Access Point Multiple Pre-Shared Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless networks use a single pre-shared key for all client devices, which does not account for varying security requirements and user tolerances, leading to inefficient key management and potential security risks due to complex key provisioning for long-term connections and simplicity for short-term connections.
Innovation Solution
An access point is configured to support multiple pre-shared keys (PSKs) with different lifetimes and complexities, allowing for selective removal of PSKs without disconnecting other devices, and grouping devices by PSK to manage network access efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single pre-shared key is used for all client devices, then device complexity is reduced and ease of operation is improved, but security is compromised and adaptability to different connection requirements is lost
Solution Approach 1:
The patent segments the single pre-shared key into multiple distinct pre-shared keys, each assigned to specific client devices or device groups. This segmentation allows different security policies to be applied to different devices while maintaining manageable complexity through structured key organization and automatic selection mechanisms.
Solution Approach 2:
The patent applies local quality by assigning different pre-shared keys with different security characteristics to different client devices or device groups based on their specific requirements. Each key can have customized properties such as lifetime, complexity, and usage conditions, allowing security to be optimized locally for each device while the access point manages the overall system.
2Reliability
If complex pre-shared keys are used for long-term connections, then security is improved, but user burden increases and ease of operation deteriorates
Solution Approach 1:
The access point implements self-service by automatically selecting the appropriate pre-shared key for each client device based on device identification, connection type, and stored device profiles. This eliminates the need for users to manually provision complex keys, as the system autonomously matches devices with suitable keys and handles key distribution transparently.
Solution Approach 2:
The patent applies preliminary action by pre-configuring the access point with multiple pre-shared keys and associated device profiles before actual connections are made. Device characteristics, key selections, and security parameters are predetermined and stored, enabling rapid automatic key selection when devices connect without requiring real-time user input or complex provisioning procedures.
3Adaptability or versatility
If multiple pre-shared keys are supported with different lifetimes, then adaptability to different connection requirements is improved, but device complexity and key management burden increase
Solution Approach 1:
The patent implements dynamics by enabling the access point to dynamically select and switch between multiple pre-shared keys based on real-time connection requirements, device identification, and stored profile information. The system adaptively matches devices with appropriate keys having suitable lifetimes and security characteristics, and can update key selections as devices connect or disconnect, maintaining optimal security without static configuration.
Solution Approach 2:
The access point achieves universality by designing a unified key management system that handles multiple pre-shared keys with different properties through a single integrated mechanism. The same access point infrastructure and authentication protocol support diverse key types, lifetimes, and device groups, providing multi-functionality without requiring separate systems for different connection scenarios.
4Reliability
If a pre-shared key is removed from the access point, then security is improved by revoking access, but network connectivity is disrupted for devices using that key
Solution Approach 1:
The patent segments client devices into different groups, each associated with specific pre-shared keys. When a key needs to be revoked for security reasons, only the devices in that specific group are affected, while other device groups using different keys continue operating normally. This segmentation isolates the impact of key removal to minimize disruption to overall network connectivity.
Solution Approach 2:
The system implements discarding and recovering by allowing pre-shared keys to be selectively discarded (removed) from the access point when security revocation is needed, while the system recovers connectivity for affected devices by assigning them alternative keys from different groups. This ensures that key removal for security purposes does not permanently disrupt legitimate connections, as devices can be reassigned to other valid keys.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of operating an access point (AP) configured to support multiple pre-shared keys. Each client device associated with the AP is provisioned with a key. To authenticate the client device, the AP determines which pre-shared key (PSK) of the multiple supported pre-shared keys, if any, matches information including the key received from the client device. When the information matches, the client device is allowed to connect to the AP. Provisioning the AP with multiple pre-shared keys allows selectively disconnecting associated client devices from the AP. Removing a PSK of the multiple pre-shared keys supported by the AP and disconnecting a client device that uses this PSK does not disconnect the rest of the client devices using different keys to access the AP. Moreover, when a lifetime of a PSK expires, the PSK is removed and each of the client devices using the PSK is disconnected.