Cloud-Assisted P2P Virtual Access Point Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional wireless access points require manual configuration and maintenance of virtual access points (VAPs), leading to airtime congestion and increased security risks due to constant availability, which complicates network management and security.

Innovation Solution

A cloud-assisted peer-to-peer (P2P) authentication exchange protocol automatically authenticates, turns on, and tears down VAPs based on client device profiles, using a hash table to manage device inventory and enforce temporary network access, thereby reducing unnecessary network exposure and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VAPs are constantly available to provide network access, then ease of operation is improved, but security risks and airtime congestion increase

Engineering Contradiction:
Improvenetwork access availabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The VAP is transformed from a static, constantly available network access point to a dynamic entity that is automatically activated and deactivated based on real-time authentication events. The system dynamically creates VAPs when client devices are authenticated and automatically tears them down when sessions expire or devices disconnect, ensuring network access is provided only when necessary while eliminating security risks associated with constant availability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary authentication of client devices against a cloud-based inventory database before activating VAPs. By pre-validating device credentials and maintaining an updated inventory of authorized devices in the cloud, the system ensures that only authenticated devices can trigger VAP activation, preventing unauthorized access while maintaining ease of operation for legitimate users

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If manual configuration and maintenance of VAPs is performed, then device complexity is reduced, but productivity and network efficiency deteriorate

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidnetwork management efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system implements self-service automation where the network infrastructure autonomously performs VAP configuration, activation, and teardown operations without manual intervention. The cloud-based service automatically manages the inventory database, authenticates devices, and controls VAP lifecycle based on authentication events, eliminating the need for manual configuration while dramatically improving network management efficiency and productivity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A cloud-based intermediary service is introduced to mediate between client devices and the network infrastructure. This intermediary maintains the inventory database, performs authentication, and provides API endpoints that automatically trigger VAP creation and teardown operations. By offloading complex management tasks to this intermediary, the system reduces device complexity at the access point while improving overall network management efficiency through centralized automated control

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cloud-based authentication and automated VAP management is implemented, then security and network efficiency are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system converts the potential harm of increased system architecture complexity into the benefit of enhanced security and automation. By implementing a cloud-based service with comprehensive inventory management and automated authentication, the initial complexity investment creates a robust security framework that automatically protects the network, with the cloud infrastructure absorbing the complexity burden rather than requiring complex local devices

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11399282B1Cloud-assisted peer-to-peer virtual access endpoint
Publication Date: 2022.07.26 AMAZON TECH INC
  • US11399282B1 patent drawing
  • US11399282B1 patent drawing
  • US11399282B1 patent drawing

AI summary

Technologies directed to a secured peer-to-peer cloud-assisted authentication exchange protocol are described. A first wireless device receives a first request including information identifying a second wireless device. The first wireless device determines that the information matches second information. The first wireless device activates a virtual access point (VAP) with a modified service set identifier (SSID) having a group identifier appended to a first SSID. The first wireless device authenticates the second wireless device to the VAP. The first wireless device sends credentials and a second SSID to the second wireless device. The second SSID corresponds to a second access point (AP). The first wireless device receives a second request from the second wireless device to connect to the second AP. The first wireless device authenticates the second wireless device with the second AP. The first wireless device deactivates the VAP after expiration of an amount of time.