Automatic Wi-Fi Subscriber Onboarding via AAA Server Key Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale Wi-Fi deployments face challenges in efficiently and securely provisioning and managing user credentials, particularly in public deployments where subscriber presence is dynamic, as traditional manual methods become unsustainable and compromise security.

Innovation Solution

The implementation of a mechanism that automatically provisions a private pre-shared key to an AAA server using a social login application, enabling secure and automatic onboarding of subscribers by generating a unique private pre-shared key for each client device, which is then used to securely update the AAA server's database, allowing access to the Wi-Fi network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional manual provisioning techniques are used to configure user credentials, then security can be maintained through controlled credential distribution, but the complexity and time required for provisioning increases significantly as subscriber base grows

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automatic self-provisioning where subscriber devices automatically obtain credentials through authentication with the AAA server without manual administrator intervention. The device autonomously generates service set identifiers and pre-shared keys, eliminating manual provisioning complexity while maintaining security through controlled automatic credential distribution.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The AAA server pre-configures credential templates and authentication policies before subscriber devices connect. When a device authenticates, the server automatically provisions credentials based on pre-established security policies, eliminating the need for manual credential configuration while ensuring security requirements are met from the outset.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual provisioning methods are used for large subscriber bases, then credential security can be controlled, but the time and resources required for provisioning and maintaining credentials become unsustainable

Engineering Contradiction:
Improvecredential securityVSAvoidprovisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Subscriber devices automatically authenticate with the AAA server and receive credentials without administrator intervention. The system handles credential generation, distribution, and renewal automatically, enabling the provisioning of large numbers of subscribers efficiently while maintaining security through centralized AAA server control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The AAA server pre-establishes security policies and credential templates that are automatically applied when devices authenticate. This preliminary configuration enables rapid provisioning of large subscriber bases while ensuring consistent security requirements are met for all credentials.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automatic credential provisioning is implemented to improve efficiency, then provisioning speed increases, but the risk of unauthorized access and security vulnerabilities increases

Engineering Contradiction:
Improveprovisioning speedVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The AAA server acts as an intermediary between subscriber devices and the Wi-Fi network. It mediates the authentication process by verifying device credentials, generating secure pre-shared keys, and controlling network access policies. This intermediary role enables automatic provisioning while maintaining security through centralized controlled credential distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system pre-configures security policies and authentication rules in the AAA server before devices connect. Automatic credential provisioning occurs only after successful authentication against these pre-established security criteria, ensuring that speed gains from automation do not compromise security through unauthorized access.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If traditional provisioning methods are used in public Wi-Fi deployments with dynamic subscriber presence, then security control can be maintained, but the ability to scale and adapt to dynamic environments deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidadaptability to dynamic environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically provisions credentials based on real-time authentication events. When devices connect to the public Wi-Fi network, the AAA server automatically generates and distributes credentials without manual intervention. This dynamic automatic provisioning enables the network to adapt to changing subscriber presence while maintaining security through centralized controlled credential distribution.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Subscriber devices in dynamic public environments automatically authenticate and receive credentials from the AAA server without administrator intervention. This self-service capability enables the system to adapt to dynamic subscriber presence while maintaining security through automated controlled credential distribution based on authentication status.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11051168B2Providing secure access for automatically on-boarded subscribers in Wi-Fi networks
Publication Date: 2021.06.29 CISCO TECHNOLOGY INC
  • US11051168B2 patent drawing
  • US11051168B2 patent drawing
  • US11051168B2 patent drawing

AI summary

A default pre-shared key is provided from a first device to a second device. The first device is configured to control network access to a network. A first authentication request is obtained at the first device from a third device. The first authentication request includes data indicative of the second device. A first response to the first authentication request is provided from the first device to the third device. The first response includes the default pre-shared key. A second authentication request containing a private pre-shared key and the data indicative of the second device is obtained at the first device from the third device. Stored data at the first device is updated in response to the second authentication request with the private pre-shared key and the data indicative of the second device to provision the first device to provide network access to the network to the second device.