Wi-Fi Network Micro-Segmentation Using Group Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network segmentation techniques are inadequate for Wi-Fi networks, lacking effective methods to divide and isolate traffic and devices into secure, manageable groups, which leads to resource inefficiencies and security vulnerabilities.
Innovation Solution
Implementing a method that assigns client devices to specific multicast groups based on description data, using group keys for encrypted communication within these groups, allowing for micro-segmentation across Wi-Fi networks, even across different SSIDs, thereby controlling and securing multicast traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network segmentation is implemented on wired networks using segment identifier metadata, then security and performance are improved, but Wi-Fi networks lack effective segmentation options
Solution Approach 1:
The patent divides the Wi-Fi network into multiple virtual groups using broadcast/multicast group identifiers. Each group is assigned a unique identifier and encrypted with a specific group key, allowing network traffic to be segmented into isolated segments similar to wired network segmentation, thereby improving security and performance on wireless networks.
Solution Approach 2:
The access point acts as an intermediary that receives description data from client devices, assigns them to appropriate broadcast/multicast groups, and distributes the corresponding group keys. This intermediary function enables automated group assignment and key distribution, making the segmentation system adaptable to various Wi-Fi scenarios.
2Area of stationary object
If all client devices on the same SSID can access multicast traffic, then network coverage is maximized, but security and resource utilization deteriorate
Solution Approach 1:
Instead of providing uniform access to all clients on an SSID, the patent assigns different broadcast/multicast groups and encryption keys to different clients based on their description data. This allows each client to receive only the multicast traffic relevant to its group, reducing unnecessary traffic processing and improving network resource utilization while maintaining full coverage.
3Reliability
If broadcast/multicast traffic is transmitted to all connected devices, then message delivery is ensured, but security and targeted delivery deteriorate
Solution Approach 1:
The patent changes the encryption parameter by assigning unique group keys to different broadcast/multicast groups. Clients decrypt received traffic using their assigned group key, ensuring that only authorized members of each group can access the traffic. This maintains reliable delivery within groups while preventing unauthorized access across groups.
Data Source
AI summary
Embodiments herein describe segmenting a Wi-Fi network into different groups. The embodiments herein assign a user, a client device, or a traffic flow originating from a client device to a group. For example, all the client devices for a particular user can be assigned to the same group tag, or each traffic flow in the client device may be assigned to different groups. Each group corresponds to a group key which can be transmitted to the client device when the device associates to an access point (AP). As such, within the same service set identifier (SSID), there can be multiple groups, and thus, client devices can use different group keys to communicate with other client devices associated to the same SSID. Put differently, rather than all devices connected the same SSID being assigned to the same group, the client devices can be assigned in different groups.


