PSK Management for Multi-Tenant Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing wireless network access in multi-dwelling units (MDUs) is challenging due to the need for efficient key management, security, and seamless connectivity across shared areas, with existing solutions like mPSK being computationally expensive and vulnerable to DoS attacks, and not compatible with newer standards like WPA3.

Innovation Solution

The implementation of pre-shared key management logic that allows for the assignment and control of multiple PSKs per unit/tenant using a single SSID, with innovative methods such as Vendor-Specific Information Element (VSIE) and EAPOL-key Frame to reduce search space and enhance security, and the use of location-based and Li-Fi enabled solutions for accurate PSK association.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple PSKs are managed per unit/tenant using traditional mPSK methods, then wireless network access can be provided to multiple tenants, but the system becomes computationally expensive and vulnerable to DoS attacks

Engineering Contradiction:
Improvewireless network access managementVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the key management system by introducing a network controller that centralizes PSK management, separating the authentication logic from individual access points. This allows multiple PSKs to be managed efficiently without each AP bearing the full computational burden, resolving the contradiction between providing versatile multi-tenant access and reducing key management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network controller acts as an intermediary between tenants and the wireless network infrastructure. It handles PSK assignment, validation, and management, reducing the computational load on individual APs and protecting the system from DoS attacks by filtering and managing authentication requests centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If traditional PSK management is used, then implementation is simpler, but join latency increases and onboarding overhead is significant

Engineering Contradiction:
Improveimplementation simplicityVSAvoidjoin latency
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-assigning PSKs to tenants before they attempt to connect to the network. The network controller maintains a database of assigned PSKs and their associated policies, so when a tenant device attempts to join, authentication is immediate rather than requiring real-time key generation or search, significantly reducing join latency while maintaining implementation simplicity.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If a single SSID is used for the entire property, then seamless connectivity across shared areas is achieved, but security and policy control per unit/tenant becomes difficult

Engineering Contradiction:
Improveconnectivity seamlessnessVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by associating different PSKs with specific geographical zones or units within the property. Each PSK has localized policies that control access to specific areas or resources. This allows a single SSID to provide seamless connectivity while maintaining granular security control, as the network controller enforces location-specific policies based on which PSK is being used.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11627464B2Grouping users by pre-shared key (PSK) in hospitality
Publication Date: 2023.04.11 CISCO TECHNOLOGY INC
  • US11627464B2 patent drawing
  • US11627464B2 patent drawing
  • US11627464B2 patent drawing

AI summary

Presented herein are techniques to manage a wireless local area network. A method includes defining a plurality of geographical zones corresponding to a geographical area that is serviced by a common service set identifier for a wireless local area network, assigning a pre-shared key to a mobile station based on the plurality of geographical zones, wherein the pre-shared key is associated with predetermined policies for a user of the mobile station, associating a media access control address of the mobile station with the pre-shared key, and controlling access of the mobile station to the wireless local area network based on the predetermined policies.