Head End Wireless Device Authentication Split-Authenticator Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless networks, particularly Wi-Fi networks, the distribution of shared secrets to access points (APs) for authenticating with authentication servers is operationally infeasible due to security concerns, as APs are often deployed in hard-to-secure locations, making them vulnerable to tampering and compromising the shared secret, which can lead to decryption and alteration of traffic.

Innovation Solution

Implementing a split-authenticator model where the authentication server functions as a central entity, with access points acting as clients, eliminating the need for shared secrets on APs by using a head end (HE) to relay authentication messages and sign them with a shared secret, thereby protecting message integrity without distributing credentials to APs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If shared secrets are distributed to APs for authentication, then authentication security is improved, but the risk of secret compromise increases due to APs being deployed in hard-to-secure locations

Engineering Contradiction:
Improveauthentication securityVSAvoidrisk of secret compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the shared secret from the AP and relocates it to the HE. The HE now holds the shared secret and signs authentication messages, while the AP acts as a client without possessing the secret. This extraction eliminates the security risk of storing secrets in hard-to-secure locations while maintaining authentication integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The HE serves as an intermediary between the AP and the authentication server. Instead of the AP directly communicating with the server using a shared secret, the HE relays authentication messages and performs signing operations. This intermediary role protects the secret from exposure at the AP while enabling secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If shared secrets are distributed to hundreds or thousands of APs, then authentication functionality is enabled, but operational feasibility deteriorates due to the complexity of managing and updating secrets across numerous devices

Engineering Contradiction:
Improveauthentication functionalityVSAvoidsecret management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the secret management function into a single centralized entity (the HE) rather than distributing it across hundreds or thousands of APs. The HE maintains the shared secret and performs all signing operations, eliminating the operational complexity of managing, updating, and rotating secrets across a large number of distributed devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

By extracting the secret management responsibility from individual APs and consolidating it at the HE, the system eliminates the scalability problem. The HE can serve any number of APs without increasing operational complexity, as all secret-related operations are centralized in one location.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12069475B2Methods and systems of head end based wireless device authentication
Publication Date: 2024.08.20 NILE GLOBAL INC
  • US12069475B2 patent drawing
  • US12069475B2 patent drawing
  • US12069475B2 patent drawing

AI summary

Embodiments of a device and method are disclosed. In an embodiment, a method of communications involves at a head end (HE), receiving an authentication message from a wireless access point (AP) deployed at a customer site and at the HE, receiving an authentication response from an authentication server in response to the authentication message.