Access Point Multiple Pre-Shared Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless networks use a single pre-shared key for all client devices, which does not account for varying security requirements and user tolerances, leading to inefficient key management and potential security risks due to complex key provisioning for long-term connections and simplicity for short-term connections.

Innovation Solution

An access point is configured to support multiple pre-shared keys (PSKs) with different lifetimes and complexities, allowing for selective removal of PSKs without disconnecting other devices, and grouping devices by PSK to manage network access efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single pre-shared key is used for all client devices, then device complexity is reduced and ease of operation is improved, but security is compromised and adaptability to different connection requirements is lost

Engineering Contradiction:
Improvekey management complexityVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single pre-shared key into multiple distinct pre-shared keys, each assigned to specific client devices or device groups. This segmentation allows different security policies to be applied to different devices while maintaining manageable complexity through structured key organization and automatic selection mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different pre-shared keys with different security characteristics to different client devices or device groups based on their specific requirements. Each key can have customized properties such as lifetime, complexity, and usage conditions, allowing security to be optimized locally for each device while the access point manages the overall system.

Inventive Principle:
Principle #3Local quality

2Reliability

If complex pre-shared keys are used for long-term connections, then security is improved, but user burden increases and ease of operation deteriorates

Engineering Contradiction:
Improvesecurity for long-term connectionsVSAvoiduser burden for key provisioning
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The access point implements self-service by automatically selecting the appropriate pre-shared key for each client device based on device identification, connection type, and stored device profiles. This eliminates the need for users to manually provision complex keys, as the system autonomously matches devices with suitable keys and handles key distribution transparently.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring the access point with multiple pre-shared keys and associated device profiles before actual connections are made. Device characteristics, key selections, and security parameters are predetermined and stored, enabling rapid automatic key selection when devices connect without requiring real-time user input or complex provisioning procedures.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple pre-shared keys are supported with different lifetimes, then adaptability to different connection requirements is improved, but device complexity and key management burden increase

Engineering Contradiction:
Improvesupport for different connection durationsVSAvoidaccess point key management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamics by enabling the access point to dynamically select and switch between multiple pre-shared keys based on real-time connection requirements, device identification, and stored profile information. The system adaptively matches devices with appropriate keys having suitable lifetimes and security characteristics, and can update key selections as devices connect or disconnect, maintaining optimal security without static configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The access point achieves universality by designing a unified key management system that handles multiple pre-shared keys with different properties through a single integrated mechanism. The same access point infrastructure and authentication protocol support diverse key types, lifetimes, and device groups, providing multi-functionality without requiring separate systems for different connection scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If a pre-shared key is removed from the access point, then security is improved by revoking access, but network connectivity is disrupted for devices using that key

Engineering Contradiction:
Improveaccess control securityVSAvoidnetwork connectivity continuity
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent segments client devices into different groups, each associated with specific pre-shared keys. When a key needs to be revoked for security reasons, only the devices in that specific group are affected, while other device groups using different keys continue operating normally. This segmentation isolates the impact of key removal to minimize disruption to overall network connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements discarding and recovering by allowing pre-shared keys to be selectively discarded (removed) from the access point when security revocation is needed, while the system recovers connectivity for affected devices by assigning them alternative keys from different groups. This ensures that key removal for security purposes does not permanently disrupt legitimate connections, as devices can be reassigned to other valid keys.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentEP2345268B1Support of multiple pre-shared keys in access point
Publication Date: 2019.08.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2345268B1 patent drawingFigure 1
  • EP2345268B1 patent drawingFigure 2
  • EP2345268B1 patent drawingFigure 3

AI summary

A method of operating an access point (AP) configured to support multiple pre-shared keys. Each client device associated with the AP is provisioned with a key. To authenticate the client device, the AP determines which pre-shared key (PSK) of the multiple supported pre-shared keys, if any, matches information including the key received from the client device. When the information matches, the client device is allowed to connect to the AP. Provisioning the AP with multiple pre-shared keys allows selectively disconnecting associated client devices from the AP. Removing a PSK of the multiple pre-shared keys supported by the AP and disconnecting a client device that uses this PSK does not disconnect the rest of the client devices using different keys to access the AP. Moreover, when a lifetime of a PSK expires, the PSK is removed and each of the client devices using the PSK is disconnected.