Ruckus Wireless claimed a new patent by the United States Patent and Trademark Office (USPTO) for an innovation that promises to radically simplify the configuration, administration and strength of wireless network security.
The new technique, commonly known as Dynamic Pre-Shared Key (PSK), effectively eliminates tedious and time-consuming manual installation of encryption keys, passphrases or user credentials needed to securely access a wireless network. Dynamic PSK changes this model by dynamically generating strong, unique security keys for each authenticated user, automatically installing these encryption keys on end user devices with little or no human intervention, says Ruckus.
“With Wi-Fi there has historically been two ends of the security spectrum,” said Sudarshan Boosupalli, Country Head Ruckus Wireless. “On one end is the simple approach that makes life easy for network managers but creates potential security concerns for companies. On the other end is a very robust but often overwhelming security framework, such as 802.1X, that requires a tremendous amount of time and effort to implement and administer. We’ve created the best of both worlds with a user-friendly and low maintenance method for providing a high level of wireless security.”
The solution works in such a way that when a user initially accesses the wireless network, they are authenticated through a captive portal on the Ruckus ZoneDirector. This information is checked against any standard back-end authentication server such as Active Directory, RADIUS or an internal database on the ZoneDirector.
Once the user has successfully authenticated, Dynamic PSK technology automatically generates a unique encryption key for that user device. This key is downloaded to the client and automatically configured, along with the requisite Wi-Fi information. This eliminates users from having to manually configure anything and thereby promises to dramatically reduce the technical support burden on IT staff.
Each Dynamic PSK is bound to a specific client device and has a configurable lifetime. With Dynamic PSK, organizations control the length of time that each key is valid in increments of hours, days, weeks or months. Once the key expires, users must re-authenticate. If a user device is stolen, others on the network are not at risk. |