Access Point Auto-Configuration via Public Key Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manually configuring hundreds or thousands of 802.11 access points in an enterprise WLAN is tedious, error-prone, and labor-intensive, especially since installation contractors are often unqualified and unauthorized to configure location-specific parameters.
Innovation Solution
A method for automatically and securely configuring 802.11 access points and wireless switches using a Configuration Management Station, which employs Public Key security methods to establish a mutual trust relationship and deliver configuration parameters, including location-specific settings, without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If manual configuration of each access point is performed, then location-specific parameters can be accurately configured, but the process becomes tedious, error-prone, and labor-intensive
Solution Approach 1:
The patent applies preliminary action by pre-configuring access points with generic configuration data and public key infrastructure at the factory before deployment. This allows the APs to be immediately operational with basic functionality, while location-specific parameters are automatically configured later through secure communication with the configuration management station, eliminating the need for manual pre-configuration at each site.
Solution Approach 2:
The patent implements self-service through automatic configuration mechanisms where the configuration management station automatically discovers newly installed access points, authenticates them using pre-installed public keys, and pushes location-specific configuration parameters without human intervention. The system uses automated IP address assignment and secure credential distribution to enable APs to configure themselves.
2Ease of operation
If installation contractors physically install access points in inaccessible areas, then deployment flexibility is improved, but configuration authorization and security are compromised
Solution Approach 1:
The patent applies preliminary action by pre-installing public key infrastructure and security credentials on access points during manufacturing, before they reach the installation site. This allows contractors to physically install APs in inaccessible locations without needing configuration authority, while maintaining security because the private keys never leave the secure AP hardware. Configuration authorization is established in advance through cryptographic means rather than physical access.
Solution Approach 2:
The patent introduces a configuration management station as an intermediary that mediates between the centralized network administrator and distributed access points. The CMS acts as a secure bridge that automatically discovers, authenticates, and configures APs through encrypted communication channels, eliminating the need for contractors to have direct configuration access while maintaining deployment flexibility.
3Reliability
If strong security is enabled with public key certificates, then configuration security is improved, but device complexity and initial setup requirements increase
Solution Approach 1:
The patent applies preliminary action by pre-configuring public key infrastructure, digital certificates, and security credentials on access points during manufacturing. This eliminates the need for complex security setup at deployment sites, as the cryptographic foundation is already in place. The pre-provisioned security enables automatic mutual authentication between APs and the configuration management station without requiring manual key exchange or certificate installation.
Data Source
AI summary
The present invention is contemplates an automatic, secure AP configuration protocol. Public/private keys and public key (PK) methods are used to automatically establish a mutual trust relationship and a secure channel between an AP and at least one configuration server. An AP automatically forwards a location identifier to the configuration server, and the configuration server delivers common, AP specific, and location specific configuration parameters to the AP.


