Wi-Fi Access Control via Two-Step Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Wi-Fi network guest access methods are inadequate for small and medium-sized businesses, as they require complex management and do not offer granular control over user access, leading to security and operational challenges.

Innovation Solution

Implementing a two-step and two-party control system with multiple access zones, using a single SSID with multiple passwords to provide granular access control, where user devices are initially placed in a holding area for administrator approval, and allowing pin holing for access to specific resources across zones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional guest access methods are used with separate SSID and password, then guest devices can connect to the Wi-Fi network, but the system complexity increases and granular access control is lost

Engineering Contradiction:
ImproveGuest access setupVSAvoidNetwork configuration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the guest access functionality into the main Wi-Fi network by using a single SSID for both main and guest devices. Instead of maintaining separate SSIDs for different user types, the system uses a unified network identifier that all devices join, then applies access control rules based on device authorization status rather than network segmentation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary access control system that mediates between guest devices and network resources. This intermediary layer implements the two-step authorization process where devices first connect to the SSID and then undergo credential verification, acting as a mediator that enables granular control without requiring separate network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprise Wi-Fi systems are deployed for business networks, then security and access control are improved, but the management complexity and IT requirements increase significantly

Engineering Contradiction:
ImproveNetwork securityVSAvoidSystem management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service capabilities where guest devices can autonomously complete the authorization process by providing credentials through web browsers or mobile devices. The system automatically verifies credentials, establishes authorization status, and configures access rules without requiring manual IT intervention for each connection event, thereby reducing management overhead while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the control parameter from network-level segmentation (separate SSIDs) to device-level authorization parameters. By implementing two-step authorization with credential verification, the system transitions from static network configuration to dynamic device-specific access control, achieving enterprise-grade security with simpler infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If full access is granted to connected devices on the Wi-Fi network, then user convenience is maximized, but security risks and unauthorized access increase

Engineering Contradiction:
ImproveUser connectivityVSAvoidUnauthorized network access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authorization verification before granting full network access. The two-step process requires devices to first connect to the SSID and then complete credential verification through a web portal or mobile interface. This preliminary action of credential checking ensures that only authorized devices receive full access privileges, preventing unauthorized access while maintaining user convenience for legitimate devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different access qualities to different devices on the same network. Instead of uniform access rules, the system implements device-specific authorization levels where main devices receive full access and guest devices receive limited access based on credential verification results. This local quality approach allows granular control over which devices can access specific network resources while maintaining overall network connectivity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11496902B2Access to Wi-Fi networks via two-step and two-party control
Publication Date: 2022.11.08 PLUME DESIGN INC
  • US11496902B2 patent drawing
  • US11496902B2 patent drawing
  • US11496902B2 patent drawing

AI summary

Systems and methods include, responsive to a Wi-Fi client device providing a password for a zone of a Wi-Fi network, determining a status of the Wi-Fi client device; when the status is unknown, placing the client device in a holding area associated with the zone, wherein the client device is connected to the Wi-Fi network while in the holding area and has restricted access that is less than full access to the zone in an allowed zone; responsive to placing the client device in the holding area, causing a notification to an administrator that the client device is in the holding area; and with the client device in the holding area, one of moving the Wi-Fi client device to the allowed area, moving the client device to a rejected area for the zone, and leaving the client device in the holding zone, based on any input or lack thereof.