SAE Passphrase Authentication for Secure Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security techniques, such as password-based authentication, are inadequate due to vulnerabilities like password memorization issues, ease of decryption, and eavesdropping, which compromise network security.

Innovation Solution

Implementing a passphrase-based authentication system using Simultaneous Authentication of Equals (SAE) that assigns a unique passphrase to end-user devices, generating a shared secret, and authenticating devices through a commitment and confirmation scheme to ensure secure network access without compromising computational resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-based authentication is used, then network access control is achieved, but security is compromised due to password vulnerabilities

Engineering Contradiction:
Improvenetwork securityVSAvoidpassword vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password from the authentication process and replaces it with public key infrastructure. Instead of relying on secret passwords that are vulnerable to eavesdropping and decryption, the system uses public keys that can be freely exchanged, eliminating the harmful factor of password transmission while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a certificate authority as an intermediary that issues digital certificates to authenticate devices. This mediator eliminates the need for direct password sharing between devices, replacing it with a trusted third-party verification system that enhances security while maintaining ease of authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If pre-shared key (PSK) technology is used, then authentication security is improved, but computational overhead increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs key pair generation and certificate issuance as preliminary actions during device enrollment, before the device needs to authenticate. This preliminary setup eliminates the need for computationally intensive operations during actual authentication, reducing real-time computational overhead while maintaining strong security through pre-established cryptographic credentials.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10735405B2Private simultaneous authentication of equals
Publication Date: 2020.08.04 EXTREME NETWORKS INC
  • US10735405B2 patent drawing
  • US10735405B2 patent drawing
  • US10735405B2 patent drawing

AI summary

Systems and methods for performing network-side Simultaneous Authentication of Equals (SAE) to allow an end user device to access a network. A passphrase is assigned to an end user device for use in authenticating the end user device for a network using SAE. An identification of the end user device is determined during an authentication process. The passphrase assigned to the end user device is determined at a network side using the identification of the end user device. A shared secret is generated using the passphrase. Whether the end user device has generated the shared secret is determined by comparing network side and user side confirmation values. The end user device is authenticated for the network, if it is determined that the end user device has generated the shared secret.