Automatic Pre-Shared Key Rotation During Wi-Fi Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Wi-Fi networks require manual passphrase updates, which are cumbersome and time-consuming, and there is a need for secure authentication before establishing connections.
Innovation Solution
A computer system automatically updates passphrases by receiving an access acceptance message, generating or selecting a new passphrase, and replacing the current passphrase during a session, reverting to the original passphrase upon session end, enhancing security and convenience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual passphrase updates are implemented, then security is improved, but user convenience deteriorates due to the complicated and time-consuming process
Solution Approach 1:
The system automatically performs passphrase updates without requiring user intervention. The access point monitors session duration and autonomously generates and distributes new passphrases to connected devices, eliminating the need for manual user action while maintaining security requirements.
Solution Approach 2:
The system performs passphrase updates in advance of security compromises by monitoring session duration and automatically renewing passphrases before they expire or become vulnerable. This preliminary action ensures continuous security without requiring users to manually track or update passphrases.
2Reliability
If frequent passphrase updates are performed, then security is improved, but time consumption increases
Solution Approach 1:
The system dynamically adjusts passphrase update timing based on session duration and security policies. Rather than using fixed intervals, the access point monitors actual connection duration and triggers updates only when necessary, optimizing the balance between security and time efficiency.
Solution Approach 2:
The system maintains continuous security protection by automatically managing passphrase lifecycle without interrupting network service. Users experience no disruption to their network connectivity during passphrase updates, as the system handles the entire process in the background while maintaining active sessions.
3Ease of operation
If automatic passphrase updates are implemented, then user convenience is improved, but system complexity increases
Solution Approach 1:
The access point performs multiple functions including authentication, session management, and automatic passphrase updates within a single system. By integrating these functions into the existing access point infrastructure, the system avoids adding separate dedicated devices while maintaining enhanced security and convenience features.
Solution Approach 2:
The system uses existing network infrastructure and authentication protocols as intermediaries to handle passphrase updates. Rather than implementing a completely new system, the solution leverages established RADIUS authentication and network management protocols to automate passphrase management, reducing overall system complexity.
Data Source
AI summary
During operation, the computer may obtain an access acceptance message, where the access acceptance message indicates that the electronic device has been authenticated and allowed to securely access a network, and where the authentication is based at least in part on a passphrase associated with a user of an electronic device. For example, the computer may receive the acceptance message from the computer network device or a second computer (such as a controller). Alternatively, the computer may obtain the access acceptance message while performing the authentication. Then, the computer may automatically provide a second passphrase addressed to a computer network device and the electronic device, where the second passphrase replaces the passphrase during a current session of the electronic device in the network. Moreover, when the current session ends, the computer may automatically revert to the passphrase for subsequent authentication of the user.


