PPSK Manager for MAC-Agnostic Wireless Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network management systems face challenges in securely onboarding and managing heterogeneous client devices, particularly due to MAC address randomization, which complicates authentication and identification, and require heavy on-premises infrastructure such as Radius, NAC, and captive portals.

Innovation Solution

A cloud-based network management system employing a horizontal architecture with a PPSK manager that provides scalable, MAC address-agnostic management of private pre-shared keys (PPSKs) for client devices, using these keys for authentication, tracking, and policy application, and enabling micro-segmentation and traffic management without relying on on-premises equipment or MAC addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MAC address randomization is implemented for security, then security is improved, but client device identification and authorization become unreliable

Engineering Contradiction:
ImprovesecurityVSAvoidclient device identification
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces PPSK as an intermediary authentication mechanism that decouples identification from MAC addresses. The PPSK manager serves as a mediator that authenticates devices using pre-shared keys rather than relying on MAC addresses, thereby maintaining security while enabling reliable device identification through alternative means.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameter from MAC address to PPSK. By transitioning from hardware-based identification (MAC address) to software-based authentication (pre-shared key), the system maintains security while enabling flexible and reliable device authorization without dependency on randomized MAC addresses.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If on-premises authentication equipment (Radius, NAC, captive portal) is deployed, then authentication capability is improved, but system complexity and infrastructure requirements increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidinfrastructure requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from heavy on-premises infrastructure and relocates it to a cloud-based PPSK manager. This extraction eliminates the need for complex local Radius servers, NAC systems, and captive portal infrastructure while maintaining authentication capability through a simplified cloud-based key management approach.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud-based PPSK manager provides universal authentication services that replace multiple specialized on-premises systems. A single cloud service handles authentication, authorization, and key management functions that previously required separate Radius, NAC, and captive portal infrastructure, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional wireless network management is used, then device connectivity is maintained, but scalability to millions of devices is limited

Engineering Contradiction:
Improvedevice connectivityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent transitions from local on-premises authentication to a cloud-based dimension for key management. This dimensional shift allows the system to scale horizontally across millions of devices by leveraging cloud infrastructure, while local APs maintain connectivity through simplified PPSK-based authentication without requiring complex local processing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP4114061A1Network management system to onboard heterogeneous client devices to wireless networks
Publication Date: 2023.01.04 JUNIPER NETWORKS INC
  • EP4114061A1 patent drawingFigure 1A
  • EP4114061A1 patent drawingFigure 1B
  • EP4114061A1 patent drawingFigure 2

AI summary

Techniques are described that enable onboarding of a plurality of heterogeneous client devices with secure access to a wireless network using a network management system (NMS). The NMS has a memory to store a plurality of private pre-shared keys (PPSKs), where each PPSK is provisioned for a particular client device or a particular group of client devices. In response to a key lookup request from an access point (AP) device for a client device, the NMS performs a key lookup and, in response to identifying a PPSK provisioned for the client device, authenticates the client device to access the wireless network via the AP device. The NMS then manages one or more of tracking the client device, policy application to the client device, or handling of network traffic from the client device while connected to the wireless network using the PPSK as an identifier of the client device.