Wireless Network Security Key Generation for Temporary Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network security protocols, such as WPA-PSK, require manual key changes across all network devices when an external station is granted temporary access, which is inconvenient and insecure, especially in environments with frequent temporary associations or large numbers of access points and stations.
Innovation Solution
A method and apparatus that allow an external station to temporarily associate with a wireless network by generating a security key using key generation information from both the access point and the station, along with an initial key, without revealing the initial key to the external station, using a key generation apparatus or key transmitter for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual key changes are implemented across all network devices to allow temporary external station access, then communication security is maintained, but network management complexity and time consumption increase significantly
Solution Approach 1:
The patent segments the key management function by introducing a separate key generation apparatus that operates independently from the access points and stations. This apparatus generates temporary security keys specifically for external stations, eliminating the need to change keys across the entire network. The segmentation allows key generation to be handled locally by the key generation apparatus rather than requiring coordinated changes across all network devices.
Solution Approach 2:
The key generation apparatus acts as an intermediary between the wireless network and external stations. It generates and distributes temporary security keys without exposing the initial key, serving as a mediator that enables secure temporary access while maintaining the security of the core network. This intermediary role resolves the contradiction by providing a dedicated mechanism for key management that doesn't require broad network changes.
2Ease of operation
If the initial key is shared with external stations for temporary access, then ease of operation improves, but security vulnerability increases due to potential key exposure
Solution Approach 1:
The patent extracts the temporary key generation function from the initial key, creating a separate security key that is derived from but distinct from the initial key. The key generation apparatus generates temporary keys using the initial key as a seed but never exposes the initial key itself to external stations. This extraction allows easy temporary access setup while maintaining security by keeping the initial key confined to the key generation apparatus.
Solution Approach 2:
The patent transforms the security key parameter from a static initial key shared by all devices to a dynamic temporary key generated specifically for each external station. The key generation apparatus uses the initial key to generate unique temporary keys with different parameters (such as station-specific identifiers and time stamps), enabling ease of operation for temporary access while preventing security vulnerabilities through parameter differentiation.
3Adaptability or versatility
If frequent temporary associations are permitted in the wireless network, then network versatility improves, but the frequency of manual key changes increases, reducing productivity
Solution Approach 1:
The patent implements preliminary action by having the key generation apparatus pre-generate temporary security keys before external stations need to access the network. The apparatus can generate and distribute keys in advance, or generate them on-demand using automated processes, eliminating the need for manual key changes when temporary associations occur. This preliminary preparation maintains network versatility while preserving productivity by removing manual intervention requirements.
Solution Approach 2:
The key generation apparatus provides self-service functionality by automatically generating and distributing temporary security keys without requiring manual intervention from network administrators. The system can autonomously manage the key generation process, including generating keys for external stations, distributing them through secure channels, and revoking them when no longer needed. This automation maintains high network versatility while ensuring continuous productivity by eliminating manual key management tasks.
Data Source
AI summary
A method and apparatus for managing communication security in a wireless network are provided. The method includes receiving from a station that intends to associate in the wireless network including an access point, first key generation information provided by the access point and second key generation information provided by the station, providing third key generation information, generating a security key using the first key generation information, the second key generation information, the third key generation information, and an initial key, and sending the third key generation information and the security key to the station.


