Secure Multi-Access Point Onboarding Through DPP Channel Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless LAN systems face challenges with narrow communication coverage and shadow areas due to the limited range of individual access points, necessitating the integration of multiple access points to enhance coverage, but current onboarding methods are vulnerable to security risks and require user intervention.

Innovation Solution

A method for onboarding an access point into a multiple access point network using a device provisioning protocol (DPP) that enables secure link establishment without additional security processes, allowing the controller to transmit and receive DPP messages on specified channels, and includes features like bootstrap public key management and channel information exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If multiple access points are integrated to enhance coverage, then communication coverage is improved, but security vulnerabilities increase due to complex onboarding requirements

Engineering Contradiction:
Improvecommunication coverageVSAvoidsecurity
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The onboarding system enables access points to automatically authenticate and join the network without manual user intervention. The controller automatically generates DPP messages, manages bootstrap public keys, and establishes secure links, allowing the system to self-configure and eliminate human error in the onboarding process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A central controller acts as an intermediary between access points and the network. The controller manages the onboarding process by transmitting DPP messages to enrollee access points, verifying bootstrap public keys, and establishing secure links, thereby centralizing security management and reducing vulnerabilities in multi-AP environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional onboarding methods are used, then user intervention is required for security, but onboarding efficiency decreases due to manual processes

Engineering Contradiction:
ImprovesecurityVSAvoidonboarding efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements automated onboarding where access points independently complete the provisioning process. The enrollee access point receives DPP messages from the controller, automatically processes bootstrap public key verification, and establishes secure links without requiring user input, thereby maintaining security while dramatically improving onboarding efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The controller performs preliminary security setup by generating and transmitting DPP messages containing bootstrap public key information before the access point joins the network. This pre-configuration ensures security credentials are established in advance, enabling rapid automated onboarding without compromising security protocols.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If additional security processes are implemented for multi-AP onboarding, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The controller performs multiple security functions through a unified DPP message exchange mechanism. It generates authentication credentials, manages bootstrap public keys, establishes secure links, and provisions access points all through the same standardized DPP protocol, eliminating the need for multiple separate security processes and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines authentication, key management, and link establishment into a single integrated DPP onboarding process. The controller transmits comprehensive DPP messages that simultaneously handle multiple security tasks, merging what would traditionally be separate security processes into one streamlined operation that reduces complexity while maintaining robust security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250220615A1Method for onboarding in multiple access point network and access point using same
Publication Date: 2025.07.03 WILUS INSTITUTE OF STANDARDS & TECHNOLOGY INC
  • US20250220615A1 patent drawing
  • US20250220615A1 patent drawing
  • US20250220615A1 patent drawing

AI summary

Disclosed is an access point, which is a registrant desiring to register with a multiple access point network. A wireless communication terminal comprises: a transmitting and receiving unit for transmitting and receiving a wireless signal; and a processor for processing the wireless signal. The processor receives a first device provisioning protocol (DPP) message from a controller of the multiple access point network when the access point is onboarding to the multiple access point network by using a DPP, obtains, from the first DPP message, information on a channel on which the DPP is performed, and transmits a second DPP message to the controller in the channel indicated by the information on the channel.