Wireless Network Provisioning Using Pre-Shared Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network provisioning methods using pre-shared keys (PSKs) face challenges in managing access for multiple users, particularly in shared networks like apartment complexes or hotels, where a single PSK can lead to security issues and cumbersome access management.

Innovation Solution

The implementation of a system that creates multiple wireless network access profiles with unique PSKs, where an access point receives a value based on the PSK and transmits it to a provisioning system to match with pre-calculated values, thereby granting network access without transmitting the PSK directly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a single pre-shared key (PSK) is used across multiple users in a shared wireless network, then ease of network provisioning is improved, but security is worsened and access management becomes cumbersome

Engineering Contradiction:
Improveease of network provisioningVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the single PSK into multiple unique PSKs, one for each user or device. The access point stores multiple PSKs in a database, and each wireless device is assigned its own PSK during provisioning. This segmentation maintains ease of provisioning (the system automatically manages the multiple keys) while improving security (each user has a unique key that cannot be used to decrypt other users' traffic).

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If a single pre-shared key (PSK) is used across multiple users, then ease of network provisioning is improved, but access management flexibility is worsened

Engineering Contradiction:
Improveease of network provisioningVSAvoidaccess management flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access management where the system can automatically add, remove, or modify user access rights without manual intervention. When a user checks out of a hotel or leaves an apartment, the provisioning system automatically revokes their PSK, and the access point stops accepting connections with that key. This dynamic approach provides flexibility in access management while maintaining ease of provisioning through automated processes.

Inventive Principle:
Principle #15Dynamics

3Reliability

If manual whitelisting or blacklisting of MAC addresses is implemented, then access control is improved, but device complexity and operational burden are worsened

Engineering Contradiction:
Improveaccess controlVSAvoidoperational burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service system where the provisioning database automatically manages access control. When a user is provisioned, the system automatically adds their MAC address to the whitelist and assigns them a PSK. When a user is removed, the system automatically blacklists their MAC address and revokes their PSK. This self-service approach maintains reliable access control while eliminating the manual operational burden of administrators having to individually whitelist or blacklist MAC addresses.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250150824A1Wireless network provisioning using a pre-shared key
Publication Date: 2025.05.08 DISH NETWORK LLC
  • US20250150824A1 patent drawing
  • US20250150824A1 patent drawing
  • US20250150824A1 patent drawing

AI summary

Various arrangements for wireless network provisioning using a pre-shared key (PSK) are presented. Wireless network access profiles that indicate PSKs may be stored. An access point may receive, from a wireless device, a value based on the PSK, which is then transmitted to a provisioning system. Values based on the PSKs of the wireless network access profiles can be created and a match with the transmitted value can be identified. Data is provided to the access point based on the PSK of the wireless network access profile. Network access can then be granted.