Mutual Authentication for Wireless Access Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless local area network (WLAN) connections between modems and routers at customer premises lack robust security, particularly due to vulnerabilities in Wi-Fi Protected Setup (WPS), allowing unauthorized access and leading to network congestion and economic harm for service providers.
Innovation Solution
Implementing a mutual authentication protocol using asymmetric keys and certificates, along with Diffie-Hellman cryptography, to ensure only authorized devices can connect, and utilizing Elliptic Curve keys for enhanced security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Wi-Fi Protected Setup (WPS) is used for establishing WLAN connections, then ease of operation is improved, but security is worsened due to vulnerabilities allowing unauthorized access
Solution Approach 1:
The patent introduces a mutual authentication protocol as an intermediary layer between the WPS connection establishment and network access. This protocol uses cryptographic verification (public key infrastructure, digital signatures) to mediate the authentication process, ensuring that both the modem and router verify each other's identities before allowing network access, thereby resolving the security vulnerability in WPS while maintaining ease of operation
Solution Approach 2:
The patent implements preliminary authentication actions before granting network access. The mutual authentication protocol performs cryptographic verification exchanges (including certificate validation and digital signature verification) prior to establishing the actual network connection, preventing unauthorized devices from accessing the network even if WPS vulnerabilities are exploited
2Adaptability or versatility
If unauthorized devices are allowed to connect, then device compatibility is improved, but network performance is worsened due to congestion and free-rider problems
Solution Approach 1:
The mutual authentication protocol acts as an intermediary gatekeeper that verifies device identities before allowing network access. It uses cryptographic credentials (certificates, digital signatures) to mediate between the desire for device compatibility and the need to prevent network congestion, allowing only authenticated devices to connect while blocking unauthorized ones
Solution Approach 2:
The patent implements a feedback mechanism where the authentication protocol continuously verifies device credentials and provides feedback on authentication status. The system monitors connection requests, validates cryptographic proofs, and provides immediate feedback by either granting or denying access, thereby preventing unauthorized devices from degrading network performance
Data Source
AI summary
A first wireless access device, associated with a wireless service provider, establishes a wireless local area network connection with a second wireless access device and receives a certificate including a unique identifier associated with the second wireless access device. The first wireless access device determines whether the second wireless access device is authorized to connect to the first wireless access device. For example, if the certificate is signed by a certificate authority associated with the wireless service provider and the unique identifier appears in a whitelist stored at the first wireless access device, the first wireless access device and the second wireless access device perform a mutual authentication procedure based on one or more ephemeral keys. The first wireless access device provides the second wireless access device with access to a wide area network based on successful completion of the mutual authentication procedure.


