[0064] At 508, a key exchange process is performed by the authentication system of the cloud-based provisioning system. The WPA3 authentication process typically utilizes the SAE key exchange protocol to derive a shared key between the device and the network using the device's public-private key pair and the network's private key to secure communication between the wireless device and the AP. The key exchange protocol may be performed using algorithms such as the Diffie-Hellman algorithm, the Elliptic Curve Diffie-Hellman (ECDH) algorithm, and the Finite Field Diffie-Hellman (FFDH) algorithm, the Dragonfly key exchange algorithm, etc., depending on the security mode and capabilities of the wireless device.

[0065] In some embodiments, operation 508 may further include operations 510-518. At 510, the public key of the public-private key pair is transmitted to the AP. The public key is used to encrypt and decrypt data communicated between the wireless device and the AP. The public key is further transmitted to an authentication system of the cloud-based provisioning system.

[0066] At 512, a validation request is sent from the authentication system via the AP to the wireless device to verify that the wireless device possesses the public key of the private-public key pair required to authenticate with the AP and establish a secure connection to a network service or resource. The validation request may be generated using the SAE protocol in the form of a challenge message. In some embodiments, the challenge message is encrypted using the Diffie-Hellman key exchange algorithm. The wireless device may decrypt the challenge message using the private key of the private-public key pair and send back a response proving that it has the correct private key corresponding to the public key (i.e., the current private-public key pair).

[0067] At 514, a response message is generated by the wireless device in response to the verification request. The response message includes a private key corresponding to the public key of the private-public key pair. In some embodiments, the response message includes a first value. The first value may be a hash value signed with the private key of the private-public key pair. For example, a hash of the data included in the response message may be generated by the wireless device using a particular algorithm, and this hash is further signed with the private key of the private-public key pair to produce a signature value that is unique to the data and the private key of the wireless device. In some embodiments, the response message may be encrypted using the public key and sent back to the authentication system via the AP.

[0068] At 516, the response message sent from the wireless device is received by the AP and further transmitted to the authentication system. The response message is decrypted using the public key and a second value is calculated by the authentication system. A determination is made as to whether the second value matches the first value included in the response message. A match of the first and second values ​​ensures that the wireless device possesses a private key associated with the public key previously exchanged in the key exchange process.

[0069] In some embodiments, the public key of the private-public key pair is obtained by the authentication system, for example, from a wireless network access profile previously registered with the authentication system and stored in a profile database. A two-step verification may be performed by the authentication system to verify the hash value and the signature value. The first value may be verified by the authentication system by independently calculating a hash value of the data included in the response message using the same algorithm as the wireless device. The signature value may be verified using the public key, as described above. In some embodiments, a mathematical operation on the signature value is performed using the public key to yield a result. A determination is made as to whether the result matches the hash value calculated by the authentication process. If the two values ​​match, the signature is considered valid and the access point may be confident that the wireless device possesses a private key corresponding to the public key it previously provided.

[0070] At 518, in response to the verified signature, a session key is generated and shared between the wireless device and the AP. The session key may be derived from a shared secret calculated during a key exchange process between the wireless device and the AP along with other data previously exchanged using a key derivation function (KDF). For example, the wireless device and the authentication system may each create a pre-shared secret value exclusively known to each of them. The key derivation function (KDF) may be used to incorporate the pre-shared value along with a random number (salt) and user identity or device information obtained from the wireless network access profile and the SSID of the network to produce a session key. The session key may be used to encrypt and decrypt data transmitted between the access point and the wireless device during the session.

[0071] 6 illustrates an example method 600 for wireless network provisioning utilizing the SAE protocol. Method 600 may be alternative or additional to methods 400 and 500. Method 600 may be implemented using system 100, system 200, or some other form of system that enables wireless network provisioning using WPA3-based authentication. Depending on the implementation, method 600 may include additional, fewer, or alternative steps performed in various orders or in parallel. Method 600, or any operations thereof, may be combined with other methods described herein in any suitable manner.

[0072] At 602, an authentication request is sent from a wireless device attempting to access a network service or resource via the AP. The authentication request is received by the AP and further transmitted to an authentication system of a cloud-based provisioning system for authentication. Both the authentication system and the wireless device have the capability to support WPA3 and SAE protocols. The authentication request may further include user-provided user credentials and information associated with the wireless device. Such user-provided credentials and device information may be compared with user credentials and device information previously stored in a wireless network access profile as described herein and registered in a profile database connected to the authentication system.

[0073] At 604, a response is sent from the authentication system via the AP to the wireless device. The response may include a message confirming the identity of the wireless device and configuration documentation for a particular key exchange algorithm or protocol. In some embodiments, upon receipt of the authentication request, the wireless device is identified. For example, a profile database associated with the authentication system is searched to locate a wireless device access profile previously registered with the authentication system, and user credentials and device information associated with the wireless device are obtained from the wireless device access profile to identify the wireless device.

[0074] At 606, a first group element and a first scalar value are generated by the wireless device using a key exchange algorithm. An example of a key exchange algorithm is the Diffie-Hellman algorithm. The group element may be in the form of a pair of coordinates (x,y), where x and y are 256-bit numbers. The coordinates are used to calculate a generating point on an elliptic curve that serves as the group element. The generating point is agreed upon by both the wireless device and the authentication system. The first group element may be calculated using the scalar value and the generating point on the particular elliptic curve. A commit message is generated by the wireless device, and the first group element and the first scalar value are included in the commit message.

[0075] At 608, a second group element and a second scalar value are generated by the authentication system using the same key exchange algorithm. The second group element may be generated in a similar manner as the first group element. At 610, the second group element is transmitted to the wireless device in a key exchange process. At 612, a first shared secret key is generated on the wireless device. The first shared secret key is calculated based on the first scalar value and the second group element provided by the authentication system using a predetermined configuration. The first shared secret key is then transmitted to the authentication system via the AP. At 614, a second shared secret key is similarly generated on the authentication system using the same predetermined configuration based on the second scalar value and the first group element provided by the wireless device. The second shared secret key is transmitted to the authentication system via the AP. At 616, a match of the first and second shared secret keys is identified to confirm authentication of the wireless device. A confirmation message of successful authentication may be transmitted to the wireless device.

[0076] It should be noted that both methods 400 and 500 described herein (i.e., DPP-based and SAE-based protocols) utilize a key exchange process and may not involve a PSK in the WPA3 authentication process. Compared to the PSK-based protocol, the DPP-based and SAE-based protocols may provide improved security, overall simplified configuration, simplified communication between the wireless device and the authentication system, and better resistance to dictionary attacks on the PSK. In addition, the wireless network access profile created and registered on the authentication system may provide an additional layer of protection for users to access network services and resources.

[0077] Example Computer Systems / Devices FIG. 7 is a schematic diagram illustrating an example of a computer system 700 (sometimes referred to as a "computer device" 700). The computer system 700 is a simplified computer system that can be used to implement various embodiments described and illustrated herein. The computer system 700 illustrated in FIG. 7 can be incorporated into a device such as a portable electronic device, a mobile phone, a wireless device, a server, or other devices and systems described herein. FIG. 7 provides a schematic diagram of one embodiment of a computer system 700 that can implement some or all of the steps of the methods and workflows provided by various embodiments. It should be noted that FIG. 7 is intended only to provide a generalized illustration of the various components, any or all of which may be utilized where appropriate. FIG. 7 thus broadly illustrates how individual system elements can be implemented in a relatively separate or relatively more integrated manner.

[0078] Computer system 700 is shown including hardware elements that may be electrically coupled via a bus 705 or, where appropriate, may otherwise be in communication. The hardware elements may include one or more processors 710, including without limitation one or more general purpose processors and / or one or more special purpose processors, such as digital signal processing chips, graphics acceleration processors, and / or the like; one or more input devices 715, which may include without limitation a mouse, a keyboard, a camera, and / or the like; and one or more output devices 720, which may include without limitation a display device, a printer, and / or the like.

[0079] The computer system 700 may further include and / or be in communication with one or more non-transitory storage devices 725, which may include, without limitation, local and / or network accessible storage, and / or may include, without limitation, disk drives, drive arrays, optical storage devices, solid-state storage devices, e.g., random access memory ("RAM"), and / or read-only memory ("ROM"), which may be programmable, flash updatable, and / or the like. Such storage devices may be configured to implement any suitable data store, including without limitation various file systems, database structures, and / or the like.

[0080] The computer system 700 may also include a communication subsystem 730, which may include, without limitation, a modem, a network card (wireless or wired), an infrared communication device, a wireless communication device, and / or a chipset, e.g., a Bluetooth™ device, a 602.11 device, a WiFi device, a WiMax device, a cellular communication facility, and / or the like. The communication subsystem 730 may include one or more input and / or output communication interfaces to allow data to be exchanged with a network, such as a network described below, to name just a few, other computer systems, a television, and / or any other device described herein. Depending on the desired functionality and / or other implementation concerns, a portable electronic device or similar device may communicate images and / or other information via the communication subsystem 730. In other embodiments, a portable electronic device, e.g., a first electronic device, may be incorporated into the computer system 700, e.g., an electronic device, as an input device 715. In some embodiments, the computer system 700 further includes a working memory 735, which may include a RAM or ROM device, as described above.

[0081] Computer system 700 may also include software elements shown currently residing in working memory 735, including operating system 760, device drivers, executable libraries, and / or other code, e.g., one or more application programs 765, that may include computer programs provided by various embodiments and / or that may be designed to perform methods and / or configure systems provided by other embodiments as described herein. By way of example only, one or more procedures described with respect to the methods discussed above, such as those described in connection with FIG. 7, may be implemented as code and / or instructions executable by a computer and / or a processor within a computer, such that in one aspect such code and / or instructions may be used to configure and / or adapt a general-purpose computer or other device to perform one or more operations in accordance with the described methods.

[0082] A set of these instructions and / or code may be stored in a non-transitory computer-readable storage medium, such as storage device 725 described above. In some cases, the storage medium may be incorporated within a computer system, such as computer system 700. In other embodiments, the storage medium may be separate from the computer system and may be a removable medium, such as, for example, a compact disc, and / or may be provided within an installation package, such that the storage medium may be used to program, configure, and / or adapt a general-purpose computer with the instructions / code stored thereon. These instructions may take the form of executable code that is executable by computer system 700 and / or may take the form of source and / or installable code that takes the form of executable code upon compilation and / or installation on computer system 700, for example, using any of a variety of commonly available compilers, installation programs, compression / decompression utilities, and the like.

[0083] It will be apparent that substantial variations can be made according to particular requirements. For example, customized hardware could also be used and / or particular elements could be implemented in hardware, software, including portable software such as applets, or both. Furthermore, connections to other computing devices, such as network input / output devices, could be used.

[0084] As noted above, in one aspect, some embodiments may employ a computer system such as computer system 700 to perform methods according to various embodiments of the present technology. According to a set of embodiments, some or all of the operations of such methods are performed by computer system 700 in response to processor 710 executing one or more sequences of one or more instructions contained in working memory 735, which may be embedded in other code, such as operating system 760 and / or application program 765. Such instructions may be read into working memory 735 from another computer-readable medium, such as one or more of storage devices 725. By way of example only, execution of a sequence of instructions contained in working memory 735 may cause processor 710 to perform one or more steps of the methods described herein. Additionally or alternatively, portions of the methods described herein may be performed through dedicated hardware.

[0085] The terms "machine-readable medium" and "computer-readable medium" as used herein refer to any medium that participates in providing data that causes a machine to operate in a particular manner. In an embodiment implemented using computer system 700, various computer-readable media may participate in providing instructions / code to processor 710 for execution and / or may be used to store and / or retain such instructions / code. In many implementations, computer-readable media are physical and / or tangible storage media. Such media may take the form of non-volatile or volatile media. Non-volatile media include, for example, optical and / or magnetic disks, such as storage device 725. Volatile media include, without limitation, dynamic memory, such as working memory 735.

[0086] Common forms of physical and / or tangible computer readable media include, for example, a floppy disk, a flexible disk, a hard disk, a magnetic tape or any other magnetic medium, a CD-ROM, any other optical medium, punch cards, paper tape, any other physical medium with a pattern of holes, RAM, PROM, EPROM, FLASH-EPROM, any other memory chip or cartridge, or any other medium from which a computer can read instructions and / or code.

[0087] Various forms of computer readable media may be involved in carrying one or more sequences of one or more instructions to the processor 710 for execution. By way of example only, the instructions may initially be carried on a magnetic and / or optical disk of a remote computer. The remote computer may load the instructions into its dynamic memory and send the instructions as signals over a transmission medium to be received and / or executed by the computer system 700.

[0088] The communications subsystem 730 and / or components thereof typically receive a signal and the bus 705 may then communicate that signal, and / or data, instructions, etc. carried by the signal, to the working memory 735, from which the processor 710 retrieves and executes the instructions. The instructions received by the working memory 735 may optionally be stored in a non-transitory storage device 725 either before or after execution by the processor 710.

[0089] The methods, systems, and devices discussed above are examples. Various configurations may omit, substitute, or add various procedures or components, where appropriate. For example, in alternative configurations, the method may be performed in a different order than described, and / or various stages may be added, omitted, and / or combined. Also, features described with respect to a particular configuration may be combined in various other configurations. Different aspects and elements of the configurations may be combined in a similar manner. Also, because technology evolves, many of the elements are examples and do not limit the scope of the disclosure or claims.

[0090] Specific details are provided in the description to provide a thorough understanding of the exemplary configurations, including implementations. However, the configurations may be practiced without these specific details. For example, well-known circuits, processes, algorithms, structures, and techniques are shown without unnecessary detail to avoid obscuring the configurations. This description provides only example configurations and does not limit the scope, applicability, or configurations of the claims. Rather, the foregoing description of the configurations provides an enabling description for implementing the described technology. Various changes may be made in the function and arrangement of elements without departing from the spirit or scope of the present disclosure.

[0091] Also, the configurations may be described as processes depicted as schematic flow charts or block diagrams. Although each may describe the operations as a sequential process, many of the operations may be performed in parallel or simultaneously. In addition, the order of operations may be rearranged. A process may have additional steps not included in the figures. Furthermore, the examples of the methods may be implemented by hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof. When implemented in software, firmware, middleware, or microcode, the program code or code segments to perform the necessary tasks may be stored in a non-transitory computer-readable medium, such as a storage medium. A processor may perform the described tasks.

[0092] As used in this specification and the appended claims, the singular forms "a," "an," and "the" include plural references unless the context clearly dictates otherwise. Thus, for example, a reference to "a user" includes a plurality of such users, a reference to "the processor" includes a reference to one or more processors and equivalents thereof known in the art, and so forth.

[0093] Additionally, the terms "comprise," "comprising," "contains," "containing," "include," "including," and "includes," when used in this specification and the claims that follow, are intended to specify the presence of stated features, integers, components, or steps, but they do not exclude the presence or addition of one or more other features, integers, components, steps, acts, or groups.

[0094] Although some example configurations have been described, various modifications, alternative constructions, and equivalents may be used without departing from the spirit of the disclosure. For example, the elements may be components of a larger system, and other rules may take precedence or otherwise modify the application of the technology. Also, some steps / operations may take place before, during, or after the elements are discussed. Thus, the above description does not bind the scope of the claims.

Claims

1. 1. A method for provisioning wireless network access for a wireless device, comprising: creating, in a cloud based provisioning system, a wireless network access profile including a user identifier associated with the wireless device; receiving, at an access point, an authentication request transmitted from the wireless device; identifying, by the cloud based provisioning system, the wireless device based on the user identifier associated with the wireless device; performing a WPA3 based authentication on the cloud-based provisioning system to authenticate the wireless device; providing wireless network access to said wireless device via said access point; A method comprising:

2. 2. The method of claim 1, wherein the wireless network access profile further includes a plurality of predetermined rules including a bandwidth restriction and a time period during which network access is permitted, and the network access is provided to the wireless device for the time period indicated by the wireless network access profile in accordance with the bandwidth restriction.

3. 2. The method of claim 1, wherein the user identifier is at least one of a username, an email address, a customer loyalty number, a condominium number, a hotel room number, a patient record identifier, a MAC address of the wireless device, an employee ID, a home address, a date of birth, a membership number, and a reservation number.

4. The method of claim 1 , wherein the wireless network access profile is manually generated by a user of the wireless device through a user interface of the wireless device.

5. The method of claim 1 , wherein the wireless network access profile is generated by an authorized representative.

6. The method of claim 1 , wherein the wireless network access profile further includes a pre-shared key (PSK) and a password identifier.

7. Implementing the WPA3 based authentication includes: receiving, by the cloud-based provisioning system, from the wireless device via the access point, the authentication request generated by the wireless device, the authentication request including a user-provided PSK and a user-provided password identifier; comparing the user-provided password identifier with the password identifier in the wireless network access profile to identify a match; providing network access to the wireless device in response to the identified match; The method of claim 6 further comprising:

8. The method of claim 1 , wherein performing the WPA3 based authentication further comprises performing a key exchange process between the wireless device and the cloud-based provisioning system.

9. performing the key exchange process, generating, by the wireless device, a public-private key pair including a public key and a private key; receiving, at the cloud-based provisioning system, the public key transmitted from the wireless device; sending a validation request to the wireless device; receiving, on the cloud-based provisioning system, a response message transmitted from the wireless device, the response message including a signature value signed by the private key; verifying, by the cloud-based provisioning system, the signature value using the public key; The method of claim 8 , further comprising:

10. performing the key exchange process, 10. The method of claim 9, further comprising generating, by the cloud-based provisioning system, a session key based on a pre-shared secret value between the wireless device and the cloud-based provisioning system, the session key being used to encrypt and decrypt data transmitted between the access point and the wireless device during a session.

11. performing the key exchange process, generating, at the wireless device, a first group element and a first scalar value using an algorithm agreed upon between the wireless device and the authentication system; receiving, on the cloud-based provisioning system, a commit message transmitted from the wireless device via the AP, the commit message including the first group element; generating, on the cloud-based provisioning system, a second group element and a second scalar value using the agreed upon algorithm; transmitting the second group elements to the wireless device; generating, on the wireless device, a first shared secret based on the first scalar value and the second group element using the agreed upon algorithm; generating, on the authentication system, a second shared secret key based on the second scalar value and the first group element using the agreed upon algorithm; identifying, by the authentication system, a match between the first shared secret key and the second shared secret key; The method of claim 8 , further comprising:

12. performing the key exchange process, 12. The method of claim 11, further comprising: sending a message to the wireless device, the message indicating the agreed upon algorithm to be used in the key exchange process.

13. The method of claim 8 , wherein the key exchange does not involve generating a pre-shared key (PSK).

14. requesting the user identifier from the wireless device; receiving a user-provided user identifier provided from the wireless device; 10. The method of claim 1, further comprising: comparing, by the cloud-based provisioning system, the user-provided user identifier with the user identifier that is part of the wireless network access profile, and providing network access is conditioned on the user identifier matching the stored user identifier.

15. The method of claim 1 , further comprising updating the wireless network access profile to include data regarding authentication of the wireless device.

16. 1. A cloud-based provisioning system, comprising: one or more processors; and a computer-readable storage medium storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to: creating a wireless network access profile for a wireless device, the wireless network access profile storing a pre-shared key (PSK) associated with the wireless device, a password identifier corresponding to the PSK, and a user identifier associated with the PSK and the password identifier; receiving an authentication request transmitted from the wireless device, the authentication request including a user-provided PSK and a user-provided password identifier; performing a WPA3 based authentication by comparing the user-provided PSK and a user-provided password identifier with the stored PSK and the stored password identifier, respectively, in the wireless network access profile; identifying a match between the user-provided PSK and the stored PSK, and between the user-provided password identifier and the stored password identifier; providing network access to the wireless device in response to the identified match; A cloud-based provisioning system that enables

17. The instructions may be for causing one or more processors to: requesting the user identifier from the wireless device; receiving a user-provided user identifier from the wireless device; 17. The cloud based provisioning system of claim 16, further operable to: compare the user-provided user identifier with the user identifier that is part of the wireless network access profile, and providing network access is conditioned on the user identifier matching the user identifier.

18. 17. The cloud-based provisioning system of claim 16, wherein the wireless network access profile further includes a plurality of predetermined rules including a bandwidth restriction and a time period during which network access is permitted, and the network access is provided to the wireless device for the time period indicated by the wireless network access profile in accordance with the bandwidth restriction.

19. 17. The cloud-based provisioning system of claim 16, wherein the user identifier is at least one of a username, an email address, a customer loyalty number, a condominium number, a hotel room number, a patient record identifier, a MAC address of the wireless device, an employee ID, a home address, a date of birth, a membership number, and a reservation number.

20. The cloud-based provisioning system of claim 16 , wherein the wireless network access profile is manually generated by a user of the wireless device through a user interface of the wireless device.