OpenRoaming EAP Feedback to Reduce Repeated Authentication Attempts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless networks fail to provide reasons for authentication and authorization failures, leading to inefficient repetitive attempts that waste network bandwidth and computing resources.

Innovation Solution

Methods are introduced to securely transmit failure codes or reasons to supplicant devices, allowing them to understand why authentication or authorization processes failed, enabling better decision-making on retrying, switching profiles, or waiting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If failure reasons are not transmitted to supplicant devices, then network security is maintained through encryption, but devices cannot understand why authentication/authorization fails and must repeatedly retry

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidfailure reason information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary mechanism (authentication server or access point) that receives failure reason information from the authorization server and transmits it to the supplicant device through EAP messages. This intermediary allows failure information to be conveyed without compromising the encryption security of the authentication process, resolving the contradiction between maintaining security and providing feedback.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where failure reason codes are transmitted back to the supplicant device through EAP messages after authentication/authorization failures. This feedback allows devices to understand why they were rejected and make informed decisions about retrying or switching profiles, improving authentication efficiency while maintaining security through encrypted channels.

Inventive Principle:
Principle #23Feedback

2Loss of energy

If devices repeatedly attempt authentication without failure reasons, then simple retry logic is used, but network bandwidth and computing resources are wasted

Engineering Contradiction:
Improvenetwork bandwidth consumptionVSAvoiddevice decision logic
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent provides feedback in the form of failure reason codes to supplicant devices, enabling them to make intelligent decisions about whether to retry authentication, switch to different profiles, or wait before attempting again. This feedback mechanism reduces unnecessary retry attempts and associated network bandwidth consumption while the added complexity of processing failure reasons is managed by standard EAP message handling.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the parameter of authentication messages by adding failure reason codes to EAP messages transmitted between devices and authentication servers. This parameter enhancement enables devices to adjust their behavior based on specific failure reasons, reducing redundant authentication attempts and optimizing network resource usage.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If failure reasons are transmitted through encrypted channels, then security is maintained, but the complexity of message handling increases

Engineering Contradiction:
Improveauthentication securityVSAvoidmessage processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses authentication servers and access points as intermediaries that handle the complexity of transmitting failure reason information through encrypted EAP messages. These intermediaries manage the message processing and ensure secure transmission, while supplicant devices only need to handle standard EAP message formats, minimizing the complexity increase at the device level while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250294357A1Openroaming augmentation method for EAP failures
Publication Date: 2025.09.18 CISCO TECHNOLOGY INC
  • US20250294357A1 patent drawing
  • US20250294357A1 patent drawing
  • US20250294357A1 patent drawing

AI summary

The presently claimed disclosure is directed to methods that may be implemented at a computer. Methods and systems consistent with the present disclosure may include extending protocols associated with authenticating client (i.e. supplicant) devices and with authorizing those supplicant devices to access a wireless network. These methods may include sending data relating to the failure of an authentication and/or an authorization process to a supplicant device attempting to access a wireless network. Methods discussed within may include securely sending failure codes or reasons to a supplicant device that identify why an authentication or authorization process failed. These methods may include sending messages between a supplicant device, an authenticator device, and an authentication and authorization server. After a first failure, the supplicant device may be able to access the wireless network after a reason or code of that failure has been reported to the supplicant device.