Wireless Access Point Mediator for Secure Network Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing secure connections between multiple wireless communication devices and a trusted network is cumbersome and time-consuming, requiring individual provisioning and configuration of each device.

Innovation Solution

A device and method that broadcast a non-trusted SSID with WLAN link layer security, establish a connection to a LAN, and then switch to a trusted SSID with WPA2-Enterprise or WPA2-Personal security, using an AAA server for authentication and routing via RADIUS protocol, allowing multiple devices to connect securely to a trusted network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual provisioning and configuration is performed for each wireless communication device to establish secure connection to trusted network, then security reliability is improved, but device complexity and user effort increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary device (access point or router) that acts as a mediator between wireless communication devices and the trusted network. This intermediary automatically handles the complex provisioning and configuration tasks, including establishing secure connections via SSL/IPSEC clients, while simpler devices only need to connect to the intermediary's network. This resolves the contradiction by maintaining security reliability through proper authentication mechanisms while reducing configuration complexity to basic network connection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intermediary device performs multiple functions: it provides wireless network access, handles secure connection establishment to trusted networks, manages authentication, and routes traffic. By consolidating these functions into a single device that can serve multiple wireless communication devices simultaneously, the system achieves both security reliability and reduced device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If manual provisioning and configuration is performed for each wireless communication device, then connection security is ensured, but time consumption increases

Engineering Contradiction:
Improveconnection securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The intermediary device performs preliminary actions by pre-configuring secure connection parameters, authentication credentials, and routing information before wireless communication devices need to connect. The system establishes secure tunnels to trusted networks in advance, so when devices connect to the intermediary, they inherit these pre-configured secure connections without requiring manual provisioning. This ensures connection security while dramatically reducing configuration time to mere seconds for basic network connection.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If each wireless communication device runs its own SSL or IPSEC client to establish secure connection, then authentication reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The intermediary device assumes the role of running SSL/IPSEC clients and handling authentication protocols, eliminating the need for end-user devices to manage complex secure connection software. Users simply connect to the intermediary's wireless network using basic credentials, while the intermediary handles the sophisticated authentication and secure tunnel establishment to trusted networks, maintaining authentication reliability while greatly simplifying user operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intermediary device provides self-service functionality where it automatically handles all authentication and secure connection tasks without requiring user intervention. The system presents a simplified interface where users only need to provide basic network access credentials, while the intermediary autonomously manages SSL/IPSEC client operations, certificate validation, and traffic routing, thus maintaining authentication reliability while maximizing ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3177101B1Device and method for enabling multiple wireless communication devices to communicate with a trusted network via a secure connection
Publication Date: 2018.07.25 BLACKBERRY LTD
  • EP3177101B1 patent drawingFigure 1
  • EP3177101B1 patent drawingFigure 2
  • EP3177101B1 patent drawingFigure 3

AI summary

The present disclosure provides a device, method, and system for enabling multiple wireless communication devices to communicate with a trusted network over a secure connection. The device includes a communication interface configured to communicate with the wireless communication devices and local area networks (LANs) and a processor configured to: broadcast a non-trusted service set identifier (SSID); in response to detecting a non-secure connection to a wireless communication device of the wireless communication devices using the non-trusted SSID, establish a connection to a local area network (LAN) of the LANs. In response to establishing a connection to the LAN: the processor establishes a secure connection to the trusted network; discontinues broadcast of the non-trusted SSID; and broadcasts a trusted SSID to the wireless communication devices to enable the wireless communication devices to wirelessly connect to the network device to communicate with the trusted network using the secure connection.