Gateway-Extender Authentication for Secure Mesh Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Wi-Fi Protected Setup (WPS) methods, such as Push Button Configuration (PBC) and Personal Information Number (PIN), are cumbersome and insecure, particularly when attempting to connect multiple devices, as they can lead to accidental connections with other networks and are prone to user error.
Innovation Solution
A network connection system where a gateway and extender router exchange authentication information to confirm compatibility, allowing the gateway to transmit backhaul security credentials for secure and automatic onboarding of devices into a wireless mesh network, minimizing user interaction and ensuring only authorized nodes can join the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Push Button Configuration (PBC) method is used for WPS, then the setup process is simplified, but the wireless client may accidentally connect to other base stations and security issues arise
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where the gateway first verifies the extender's authentication information (manufacturer information, model name, model number) before allowing connection. This intermediary verification step prevents direct accidental connections to other base stations while maintaining the simplified button-based operation, thus resolving the contradiction between ease of operation and connection security.
2Reliability
If Personal Information Number (PIN) method is used for WPS, then connection security is improved, but the process becomes complex and error-prone due to manual input requirements
Solution Approach 1:
The patent implements self-service by having the extender automatically provide its authentication information (manufacturer information, model name, model number) to the gateway without requiring manual user input. The system automatically verifies compatibility and exchanges security credentials, eliminating the error-prone manual PIN input process while maintaining high connection security.
3Reliability
If traditional WPS methods are used, then single device connection is achieved, but simultaneous login of multiple devices is difficult to realize
Solution Approach 1:
The patent achieves multi-device simultaneous login by making the gateway and extender capable of serving multiple enrollee devices concurrently. The gateway maintains a list of authenticated extenders and can issue security credentials to multiple devices simultaneously, allowing one-time setup that enables multiple devices to connect to the wireless mesh network at the same time while preserving security through centralized authentication.
4Ease of operation
If automatic onboarding process is implemented, then user difficulty in WPS setting is reduced, but authentication information verification complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-configuring the gateway with a list of authenticated extenders and their authentication information before actual connection requests. When an extender connects, the gateway simply checks against this pre-verified list rather than performing complex real-time authentication, thus achieving automatic onboarding with minimal user difficulty while keeping the verification process computationally simple.
Data Source
AI summary
The present invention relates to a network connection system. The network connection system includes a gateway, an extender, and a wireless access point. Wherein, the gateway can be used as one of the enrollee router and the registrar router, and the extender can be used as the other of the enrollee router and the registrar router, and the extender can send authentication information to the gateway. After the gateway confirms that the extender is a model supported by the gateway according to the authentication information, the gateway sends a credential to the extender, allowing the extender to establish a wireless mesh network through the wireless access point. In this way, the purpose of seamless connection is achieved. In addition, the network connection system of the present invention has functions such as high security and convenience.


