Wireless Network Community Management System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless network owners face challenges in managing access to their networks while maintaining security, as existing solutions are either insecure or overly complex, and existing technologies struggle to facilitate secure and easy sharing of wireless networks among multiple users.
Innovation Solution
A community management system that includes a web server, authentication server, and data store, allowing users to register their wireless access points and control access permissions, enabling secure and easy sharing of networks among registered members while using the IEEE 802.1x standard for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If WPA-PSK mode is used for network security, then ease of operation is improved, but security is worsened due to vulnerability to deciphering attacks
Solution Approach 1:
The patent introduces a central authentication server as an intermediary between wireless clients and access points. This server handles security operations using robust protocols like EAP-TLS, eliminating the need for vulnerable WPA-PSK while maintaining ease of use through automated authentication. The intermediary absorbs the security complexity, allowing simple client devices to connect securely without implementing complex security mechanisms themselves.
2Reliability
If 802.1x authentication server is used, then security is improved, but device complexity and cost are worsened
Solution Approach 1:
The patent merges the authentication server functionality into a centralized cloud-based service that multiple access points can share. Instead of each access point requiring its own 802.1x server (which would be complex and expensive), the authentication functionality is combined into a single shared resource that provides security for the entire wireless community through a unified authentication mechanism.
3Area of stationary object
If AP range is increased by adding more APs, then coverage area is improved, but cost and coordination complexity are worsened
Solution Approach 1:
The patent creates a universal authentication system that works across all access points in the community regardless of manufacturer or model. The centralized authentication server provides multi-functional support for different authentication methods (EAP-TLS, PEAP, TTLS) and seamlessly manages clients as they move between different access points. This universality eliminates the need for complex manual coordination between AP owners, as the system automatically handles authentication and roaming across the expanded coverage area.
4Reliability
If passphrase management is required for multiple users, then security is improved, but ease of operation is worsened due to tedious burden
Solution Approach 1:
The patent implements self-service authentication where users automatically present their credentials (such as digital certificates) to the authentication server without requiring manual passphrase entry or distribution. The system autonomously manages authentication credentials, handling certificate validation and key exchange processes. This eliminates the tedious burden of passphrase management while maintaining strong security through automated cryptographic authentication.
Data Source
AI summary
A wireless network community includes a plurality of wireless access points associated with a plurality of owners and a community management system in communication with each of the plurality of wireless access points via an Internet. The community management system includes a web server for interacting with the owners and for allowing each of the owners to register as a member of the network community. The community management system also includes an authentication server, and a data store coupled to the web server and to the authentication server. The community management system is configured to allow each registered member to register an associated wireless access point and to control which of the other members is authorized to access the wireless access point.


