Automatic Access Point Registration via Reference Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing mission-critical networks, especially those with IoT devices, is challenging due to the difficulty in automatically and securely registering new access points, particularly in areas with dead zones, where existing endpoint security solutions are inadequate.

Innovation Solution

A method and system for automatic access point registration, which involves detecting candidate devices using reference devices, obtaining configuration parameters, and configuring new devices securely within the network, reducing the need for user-provided information and enhancing security through neighborhood detection and security policy application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automatic device onboarding is implemented, then ease of operation is improved, but security risk increases

Engineering Contradiction:
Improveautomatic device onboardingVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A cloud-based device configuration system acts as an intermediary between new devices and the network. The system receives device identifiers from new devices, checks them against a whitelist of authorized devices, and only permits onboarding of authorized devices. This mediator approach maintains security while enabling automatic onboarding.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where reference devices detect new devices and report their identifiers to the configuration system. The configuration system then provides feedback by determining whether each device is authorized and communicating configuration parameters back to authorized devices, creating a closed-loop security verification process.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual configuration is required for each device, then security is improved, but productivity decreases

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice onboarding speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Device authorization is performed in advance by maintaining a whitelist of authorized device identifiers in the cloud configuration system. Before devices are physically deployed, their identifiers are pre-registered and authorized. When devices are deployed, the system automatically verifies their identifiers against the pre-prepared whitelist, enabling rapid onboarding while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of manually configuring each device individually, the system automatically copies configuration parameters from the cloud configuration system to multiple authorized devices. The configuration system retrieves authorized device identifiers and批量 distributes appropriate configuration parameters to all authorized devices simultaneously, dramatically improving onboarding productivity while maintaining consistent security controls.

Inventive Principle:
Principle #26Copying

3Area of stationary object

If more reference devices are deployed to cover dead zones, then network coverage is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork coverage areaVSAvoidnumber of access points
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

Reference devices automatically perform device detection and reporting functions without requiring manual configuration or intervention. When new devices enter the network, reference devices autonomously detect them and report their identifiers to the cloud configuration system. This self-service capability simplifies the deployment of additional reference devices to expand coverage, as each device independently contributes to the onboarding process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Reference devices serve multiple functions: they provide network coverage for dead zones, detect new devices attempting to join the network, and report device identifiers to the configuration system. This multi-functionality allows a single device to simultaneously address coverage expansion and security onboarding, reducing the overall complexity compared to having separate systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11765027B2Access point registration in a network
Publication Date: 2023.09.19 SOPHOS LTD
  • US11765027B2 patent drawing
  • US11765027B2 patent drawing
  • US11765027B2 patent drawing

AI summary

Implementations generally relate methods, systems, and computer readable media for providing automatic access point registration. In some implementations, a method includes receiving an indication of automatic device onboarding activation. The method further includes receiving a selection of one or more reference devices. The method further includes determining one or more detectable devices of the one or more candidate devices to be onboarded that are detectable by at least one of the one or more reference devices. The method further includes obtaining one or more automatic configuration parameters from one or more of the reference devices. The method further includes configuring one or more of the detectable devices to be onboarded with the one or more automatic configuration parameters.