Gateway-Extender Authentication for Secure Mesh Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Wi-Fi Protected Setup (WPS) methods, such as Push Button Configuration (PBC) and Personal Information Number (PIN), are cumbersome and insecure, particularly when attempting to connect multiple devices, as they can lead to accidental connections with other networks and are prone to user error.

Innovation Solution

A network connection system where a gateway and extender router exchange authentication information to confirm compatibility, allowing the gateway to transmit backhaul security credentials for secure and automatic onboarding of devices into a wireless mesh network, minimizing user interaction and ensuring only authorized nodes can join the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Push Button Configuration (PBC) method is used for WPS, then the setup process is simplified, but the wireless client may accidentally connect to other base stations and security issues arise

Engineering Contradiction:
ImproveWPS setup processVSAvoidconnection security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where the gateway first verifies the extender's authentication information (manufacturer information, model name, model number) before allowing connection. This intermediary verification step prevents direct accidental connections to other base stations while maintaining the simplified button-based operation, thus resolving the contradiction between ease of operation and connection security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Personal Information Number (PIN) method is used for WPS, then connection security is improved, but the process becomes complex and error-prone due to manual input requirements

Engineering Contradiction:
Improveconnection securityVSAvoidWPS setup process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by having the extender automatically provide its authentication information (manufacturer information, model name, model number) to the gateway without requiring manual user input. The system automatically verifies compatibility and exchanges security credentials, eliminating the error-prone manual PIN input process while maintaining high connection security.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional WPS methods are used, then single device connection is achieved, but simultaneous login of multiple devices is difficult to realize

Engineering Contradiction:
Improveconnection securityVSAvoidmulti-device simultaneous login
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent achieves multi-device simultaneous login by making the gateway and extender capable of serving multiple enrollee devices concurrently. The gateway maintains a list of authenticated extenders and can issue security credentials to multiple devices simultaneously, allowing one-time setup that enables multiple devices to connect to the wireless mesh network at the same time while preserving security through centralized authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If automatic onboarding process is implemented, then user difficulty in WPS setting is reduced, but authentication information verification complexity increases

Engineering Contradiction:
ImproveWPS setting difficultyVSAvoidauthentication verification process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring the gateway with a list of authenticated extenders and their authentication information before actual connection requests. When an extender connects, the gateway simply checks against this pre-verified list rather than performing complex real-time authentication, thus achieving automatic onboarding with minimal user difficulty while keeping the verification process computationally simple.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230239690A1Network connection system and network connection method thereof
Publication Date: 2023.07.27 ARCADYAN
  • US20230239690A1 patent drawing
  • US20230239690A1 patent drawing
  • US20230239690A1 patent drawing

AI summary

The present invention relates to a network connection system. The network connection system includes a gateway, an extender, and a wireless access point. Wherein, the gateway can be used as one of the enrollee router and the registrar router, and the extender can be used as the other of the enrollee router and the registrar router, and the extender can send authentication information to the gateway. After the gateway confirms that the extender is a model supported by the gateway according to the authentication information, the gateway sends a credential to the extender, allowing the extender to establish a wireless mesh network through the wireless access point. In this way, the purpose of seamless connection is achieved. In addition, the network connection system of the present invention has functions such as high security and convenience.