Persona-Based Authentication Policy for Multi-Method Device Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic devices face challenges in distributing and using cryptographic information such as passphrases due to different authentication techniques, leading to cumbersome and time-consuming onboarding processes and difficulties in establishing common behaviors or services.
Innovation Solution
An electronic device applies attributes or characteristics of a persona group, including authentication rules and cryptographic information, to authenticate and manage different authentication techniques, allowing for efficient distribution and use of passphrases across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If different authentication techniques are used for different electronic devices, then device compatibility and security are improved, but onboarding complexity and time consumption increase
Solution Approach 1:
The patent implements a universal authentication framework where a single network passphrase can be used across multiple authentication techniques (WPA2-Personal, WPA3-SAE, EAP-TLS). The authentication server dynamically selects the appropriate authentication method based on device capabilities, allowing one passphrase to serve multiple authentication functions simultaneously, thereby reducing onboarding complexity while maintaining security
Solution Approach 2:
An authentication server acts as an intermediary between electronic devices and the network. This server receives authentication requests from devices with different authentication techniques, processes them appropriately, and grants network access. The intermediary handles the complexity of multiple authentication methods centrally, simplifying the onboarding process for individual devices while maintaining robust security
2Adaptability or versatility
If multiple authentication techniques are supported, then device versatility is improved, but cryptographic information distribution becomes more difficult
Solution Approach 1:
The patent extracts the cryptographic information management complexity from individual devices and centralizes it in an authentication server. Devices only need to store a single network passphrase, while the server handles the generation, management, and distribution of authentication credentials appropriate for each device type, thereby simplifying cryptographic information distribution while supporting multiple authentication techniques
Solution Approach 2:
The system changes the parameter of cryptographic information from device-specific credentials to a universal network passphrase. This parameter change allows the same passphrase to work across different authentication techniques (WPA2, WPA3, EAP-TLS), simplifying distribution while maintaining adaptability to various device authentication capabilities
3Productivity
If common attributes are applied across all devices, then network management efficiency is improved, but device-specific authentication requirements are compromised
Solution Approach 1:
The patent implements dynamic attribute application where the authentication server selectively applies common network attributes (passphrase, security policies) to all devices while simultaneously applying device-specific authentication requirements. The system dynamically adjusts authentication parameters based on device capabilities, ensuring both efficient centralized management and appropriate device-specific security measures
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An electronic device that applies attributes or characteristics of a persona group is described. Notably, the electronic device may authenticate, using an associated authentication technique, a given second electronic device in a set of second electronic devices to a network, where at least some second electronic devices in the set of second electronic devices use different authentication techniques to authenticate to the network. Then, the electronic device may obtain (e.g., in a non-transitory memory), based at least in part on an identifier of a user associated with the set of second electronic devices, information specifying the persona group. Moreover, the electronic device may apply, based at least in part on the information, the attributes or characteristics of the persona group to the set of second electronic devices.