Instant Virtual Access Points with Hidden SSIDs for Secure Wi-Fi
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless access points lack secure communication options for sensitive information, with PSK-based security systems vulnerable to unauthorized access and requiring technical expertise to implement and maintain.
Innovation Solution
Implementing instant virtual access points (iVAPs) with hidden SSIDs, decoy beacons, and a 4-way handshake to verify pre-shared keys (PSKs) for secure network access, allowing unique SSIDs, passphrases, and VLANs without disrupting existing VAP configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PSK-based security systems are implemented, then security for sensitive information is improved, but device complexity and difficulty of maintenance increase
Solution Approach 1:
The patent introduces an intermediary mechanism where the access point automatically generates and manages PSKs for multiple virtual access points. Instead of requiring manual configuration of PSKs on each client device, the system acts as a mediator that handles key generation, distribution, and rotation centrally, thereby maintaining security while reducing complexity
Solution Approach 2:
The system implements self-service capabilities where the access point autonomously generates PSKs, manages their distribution to authorized devices, and handles key rotation without requiring manual intervention. This automated key management reduces the burden of maintenance while preserving security
2Ease of operation
If pre-shared keys are stored at both client station and access point, then authentication is enabled, but vulnerability to unauthorized access increases
Solution Approach 1:
The patent implements dynamic PSK management where pre-shared keys are not static but are automatically generated, rotated, and updated by the access point. This dynamic approach ensures that even if one PSK is compromised, the system can rotate to new keys, reducing the window of vulnerability while maintaining ease of authentication
Solution Approach 2:
The system performs preliminary actions by pre-generating and distributing PSKs to authorized devices before they need to connect. This allows devices to authenticate immediately without manual key entry, while the access point maintains control over key distribution and can revoke or rotate keys as needed, balancing ease of operation with security
3Adaptability or versatility
If multiple virtual access points are created with unique SSIDs and security settings, then network versatility is improved, but configuration complexity increases
Solution Approach 1:
The patent merges the management of multiple virtual access points into a single centralized system. The access point consolidates the configuration and key management for multiple VAPs with unique SSIDs and security settings, allowing administrators to manage diverse network segments without proportionally increasing configuration complexity
Solution Approach 2:
The access point is designed with multi-functionality to handle multiple VAPs, each with different SSIDs, security settings, and PSKs, through a unified management interface. This universal capability allows the system to adapt to various network requirements without requiring separate configuration processes for each VAP
Data Source
AI summary
Systems and methods for providing instant secured network access for station devices. Multiple sets of SSIDs and passphrases construct different instant virtual access points (iVAPs) by utilizing a hidden virtual access point (VAP); where station devices can connect to the hidden VAP using different iVAP credentials, reducing the security risk as the unique access credentials allow the station devices to access the hidden VAP without other devices decrypting the data; where iVAPs can be created, deleted, and modified without changing the VAP configurations, without disconnections, and without system downtime; and where the iVAP solution includes using hidden SSIDs, sending decoy beacons and probe responses, an association process, and a 4-way handshake.


