Wireless Network Authentication via Pre-Shared Key User Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managed wireless networks require individual configuration and identification of each device for network policies, which is cumbersome for nontechnical users and inefficient, especially when device-identifying information like MAC addresses change frequently.

Innovation Solution

A network system that uses a unique pre-shared key (PSK) mapped to a user profile, allowing devices to connect without registering individually, with the PSK encrypting and decrypting data and determining network access policies based on user identity rather than device information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-level authentication using MAC addresses is implemented, then network policies can be applied to individual devices, but nontechnical users cannot connect their devices independently and require technical assistance

Engineering Contradiction:
Improvenetwork policy applicationVSAvoiddevice connection
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a portal server as an intermediary between users and the network authentication system. The portal server provides a web-based interface that guides nontechnical users through the authentication process, eliminating the need for users to directly handle MAC addresses or configuration commands. The portal server translates user-friendly interactions into the technical authentication requirements of the network system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables users to autonomously connect their devices through a self-service portal interface. Users can independently obtain their device's MAC address, access the portal server through a web browser, and complete authentication without requiring technical support personnel. The system automatically processes the authentication and applies appropriate network policies.

Inventive Principle:
Principle #25Self-service

2Reliability

If individual device registration is required for network policies, then network security and policy control are maintained, but the configuration process becomes cumbersome and time-consuming

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically gathering device information (MAC address) and preparing authentication credentials before the user needs to connect. The portal server pre-configures the authentication process, retrieves necessary device identifiers, and sets up the connection parameters in advance, so users only need to follow simple on-screen instructions rather than performing complex configuration steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated portal system eliminates manual configuration steps by automatically extracting MAC addresses, validating device information, and applying network policies without requiring user intervention in technical processes. This self-service approach maintains security controls while dramatically reducing the time and effort users must invest in the configuration process.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If MAC addresses are used for device identification, then individual device tracking is possible, but MAC addresses may change frequently causing connection issues

Engineering Contradiction:
Improvedevice identificationVSAvoiddevice identifier consistency
Core Design Contradiction:
Measurement precisionVSStability of the object's composition

Solution Approach 1:

The portal server acts as an intermediary that manages the relationship between device identifiers and network authentication. Instead of relying directly on MAC addresses as the primary identification mechanism, the portal server provides a stable interface that can accommodate MAC address changes. The system captures and stores device identifiers through the portal, creating a more resilient identification system that can handle identifier changes without breaking connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250373412A1Authentication for wireless networks
Publication Date: 2025.12.04 INSIGHT DIRECT USA INC
  • US20250373412A1 patent drawing
  • US20250373412A1 patent drawing
  • US20250373412A1 patent drawing

AI summary

A network system includes a processor and memory encoded with instructions that, when executed, cause the system to receive an offered pre-shared key from a wireless device via a wireless network; access a mapped key-user pair comprising a unique pre-shared key and a user profile; and determine whether the offered pre-shared key corresponds to the unique pre-shared key. The instructions further permit the wireless device to connect to the wireless network according to a network policy associated with the mapped key-user pair in response to determining that the offered pre-shared key corresponds to the unique pre-shared key, or reject a network connection between the wireless device and the wireless network in response to determining that the offered pre-shared key does not correspond to the unique pre-shared key. The unique pre-shared key is used to encrypt and decrypt data transmitted between the wireless device and the wireless network.