Multi-Factor Wireless Authentication via Captive Portal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of securing wireless networks due to diverse portable devices and the inadequacy of guest networks in providing secure access to internal files or proprietary information, as existing security algorithms rely on static keys and lack unique identification of connecting entities, making them vulnerable to exploitation.
Innovation Solution
Implementing a multi-factor authentication system that includes device authentication followed by user authentication through a captive portal, with the option for additional secure tunnels based on various factors, to ensure secure access to wireless networks, employing standards like WPA-2 and 802.1X for wireless security and using AAA management servers for authentication and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If standard wireless security algorithms with static keys are used, then network access is simplified, but security is compromised and unique identification of connecting entities is not achieved
Solution Approach 1:
The authentication process is divided into multiple independent stages: device authentication (first factor) and user authentication (second factor). Each stage verifies a different aspect of identity, with device authentication confirming the device's identity and user authentication confirming the user's identity. This segmentation allows the system to maintain simplicity while enhancing security through layered verification.
Solution Approach 2:
A captive portal is introduced as an intermediary component that mediates between the wireless client and the network. The captive portal intercepts authentication requests and redirects users to a web-based authentication interface, serving as a bridge that enables multi-factor authentication without requiring changes to the underlying wireless infrastructure or client devices.
2Adaptability or versatility
If guest networks are implemented to permit roaming user access, then network accessibility is improved, but security for internal files and proprietary information deteriorates
Solution Approach 1:
Different authentication requirements and access permissions are assigned to different users and devices based on their specific identities and roles. The system evaluates multiple factors including device identity, user credentials, and authentication outcomes to dynamically determine appropriate access levels. This allows roaming users to access the network while maintaining differentiated security permissions for internal files and proprietary information.
3Reliability
If multi-factor authentication with multiple authentication layers is implemented, then network security is enhanced, but system complexity increases
Solution Approach 1:
Device authentication is performed automatically as a preliminary step before user authentication. The device's identity is verified in advance through wireless security protocols, and the results are stored for later use. This preliminary action reduces the complexity of the overall system by automating the first factor of authentication and preparing authentication data beforehand, so that when the user connects, much of the verification work has already been completed.
4Reliability
If device authentication precedes access to additional authentication layers, then security is improved, but authentication time increases
Solution Approach 1:
Device authentication is performed in advance and its results are cached and stored. When a user connects to the network, the system retrieves the pre-computed device authentication results rather than re-verifying them. This preliminary action significantly reduces the time required for multi-factor authentication while maintaining security, as the most time-consuming verification step has already been completed beforehand.
Data Source
AI summary
Systems and methods for device-agnostic, multi-factor network authentication are disclosed. In some embodiments, a wireless network connection can authenticate a device over secure authentication means with a certificate that confirms a device identity. After authenticating the device, a user can be prompted to provide credentials in a captive portal. The captive portal can be inaccessible to devices that have not already authenticated using a certificate. After providing approved credentials to the captive portal, the user can access the network. This embodiment and additional embodiments are readily integrated into private wireless networks and others.


