SAE Authentication Prioritization in Mixed WPA2/WPA3 Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless communication systems prioritize connecting to less secure WPA 2 access points over more secure WPA 3 access points when both are within the same wireless communication range, leaving networks vulnerable to attacks by malicious actors who can exploit the less secure protocol.

Innovation Solution

Implementing a method and device that prioritize connection to WPA 3 access points using the Simultaneous Authentication of Equals (SAE) authentication type, even when both WPA 2 and WPA 3 access points share the same Service Set Identifier (SSID), and separate grouping of access points to avoid inadvertently connecting to WPA 2.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the wireless STA prioritizes connecting to WPA 2 access points for better compatibility, then ease of operation is improved, but security is worsened due to vulnerability to attacks by malicious actors

Engineering Contradiction:
ImprovecompatibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the list of available access points by authentication type, separating WPA 3-capable APs from WPA 2-only APs. This segmentation allows the wireless STA to present only WPA 3-capable APs to the user, ensuring secure connections while maintaining ease of operation through automatic filtering and grouping.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the wireless STA groups all access points with the same SSID together, then ease of operation is improved by simplifying user selection, but security is worsened because the STA may inadvertently connect to less secure WPA 2 access points

Engineering Contradiction:
Improveuser selection simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by differentiating the presentation of access points based on their authentication capabilities. WPA 3-capable access points are highlighted or grouped separately with visual indicators, while WPA 2-only access points are either separated or marked differently. This allows users to easily identify and select secure options while maintaining simplicity.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If the wireless STA connects to WPA 2 access points to maintain broader device compatibility, then adaptability is improved, but the system becomes more vulnerable to password exposure and packet manipulation attacks

Engineering Contradiction:
Improvedevice compatibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary action by checking the authentication capabilities of available access points before presenting them to the user. The system proactively identifies and filters WPA 3-capable access points, and can pre-configure the connection to use secure authentication methods. This preliminary assessment prevents connection to vulnerable WPA 2 networks while maintaining compatibility through automatic detection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250301320A1Preventing attacks in a mixed WPA2 and WPA3 environment
Publication Date: 2025.09.25 QUALCOMM INC
  • US20250301320A1 patent drawing
  • US20250301320A1 patent drawing
  • US20250301320A1 patent drawing

AI summary

This disclosure provides methods, devices and systems for improving security in wireless communication networks. An example method includes scanning a wireless medium for a presence of access points (APs) in a wireless communication range of the first wireless STA, identifying, based on the scanning, two or more APs each having a same first Service Set Identifier (SSID), the two or more APs including a first AP that supports a Wi-Fi Protected Access (WPA) 3 wireless security protocol and a WPA 2 wireless security protocol and including a second AP that supports the WPA 2 wireless security protocol but does not support the WPA 3 wireless security protocol, selecting a first simultaneous authentication of equals (SAE) authentication type for a first group of APs that includes the first AP based on at least one AP of the first group of APs supporting the WPA 3 wireless security protocol, and authenticating with the first AP based at least in part on the same first SSID and the first SAE authentication type.