Virtual Access Point Guest Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless network access points face security vulnerabilities when providing guest access, as distributing a single password compromises network security, as it is not device-specific and can be widely distributed, leading to unauthorized access.

Innovation Solution

Establishing a virtual access point with a unique password associated with a guest device's identifier, such as a MAC address, allowing only approved devices to access the network without revealing the main network password.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single shared key password is used for network access, then ease of operation is improved (guests can easily connect), but network security deteriorates (password can be widely distributed and compromised)

Engineering Contradiction:
Improveease of guest accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the single shared key into multiple individual passwords, each assigned to a specific guest device. Instead of one password serving all guests, the system creates separate authentication credentials for each device, thereby maintaining ease of access while preventing widespread password distribution and enhancing network security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making each password device-specific rather than universally applicable. Each guest device receives a unique password tied to its identifier, so the security property varies locally for each device rather than being uniform across all guests. This ensures that compromise of one password does not affect others.

Inventive Principle:
Principle #3Local quality

2Reliability

If periodic password changes are implemented, then network security is improved (reduces risk of compromised passwords), but loss of time increases (password must be re-distributed to guests)

Engineering Contradiction:
Improvenetwork securityVSAvoidtime for password redistribution
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By segmenting the password system into individual device-specific credentials, the patent eliminates the need for periodic mass password changes. Each guest device has its own password that remains valid, so administrators don't need to redistribute passwords periodically, saving time while maintaining security through initial device-specific assignment.

Inventive Principle:
Principle #1Segmentation

3Reliability

If guest accounts with separate passwords are created, then network security is improved (main password is protected), but device complexity increases (requires additional SSIDs or access points)

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functionality of multiple virtual access points into a single physical access point. By creating virtual APs within the existing hardware, the system provides separate passwords for different guests without requiring additional physical access points or complex hardware configuration, thus improving security while minimizing device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces virtual access points as intermediaries between the physical access point and guest devices. These virtual APs act as mediators that provide device-specific passwords and authentication, simplifying the configuration by avoiding the need for multiple physical access points while still achieving enhanced security through individualized password management.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If virtual access points with device-specific passwords are established, then network security is improved (only authorized devices can access), but device complexity increases (requires virtual AP management)

Engineering Contradiction:
Improvenetwork securityVSAvoidvirtual access point management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the access point to automatically generate and manage device-specific passwords based on guest device identifiers. The system autonomously creates virtual access points and assigns unique passwords without requiring manual configuration for each guest, thereby improving security through device-specific authentication while reducing the complexity of virtual AP management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3080963B1Methods, devices and systems for dynamic network access administration
Publication Date: 2017.12.20 QUALCOMM INC
  • EP3080963B1 patent drawingFigure 1A~1B
  • EP3080963B1 patent drawingFigure 1C
  • EP3080963B1 patent drawingFigure 2A

AI summary

Methods and devices for providing access to a wireless network through a network access point secured with a network password may include receiving a request to provide access to the wireless network for a device on the network access point. A virtual access point may be established to provide access to the wireless network for the device in response to receiving the request to provide access for the device on the network access point. A virtual access point password may be established for the device and associated with a unique identifier of the device. The virtual access point password may be different from the network password. The device may be provided with access to the network when an entered password matches the virtual access point password and the device identifier matches the unique identifier of the device associated with the virtual access point password.