Device-Independent Passphrase Authentication for Policy-Based WLAN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for establishing secure connections in wireless local area networks (WLANs) face challenges such as cumbersome onboarding processes and complicated passphrase management due to the distribution and use of dynamic pre-shared keys (DPSKs), especially when multiple overlapping personal area networks (PANs) are present, leading to inefficient and time-consuming enrollment.

Innovation Solution

An electronic device selectively approves secure access to a network by performing cryptographic calculations based on passphrase parameters and policies, allowing dynamic and flexible network access while isolating traffic within a virtual network, reducing the need for cumbersome passphrase management and simplifying the onboarding process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate passphrases are distributed to each electronic device for secure PAN connections, then security is improved, but device onboarding becomes cumbersome and time-consuming

Engineering Contradiction:
Improvesecure connectionVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

A central controller pre-generates and distributes passphrases to electronic devices before they need to join the PAN. The passphrases are prepared in advance and stored in a database, eliminating the need for time-consuming on-site passphrase distribution and enrollment procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A central controller acts as an intermediary between the PAN coordinator and electronic devices. The controller manages passphrase distribution, validates device credentials, and coordinates secure connections, simplifying the enrollment process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate passphrases are assigned to each electronic device, then secure access is achieved, but passphrase management becomes complicated

Engineering Contradiction:
Improvesecure accessVSAvoidpassphrase management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple passphrase management functions are merged into a single central controller. The controller generates, stores, distributes, and revokes passphrases for all devices in the PAN, consolidating what would otherwise be complex distributed management into a unified system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The central controller automatically manages passphrase lifecycle operations including generation, distribution, validation, and revocation without requiring manual intervention. The system self-manages the complexity of tracking and updating passphrases for multiple devices.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple overlapping PANs are allowed in a WLAN, then network flexibility is improved, but access control and traffic isolation become difficult

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidaccess control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Each PAN is assigned unique local identifiers and cryptographic credentials that distinguish it from other PANs. The central controller enforces access control policies specific to each PAN, ensuring that devices can flexibly join different PANs while maintaining proper isolation and security boundaries.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4028871B1Device-independent authentication based on a passphrase and a policy
Publication Date: 2025.11.05 RUCKUS IP HOLDINGS LLC
  • EP4028871B1 patent drawingFigure 1
  • EP4028871B1 patent drawingFigure 2
  • EP4028871B1 patent drawingFigure 3

AI summary

An electronic device that selectively approves secure access of a second electronic device to a network is described. This electronic device receives an access request associated with a computer, where the access request includes passphrase parameters associated with a user, and the passphrase parameters include inputs to and an output of a cryptographic calculation. In response, the electronic device calculates one or more second outputs of the cryptographic calculation based at least in part on the inputs and one or more stored passphrases. Moreover, when there is a match between one of the one or more second outputs and the output, the electronic device accesses a policy associated with the user. Then, when one or more criteria associated with the policy are met, the electronic device selectively provides an access acceptance message to the computer, which includes information for establishing the secure access of the second electronic device.