Tenant SSID Provisioning for Time-Limited WLAN Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current WLAN systems do not provide efficient methods for hosts to manage tenant service set identifiers (SSIDs) of specified duration and distributed authorization, leading to burdensome manual processes and potential security threats in shared use spaces like homestays and shared offices.
Innovation Solution
A network management system comprising a network controller, WLAN controller, and AAA servers provisions SSIDs in access points to grant temporary network access to guests, generating instructions for activation and deactivation, and using Pre-Shared Keys for secure, time-limited access, enabling primary guest devices to authorize secondary devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual SSID management is used, then hosts can provide network access to guests, but the process becomes burdensome and creates security threats
Solution Approach 1:
The system enables self-service through automated SSID provisioning where guests can obtain network access credentials automatically without manual host intervention. The host simply defines access policies and duration parameters, while the system automatically generates, distributes, and manages SSIDs for multiple guests throughout their authorized time periods.
Solution Approach 2:
The system performs preliminary actions by pre-configuring SSID generation rules, access policies, and duration parameters in advance. The host sets up the authorization framework beforehand, and the system automatically executes SSID creation and distribution when guests need access, eliminating last-minute manual configuration.
2Adaptability or versatility
If SSIDs with indefinite durations are used, then guests can access the network, but hosts must manually deactivate SSIDs to prohibit access
Solution Approach 1:
The system implements dynamic SSID management where each SSID is automatically configured with a specific duration parameter. The system continuously monitors time and automatically deactivates SSIDs when their authorized duration expires, transforming the static, manual process into a dynamic, automated system that adapts to each guest's specific time requirements.
Solution Approach 2:
The system changes the critical parameter of SSID duration from indefinite to fixed and configurable. By introducing duration as a controllable parameter that can be set for each SSID, the system enables precise control over network access time periods, automatically managing the entire lifecycle from creation to deactivation based on the specified duration.
3Ease of operation
If hosts manually create and distribute new SSIDs for each guest, then access can be granted, but errors can pose serious security threats
Solution Approach 1:
The system replaces the manual mechanical process of SSID creation and distribution with an automated computational system. Instead of hosts manually configuring each SSID, the system automatically generates SSIDs according to predefined policies, eliminating human errors in configuration, distribution, and management while maintaining ease of guest access provisioning.
Data Source
AI summary
Systems and methods provide for provisioning network access using a tenant service set identifier (SSID) or an SSID of a specified duration and distributed authorization. A network management system can provision a wireless local area network (WLAN) and the SSID in an access point to enable a primary guest device to access the WLAN for a specified time period (e.g., a start time and end time). The network management system can cause the SSID and authentication data (e.g., authentication token, Pre-Shared Key (PSK), etc.) to be transmitted for receipt by the first client device. After the start time and in response to successfully authenticating the first client device, the first client device can authorize a second client device to access the WLAN. The network management system or the AP can disable access to the network via the SSID at the end time.


