Gateway Authentication with SAE and Multi-PSK Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless security protocols like WPA2 and WPA3 face vulnerabilities such as brute force attacks and limitations in creating separate login groups with different network access capabilities, especially when using simultaneous authentication of equals (SAE) encryption methods.

Innovation Solution

Implementing an enhanced SAE encryption protocol that allows for multiple pre-shared keys (multi-PSK) to create distinct network groups with varying access levels, enabling a gateway to monitor login attempts and apply alternative encryption methods based on device identification and pre-approval, thereby providing differentiated network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SAE encryption method is used, then security against brute force attacks is improved, but ability to create separate network groups with different access levels deteriorates

Engineering Contradiction:
Improvesecurity against brute force attacksVSAvoidability to create separate network groups
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network access by implementing multiple SSIDs (Service Set Identifiers), each associated with different encryption methods and access levels. This allows the network to divide users into distinct groups (e.g., guests, employees, administrators) with different resource access rights, resolving the contradiction between security and group differentiation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic authentication by allowing devices to be pre-approved for alternative encryption methods based on their device identification. The gateway dynamically selects between SAE and multi-PSK protocols based on device trust levels, enabling flexible access control that adapts to different device types and user needs.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If multi-PSK encryption is used, then ability to create network groups with different access levels is improved, but vulnerability to brute force attacks increases

Engineering Contradiction:
Improveability to create network groupsVSAvoidvulnerability to brute force attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by assigning different encryption methods to different network groups based on their specific needs and trust levels. Pre-approved devices use SAE encryption for enhanced security, while other devices use multi-PSK for group differentiation. This localized approach optimizes security without uniformly compromising the entire network.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If gateway monitors and handles different login attempts, then network access control is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork access controlVSAvoidgateway complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by having devices automatically authenticated based on pre-approval status. Pre-approved devices are automatically granted access using SAE encryption without manual intervention, while other devices are automatically directed to multi-PSK authentication. This automation reduces the operational burden on administrators while maintaining robust access control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250279893A1Providing Authentication in a Network
Publication Date: 2025.09.04 COMCAST CABLE COMM LLC
  • US20250279893A1 patent drawing
  • US20250279893A1 patent drawing
  • US20250279893A1 patent drawing

AI summary

Methods are described for use of encryption methods for multiple network groups with different passkeys. A gateway may be configured so that the gateway may manage an authentication process of particular or pre-identified devices wireless devices differently from other devices. The gateway may determine if the device is a pre-identified device and if the passkey used by the device is an authorized passkey, and may authenticate the device using a particular encryption method.