SAE-PK Mutual Authentication for Wi-Fi Evil Twin Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Wi-Fi authentication protocols, such as SAE, face vulnerabilities in public networks, particularly due to the reliance on shared passwords, which can lead to evil twin attacks, and lack strong per-STA authentication methods that differentiate devices for virtual LANs or services.

Innovation Solution

The implementation of SAE-PK-MA, which uses out-of-band provisioning of per-SAE passwords and protected in-band provisioning of per-STA authentication credentials, including self-signed certificates and public key-based authentication, to enhance security and differentiate devices within Wi-Fi networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SAE protocol uses shared passwords for authentication, then authentication simplicity is improved, but security against evil twin attacks deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity against evil twin attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces public key infrastructure as an intermediary mechanism between the authentication protocol and the devices. Instead of directly using shared passwords, the system uses digital certificates and public key pairs to mediate the authentication process, allowing devices to verify each other's identities without relying solely on shared secrets, thus preventing evil twin attacks while maintaining ease of use

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If per-STA authentication credentials are implemented, then device differentiation capability is improved, but authentication system complexity worsens

Engineering Contradiction:
Improvedevice differentiation capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning each station with unique authentication credentials (such as digital certificates or public key pairs) before they join the network. This allows the authentication system to differentiate between devices using pre-configured unique identifiers rather than requiring complex real-time differentiation mechanisms, thus enabling device differentiation while keeping the authentication process relatively simple

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250015975A1SAE-PK protected AP-sta mutual authentication
Publication Date: 2025.01.09 APPLE INC
  • US20250015975A1 patent drawing
  • US20250015975A1 patent drawing
  • US20250015975A1 patent drawing

AI summary

Embodiments herein provide systems, apparatuses, and methods for authentication of an access point and a station in a wireless local area network. An access point and station may generate a Key Encryption Key (KEK). The access point and station may send authentication credentials encrypted based on the KEK. The access point may authenticate the station by validating the station authentication credential, and the station may authenticate the access point by validating the access point authentication credential.