WPA3 Authentication Binding via WPA2 Transition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Wi-Fi networks face challenges in securely authenticating devices due to vulnerabilities in security protocols like WPA and WPA2, leading to the need for transition to WPA3, which is incompatible with dynamic pre-shared keys (DPSKs), thereby complicating the onboarding of devices to personal area networks (PANs).

Innovation Solution

An access point provides both WPA2-compatible and WPA3-compatible Wi-Fi networks, using a passphrase associated with a device to establish a binding between the device and the WPA3 network, allowing for a BSS transition from the WPA2 network to the WPA3 network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WPA3-compatible authentication protocol is used, then security is improved, but compatibility with dynamic pre-shared keys (DPSKs) is lost

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility with DPSKs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the authentication process into two distinct phases: an initial WPA2-compatible authentication phase that accepts DPSKs, and a subsequent WPA3 authentication phase. This segmentation allows the system to maintain compatibility with legacy DPSK-based systems while transitioning to the more secure WPA3 protocol, thereby resolving the contradiction between security improvement and compatibility loss.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary authentication using WPA2 and DPSKs before transitioning to WPA3. By establishing initial connectivity and security bindings through the legacy protocol, the system prepares the groundwork for subsequent WPA3 authentication, ensuring that devices can first connect using familiar DPSKs before migrating to the enhanced security protocol.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If WPA2-compatible authentication protocol is used, then compatibility with DPSKs is maintained, but security is reduced

Engineering Contradiction:
Improvecompatibility with DPSKsVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a dynamic authentication mechanism that adapts the security protocol based on the authentication phase. Initially, the system operates in WPA2 mode to maintain DPSK compatibility, then dynamically transitions to WPA3 mode for enhanced security. This dynamic switching resolves the contradiction by allowing the system to exhibit different security behaviors at different stages of the authentication process.

Inventive Principle:
Principle #15Dynamics

3Reliability

If BSS transition from WPA2 to WPA3 is performed, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a binding mechanism as an intermediary between WPA2 and WPA3 authentication. This binding stores cryptographic relationships established during initial WPA2 authentication and uses them to facilitate seamless transition to WPA3. The binding acts as a mediator that simplifies the transition process, reducing the complexity burden that would otherwise be imposed on devices by the dual-protocol requirement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250039668A1Wi-fi protected access 3-compatible authentication using an established binding
Publication Date: 2025.01.30 RUCKUS IP HOLDINGS LLC
  • US20250039668A1 patent drawing
  • US20250039668A1 patent drawing
  • US20250039668A1 patent drawing

AI summary

During operation, an access point may provide a first WLAN and a second WLAN, where the first WLAN uses a WPA2-compatible authentication protocol and the second WLAN uses a WPA3-compatible authentication protocol. In response to an association request or a probe request associated with (or from) an electronic device, the access point may establish a connection with the electronic device using the first WLAN. Then, when a binding between a passphrase associated with the electronic device and the second WLAN does not exist, the access point may establish the binding in the computer system. Next, the access point may perform a BSS transition of the electronic device from the first WLAN to the second WLAN. Moreover, the access point may authenticate the electronic device without a time constraint.