Wireless LAN Password-Mapped SAE Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless network security systems, particularly those employing WPA3, are vulnerable to single, one-time password guess attacks, posing a security threat when tenants move out and still have access to the network, compromising end-user security.

Innovation Solution

Implementing password-mapped simultaneous authentication of equals (SAE) in wireless network controllers and client devices, where a password-mapped identifier is used instead of the actual password for authentication, preventing unauthorized access and reducing security vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single common password is provided to each tenant for Wi-Fi access, then ease of operation is improved, but security is worsened because moved-out tenants can still access the network

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system by introducing per-device authentication credentials (password-mapped identifiers) instead of a single common password. Each client device receives its own unique credential tied to its identifier, allowing individual device management and revocation while maintaining ease of connection for users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using password-mapped identifiers derived from device identifiers through a key derivation function. This intermediary credential system sits between the common password and individual device authentication, enabling secure per-device access control without requiring users to manage complex individual passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If WPA3 with SAE is used to protect against security vulnerabilities, then security is improved, but the system remains vulnerable to single, one-time password guess attacks

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a copy of the authentication mechanism that operates at the credential level rather than the password level. By deriving password-mapped identifiers from device identifiers through cryptographic key derivation, the system creates authenticated credentials that are as secure as WPA3 but immune to password-guessing attacks, since the identifiers are device-specific and not human-memorable passwords.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the authentication parameter from password-based to identifier-based authentication. By using device identifiers (such as MAC addresses or other unique device characteristics) as the foundation for authentication credentials, the system transforms the authentication space from vulnerable human-chosen passwords to cryptographically secure device-specific identifiers that cannot be guessed.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11129022B2Wireless LAN deployment based on mapped password SAE authentication
Publication Date: 2021.09.21 CISCO TECHNOLOGY INC
  • US11129022B2 patent drawing
  • US11129022B2 patent drawing
  • US11129022B2 patent drawing

AI summary

A wireless network environment includes a plurality of access points, a wireless local area network (WLAN) controller, and a plurality of client devices. The client devices attempt to authenticate with the WLAN controller to gain access to wireless services provided by the WLAN controller and/or the access points. To authenticate with the WLAN controller, the WLAN controller obtains a request to establish a wireless network connection from one or more of the client devices. The WLAN controller then provides a response to the request. The response indicates whether the WLAN controller supports performing password-mapped simultaneous authentication of equals (SAE). The WLAN controller then obtains a message including a password-mapped identifier from the client device. The WLAN controller then establishes a connection with the client device based on the password obtained with password-mapped identifier mapping at WLC.