Group Passphrase Policy for Wireless Network Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in establishing secure connections for electronic devices in dynamic personal area networks (PANs) within wireless local area networks (WLANs), particularly due to the complexity of distributing and managing cryptographic information like passphrases.
Innovation Solution
An electronic device that selectively provides secure access to a network by receiving passphrase parameters, calculating outputs of a cryptographic calculation based on stored passphrases, and accessing a policy associated with the user to determine access acceptance, thereby establishing secure connections independent of other PANs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate passphrases are assigned to each electronic device in a PAN, then secure connections can be established, but the onboarding process becomes cumbersome and time-consuming
Solution Approach 1:
The patent merges multiple device-specific passphrases into a single group passphrase that can be shared across multiple electronic devices. This consolidation allows devices to be onboarded quickly without requiring individual passphrase distribution, while still maintaining secure connections through the shared passphrase and policy-based access control.
Solution Approach 2:
The patent implements a universal passphrase system where a single passphrase can serve multiple devices simultaneously. The policy mechanism provides multi-functionality by enabling different access levels and permissions for different devices using the same passphrase, thus reducing onboarding time while maintaining security.
2Reliability
If separate passphrases are assigned to each electronic device in a PAN, then secure connections can be established, but passphrase management becomes complicated
Solution Approach 1:
The patent combines multiple passphrase management tasks into a single centralized system. Instead of managing separate passphrases for each device, the system uses one group passphrase managed through policy configurations, significantly simplifying the management overhead while maintaining secure connections.
Solution Approach 2:
The patent introduces a policy mechanism as an intermediary between the passphrase and device access. This policy layer abstracts the complexity of passphrase management, allowing centralized control and simplified deployment while maintaining secure device connections through policy-based access decisions.
3Ease of operation
If a single passphrase is used for multiple devices, then onboarding is simplified, but secure isolation between different PANs becomes challenging
Solution Approach 1:
The patent introduces a policy mechanism as an intermediary that sits between the shared passphrase and device access decisions. This policy layer ensures that even though multiple devices share a passphrase, secure isolation between different PANs is maintained through policy-based access control that verifies device authorization before allowing connections.
Solution Approach 2:
The patent applies local quality by implementing device-specific policy rules that are enforced at each access point. While the passphrase is shared globally across devices, the policy enforcement ensures that each device receives appropriate local access control, maintaining PAN isolation while allowing simplified onboarding.
Data Source
AI summary
An electronic device that selectively provides secure access of a second electronic device to a network is described. This electronic device receives an access request associated with a computer, where the access request includes one or more authentication parameters associated with a user. In response, the electronic device confirms the one or more authentication parameters to determine whether there is an authentication match. Moreover, when there is an authentication match, the electronic device accesses a policy associated with or that includes: a spatial criterion, a temporal criterion, information associated with the user, information associated with the one or more authentication parameters, and/or information associated with the network. Then, when one or more criteria associated with the policy are met, the electronic device selectively provides an access acceptance message to the computer, which includes information for establishing the secure access of the second electronic device and an attribute of the policy.


