Wi-Fi Network Micro-Segmentation Using Group Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network segmentation techniques are inadequate for Wi-Fi networks, lacking effective methods to divide and isolate traffic and devices into secure, manageable groups, which leads to resource inefficiencies and security vulnerabilities.

Innovation Solution

Implementing a method that assigns client devices to specific multicast groups based on description data, using group keys for encrypted communication within these groups, allowing for micro-segmentation across Wi-Fi networks, even across different SSIDs, thereby controlling and securing multicast traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network segmentation is implemented on wired networks using segment identifier metadata, then security and performance are improved, but Wi-Fi networks lack effective segmentation options

Engineering Contradiction:
Improvenetwork securityVSAvoidsegmentation applicability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the Wi-Fi network into multiple virtual groups using broadcast/multicast group identifiers. Each group is assigned a unique identifier and encrypted with a specific group key, allowing network traffic to be segmented into isolated segments similar to wired network segmentation, thereby improving security and performance on wireless networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point acts as an intermediary that receives description data from client devices, assigns them to appropriate broadcast/multicast groups, and distributes the corresponding group keys. This intermediary function enables automated group assignment and key distribution, making the segmentation system adaptable to various Wi-Fi scenarios.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Area of stationary object

If all client devices on the same SSID can access multicast traffic, then network coverage is maximized, but security and resource utilization deteriorate

Engineering Contradiction:
Improvenetwork coverageVSAvoidnetwork resource utilization
Core Design Contradiction:
Area of stationary objectVSLoss of energy

Solution Approach 1:

Instead of providing uniform access to all clients on an SSID, the patent assigns different broadcast/multicast groups and encryption keys to different clients based on their description data. This allows each client to receive only the multicast traffic relevant to its group, reducing unnecessary traffic processing and improving network resource utilization while maintaining full coverage.

Inventive Principle:
Principle #3Local quality

3Reliability

If broadcast/multicast traffic is transmitted to all connected devices, then message delivery is ensured, but security and targeted delivery deteriorate

Engineering Contradiction:
Improvemessage deliveryVSAvoidinformation dissemination security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the encryption parameter by assigning unique group keys to different broadcast/multicast groups. Clients decrypt received traffic using their assigned group key, ensuring that only authorized members of each group can access the traffic. This maintains reliable delivery within groups while preventing unauthorized access across groups.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10944734B2Creating secure encrypted broadcast/multicast groups over wireless network
Publication Date: 2021.03.09 CISCO TECHNOLOGY INC
  • US10944734B2 patent drawing
  • US10944734B2 patent drawing
  • US10944734B2 patent drawing

AI summary

Embodiments herein describe segmenting a Wi-Fi network into different groups. The embodiments herein assign a user, a client device, or a traffic flow originating from a client device to a group. For example, all the client devices for a particular user can be assigned to the same group tag, or each traffic flow in the client device may be assigned to different groups. Each group corresponds to a group key which can be transmitted to the client device when the device associates to an access point (AP). As such, within the same service set identifier (SSID), there can be multiple groups, and thus, client devices can use different group keys to communicate with other client devices associated to the same SSID. Put differently, rather than all devices connected the same SSID being assigned to the same group, the client devices can be assigned in different groups.