WiFi Link Setup Authentication Streamlining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing WiFi link setup process is inefficient due to the separation of Access Points (APs) and Authentication Servers (AS), which complicates the EAP authentication and four-way handshake procedures, leading to increased air interface messages and prolonged setup times.
Innovation Solution
A method that involves sending authentication messages with user identifiers and Nonces to generate pairwise transient keys (PTKs) for secure communication, integrating EAP authentication with other link setup procedures like open system authentication and IP address allocation, reducing the number of air interface messages while maintaining security and functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the AP and AS are separated as in practical network deployment, then the authentication function is more flexible and scalable, but the link setup time is prolonged and the number of air interface messages is increased
Solution Approach 1:
The patent performs EAP authentication before the four-way handshake, establishing the PMK in advance. This preliminary authentication action allows the subsequent key generation and message protection to proceed more efficiently, reducing the overall link setup time while maintaining the separated AP-AS architecture
Solution Approach 2:
The patent merges the EAP authentication procedure with the four-way handshake by integrating the PMK derivation from EAP authentication into the key hierarchy used during the handshake. This combination reduces the number of separate authentication phases and minimizes air interface message exchanges
2Reliability
If multiple authentication procedures (open authentication, EAP authentication, four-way handshake) are performed sequentially, then security is maintained, but the link setup duration is prolonged
Solution Approach 1:
The patent performs EAP authentication before the four-way handshake, establishing the PMK in advance. This preliminary authentication action allows the subsequent key generation and message protection to proceed more efficiently, reducing the overall link setup time while maintaining the separated AP-AS architecture
Solution Approach 2:
The patent changes the temporal sequence and dependency relationships between authentication parameters. By deriving PMK from EAP authentication results and using it immediately in the four-way handshake key derivation, the patent eliminates waiting periods and reduces the total duration of authentication procedures while maintaining security
3Reliability
If the STA and AP exchange multiple messages for authentication and key negotiation, then security is ensured, but power consumption increases
Solution Approach 1:
The patent merges the EAP authentication procedure with the four-way handshake by integrating the PMK derivation from EAP authentication into the key hierarchy used during the handshake. This combination reduces the number of separate authentication phases and minimizes air interface message exchanges
Solution Approach 2:
The patent performs EAP authentication before the four-way handshake, establishing the PMK in advance. This preliminary authentication action allows the subsequent key generation and message protection to proceed more efficiently, reducing the overall link setup time while maintaining the separated AP-AS architecture
Data Source
AI summary
A method for link setup includes sending a first authentication message including a user identifier to an access point (AP). A second authentication message sent by the AP according to the user identifier is received and includes an EAP method request message and a ANonce of the AP. A first PTK is generated according to the ANonce, an SNonce, and a first MSK. A third authentication message is sent to the AP. The third authentication message includes an EAP method response message, the SNonce, and a first MIC that is generated according to the first PTK. A fourth authentication message is sent by the AP when it authenticates, according to a second PTK, that the first MIC is correct. The fourth authentication message includes an EAP-Success message, configuration information configured by the AP for the terminal, and a second MIC. The second MIC is authenticated according to the first PTK.


