WLAN Access Point PSK Verification for Selective Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless networks face inefficiencies in managing access and forwarding of encrypted data due to the use of a single pre-shared key (PSK) for all stations, leading to unnecessary network resource utilization when devices lack the decryption key, and increased overhead in end-to-end encryption scenarios.

Innovation Solution

Implementing a system where access points check the association of the PSK used for encryption with the destination device before forwarding data, allowing access control based on key association records maintained by management nodes or access points, and using different encryption keys for secure communication across different networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single pre-shared key (PSK) is used for all stations on the WLAN, then ease of operation is improved, but network resource utilization deteriorates due to unnecessary data transmission to devices that cannot decrypt the content

Engineering Contradiction:
Improveease of operationVSAvoidnetwork resource utilization
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The access point performs preliminary verification by checking the key association record before forwarding encrypted data. This preliminary action identifies whether the destination device is associated with the PSK used to encrypt the data, preventing wasteful transmission to unauthorized devices and resolving the contradiction between ease of operation and network resource utilization

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the access point checks the key association record and uses this information to control data forwarding. This feedback loop ensures that only devices associated with the encryption key receive data, optimizing network resources while maintaining operational simplicity

Inventive Principle:
Principle #23Feedback

2Reliability

If end-to-end encryption is used, then security is improved, but device complexity increases due to multiple encryption keys and management overhead

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption system is segmented into two distinct layers: wireless link encryption using PSK for air interface security, and application layer encryption for end-to-end security. This segmentation allows each layer to handle specific security requirements independently, improving overall security while managing complexity through clear separation of functions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point acts as an intermediary that manages key association records and controls data forwarding based on key verification. This intermediary role simplifies the complexity for end devices by centralizing key management at the access point, allowing end devices to focus on application layer encryption without managing wireless link keys

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data is transmitted in encrypted form without decryption at the access point, then security is improved, but productivity deteriorates due to wasted network resources delivering undecryptable content

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The access point performs preliminary verification by checking the key association record before forwarding encrypted data. This preliminary action determines whether the destination device can decrypt the content, preventing wasteful transmission and improving productivity while maintaining security through selective forwarding

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service security verification where the access point autonomously checks key association records and makes forwarding decisions without requiring external intervention. This self-service mechanism improves productivity by automatically preventing wasteful transmissions while maintaining security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250274757A1Methods and apparatus for performing access and/or forwarding control in wireless networks such as wlans
Publication Date: 2025.08.28 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250274757A1 patent drawing
  • US20250274757A1 patent drawing
  • US20250274757A1 patent drawing

AI summary

Methods and apparatus for controlling access to and/or forwarding of communicated information, e.g. traffic, in a wireless communication system are described. The key, e.g., PSK, used to secure data that is transmitted to an access point for communication to a destination device is taken into consideration when deciding whether or not to provide the destination device access to the communicated content. The decision of whether or not to provide the destination device access to a communication may involve deciding whether or not to forward the received data to another device, e.g., another access point, for delivery to the destination device and/or may involve deciding whether or not to transmit the data to the destination device. If the destination device is not associated with, e.g., does not have access to and/or authorization to use, the key used to secure the received data, the data is not communicated to the destination device.