Wireless Network Authentication via Pre-Shared Key User Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managed wireless networks require individual configuration and identification of each device for network policies, which is cumbersome for nontechnical users and inefficient, especially when device-identifying information like MAC addresses change frequently.
Innovation Solution
A network system that uses a unique pre-shared key (PSK) mapped to a user profile, allowing devices to connect without registering individually, with the PSK encrypting and decrypting data and determining network access policies based on user identity rather than device information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device-level authentication using MAC addresses is implemented, then network policies can be applied to individual devices, but nontechnical users cannot connect their devices independently and require technical assistance
Solution Approach 1:
The patent introduces a portal server as an intermediary between users and the network authentication system. The portal server provides a web-based interface that guides nontechnical users through the authentication process, eliminating the need for users to directly handle MAC addresses or configuration commands. The portal server translates user-friendly interactions into the technical authentication requirements of the network system.
Solution Approach 2:
The system enables users to autonomously connect their devices through a self-service portal interface. Users can independently obtain their device's MAC address, access the portal server through a web browser, and complete authentication without requiring technical support personnel. The system automatically processes the authentication and applies appropriate network policies.
2Reliability
If individual device registration is required for network policies, then network security and policy control are maintained, but the configuration process becomes cumbersome and time-consuming
Solution Approach 1:
The system performs preliminary actions by automatically gathering device information (MAC address) and preparing authentication credentials before the user needs to connect. The portal server pre-configures the authentication process, retrieves necessary device identifiers, and sets up the connection parameters in advance, so users only need to follow simple on-screen instructions rather than performing complex configuration steps.
Solution Approach 2:
The automated portal system eliminates manual configuration steps by automatically extracting MAC addresses, validating device information, and applying network policies without requiring user intervention in technical processes. This self-service approach maintains security controls while dramatically reducing the time and effort users must invest in the configuration process.
3Measurement precision
If MAC addresses are used for device identification, then individual device tracking is possible, but MAC addresses may change frequently causing connection issues
Solution Approach 1:
The portal server acts as an intermediary that manages the relationship between device identifiers and network authentication. Instead of relying directly on MAC addresses as the primary identification mechanism, the portal server provides a stable interface that can accommodate MAC address changes. The system captures and stores device identifiers through the portal, creating a more resilient identification system that can handle identifier changes without breaking connections.
Data Source
AI summary
A network system includes a processor and memory encoded with instructions that, when executed, cause the system to receive an offered pre-shared key from a wireless device via a wireless network; access a mapped key-user pair comprising a unique pre-shared key and a user profile; and determine whether the offered pre-shared key corresponds to the unique pre-shared key. The instructions further permit the wireless device to connect to the wireless network according to a network policy associated with the mapped key-user pair in response to determining that the offered pre-shared key corresponds to the unique pre-shared key, or reject a network connection between the wireless device and the wireless network in response to determining that the offered pre-shared key does not correspond to the unique pre-shared key. The unique pre-shared key is used to encrypt and decrypt data transmitted between the wireless device and the wireless network.


