Head End Wireless Device Authentication Split-Authenticator Model
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless networks, particularly Wi-Fi networks, the distribution of shared secrets to access points (APs) for authenticating with authentication servers is operationally infeasible due to security concerns, as APs are often deployed in hard-to-secure locations, making them vulnerable to tampering and compromising the shared secret, which can lead to decryption and alteration of traffic.
Innovation Solution
Implementing a split-authenticator model where the authentication server functions as a central entity, with access points acting as clients, eliminating the need for shared secrets on APs by using a head end (HE) to relay authentication messages and sign them with a shared secret, thereby protecting message integrity without distributing credentials to APs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If shared secrets are distributed to APs for authentication, then authentication security is improved, but the risk of secret compromise increases due to APs being deployed in hard-to-secure locations
Solution Approach 1:
The patent extracts the shared secret from the AP and relocates it to the HE. The HE now holds the shared secret and signs authentication messages, while the AP acts as a client without possessing the secret. This extraction eliminates the security risk of storing secrets in hard-to-secure locations while maintaining authentication integrity.
Solution Approach 2:
The HE serves as an intermediary between the AP and the authentication server. Instead of the AP directly communicating with the server using a shared secret, the HE relays authentication messages and performs signing operations. This intermediary role protects the secret from exposure at the AP while enabling secure authentication.
2Adaptability or versatility
If shared secrets are distributed to hundreds or thousands of APs, then authentication functionality is enabled, but operational feasibility deteriorates due to the complexity of managing and updating secrets across numerous devices
Solution Approach 1:
The patent merges the secret management function into a single centralized entity (the HE) rather than distributing it across hundreds or thousands of APs. The HE maintains the shared secret and performs all signing operations, eliminating the operational complexity of managing, updating, and rotating secrets across a large number of distributed devices.
Solution Approach 2:
By extracting the secret management responsibility from individual APs and consolidating it at the HE, the system eliminates the scalability problem. The HE can serve any number of APs without increasing operational complexity, as all secret-related operations are centralized in one location.
Data Source
AI summary
Embodiments of a device and method are disclosed. In an embodiment, a method of communications involves at a head end (HE), receiving an authentication message from a wireless access point (AP) deployed at a customer site and at the HE, receiving an authentication response from an authentication server in response to the authentication message.


