Group Key Authentication for Isolated Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems lack effective methods to securely manage network access for host devices belonging to different users, leading to potential data link layer communication breaches between devices of different users.

Innovation Solution

Implementing a network access management system that assigns unique user-specific keys to each user, using a network access management server to authenticate and authorize network access through access points, ensuring secure isolation between user groups by managing host device groups and device-group-specific keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique user-specific keys are assigned to each user for network access authentication, then data security and isolation between users are improved, but device complexity and key management overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments network access rights by assigning unique user-specific keys to each user, creating distinct authentication domains. This segmentation ensures that compromise of one user's key does not affect others, thereby improving data security while maintaining manageable complexity through structured key distribution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point serves as an intermediary between clients and the network, managing key distribution and authentication. It receives user credentials, validates them against stored user-specific keys, and controls access accordingly, reducing the complexity burden on individual clients while maintaining strong security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If host devices from different users are isolated through user-specific keys, then unauthorized access between users is prevented, but network access management complexity increases

Engineering Contradiction:
Improveunauthorized accessVSAvoidnetwork access management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The network is segmented into distinct user domains through unique keys, preventing unauthorized access between users. Each user's data and communications are isolated within their key-protected domain, effectively blocking harmful cross-user access while maintaining overall network functionality

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Clients perform self-authentication by presenting their user-specific keys to the access point, which automatically validates them and grants or denies access. This self-service mechanism reduces the need for complex centralized management while maintaining strong isolation between users

Inventive Principle:
Principle #25Self-service

3Reliability

If a network access management server maintains records of client devices and keys, then authentication reliability is improved, but information storage requirements and system complexity increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidinformation storage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The access point extracts and stores only the necessary authentication information (user-specific keys and associated metadata) rather than maintaining complete device profiles. This minimalistic approach ensures authentication reliability while significantly reducing information storage requirements compared to traditional systems

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12634122B2Group-based network access management
Publication Date: 2026.05.19 ARISTA NETWORKS INC
  • US12634122B2 patent drawing
  • US12634122B2 patent drawing
  • US12634122B2 patent drawing

AI summary

Client devices in the same device group may use the same group-specific key to perform a key exchange operation with access point(s) to obtain network access. A network access management server may provide centralized management of different device groups each being associated with a different group-specific key during the life cycles of the device groups. An access point may communicate with the network access management server to obtain the group-specific key to assist in authenticating network access of a connecting client device.