Wireless LAN Password-Mapped SAE Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless network security systems, particularly those employing WPA3, are vulnerable to single, one-time password guess attacks, posing a security threat when tenants move out and still have access to the network, compromising end-user security.
Innovation Solution
Implementing password-mapped simultaneous authentication of equals (SAE) in wireless network controllers and client devices, where a password-mapped identifier is used instead of the actual password for authentication, preventing unauthorized access and reducing security vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single common password is provided to each tenant for Wi-Fi access, then ease of operation is improved, but security is worsened because moved-out tenants can still access the network
Solution Approach 1:
The patent segments the authentication system by introducing per-device authentication credentials (password-mapped identifiers) instead of a single common password. Each client device receives its own unique credential tied to its identifier, allowing individual device management and revocation while maintaining ease of connection for users.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using password-mapped identifiers derived from device identifiers through a key derivation function. This intermediary credential system sits between the common password and individual device authentication, enabling secure per-device access control without requiring users to manage complex individual passwords.
2Reliability
If WPA3 with SAE is used to protect against security vulnerabilities, then security is improved, but the system remains vulnerable to single, one-time password guess attacks
Solution Approach 1:
The patent creates a copy of the authentication mechanism that operates at the credential level rather than the password level. By deriving password-mapped identifiers from device identifiers through cryptographic key derivation, the system creates authenticated credentials that are as secure as WPA3 but immune to password-guessing attacks, since the identifiers are device-specific and not human-memorable passwords.
Solution Approach 2:
The patent changes the authentication parameter from password-based to identifier-based authentication. By using device identifiers (such as MAC addresses or other unique device characteristics) as the foundation for authentication credentials, the system transforms the authentication space from vulnerable human-chosen passwords to cryptographically secure device-specific identifiers that cannot be guessed.
Data Source
AI summary
A wireless network environment includes a plurality of access points, a wireless local area network (WLAN) controller, and a plurality of client devices. The client devices attempt to authenticate with the WLAN controller to gain access to wireless services provided by the WLAN controller and/or the access points. To authenticate with the WLAN controller, the WLAN controller obtains a request to establish a wireless network connection from one or more of the client devices. The WLAN controller then provides a response to the request. The response indicates whether the WLAN controller supports performing password-mapped simultaneous authentication of equals (SAE). The WLAN controller then obtains a message including a password-mapped identifier from the client device. The WLAN controller then establishes a connection with the client device based on the password obtained with password-mapped identifier mapping at WLC.


