Multi-Factor Wireless Authentication via Captive Portal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of securing wireless networks due to diverse portable devices and the inadequacy of guest networks in providing secure access to internal files or proprietary information, as existing security algorithms rely on static keys and lack unique identification of connecting entities, making them vulnerable to exploitation.

Innovation Solution

Implementing a multi-factor authentication system that includes device authentication followed by user authentication through a captive portal, with the option for additional secure tunnels based on various factors, to ensure secure access to wireless networks, employing standards like WPA-2 and 802.1X for wireless security and using AAA management servers for authentication and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard wireless security algorithms with static keys are used, then network access is simplified, but security is compromised and unique identification of connecting entities is not achieved

Engineering Contradiction:
Improvenetwork access simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is divided into multiple independent stages: device authentication (first factor) and user authentication (second factor). Each stage verifies a different aspect of identity, with device authentication confirming the device's identity and user authentication confirming the user's identity. This segmentation allows the system to maintain simplicity while enhancing security through layered verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A captive portal is introduced as an intermediary component that mediates between the wireless client and the network. The captive portal intercepts authentication requests and redirects users to a web-based authentication interface, serving as a bridge that enables multi-factor authentication without requiring changes to the underlying wireless infrastructure or client devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If guest networks are implemented to permit roaming user access, then network accessibility is improved, but security for internal files and proprietary information deteriorates

Engineering Contradiction:
Improvenetwork accessibilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Different authentication requirements and access permissions are assigned to different users and devices based on their specific identities and roles. The system evaluates multiple factors including device identity, user credentials, and authentication outcomes to dynamically determine appropriate access levels. This allows roaming users to access the network while maintaining differentiated security permissions for internal files and proprietary information.

Inventive Principle:
Principle #3Local quality

3Reliability

If multi-factor authentication with multiple authentication layers is implemented, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Device authentication is performed automatically as a preliminary step before user authentication. The device's identity is verified in advance through wireless security protocols, and the results are stored for later use. This preliminary action reduces the complexity of the overall system by automating the first factor of authentication and preparing authentication data beforehand, so that when the user connects, much of the verification work has already been completed.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If device authentication precedes access to additional authentication layers, then security is improved, but authentication time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Device authentication is performed in advance and its results are cached and stored. When a user connects to the network, the system retrieves the pre-computed device authentication results rather than re-verifying them. This preliminary action significantly reduces the time required for multi-factor authentication while maintaining security, as the most time-consuming verification step has already been completed beforehand.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10966088B1Wireless multi-factor authentication with captive portals
Publication Date: 2021.03.30 WELLS FARGO BANK NA
  • US10966088B1 patent drawing
  • US10966088B1 patent drawing
  • US10966088B1 patent drawing

AI summary

Systems and methods for device-agnostic, multi-factor network authentication are disclosed. In some embodiments, a wireless network connection can authenticate a device over secure authentication means with a certificate that confirms a device identity. After authenticating the device, a user can be prompted to provide credentials in a captive portal. The captive portal can be inaccessible to devices that have not already authenticated using a certificate. After providing approved credentials to the captive portal, the user can access the network. This embodiment and additional embodiments are readily integrated into private wireless networks and others.