Access Point Auto-Configuration via Public Key Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manually configuring hundreds or thousands of 802.11 access points in an enterprise WLAN is tedious, error-prone, and labor-intensive, especially since installation contractors are often unqualified and unauthorized to configure location-specific parameters.

Innovation Solution

A method for automatically and securely configuring 802.11 access points and wireless switches using a Configuration Management Station, which employs Public Key security methods to establish a mutual trust relationship and deliver configuration parameters, including location-specific settings, without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual configuration of each access point is performed, then location-specific parameters can be accurately configured, but the process becomes tedious, error-prone, and labor-intensive

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidconfiguration efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-configuring access points with generic configuration data and public key infrastructure at the factory before deployment. This allows the APs to be immediately operational with basic functionality, while location-specific parameters are automatically configured later through secure communication with the configuration management station, eliminating the need for manual pre-configuration at each site.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service through automatic configuration mechanisms where the configuration management station automatically discovers newly installed access points, authenticates them using pre-installed public keys, and pushes location-specific configuration parameters without human intervention. The system uses automated IP address assignment and secure credential distribution to enable APs to configure themselves.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If installation contractors physically install access points in inaccessible areas, then deployment flexibility is improved, but configuration authorization and security are compromised

Engineering Contradiction:
Improveinstallation flexibilityVSAvoidconfiguration security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-installing public key infrastructure and security credentials on access points during manufacturing, before they reach the installation site. This allows contractors to physically install APs in inaccessible locations without needing configuration authority, while maintaining security because the private keys never leave the secure AP hardware. Configuration authorization is established in advance through cryptographic means rather than physical access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a configuration management station as an intermediary that mediates between the centralized network administrator and distributed access points. The CMS acts as a secure bridge that automatically discovers, authenticates, and configures APs through encrypted communication channels, eliminating the need for contractors to have direct configuration access while maintaining deployment flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If strong security is enabled with public key certificates, then configuration security is improved, but device complexity and initial setup requirements increase

Engineering Contradiction:
Improveconfiguration securityVSAvoidsecurity implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring public key infrastructure, digital certificates, and security credentials on access points during manufacturing. This eliminates the need for complex security setup at deployment sites, as the cryptographic foundation is already in place. The pre-provisioned security enables automatic mutual authentication between APs and the configuration management station without requiring manual key exchange or certificate installation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7542572B2Method for securely and automatically configuring access points
Publication Date: 2009.06.02 CISCO TECHNOLOGY INC
  • US7542572B2 patent drawing
  • US7542572B2 patent drawing
  • US7542572B2 patent drawing

AI summary

The present invention is contemplates an automatic, secure AP configuration protocol. Public/private keys and public key (PK) methods are used to automatically establish a mutual trust relationship and a secure channel between an AP and at least one configuration server. An AP automatically forwards a location identifier to the configuration server, and the configuration server delivers common, AP specific, and location specific configuration parameters to the AP.