Automatic Pre-Shared Key Rotation During Wi-Fi Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Wi-Fi networks require manual passphrase updates, which are cumbersome and time-consuming, and there is a need for secure authentication before establishing connections.

Innovation Solution

A computer system automatically updates passphrases by receiving an access acceptance message, generating or selecting a new passphrase, and replacing the current passphrase during a session, reverting to the original passphrase upon session end, enhancing security and convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual passphrase updates are implemented, then security is improved, but user convenience deteriorates due to the complicated and time-consuming process

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs passphrase updates without requiring user intervention. The access point monitors session duration and autonomously generates and distributes new passphrases to connected devices, eliminating the need for manual user action while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs passphrase updates in advance of security compromises by monitoring session duration and automatically renewing passphrases before they expire or become vulnerable. This preliminary action ensures continuous security without requiring users to manually track or update passphrases.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If frequent passphrase updates are performed, then security is improved, but time consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts passphrase update timing based on session duration and security policies. Rather than using fixed intervals, the access point monitors actual connection duration and triggers updates only when necessary, optimizing the balance between security and time efficiency.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system maintains continuous security protection by automatically managing passphrase lifecycle without interrupting network service. Users experience no disruption to their network connectivity during passphrase updates, as the system handles the entire process in the background while maintaining active sessions.

Inventive Principle:
Principle #20Continuity of useful action

3Ease of operation

If automatic passphrase updates are implemented, then user convenience is improved, but system complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The access point performs multiple functions including authentication, session management, and automatic passphrase updates within a single system. By integrating these functions into the existing access point infrastructure, the system avoids adding separate dedicated devices while maintaining enhanced security and convenience features.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses existing network infrastructure and authentication protocols as intermediaries to handle passphrase updates. Rather than implementing a completely new system, the solution leverages established RADIUS authentication and network management protocols to automate passphrase management, reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12418530B2Automatic periodic pre-shared key update
Publication Date: 2025.09.16 RUCKUS IP HOLDINGS LLC
  • US12418530B2 patent drawing
  • US12418530B2 patent drawing
  • US12418530B2 patent drawing

AI summary

During operation, the computer may obtain an access acceptance message, where the access acceptance message indicates that the electronic device has been authenticated and allowed to securely access a network, and where the authentication is based at least in part on a passphrase associated with a user of an electronic device. For example, the computer may receive the acceptance message from the computer network device or a second computer (such as a controller). Alternatively, the computer may obtain the access acceptance message while performing the authentication. Then, the computer may automatically provide a second passphrase addressed to a computer network device and the electronic device, where the second passphrase replaces the passphrase during a current session of the electronic device in the network. Moreover, when the current session ends, the computer may automatically revert to the passphrase for subsequent authentication of the user.