Multi-Enterprise Wireless Network Authentication via Cloud Lookup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As employees transition to work-from-home models, extending corporate network security to remote and public environments remains a challenge, particularly in ensuring secure Wi-Fi connections for employees across different enterprises.

Innovation Solution

A multi-enterprise Wi-Fi network configuration service is implemented on access points, using WPA-Enterprise security, which determines the appropriate authentication server for clients based on their enterprise credentials, allowing secure connections even in public settings by managing associations between client network information and authentication servers through a cloud database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If WPA-Personal security with a single password is used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of connectionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access point is configured to support multiple enterprise networks simultaneously, each with their own authentication server and credentials. This allows a single access point to serve multiple enterprises with different security requirements while maintaining individualized authentication for each enterprise, thus improving security without compromising ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If WPA-Enterprise security with individual authentication is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A cloud-based authentication server acts as an intermediary to manage authentication credentials for multiple enterprises. The access point forwards authentication requests to the appropriate enterprise's authentication server in the cloud, eliminating the need to store multiple sets of credentials locally and reducing device complexity while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication infrastructure is moved from the local access point to the cloud dimension. By storing and managing authentication credentials remotely in the cloud rather than locally on the access point, the system reduces local device complexity while maintaining enterprise-level security through individual authentication.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If cloud-based authentication server selection is implemented, then adaptability is improved, but loss of information is worsened

Engineering Contradiction:
Improveenterprise compatibilityVSAvoidauthentication failure
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms where the access point receives authentication status information from the cloud authentication server and communicates this back to the client device. This feedback loop ensures that authentication failures are properly reported and handled, preventing information loss while maintaining adaptability across multiple enterprises.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20230247422A1Secure multi-enterprise wireless network
Publication Date: 2023.08.03 PALO ALTO NETWORKS INC
  • US20230247422A1 patent drawing
  • US20230247422A1 patent drawing
  • US20230247422A1 patent drawing

AI summary

An access point service configures and manages a multi-enterprise wireless network in public settings. During network profile setup for a client connecting to an enterprise-issued access point (e.g., in a home environment), the service determines network information unique to the client and an authentication server associated with the enterprise to which the client is to authenticate for 802.1X authentication and stores the client network information and an indication of the authentication server in a cloud database. For access points in a public setting, upon detection of an association request by a client, the service determines network information that identifies the client and performs a lookup of the cloud database with the network information to determine to which of the recognized authentication servers to forward authentication messages transmitted by the client. If the result of the lookup does not indicate an authentication server, the connection is terminated.