Network Device Whitelist Automation for WiFi Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current WiFi network security systems relying solely on passwords are inadequate, as unskilled hackers can easily obtain or steal passwords to gain unauthorized access to private networks, and users often fail to implement additional security features due to complexity.

Innovation Solution

A network device automatically detects unrecognized client devices and sends a message to the network manager for access approval, integrating a whitelist or blacklist system that adds identification information of authorized devices, eliminating the need for manual setup and enhancing security with a two-factor authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a whitelist/blacklist authentication system is implemented, then network security is improved, but device complexity and ease of operation deteriorate due to manual setup requirements

Engineering Contradiction:
Improvenetwork securityVSAvoidmanual setup requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network device automatically performs whitelist management functions including detecting unrecognized client devices, sending notification messages to network managers, and adding approved devices to the whitelist without requiring manual user configuration. This self-service automation resolves the contradiction by maintaining high security through whitelist authentication while eliminating manual setup burdens.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures the network device with the capability to automatically manage whitelist authentication. When a new client device attempts to connect, the system has already established the framework for automatic detection and manager notification, so no manual whitelist setup is needed at deployment time.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automatic whitelist management is implemented, then ease of operation is improved by minimizing user interaction, but device complexity increases due to automated detection and messaging functions

Engineering Contradiction:
Improveuser interaction requirementVSAvoidautomated detection and messaging
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The network device autonomously handles client device detection, manager notification message generation and transmission, and whitelist update operations. This self-service capability minimizes user interaction to simple approval actions while the system automatically manages the complex authentication workflow.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent combines multiple functions (client device detection, message composition, message transmission, and whitelist management) into a single integrated automated process within the network device, simplifying the user experience while managing complexity internally.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If password-only authentication is used, then ease of operation is improved, but network security deteriorates as hackers can easily obtain passwords

Engineering Contradiction:
Improveauthentication simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct phases: initial password-based authentication for ease of access, followed by automated whitelist verification for enhanced security. This segmentation allows the system to maintain operational simplicity while adding a security layer that prevents unauthorized access even when passwords are compromised.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary password authentication to establish initial access, then immediately follows with whitelist verification. This preliminary action sequence maintains ease of operation for authorized users while adding security validation that prevents hacker access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11683312B2Client device authentication to a secure network
Publication Date: 2023.06.20 ARRIS ENTERPRISES LLC
  • US11683312B2 patent drawing
  • US11683312B2 patent drawing
  • US11683312B2 patent drawing

AI summary

A method for authenticating an electronic client device for purposes of granting/denying access to a secure network is provided. The network device detects whether a client device requesting access to the secure network is a known client device on a list maintained by the network device or an unrecognized client device that is not on the list. If the client device is detected as being an unrecognized client device, the network device causes a message to be sent to a manager of the secure network. When a response is received, identification information of the unrecognized client device is automatically added to the list of known client devices by the network device. A network device is also provided.