SAE-PK Mutual Authentication for Wi-Fi Evil Twin Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Wi-Fi authentication protocols, such as SAE, face vulnerabilities in public networks, particularly due to the reliance on shared passwords, which can lead to evil twin attacks, and lack strong per-STA authentication methods that differentiate devices for virtual LANs or services.
Innovation Solution
The implementation of SAE-PK-MA, which uses out-of-band provisioning of per-SAE passwords and protected in-band provisioning of per-STA authentication credentials, including self-signed certificates and public key-based authentication, to enhance security and differentiate devices within Wi-Fi networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If SAE protocol uses shared passwords for authentication, then authentication simplicity is improved, but security against evil twin attacks deteriorates
Solution Approach 1:
The patent introduces public key infrastructure as an intermediary mechanism between the authentication protocol and the devices. Instead of directly using shared passwords, the system uses digital certificates and public key pairs to mediate the authentication process, allowing devices to verify each other's identities without relying solely on shared secrets, thus preventing evil twin attacks while maintaining ease of use
2Adaptability or versatility
If per-STA authentication credentials are implemented, then device differentiation capability is improved, but authentication system complexity worsens
Solution Approach 1:
The patent applies preliminary action by pre-provisioning each station with unique authentication credentials (such as digital certificates or public key pairs) before they join the network. This allows the authentication system to differentiate between devices using pre-configured unique identifiers rather than requiring complex real-time differentiation mechanisms, thus enabling device differentiation while keeping the authentication process relatively simple
Data Source
AI summary
Embodiments herein provide systems, apparatuses, and methods for authentication of an access point and a station in a wireless local area network. An access point and station may generate a Key Encryption Key (KEK). The access point and station may send authentication credentials encrypted based on the KEK. The access point may authenticate the station by validating the station authentication credential, and the station may authenticate the access point by validating the access point authentication credential.


