Optimized SAE Authentication Reducing Wireless Network Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Simultaneous Authentication of Equals (SAE) in wireless networks results in higher latency and increased network messaging, leading to inefficiencies and increased load on Access Points (APs) and Wireless Local Area Network Controllers (WLCs, affecting client association and roaming.
Innovation Solution
Optimized SAE call flow that reduces the number of per-client association messages by three, utilizing Finite Field Cryptography (FFC) and Elliptic Curve Cryptography (ECC) for secure authentication, generating and verifying Pairwise Master Keys (PMK) and Pairwise Transient Keys (PTK) to minimize message load and latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Simultaneous Authentication of Equals (SAE) is used for authentication in wireless networks, then security is improved, but latency increases and network messaging load increases
Solution Approach 1:
The patent applies preliminary action by pre-computing and caching authentication credentials (PMK, PTK, GTK) during the SAE handshake process before actual data transmission begins. This allows the authentication state to be prepared in advance, reducing the latency experienced during client association and roaming operations while maintaining the security benefits of SAE
2Reliability
If Simultaneous Authentication of Equals (SAE) is used for authentication in wireless networks, then security is improved, but network messaging load increases
Solution Approach 1:
The patent merges multiple authentication and key management messages into a consolidated SAE handshake sequence. By combining the PMK derivation, PTK generation, and GTK distribution into a single integrated authentication flow, the patent reduces the total number of separate messages exchanged between clients and access points while maintaining comprehensive security coverage
3Loss of time
If optimized SAE authentication is implemented, then authentication latency is reduced, but device complexity increases
Solution Approach 1:
The patent implements self-service by enabling client devices to autonomously perform cryptographic operations (FFC/ECC key pair generation, PMK derivation, PTK computation) without requiring continuous intervention from the access point or wireless LAN controller. The client independently completes the authentication handshake and key material generation, reducing access point processing complexity while achieving lower latency
Data Source
AI summary
Authentication with security in wireless networks may be provided. A first confirm message comprising a first send-confirm element and a first confirm element may be received. Next, an Authenticator Number Used Once (ANonce) may be generated and a second confirm message may be sent comprising the ANonce, a second send-confirm element, and a second confirm element. Then an association request may be received comprising a Supplicant Number Used Once (SNonce) and a Message Integrity Code (MIC). An association response may be sent comprising an encrypted Group Temporal Key (GTK), an encrypted Integrity Group Temporal Key (IGTK), the ANonce, and the MIC. An acknowledgment may be received comprising the MIC in an Extensible Authentication Protocol (EAP) over LAN (EAPoL) key frame and a controller port may be unblocked in response to receiving the acknowledgment.


