OpenRoaming EAP Feedback to Reduce Repeated Authentication Attempts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless networks fail to provide reasons for authentication and authorization failures, leading to inefficient repetitive attempts that waste network bandwidth and computing resources.
Innovation Solution
Methods are introduced to securely transmit failure codes or reasons to supplicant devices, allowing them to understand why authentication or authorization processes failed, enabling better decision-making on retrying, switching profiles, or waiting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If failure reasons are not transmitted to supplicant devices, then network security is maintained through encryption, but devices cannot understand why authentication/authorization fails and must repeatedly retry
Solution Approach 1:
The patent introduces an intermediary mechanism (authentication server or access point) that receives failure reason information from the authorization server and transmits it to the supplicant device through EAP messages. This intermediary allows failure information to be conveyed without compromising the encryption security of the authentication process, resolving the contradiction between maintaining security and providing feedback.
Solution Approach 2:
The patent implements a feedback mechanism where failure reason codes are transmitted back to the supplicant device through EAP messages after authentication/authorization failures. This feedback allows devices to understand why they were rejected and make informed decisions about retrying or switching profiles, improving authentication efficiency while maintaining security through encrypted channels.
2Loss of energy
If devices repeatedly attempt authentication without failure reasons, then simple retry logic is used, but network bandwidth and computing resources are wasted
Solution Approach 1:
The patent provides feedback in the form of failure reason codes to supplicant devices, enabling them to make intelligent decisions about whether to retry authentication, switch to different profiles, or wait before attempting again. This feedback mechanism reduces unnecessary retry attempts and associated network bandwidth consumption while the added complexity of processing failure reasons is managed by standard EAP message handling.
Solution Approach 2:
The patent changes the parameter of authentication messages by adding failure reason codes to EAP messages transmitted between devices and authentication servers. This parameter enhancement enables devices to adjust their behavior based on specific failure reasons, reducing redundant authentication attempts and optimizing network resource usage.
3Reliability
If failure reasons are transmitted through encrypted channels, then security is maintained, but the complexity of message handling increases
Solution Approach 1:
The patent uses authentication servers and access points as intermediaries that handle the complexity of transmitting failure reason information through encrypted EAP messages. These intermediaries manage the message processing and ensure secure transmission, while supplicant devices only need to handle standard EAP message formats, minimizing the complexity increase at the device level while maintaining security.
Data Source
AI summary
The presently claimed disclosure is directed to methods that may be implemented at a computer. Methods and systems consistent with the present disclosure may include extending protocols associated with authenticating client (i.e. supplicant) devices and with authorizing those supplicant devices to access a wireless network. These methods may include sending data relating to the failure of an authentication and/or an authorization process to a supplicant device attempting to access a wireless network. Methods discussed within may include securely sending failure codes or reasons to a supplicant device that identify why an authentication or authorization process failed. These methods may include sending messages between a supplicant device, an authenticator device, and an authentication and authorization server. After a first failure, the supplicant device may be able to access the wireless network after a reason or code of that failure has been reported to the supplicant device.


