Persona-Based Authentication Policy for Multi-Device Network Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices face challenges in defining attributes or characteristics when using different authentication techniques, leading to cumbersome and time-consuming onboarding processes and difficulty in establishing common behaviors or services across networks.

Innovation Solution

An electronic device applies attributes or characteristics of a persona group, authenticating devices using various authentication techniques, and distributes cryptographic information such as DPSKs to facilitate secure and efficient network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If different authentication techniques are used for different electronic devices, then security and authentication capability are improved, but onboarding complexity and time consumption increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidonboarding complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a controller as an intermediary device that manages authentication for multiple electronic devices. The controller stores credential data and authentication information, and coordinates the authentication process between different devices and the network, thereby simplifying the onboarding complexity while maintaining strong authentication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The controller serves multiple functions: it acts as an authentication server, stores credential data for multiple devices, manages different authentication techniques (passphrase-based and certificate-based), and coordinates network access. This multi-functionality reduces the need for separate systems and simplifies the overall onboarding process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If different authentication techniques are used for different electronic devices, then authentication flexibility is improved, but time consumption for onboarding increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidonboarding time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The controller pre-stores credential data and authentication information for multiple electronic devices before they need to connect to the network. When a device needs to onboard, the authentication process is expedited because the necessary credentials are already prepared and stored in the controller, significantly reducing onboarding time while maintaining authentication flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The controller as an intermediary pre-coordinates authentication credentials and streamlines the authentication process. By having the controller manage and distribute credentials in advance, the actual onboarding time for each device is reduced while still supporting multiple authentication techniques for different device types.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If common attributes or policies are applied to all devices, then network management is simplified, but authentication capability for different device types is reduced

Engineering Contradiction:
Improvenetwork management complexityVSAvoidauthentication capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The controller applies different authentication methods and policies locally to different types of electronic devices based on their specific requirements. For example, passphrase-based authentication may be applied to simpler devices while certificate-based authentication is applied to more security-sensitive devices, allowing tailored authentication capability while maintaining centralized management.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes authentication parameters (such as credential type, authentication protocol, and security level) based on the specific device type and requirements. The controller can dynamically adjust authentication parameters for different devices, enabling both simplified management through centralized control and differentiated authentication capability for various device types.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250385779A1Persona-based policy for different authentication techniques
Publication Date: 2025.12.18 RUCKUS IP HOLDINGS LLC
  • US20250385779A1 patent drawing
  • US20250385779A1 patent drawing
  • US20250385779A1 patent drawing

AI summary

An electronic device that applies attributes or characteristics of a persona group is described. Notably, the electronic device may authenticate, using an associated authentication technique, a given second electronic device in a set of second electronic devices to a network, where at least some second electronic devices in the set of second electronic devices use different authentication techniques to authenticate to the network. Then, the electronic device may obtain (e.g., in a non-transitory memory), based at least in part on an identifier of a user associated with the set of second electronic devices, information specifying the persona group. Moreover, the electronic device may apply, based at least in part on the information, the attributes or characteristics of the persona group to the set of second electronic devices.