Multi-Access-Point WiFi Setup with Encrypted Credential Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks face challenges in providing complete WiFi coverage in large areas, necessitating the setup and configuration of additional access points, which is often complex and inefficient for customers and service providers.

Innovation Solution

A system utilizing public key cryptography and QR codes or cloud-based management to automate the configuration of new 802.11 access points, enabling secure and efficient integration into existing networks without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If manual configuration methods are used for setting up additional access points, then customers can establish WiFi networks in large areas, but the setup process becomes complex and time-consuming

Engineering Contradiction:
ImproveWiFi coverage areaVSAvoidConfiguration complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The system enables access points to automatically configure themselves by generating and exchanging cryptographic key pairs. When a new AP powers on, it autonomously establishes secure communication with the gateway, receives encrypted credentials, and integrates into the network without manual customer intervention, thus maintaining large area coverage while eliminating configuration complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway pre-generates encrypted credential sets for multiple potential access points before they are deployed. When new APs are added to the network, they can immediately use these pre-prepared credentials to join the network, eliminating the need for customers to perform configuration actions at setup time

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If traditional credential distribution methods are used, then access points can be added to the network, but security is compromised due to unencrypted credential transmission

Engineering Contradiction:
ImproveNetwork expandabilityVSAvoidSecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces cryptographic primitives as an intermediary layer between the gateway and access points. Public-key cryptography serves as the mediator that enables secure credential exchange without exposing sensitive information during transmission, allowing the network to expand while maintaining security through mathematically secure key exchange mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms credential transmission from plaintext to encrypted form by applying cryptographic transformations. Credentials are encrypted using the recipient AP's public key before transmission, and only the intended AP can decrypt them using its private key, fundamentally changing the transmission parameter from insecure to secure while enabling network expansion

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If automated configuration systems are implemented, then setup time is reduced, but system complexity increases requiring cryptographic infrastructure

Engineering Contradiction:
ImproveSetup timeVSAvoidSystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The gateway performs complex cryptographic operations in advance by generating encrypted credential sets for multiple access points before deployment. This preliminary action shifts the computational complexity from the customer's setup time to the service provider's pre-configuration process, enabling rapid automated onboarding of new APs without requiring customers to understand or manage cryptographic complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

New access points autonomously execute the configuration process by generating their own key pairs, broadcasting their public keys, receiving encrypted credentials, and decrypting them using their private keys. This self-service automation eliminates manual setup time while containing system complexity within the automated protocols rather than requiring customer expertise

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3955699B1WIFI network setup for multiple access points
Publication Date: 2025.10.01 AIRTIES SAS
  • EP3955699B1 patent drawingFigure 1A~1B
  • EP3955699B1 patent drawingFigure 2A
  • EP3955699B1 patent drawingFigure 2B

AI summary

Methods, systems, and devices for facilitating the automated configuration of one or more new 802.11 access points (APs) are disclosed herein. A cloud server may receive a message associated with a customer account for one or more new APs. The cloud server may associate a first AP of the one or more new APs based on the message. The cloud server may then retrieve a public key associated with the first AP which has a reciprocal private key. The cloud server may send the public key to a gateway (GW) associated with the customer account. The GW may encrypt the GW credentials, such as a password and SSID, into a ciphertext using the public key and then broadcast this information. When the first AP has been powered on it may decrypt the ciphertext using the private key and use the credentials to act as a node in the GW's network.