Multi-Part Passphrase Authentication for Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless networks using a single password for access are vulnerable to password leakage and cannot provide user-differentiated services, raising privacy and security concerns.

Innovation Solution

The proposed solution involves storing a passphrase comprising a common password and a specific password on wireless devices, transforming these passwords into finite field elements, and using them to generate encryption keys for secure wireless connections, allowing differentiated access to network features based on the specific password.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single password is used for wireless network access, then ease of operation is improved, but security and user privacy deteriorate due to password leakage vulnerability and inability to provide differentiated services

Engineering Contradiction:
Improveease of network accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the single password into two distinct components: a common password (shared by all users) and a specific password (unique to each user). This segmentation allows the system to maintain ease of operation with a simple passphrase while improving security through differentiated authentication. The common password provides basic network access, while the specific password enables user-specific authorization and privacy protection.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If password identifiers are passed in clear text to enable differentiated authorization, then adaptability is improved, but privacy deteriorates due to exposure of user identification information

Engineering Contradiction:
Improveuser differentiation capabilityVSAvoiduser privacy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent extracts the user identification information (specific password) from the authentication process and processes it in a way that prevents its exposure. By using the specific password to generate unique cryptographic keys and authorization tokens, the system achieves user differentiation without transmitting or storing the actual password identifier in clear text, thereby protecting user privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If Enterprise Mode with AAA server is used to encrypt user ids, then security is improved, but device complexity and cost increase due to requirement of AAA server infrastructure

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service authentication mechanism where wireless devices autonomously generate cryptographic keys and perform authentication without requiring a centralized AAA server. Each device uses its specific password to generate unique keys locally, enabling secure differentiated access while eliminating the need for complex server infrastructure and reducing system overall complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250142323A1Methods, devices and systems for authentication of devices to a wireless network with multi-part passphrases
Publication Date: 2025.05.01 INFINEON TECHNOLOGIES AMERICAS CORP
  • US20250142323A1 patent drawing
  • US20250142323A1 patent drawing
  • US20250142323A1 patent drawing

AI summary

A method can include, by operation of a first wireless device, storing a first passphrase comprising a common password and a specific password, transforming the common password into a first finite field (FF) element and the specific password into a second FF element. A first key can be generated using a received third scalar value and third FF element. A commit message can be transmitted with a portion encrypted with the first key. In response to receiving a fourth scalar value and a fourth FF element, generating a second key using at least the fourth scalar value and the fourth FF element, and transmitting a second wireless message with a portion encrypted with the second key. In response to validating a received confirmation message using the second key, establishing encryption keys for a wireless connection using at least the second key. Corresponding devices and systems are also disclosed.