Pre-Shared Key Management for Branded Hotspot Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hotspots face challenges in providing secure network access due to the complexity of implementing and maintaining security features, especially with transient users and diverse security needs, as well as the inconvenience of requiring users to authenticate anew at each location within a branded network.

Innovation Solution

A system that uses a unique pre-shared key for user devices to access secured networks, where a query for the key is sent to a database, and the corresponding key is retrieved and used to provide secure access based on associated parameters, allowing seamless and secure connectivity across branded hotspots.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PSK-based security systems are implemented with manual secret entry on all user devices, then network security is improved, but device complexity and ease of operation deteriorate due to the need to manually configure and update secrets on numerous diverse devices

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized server as an intermediary that automatically manages and distributes pre-shared keys to multiple access points and user devices. This mediator eliminates the need for manual secret configuration on each device, while still providing robust PSK-based security through automated key provisioning and rotation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automated self-service key management where the centralized server automatically generates, distributes, and rotates pre-shared keys across the network without requiring manual intervention. User devices automatically receive and configure their security credentials, eliminating the burden of manual setup and updates.

Inventive Principle:
Principle #25Self-service

2Reliability

If the shared secret is changed on all client stations to maintain security, then network security is improved, but loss of time and ease of operation worsen due to the need to update every device whenever a user departs or security credentials are compromised

Engineering Contradiction:
Improvenetwork securityVSAvoidtime to update all devices
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The centralized key management system automatically handles secret rotation by generating new pre-shared keys and distributing them to all access points and user devices without manual intervention. When security credentials need updating, the system self-service updates the entire network simultaneously, eliminating the time-consuming manual process of updating each device individually.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary key generation and distribution through the centralized server before users need to connect to the network. New pre-shared keys are prepared in advance and automatically provisioned to devices, so when security updates are needed, the work has already been completed beforehand rather than requiring reactive updates to every device.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If users are required to login and authenticate anew at each branded location, then network security is improved through location-specific authentication, but ease of operation deteriorates due to the inconvenience of repeated authentication

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication system where a single pre-shared key issued by the centralized server works across multiple branded hotspots and locations. The system maintains location-specific security requirements while allowing users to authenticate once and access any participating location, combining security with user convenience through multi-functional key acceptance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10182350B2Key assignment for a brand
Publication Date: 2019.01.15 RUCKUS IP HOLDINGS LLC
  • US10182350B2 patent drawing
  • US10182350B2 patent drawing

AI summary

Systems and methods for providing secured network access are provided. A user device located within range of a branded hotspot initiates a request for the secured network access. The request concerns secured network access at the hotspot by the user device and includes a unique pre-shared key. A query regarding the unique pre-shared key is sent to a database, which retrieves information regarding a corresponding pre-shared key. That information is sent to the hotspot controller, which allows the user device secured network access as governed by one or more parameters associated with the pre-shared key.