Persona-Based Authentication Policy for Multi-Method Device Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices face challenges in distributing and using cryptographic information such as passphrases due to different authentication techniques, leading to cumbersome and time-consuming onboarding processes and difficulties in establishing common behaviors or services.

Innovation Solution

An electronic device applies attributes or characteristics of a persona group, including authentication rules and cryptographic information, to authenticate and manage different authentication techniques, allowing for efficient distribution and use of passphrases across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If different authentication techniques are used for different electronic devices, then device compatibility and security are improved, but onboarding complexity and time consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoidonboarding complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework where a single network passphrase can be used across multiple authentication techniques (WPA2-Personal, WPA3-SAE, EAP-TLS). The authentication server dynamically selects the appropriate authentication method based on device capabilities, allowing one passphrase to serve multiple authentication functions simultaneously, thereby reducing onboarding complexity while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

An authentication server acts as an intermediary between electronic devices and the network. This server receives authentication requests from devices with different authentication techniques, processes them appropriately, and grants network access. The intermediary handles the complexity of multiple authentication methods centrally, simplifying the onboarding process for individual devices while maintaining robust security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple authentication techniques are supported, then device versatility is improved, but cryptographic information distribution becomes more difficult

Engineering Contradiction:
Improveauthentication technique diversityVSAvoidcryptographic information distribution
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent extracts the cryptographic information management complexity from individual devices and centralizes it in an authentication server. Devices only need to store a single network passphrase, while the server handles the generation, management, and distribution of authentication credentials appropriate for each device type, thereby simplifying cryptographic information distribution while supporting multiple authentication techniques

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameter of cryptographic information from device-specific credentials to a universal network passphrase. This parameter change allows the same passphrase to work across different authentication techniques (WPA2, WPA3, EAP-TLS), simplifying distribution while maintaining adaptability to various device authentication capabilities

Inventive Principle:
Principle #35Parameter changes

3Productivity

If common attributes are applied across all devices, then network management efficiency is improved, but device-specific authentication requirements are compromised

Engineering Contradiction:
Improvenetwork management efficiencyVSAvoidauthentication appropriateness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic attribute application where the authentication server selectively applies common network attributes (passphrase, security policies) to all devices while simultaneously applying device-specific authentication requirements. The system dynamically adjusts authentication parameters based on device capabilities, ensuring both efficient centralized management and appropriate device-specific security measures

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4668676A1Persona-based policy for different authentication techniques
Publication Date: 2025.12.24 RUCKUS IP HOLDINGS LLC
  • EP4668676A1 patent drawingFigure 1
  • EP4668676A1 patent drawingFigure 2
  • EP4668676A1 patent drawingFigure 3

AI summary

An electronic device that applies attributes or characteristics of a persona group is described. Notably, the electronic device may authenticate, using an associated authentication technique, a given second electronic device in a set of second electronic devices to a network, where at least some second electronic devices in the set of second electronic devices use different authentication techniques to authenticate to the network. Then, the electronic device may obtain (e.g., in a non-transitory memory), based at least in part on an identifier of a user associated with the set of second electronic devices, information specifying the persona group. Moreover, the electronic device may apply, based at least in part on the information, the attributes or characteristics of the persona group to the set of second electronic devices.