SAE Passphrase Authentication for Secure Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security techniques, such as password-based authentication, are inadequate due to vulnerabilities like password memorization issues, ease of decryption, and eavesdropping, which compromise network security.
Innovation Solution
Implementing a passphrase-based authentication system using Simultaneous Authentication of Equals (SAE) that assigns a unique passphrase to end-user devices, generating a shared secret, and authenticating devices through a commitment and confirmation scheme to ensure secure network access without compromising computational resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication is used, then network access control is achieved, but security is compromised due to password vulnerabilities
Solution Approach 1:
The patent extracts the password from the authentication process and replaces it with public key infrastructure. Instead of relying on secret passwords that are vulnerable to eavesdropping and decryption, the system uses public keys that can be freely exchanged, eliminating the harmful factor of password transmission while maintaining authentication capability.
Solution Approach 2:
The patent introduces a certificate authority as an intermediary that issues digital certificates to authenticate devices. This mediator eliminates the need for direct password sharing between devices, replacing it with a trusted third-party verification system that enhances security while maintaining ease of authentication.
2Reliability
If pre-shared key (PSK) technology is used, then authentication security is improved, but computational overhead increases
Solution Approach 1:
The patent performs key pair generation and certificate issuance as preliminary actions during device enrollment, before the device needs to authenticate. This preliminary setup eliminates the need for computationally intensive operations during actual authentication, reducing real-time computational overhead while maintaining strong security through pre-established cryptographic credentials.
Data Source
AI summary
Systems and methods for performing network-side Simultaneous Authentication of Equals (SAE) to allow an end user device to access a network. A passphrase is assigned to an end user device for use in authenticating the end user device for a network using SAE. An identification of the end user device is determined during an authentication process. The passphrase assigned to the end user device is determined at a network side using the identification of the end user device. A shared secret is generated using the passphrase. Whether the end user device has generated the shared secret is determined by comparing network side and user side confirmation values. The end user device is authenticated for the network, if it is determined that the end user device has generated the shared secret.


