Wi-Fi Access Point Guest Network Segmentation via Multi-Key Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Wi-Fi networks face challenges in providing controlled guest access, as they often require separate SSIDs and passwords, limiting the ability to offer selective access to devices or resources and complicating network management.

Innovation Solution

Implementing a single SSID with multiple passwords or certificates that define access zones, using Software Defined Networking (SDN) and a cloud-based controller to manage access rules, allowing granular control over traffic, time, location, and device access, and providing a captive portal for users to request access to restricted services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a separate SSID is used for guest access, then guest users can be provided access to the Wi-Fi network, but the network management complexity increases and selective access control to specific devices or resources cannot be implemented

Engineering Contradiction:
Improveguest access capabilityVSAvoidnetwork management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges guest access and main network access into a single SSID, eliminating the need for separate SSIDs. Different access levels are implemented through multiple passwords or certificates associated with the same SSID, where each password/certificate defines specific access zones and permissions. This consolidation reduces network management complexity while maintaining the ability to provide controlled guest access.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If a separate SSID is used for guest access, then guest users can connect to the network, but selective access to specific devices or resources on the main network cannot be controlled

Engineering Contradiction:
Improveselective access controlVSAvoidaccess control mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by associating different passwords or certificates with specific access zones within the network. Each password/certificate grants access to particular devices or resources based on predefined rules, allowing granular control over what guest users can access. This enables selective access control where different portions of the network have different access permissions tied to specific authentication credentials.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If multiple SSIDs are used for different user types, then access control can be implemented, but the number of SSIDs and passwords increases making the system more complex

Engineering Contradiction:
Improveaccess control implementationVSAvoidnumber of SSIDs and passwords
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes the single SSID universal by enabling it to serve multiple user types (guests and main network users) simultaneously. Instead of creating separate SSIDs for different user categories, the system allows the same SSID to accept multiple passwords or certificates, each with different access permissions. This multi-functional approach simplifies the system by reducing the number of SSIDs while maintaining comprehensive access control capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20230284024A1Controlled guest access to wi-fi networks
Publication Date: 2023.09.07 PLUME DESIGN INC
  • US20230284024A1 patent drawing
  • US20230284024A1 patent drawing
  • US20230284024A1 patent drawing

AI summary

A Wi-Fi network includes one or more access point devices configured to connect to one or more devices; wherein the Wi-Fi network is designated by a Service Set Identifier (SSID); wherein each Wi-Fi client device accesses the Wi-Fi network using the SSID and a key of a plurality of keys each being a password or certificate for the Wi-Fi network; and wherein each of the plurality of keys designates an access zone of a plurality of access zones each defining rules for network and/or device access such that the one or more access point devices provide selective access based on which of the plurality of keys is used for each of the one or more devices.