PPSK Manager for MAC-Agnostic Wireless Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network management systems face challenges in securely onboarding and managing heterogeneous client devices, particularly due to MAC address randomization, which complicates authentication and identification, and require heavy on-premises infrastructure such as Radius, NAC, and captive portals.
Innovation Solution
A cloud-based network management system employing a horizontal architecture with a PPSK manager that provides scalable, MAC address-agnostic management of private pre-shared keys (PPSKs) for client devices, using these keys for authentication, tracking, and policy application, and enabling micro-segmentation and traffic management without relying on on-premises equipment or MAC addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAC address randomization is implemented for security, then security is improved, but client device identification and authorization become unreliable
Solution Approach 1:
The patent introduces PPSK as an intermediary authentication mechanism that decouples identification from MAC addresses. The PPSK manager serves as a mediator that authenticates devices using pre-shared keys rather than relying on MAC addresses, thereby maintaining security while enabling reliable device identification through alternative means.
Solution Approach 2:
The patent changes the authentication parameter from MAC address to PPSK. By transitioning from hardware-based identification (MAC address) to software-based authentication (pre-shared key), the system maintains security while enabling flexible and reliable device authorization without dependency on randomized MAC addresses.
2Reliability
If on-premises authentication equipment (Radius, NAC, captive portal) is deployed, then authentication capability is improved, but system complexity and infrastructure requirements increase
Solution Approach 1:
The patent extracts the authentication functionality from heavy on-premises infrastructure and relocates it to a cloud-based PPSK manager. This extraction eliminates the need for complex local Radius servers, NAC systems, and captive portal infrastructure while maintaining authentication capability through a simplified cloud-based key management approach.
Solution Approach 2:
The cloud-based PPSK manager provides universal authentication services that replace multiple specialized on-premises systems. A single cloud service handles authentication, authorization, and key management functions that previously required separate Radius, NAC, and captive portal infrastructure, thereby reducing overall system complexity.
3Reliability
If traditional wireless network management is used, then device connectivity is maintained, but scalability to millions of devices is limited
Solution Approach 1:
The patent transitions from local on-premises authentication to a cloud-based dimension for key management. This dimensional shift allows the system to scale horizontally across millions of devices by leveraging cloud infrastructure, while local APs maintain connectivity through simplified PPSK-based authentication without requiring complex local processing.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
Techniques are described that enable onboarding of a plurality of heterogeneous client devices with secure access to a wireless network using a network management system (NMS). The NMS has a memory to store a plurality of private pre-shared keys (PPSKs), where each PPSK is provisioned for a particular client device or a particular group of client devices. In response to a key lookup request from an access point (AP) device for a client device, the NMS performs a key lookup and, in response to identifying a PPSK provisioned for the client device, authenticates the client device to access the wireless network via the AP device. The NMS then manages one or more of tracking the client device, policy application to the client device, or handling of network traffic from the client device while connected to the wireless network using the PPSK as an identifier of the client device.