Mutable Network Device for Single-SSID Passphrase Policy Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless networks face challenges in providing differentiated functionalities to different users or devices without requiring multiple SSIDs or complex, enterprise-grade solutions, especially in small-scale environments like homes or small businesses.
Innovation Solution
A mutable network device that associates different sets of network policies with authentication assets, determining the appropriate policy set based on the authentication asset used by a client device, and configuring the network connection accordingly through a traffic kernel module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple SSIDs are created to provide differentiated functionalities to different users, then network functionality differentiation is improved, but device complexity and configuration difficulty increase
Solution Approach 1:
The patent implements a single SSID that serves multiple functions by associating different passphrases with different network policies. Instead of creating multiple SSIDs for different functionalities, the system allows one SSID to universally provide differentiated access through passphrase-based policy selection, thereby reducing configuration complexity while maintaining functionality differentiation.
Solution Approach 2:
The system changes the parameter of network policy association from SSID-level to passphrase-level. By modifying how network policies are triggered (from multiple SSIDs to multiple passphrases within one SSID), the system achieves functionality differentiation without increasing the number of SSIDs, thus reducing configuration complexity.
2Reliability
If enterprise-grade authentication solutions like RADIUS are implemented, then network security and policy enforcement are improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the essential authentication and policy enforcement functionality from complex enterprise-grade RADIUS solutions and implements it directly within the access point. By taking out only the necessary components (passphrase verification and policy association) and removing unnecessary enterprise infrastructure, the system achieves reliable security and policy enforcement with reduced complexity.
Solution Approach 2:
The access point performs authentication and policy determination autonomously using locally stored passphrase-policy associations. Instead of requiring external RADIUS servers for authentication and policy enforcement, the system enables the access point to self-service these functions, thereby reducing system complexity while maintaining security and reliability.
3Adaptability or versatility
If per-device permissions are configured to provide differentiated access, then network functionality control is improved, but ease of operation deteriorates when new devices are introduced
Solution Approach 1:
The patent implements preliminary action by pre-configuring passphrase-policy associations in the access point before devices are introduced. Instead of configuring permissions for each device individually at onboarding time, the system prepares the authentication-assets-to-policies mapping in advance, allowing new devices to be onboarded simply by providing the appropriate passphrase without complex per-device configuration.
Data Source
AI summary
A method for modifying functionality within a wireless network based on an applied authentication asset is disclosed that includes: defining a first set of network policies and a second set of network policies associated with a first authentication asset and a second authentication asset, respectively, for the wireless network, the second authentication asset being different from the first authentication asset; determining if the applied authentication asset used by a client device while engaging in an authentication process with an authentication server to secure a network connection with the wireless network matches one of the first authentication asset and the second authentication asset; and providing the network connection defined at least in part by the first set or the second set of network policies if the applied authentication asset is the first authentication asset and the second authentication asset, respectively to the client device through a mutable network device.


