MPSK Portal PSK Provisioning Without MAC Address Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in obtaining pre-shared keys (PSKs) for wireless devices due to the need to determine and register the device's MAC address, which is time-consuming and often requires technical assistance, hindering efficient wireless network connectivity.
Innovation Solution
A registration-less mechanism using a cloud authentication server provides PSKs to wireless devices through a MPSK portal accessible via a URL, eliminating the need for MAC address registration and enabling multiple PSKs per device or group, facilitated by an MPSK management engine and identity and access management server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional MAC address registration is used to obtain PSKs, then security control is maintained, but user operation complexity increases and registration time is extended
Solution Approach 1:
The patent extracts the MAC address determination step from the PSK acquisition process. Instead of requiring users to manually find and register MAC addresses, the system generates PSKs independently of MAC addresses, removing the time-consuming step of MAC address lookup and registration while maintaining security through the authentication server's control over PSK distribution.
Solution Approach 2:
The authentication server acts as an intermediary that directly provides PSKs to wireless devices without requiring MAC address registration. The server generates and distributes PSKs based on authentication credentials rather than device hardware identifiers, simplifying the user process while maintaining centralized security control.
2Device complexity
If MAC address registration is required for PSK distribution, then device identification is ensured, but system complexity increases due to registration procedures
Solution Approach 1:
The patent removes the MAC address registration subsystem from the PSK distribution process. The authentication server generates PSKs directly based on user credentials or device authentication without requiring MAC address input, storage, or validation, thereby reducing system complexity and eliminating the need for registration procedures while simplifying device setup.
Solution Approach 2:
The authentication server automatically generates and distributes PSKs without requiring user intervention for MAC address registration. The system performs self-service by autonomously managing PSK generation and distribution based on authentication outcomes, eliminating complex registration procedures and simplifying the user experience.
3Adaptability or versatility
If single PSK per SSID is used, then security management is simplified, but security flexibility is reduced
Solution Approach 1:
The authentication server implements multi-functionality by supporting both single PSK and multiple PSKs per SSID through the same infrastructure. The system can dynamically assign one or multiple PSKs based on authentication outcomes, user requirements, or security policies, providing flexibility without requiring separate management systems for different PSK scenarios.
Data Source
AI summary
In some examples, a system receives, from an identity and access management server, information of whether a portal for obtaining pre-shared keys (PSKs) is enabled. Responsive to receiving an indication that the portal for obtaining PSKs is enabled, the system adds, to a policy, a service set identifier (SSID) that is associated with use of a multi-pre-shared key (MPSK) arrangement. The system retrieves, in response to the policy, a reference useable by wireless devices to obtain respective PSKs of the wireless devices, and outputs a representation of the reference to share with the wireless devices to obtain from the portal the respective PSKs by the wireless devices for connecting to the WLAN.


