Multi-Password Wi-Fi Authentication for Per-Device Access Revocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Wi-Fi wireless communication networks typically use a single password for all users and devices, making it inconvenient to revoke access for specific users or devices without changing the network password, which is particularly problematic for IoT devices with limited interfaces, and MAC address filtering is inadequate for per-user control.
Innovation Solution
Implementing a system that supports multiple passwords per user or device, allowing customized access control and network parameters, compatible with protocols like WPA2, and enabling per-user, per-device, or per-policy password assignment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single password is used for all users and devices, then network configuration is simple, but access control cannot be revoked for specific users or devices
Solution Approach 1:
The patent segments the single network password into multiple individual passwords, one for each user or device. This allows the network to maintain a simple configuration structure while enabling granular per-user access control. Each user/device receives a unique password that can be independently managed and revoked without affecting others.
Solution Approach 2:
The patent creates a universal password distribution mechanism that serves multiple functions: it maintains backward compatibility with conventional single-password networks while simultaneously enabling per-user password assignment, automated distribution to devices including IoT devices, and independent revocation capability. This multi-functional approach resolves the contradiction between simplicity and versatility.
2Adaptability or versatility
If the network password is changed to revoke access, then access control is updated, but all users are inconvenienced by requiring a new password
Solution Approach 1:
By segmenting the network authentication into individual user passwords rather than a single shared password, the system enables selective revocation. When access control updates are needed, only the specific user's password can be changed or revoked, leaving all other users' passwords unchanged. This eliminates the need for network-wide password changes while maintaining updated access control policies.
Solution Approach 2:
The system implements automated password distribution and management where the network infrastructure automatically handles password assignment, updates, and revocation without requiring manual user intervention. This self-service mechanism ensures that access control updates are applied seamlessly to individual users without inconveniencing the broader user base.
3Adaptability or versatility
If MAC address filtering is used for per-device control, then device access can be restricted, but it cannot control access on a per-user basis and devices with random MAC addresses can bypass it
Solution Approach 1:
The patent introduces passwords as an intermediary authentication mechanism that bridges the gap between user identity and network access. Instead of relying solely on device identifiers like MAC addresses, the system uses passwords that can be tied to specific users or devices. This intermediary layer provides more reliable per-user control and is immune to MAC address spoofing or randomization techniques.
Solution Approach 2:
The system changes the authentication parameter from device-based identification (MAC address) to credential-based identification (password). This parameter change fundamentally improves reliability because passwords are secret credentials that cannot be easily spoofed or randomized, while still maintaining the ability to control access on a per-device or per-user basis through appropriate password assignment.
Data Source
AI summary
A method for supporting a plurality of passwords in a communication network includes (a) receiving a client authentication message generated by a network client wishing to connect to the communication network, (b) computing a respective password authentication message for at least one password of a plurality of passwords stored in a password database to generate a set of one or more password authentication messages, each password of the plurality of passwords being a password for the communication network, (c) identifying a password authentication message of the set of one or more password authentication messages that matches the client authentication message, and (d) associating, with the network client, metadata corresponding to a password of the password database used to compute the password authentication message that matches the client authentication message.


