Instant Virtual Access Points with Hidden SSIDs for Secure Wi-Fi

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless access points lack secure communication options for sensitive information, with PSK-based security systems vulnerable to unauthorized access and requiring technical expertise to implement and maintain.

Innovation Solution

Implementing instant virtual access points (iVAPs) with hidden SSIDs, decoy beacons, and a 4-way handshake to verify pre-shared keys (PSKs) for secure network access, allowing unique SSIDs, passphrases, and VLANs without disrupting existing VAP configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PSK-based security systems are implemented, then security for sensitive information is improved, but device complexity and difficulty of maintenance increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism where the access point automatically generates and manages PSKs for multiple virtual access points. Instead of requiring manual configuration of PSKs on each client device, the system acts as a mediator that handles key generation, distribution, and rotation centrally, thereby maintaining security while reducing complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service capabilities where the access point autonomously generates PSKs, manages their distribution to authorized devices, and handles key rotation without requiring manual intervention. This automated key management reduces the burden of maintenance while preserving security

Inventive Principle:
Principle #25Self-service

2Ease of operation

If pre-shared keys are stored at both client station and access point, then authentication is enabled, but vulnerability to unauthorized access increases

Engineering Contradiction:
ImproveauthenticationVSAvoidvulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic PSK management where pre-shared keys are not static but are automatically generated, rotated, and updated by the access point. This dynamic approach ensures that even if one PSK is compromised, the system can rotate to new keys, reducing the window of vulnerability while maintaining ease of authentication

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-generating and distributing PSKs to authorized devices before they need to connect. This allows devices to authenticate immediately without manual key entry, while the access point maintains control over key distribution and can revoke or rotate keys as needed, balancing ease of operation with security

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple virtual access points are created with unique SSIDs and security settings, then network versatility is improved, but configuration complexity increases

Engineering Contradiction:
ImproveversatilityVSAvoidconfiguration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the management of multiple virtual access points into a single centralized system. The access point consolidates the configuration and key management for multiple VAPs with unique SSIDs and security settings, allowing administrators to manage diverse network segments without proportionally increasing configuration complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access point is designed with multi-functionality to handle multiple VAPs, each with different SSIDs, security settings, and PSKs, through a unified management interface. This universal capability allows the system to adapt to various network requirements without requiring separate configuration processes for each VAP

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250274756A1Systems and methods for an instant virtual access point
Publication Date: 2025.08.28 ALLIED TELESIS
  • US20250274756A1 patent drawing
  • US20250274756A1 patent drawing
  • US20250274756A1 patent drawing

AI summary

Systems and methods for providing instant secured network access for station devices. Multiple sets of SSIDs and passphrases construct different instant virtual access points (iVAPs) by utilizing a hidden virtual access point (VAP); where station devices can connect to the hidden VAP using different iVAP credentials, reducing the security risk as the unique access credentials allow the station devices to access the hidden VAP without other devices decrypting the data; where iVAPs can be created, deleted, and modified without changing the VAP configurations, without disconnections, and without system downtime; and where the iVAP solution includes using hidden SSIDs, sending decoy beacons and probe responses, an association process, and a 4-way handshake.