Devices and methods for client device authentication
Abstract
An access point receives from a client a first nonce and a first cryptographic hash for the first nonce, the first cryptographic hash calculated using a first key derived from a second key, the second key input on the client or derived from a passphrase input on the client, derives first keys from each of a stored primary input and at least one stored secondary input valid at the deriving, the stored primary input and the at least one stored secondary input each being one of a second key and a passphrase, verifies the cryptographic hash using each derived first key to find a derived first key that checks the first cryptographic hash, generates a third key and a second cryptographic hash using the derived first key that checks the first cryptographic hash, and sends the third key and the second cryptographic hash to the client.
Claims
exact text as granted — not AI-modified1 . A method for authenticating a client device at a Wi-Fi Protected Access 2 Enterprise authenticator device, the method comprising:
sending to the client device a session identifier and a first challenge; receiving from the client device a username, a second challenge and a cryptographic hash for a first challenge, the second challenge, a session identifier and a passphrase; verifying if a valid stored primary passphrase or at least one valid stored secondary passphrase checks the cryptographic hash, each stored secondary passphrase valid during a limited defined period of validity or each stored secondary input corresponding to the primary input with at least one typing error; and in case a passphrase checks the cryptographic hash:
sending to the client device a message indicating successful authentication; and
performing a handshake with the client device to adopt a key.
2 . A Wi-Fi Protected Access 2 Enterprise authenticator device comprising:
a communications interface configured to:
send to a client device a session identifier and a first challenge; and
receive from the client device a username, a second challenge and a cryptographic hash for a first challenge, the second challenge, a session identifier and a passphrase; and
at least one hardware processor configured to:
verify if a valid stored primary passphrase or at least one valid stored secondary passphrase checks the cryptographic hash, each stored secondary passphrase valid during a limited defined period of validity or each stored secondary input corresponding to the primary input with at least one typing error; and
in case a passphrase checks the cryptographic hash:
send to the client device, via the communications interface, a message indicating successful authentication; and
perform a handshake with the client device to adopt a key.
3 . A computer program product which is stored on a non-transitory computer readable medium and comprises program code instructions executable by a processor to:
send to the client device a session identifier and a first challenge; receive from the client device a username, a second challenge and a cryptographic hash for a first challenge, the second challenge, a session identifier and a passphrase; verify if a valid stored primary passphrase or at least one valid stored secondary passphrase checks the cryptographic hash, each stored secondary passphrase valid during a limited defined period of validity or each stored secondary input corresponding to the primary input with at least one typing error; and in case a passphrase checks the cryptographic hash:
send to the client device a message indicating successful authentication; and
perform a handshake with the client device to adopt a key.Join the waitlist — get patent alerts
Track US2020287720A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.