Multi-Access-Point WiFi Setup with Encrypted Credential Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication networks face challenges in providing complete WiFi coverage in large areas, necessitating the setup and configuration of additional access points, which is often complex and inefficient for customers and service providers.
Innovation Solution
A system utilizing public key cryptography and QR codes or cloud-based management to automate the configuration of new 802.11 access points, enabling secure and efficient integration into existing networks without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If manual configuration methods are used for setting up additional access points, then customers can establish WiFi networks in large areas, but the setup process becomes complex and time-consuming
Solution Approach 1:
The system enables access points to automatically configure themselves by generating and exchanging cryptographic key pairs. When a new AP powers on, it autonomously establishes secure communication with the gateway, receives encrypted credentials, and integrates into the network without manual customer intervention, thus maintaining large area coverage while eliminating configuration complexity
Solution Approach 2:
The gateway pre-generates encrypted credential sets for multiple potential access points before they are deployed. When new APs are added to the network, they can immediately use these pre-prepared credentials to join the network, eliminating the need for customers to perform configuration actions at setup time
2Adaptability or versatility
If traditional credential distribution methods are used, then access points can be added to the network, but security is compromised due to unencrypted credential transmission
Solution Approach 1:
The patent introduces cryptographic primitives as an intermediary layer between the gateway and access points. Public-key cryptography serves as the mediator that enables secure credential exchange without exposing sensitive information during transmission, allowing the network to expand while maintaining security through mathematically secure key exchange mechanisms
Solution Approach 2:
The system transforms credential transmission from plaintext to encrypted form by applying cryptographic transformations. Credentials are encrypted using the recipient AP's public key before transmission, and only the intended AP can decrypt them using its private key, fundamentally changing the transmission parameter from insecure to secure while enabling network expansion
3Loss of time
If automated configuration systems are implemented, then setup time is reduced, but system complexity increases requiring cryptographic infrastructure
Solution Approach 1:
The gateway performs complex cryptographic operations in advance by generating encrypted credential sets for multiple access points before deployment. This preliminary action shifts the computational complexity from the customer's setup time to the service provider's pre-configuration process, enabling rapid automated onboarding of new APs without requiring customers to understand or manage cryptographic complexity
Solution Approach 2:
New access points autonomously execute the configuration process by generating their own key pairs, broadcasting their public keys, receiving encrypted credentials, and decrypting them using their private keys. This self-service automation eliminates manual setup time while containing system complexity within the automated protocols rather than requiring customer expertise
Data Source
Figure 1A~1B
Figure 2A
Figure 2B
AI summary
Methods, systems, and devices for facilitating the automated configuration of one or more new 802.11 access points (APs) are disclosed herein. A cloud server may receive a message associated with a customer account for one or more new APs. The cloud server may associate a first AP of the one or more new APs based on the message. The cloud server may then retrieve a public key associated with the first AP which has a reciprocal private key. The cloud server may send the public key to a gateway (GW) associated with the customer account. The GW may encrypt the GW credentials, such as a password and SSID, into a ciphertext using the public key and then broadcast this information. When the first AP has been powered on it may decrypt the ciphertext using the private key and use the credentials to act as a node in the GW's network.