OpenRoaming EAP Failure Feedback for Adaptive Authentication Retries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless networks fail to provide detailed reasons for authentication and authorization failures, leading to inefficient repetitive attempts by devices, which waste network bandwidth and resources.

Innovation Solution

Implement methods to extend protocols for authenticating devices, allowing secure transmission of failure codes or reasons to the supplicant device, enabling it to make informed decisions on retrying, switching profiles, or waiting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If wireless networks use encrypted communications for authentication and authorization, then security is improved, but the ability to communicate failure reasons to devices is lost

Engineering Contradiction:
Improveauthentication securityVSAvoidfailure reason information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the authentication failure information into two parts: a public portion that can be safely transmitted to the supplicant device (containing the failure reason code) and a private portion that remains secure. This allows the failure reason to be communicated without compromising the encrypted authentication channel.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (a separate information channel or augmented EAP message structure) that carries failure reason information without interfering with the encrypted authentication process. This intermediary allows transparent transmission of diagnostic information while maintaining security protocol integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If devices repeatedly attempt authentication without knowing the failure reason, then they can try different approaches, but network bandwidth is wasted due to unnecessary retry attempts

Engineering Contradiction:
Improveauthentication retry flexibilityVSAvoidnetwork bandwidth
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent implements a feedback mechanism where the authentication system provides failure reason information back to the supplicant device. This feedback enables the device to make informed decisions about retry attempts, adjusting its behavior based on the specific failure cause (e.g., stopping retries for permanent failures like invalid credentials while allowing retries for temporary failures).

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables dynamic adjustment of authentication retry behavior based on the received failure reason. The supplicant device can adaptively modify its retry strategy in real-time, increasing or decreasing retry attempts depending on the nature of the failure, thereby optimizing network resource usage while maintaining connection reliability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12389226B2Openroaming augmentation method for EAP failures
Publication Date: 2025.08.12 CISCO TECHNOLOGY INC
  • US12389226B2 patent drawing
  • US12389226B2 patent drawing
  • US12389226B2 patent drawing

AI summary

The presently claimed disclosure is directed to methods that may be implemented at a computer. Methods and systems consistent with the present disclosure may include extending protocols associated with authenticating client (i.e. supplicant) devices and with authorizing those supplicant devices to access a wireless network. These methods may include sending data relating to the failure of an authentication and/or an authorization process to a supplicant device attempting to access a wireless network. Methods discussed within may include securely sending failure codes or reasons to a supplicant device that identify why an authentication or authorization process failed. These methods may include sending messages between a supplicant device, an authenticator device, and an authentication and authorization server. After a first failure, the supplicant device may be able to access the wireless network after a reason or code of that failure has been reported to the supplicant device.