IP Library Patent Application 19393859
Patent Application
App. No. 19/393,859

WI-FI PROTECTED ACCESS 3-COMPATIBLE AUTHENTICATION USING AN ESTABLISHED BINDING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/393,859
Abstract

In response to an association request associated with an electronic device to a second WLAN that uses a WPA3-compatible authentication protocol, an access point may establish a connection with an electronic device using the second WLAN when a binding between a passphrase associated with the electronic device and the second WLAN exists in a computer system. Alternatively, when the binding does not exist, the access point may reject the association request. Instead, the access point may establish a second connection with the electronic device using a first WLAN that uses a WPA2-compatible authentication protocol, and may establish the binding in a computer system. Next, the access point may perform a BSS transition of the electronic device from the first WLAN to the second WLAN. Furthermore, the access point may perform authentication of the electronic device after the connection or the second connection is established.

Claims (61)

1 . A computer network device, comprising:

an interface circuit configured to communicate with an electronic device and a computer system;

a processor; and

a memory that stores program instructions, wherein, when executed by the processor, the program instructions cause the computer to perform operations, comprising:

providing a first wireless local area network (WLAN) and a second WLAN, wherein the first WLAN uses a Wi-Fi Protected Access 2 (WPA2)-compatible authentication protocol and the second WLAN uses a Wi-Fi Protected Access 3 (WPA3)-compatible authentication protocol;

receiving, associated with the electronic device, an association request or a probe request to the second WLAN;

when a binding between a passphrase associated with the electronic device and the second WLAN exists in the computer system:

establishing a connection with the electronic device using the second WLAN;

performing authentication of the electronic device; and

when a binding between a passphrase associated with the electronic device and the second WLAN does not exist:

rejecting the association request or not responding to the probe request;

receiving, associated with the electronic device, a second association request or a second probe request to the first WLAN;

establishing a second connection with the electronic device using the first WLAN;

establishing the binding in the computer system;

performing a basic service set (BSS) transition of the electronic device from the first WLAN to the second WLAN; and

performing second authentication of the electronic device.

2 . The computer network device of claim 1 , wherein the authentication or the second authentication are performed without a time constraint.

3 . The computer network device of claim 1 , wherein the authentication or the second authentication is performed with an authentication, authorization, and accounting (AAA) server.

4 . The computer network device of claim 1 , wherein, when a connection to the second WLAN is lost, re-establishing a third connection with the electronic device using the second WLAN.

5 . The computer network device of claim 1 , wherein the operations comprise updating a state entry associated with the electronic device in a state table when the binding is established.

6 . The computer network device of claim 5 , wherein the computer network device confirms that the binding has been established or exists based at least in part on the state entry in the state table.

7 . The computer network device of claim 1 , wherein the second connection with the electronic device is established using the first WLAN when the electronic device is associated with or is provided by a predefined manufacturer.

8 . The computer network device of claim 7 , wherein, after the second connection and the binding are established for the electronic device associated or provided by the predefined manufacturer, the operations comprise performing the BSS transition of the electronic device from the first WLAN to the second WLAN.

9 . The computer network device of claim 1 , wherein the second WLAN uses WPA3-simultaneous authentication of equals (SAE).

10 . The computer network device of claim 1 , wherein the first WLAN and the second WLAN have a common service set identifier (SSID) and different basic service set identifiers (BSSIDs).

11 . The computer network device of claim 1 , wherein the BSS transition is based at least in part on the association of the electronic device and the computer network device using the first WLAN.

12 . The computer network device of claim 1 , wherein the passphrase comprises a dynamic pre-shared key (DPSK) of the electronic device.

13 . The computer network device of claim 1 , wherein the authentication occurs without the computer system performing a cryptographic calculation or using a single cryptographic calculation.

14 . The computer network device of claim 1 , wherein the computer network device comprises an access point.

15 . A non-transitory computer-readable storage medium for use in conjunction with a computer network device, the computer-readable storage medium storing program instructions that, when executed by the computer network device, cause the computer network device to perform operations comprising:

providing a first wireless local area network (WLAN) and a second WLAN, wherein the first WLAN uses a Wi-Fi Protected Access 2 (WPA2)-compatible authentication protocol and the second WLAN uses a Wi-Fi Protected Access 3 (WPA3)-compatible authentication protocol;

receiving, associated with an electronic device, an association request or a probe request to the second WLAN;

when a binding between a passphrase associated with the electronic device and the second WLAN exists in a computer system:

establishing a connection with the electronic device using the second WLAN;

performing authentication of the electronic device; and

when a binding between a passphrase associated with the electronic device and the second WLAN does not exist:

rejecting the association request or not responding to the probe request;

receiving, associated with the electronic device, a second association request or a second probe request to the first WLAN;

establishing a second connection with the electronic device using the first WLAN;

establishing the binding in the computer system;

performing a basic service set (BSS) transition of the electronic device from the first WLAN to the second WLAN; and

performing second authentication of the electronic device.

16 . The non-transitory computer-readable storage medium of claim 15 , wherein the operations comprise updating a state entry associated with the electronic device in a state table when the binding is established.

17 . The non-transitory computer-readable storage medium of claim 16 , wherein the computer network device confirms that the binding has been established or exists based at least in part on the state entry in the state table.

18 . A method for authenticating an electronic device, comprising:

by a computer network device:

providing a first wireless local area network (WLAN) and a second WLAN, wherein the first WLAN uses a Wi-Fi Protected Access 2 (WPA2)-compatible authentication protocol and the second WLAN uses a Wi-Fi Protected Access 3 (WPA3)-compatible authentication protocol;

receiving, associated with the electronic device, an association request or a probe request to the second WLAN;

when a binding between a passphrase associated with the electronic device and the second WLAN exists in a computer system:

establishing a connection with the electronic device using the second WLAN;

performing authentication of the electronic device; and

when a binding between a passphrase associated with the electronic device and the second WLAN does not exist:

rejecting the association request or not responding to the probe request;

receiving, associated with the electronic device, a second association request or a second probe request to the first WLAN;

establishing a second connection with the electronic device using the first WLAN;

establishing the binding in the computer system;

performing a basic service set (BSS) transition of the electronic device from the first WLAN to the second WLAN; and

performing second authentication of the electronic device.

19 . The method of claim 18 , wherein the method comprises updating a state entry associated with the electronic device in a state table when the binding is established; and

wherein the computer network device confirms that the binding has been established or exists based at least in part on the state entry in the state table.

20 . The method of claim 18 , wherein the second connection with the electronic device is established using the first WLAN when the electronic device is associated with or is provided by a predefined manufacturer.

Assignments (2)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2026
From: HSU, WEI-SHENG; CHANG, YU-TING
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 073638/0017 →