Wireless Access Point Mediator for Secure Network Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing secure connections between multiple wireless communication devices and a trusted network is cumbersome and time-consuming, requiring individual provisioning and configuration of each device.
Innovation Solution
A device and method that broadcast a non-trusted SSID with WLAN link layer security, establish a connection to a LAN, and then switch to a trusted SSID with WPA2-Enterprise or WPA2-Personal security, using an AAA server for authentication and routing via RADIUS protocol, allowing multiple devices to connect securely to a trusted network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual provisioning and configuration is performed for each wireless communication device to establish secure connection to trusted network, then security reliability is improved, but device complexity and user effort increase
Solution Approach 1:
The patent introduces an intermediary device (access point or router) that acts as a mediator between wireless communication devices and the trusted network. This intermediary automatically handles the complex provisioning and configuration tasks, including establishing secure connections via SSL/IPSEC clients, while simpler devices only need to connect to the intermediary's network. This resolves the contradiction by maintaining security reliability through proper authentication mechanisms while reducing configuration complexity to basic network connection.
Solution Approach 2:
The intermediary device performs multiple functions: it provides wireless network access, handles secure connection establishment to trusted networks, manages authentication, and routes traffic. By consolidating these functions into a single device that can serve multiple wireless communication devices simultaneously, the system achieves both security reliability and reduced device complexity.
2Reliability
If manual provisioning and configuration is performed for each wireless communication device, then connection security is ensured, but time consumption increases
Solution Approach 1:
The intermediary device performs preliminary actions by pre-configuring secure connection parameters, authentication credentials, and routing information before wireless communication devices need to connect. The system establishes secure tunnels to trusted networks in advance, so when devices connect to the intermediary, they inherit these pre-configured secure connections without requiring manual provisioning. This ensures connection security while dramatically reducing configuration time to mere seconds for basic network connection.
3Reliability
If each wireless communication device runs its own SSL or IPSEC client to establish secure connection, then authentication reliability is improved, but ease of operation deteriorates
Solution Approach 1:
The intermediary device assumes the role of running SSL/IPSEC clients and handling authentication protocols, eliminating the need for end-user devices to manage complex secure connection software. Users simply connect to the intermediary's wireless network using basic credentials, while the intermediary handles the sophisticated authentication and secure tunnel establishment to trusted networks, maintaining authentication reliability while greatly simplifying user operation.
Solution Approach 2:
The intermediary device provides self-service functionality where it automatically handles all authentication and secure connection tasks without requiring user intervention. The system presents a simplified interface where users only need to provide basic network access credentials, while the intermediary autonomously manages SSL/IPSEC client operations, certificate validation, and traffic routing, thus maintaining authentication reliability while maximizing ease of operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure provides a device, method, and system for enabling multiple wireless communication devices to communicate with a trusted network over a secure connection. The device includes a communication interface configured to communicate with the wireless communication devices and local area networks (LANs) and a processor configured to: broadcast a non-trusted service set identifier (SSID); in response to detecting a non-secure connection to a wireless communication device of the wireless communication devices using the non-trusted SSID, establish a connection to a local area network (LAN) of the LANs. In response to establishing a connection to the LAN: the processor establishes a secure connection to the trusted network; discontinues broadcast of the non-trusted SSID; and broadcasts a trusted SSID to the wireless communication devices to enable the wireless communication devices to wirelessly connect to the network device to communicate with the trusted network using the secure connection.