Group Passphrase Policy for Wireless Network Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in establishing secure connections for electronic devices in dynamic personal area networks (PANs) within wireless local area networks (WLANs), particularly due to the complexity of distributing and managing cryptographic information like passphrases.

Innovation Solution

An electronic device that selectively provides secure access to a network by receiving passphrase parameters, calculating outputs of a cryptographic calculation based on stored passphrases, and accessing a policy associated with the user to determine access acceptance, thereby establishing secure connections independent of other PANs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate passphrases are assigned to each electronic device in a PAN, then secure connections can be established, but the onboarding process becomes cumbersome and time-consuming

Engineering Contradiction:
Improvesecure connectionVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple device-specific passphrases into a single group passphrase that can be shared across multiple electronic devices. This consolidation allows devices to be onboarded quickly without requiring individual passphrase distribution, while still maintaining secure connections through the shared passphrase and policy-based access control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal passphrase system where a single passphrase can serve multiple devices simultaneously. The policy mechanism provides multi-functionality by enabling different access levels and permissions for different devices using the same passphrase, thus reducing onboarding time while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate passphrases are assigned to each electronic device in a PAN, then secure connections can be established, but passphrase management becomes complicated

Engineering Contradiction:
Improvesecure connectionVSAvoidpassphrase management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple passphrase management tasks into a single centralized system. Instead of managing separate passphrases for each device, the system uses one group passphrase managed through policy configurations, significantly simplifying the management overhead while maintaining secure connections.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a policy mechanism as an intermediary between the passphrase and device access. This policy layer abstracts the complexity of passphrase management, allowing centralized control and simplified deployment while maintaining secure device connections through policy-based access decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a single passphrase is used for multiple devices, then onboarding is simplified, but secure isolation between different PANs becomes challenging

Engineering Contradiction:
Improveonboarding processVSAvoidPAN isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a policy mechanism as an intermediary that sits between the shared passphrase and device access decisions. This policy layer ensures that even though multiple devices share a passphrase, secure isolation between different PANs is maintained through policy-based access control that verifies device authorization before allowing connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies local quality by implementing device-specific policy rules that are enforced at each access point. While the passphrase is shared globally across devices, the policy enforcement ensures that each device receives appropriate local access control, maintaining PAN isolation while allowing simplified onboarding.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250184326A1Device-Independent Authentication Based on an Authentication Parameter and a Policy
Publication Date: 2025.06.05 RUCKUS IP HOLDINGS LLC
  • US20250184326A1 patent drawing
  • US20250184326A1 patent drawing
  • US20250184326A1 patent drawing

AI summary

An electronic device that selectively provides secure access of a second electronic device to a network is described. This electronic device receives an access request associated with a computer, where the access request includes one or more authentication parameters associated with a user. In response, the electronic device confirms the one or more authentication parameters to determine whether there is an authentication match. Moreover, when there is an authentication match, the electronic device accesses a policy associated with or that includes: a spatial criterion, a temporal criterion, information associated with the user, information associated with the one or more authentication parameters, and/or information associated with the network. Then, when one or more criteria associated with the policy are met, the electronic device selectively provides an access acceptance message to the computer, which includes information for establishing the secure access of the second electronic device and an attribute of the policy.