Personal-Public Service Set Identifier

The implementation of Personal-Public (PP) SSID connections addresses the security challenges of current SSID technologies by creating secure, single-device, and encrypted networking channels, thereby enhancing network security and protecting data from unauthorized access.

JP7678788B2Active Publication Date: 2025-05-16KYNDRYL INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022502106
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-07-11
Filing Date
2020-07-08
Publication Date
2025-05-16
Estimated Expiration
2040-07-08

AI Technical Summary

Technical Problem

Current SSID technologies face challenges in network security due to their public nature, making them susceptible to unauthorized access, brute force attacks, and data interception.

Method used

A system that implements Personal-Public (PP) SSID connections, which are single-device, single-use, password-protected, unpublished, and encrypted networking channels, managed by a credential server and a wireless access point.

Benefits of technology

The PP SSID connections significantly enhance network security by limiting malicious device connections, reducing intrusion time, providing additional password protection, making it difficult for malicious actors to discover the connections, and encrypting data to render intercepted data useless.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007678788000001
    Figure 0007678788000001
  • Figure 0007678788000002
    Figure 0007678788000002
  • Figure 0007678788000003
    Figure 0007678788000003
Patent Text Reader

Abstract

Embodiments are directed to techniques for secure network connectivity. The techniques include a system having a credential server that stores a personal-public (PP) service set identifier (SSID) profile configured according to registration information provided by a personal computing device. The system further includes a wireless access point (WAP) communicatively coupled to the credential server, the wireless access point (WAP) configured to implement a PP SSID connection using the PP SSID profile, creating a single-device, single-use, password-protected, private, and encrypted networking channel between the personal computing device and the Internet.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to networks, and more particularly to network security. A service set identifier (SSID) is a unique identifier (e.g., 32 characters, 32 bytes, etc.) used to identify a wireless (e.g., Wi-Fi) network. In some cases, multiple wireless networks may overlap in one geographic area. In such cases, the SSID is used to ensure that data is transmitted over the appropriate Wi-Fi connection. SSID broadcasting is used to inform users of available SSIDs. SSID broadcasting involves continuous packet transmission from a Wi-Fi access point. [Background technology]

[0002] Unauthorized access to an SSID compromises the security of other user devices connected to that SSID. For example, a malicious user who has unauthorized access to an SSID can intercept network traffic from other users. The intercepted network traffic may contain confidential, private, personal, or other secret information and may be used by malicious actors for malicious purposes. Therefore, it is necessary to utilize security protocols by SSID to enhance network security.

[0003] SSIDs have various levels of security associated with them. As an example, some SSIDs are password protected to increase network security. In these situations, the SSID is publicly visible, but a password is required to access the associated Wi-Fi network. One weakness associated with password-protected SSIDs is that publicly visible SSIDs protected by traditional alphanumeric passwords are susceptible to compromise through brute force attacks, phishing attacks, and / or other attacks.

[0004] Another example is when the SSID is hidden to increase network security. In these situations, the SSID is not broadcast and therefore cannot be seen publicly when user devices are searching for Wi-Fi access points. Instead, users manually enter the SSID to access the hidden Wi-Fi network. One weakness of a hidden SSID is that it can be discovered by eavesdropping on data packet transmissions with simple traffic monitoring software.

[0005] Thus, current SSID technology is configured to allow multiple devices to access a network using a common SSID, and poses technical challenges related to network security due to its public nature. Summary of the Invention

[0006] Aspects of the present disclosure are directed to a system including a credential server that stores a personal-public (PP) service set identifier (SSID) profile configured according to registration information provided by a personal computing device, and further includes a wireless access point (WAP) communicatively coupled to the credential server, the WAP configured to implement a PP SSID connection using the PP SSID profile, creating a single-device, single-use, password-protected, unadvertised, and encrypted networking channel between the personal computing device and the Internet.

[0007] Advantageously, the above-described system improves network security by implementing a PP SSID connection that is a single-device, single-use, password-protected, unpublished, and encrypted networking channel. The single-device networking channel limits the ability of a malicious device to connect to the PP SSID connection. The single-use networking channel limits the amount of time the PP SSID connection is susceptible to compromise by a malicious actor. The password-protected PP SSID connection provides an additional layer of security associated with the PP SSID connection. The unpublished PP SSID connection makes it difficult for a malicious actor to discover the PP SSID connection. The encrypted PP SSID connection renders any data intercepted from the PP SSID connection less valuable or worthless.

[0008] Another optional aspect of the present disclosure that includes the limitations presented in the above system further includes that the PP SSID profile is associated with an expiration limit, and the PP SSID connection is configured to terminate according to the expiration limit, where the expiration limit is selected from the group consisting of time, amount of usage, and type of usage.

[0009] The aforementioned optional aspects of the present disclosure advantageously promote network security and improve computational efficiency. For example, the aforementioned optional aspects enhance network security by terminating PP SSID connections according to time-based or usage-based validity limits to limit the lifetime of a PP SSID connection. Limiting the lifetime of a PP SSID connection reduces the ability of malicious actors to compromise a PP SSID connection by introducing time pressure. Additionally, the aforementioned optional aspects of the present disclosure improve computational efficiency by limiting the lifetime of a PP SSID connection such that the PP SSID connection is not unnecessarily maintained beyond the time-based or usage-based validity limits.

[0010] Another optional aspect of the present disclosure that includes the limitations presented in the above system further includes the PP SSID profile being associated with an availability limit, and the PP SSID connection is configured to be terminated according to the availability limit, where the availability limit is based on a location and a geofence of the personal computing device defined in the PP SSID profile, and the PP SSID connection is terminated when the personal computing device is outside the geofence.

[0011] The foregoing optional aspects of the present disclosure advantageously promote network security and improve computational efficiency by terminating PP SSID connections according to location-based validity limits. Location-based validity limits can improve security by terminating PP SSID connections outside of predefined safe use zones (e.g., zones protected from eavesdropping, snooping, etc.). Similarly, location-based validity limits improve computational efficiency by preventing maintenance of PP SSID connections beyond the location-based validity limits.

[0012] Further aspects of the present disclosure are directed to a computer-implemented method, the method including receiving, at a credential server, from a wireless access point (WAP) registration information from the personal computing device in response to the personal computing device connecting to a publicly advertised service set identifier (SSID) provided by the WAP. The method further includes configuring, by the credential server, a personal-public (PP) SSID profile based on the registration information. The method further includes providing, via the WAP, to the personal computing device, a PP SSID network name and a PP SSID password of the PP SSID profile, the PP SSID profile enabling the personal computing device to establish a PP SSID connection between the personal computing device and the Internet, the PP SSID connection including a single-device, single-use, password-protected, private, and encrypted networking channel. Additional aspects of the present disclosure are directed to systems and computer program products configured to perform the aforementioned computer-implemented methods.

[0013] Advantageously, the foregoing method improves network security by implementing a PP SSID connection that is a single-device, single-use, password-protected, unpublished, and encrypted networking channel. The single-device networking channel limits the ability of a malicious device to connect to the PP SSID connection. The single-use networking channel limits the amount of time the PP SSID connection is susceptible to compromise by a malicious actor. The password-protected PP SSID connection provides an additional layer of security associated with the PP SSID connection. The unpublished PP SSID connection makes it difficult for a malicious actor to discover the PP SSID connection. The encrypted PP SSID connection renders any data intercepted from the PP SSID connection less or worthless.

[0014] Another optional aspect of the present disclosure, including a limitation of the above method, further includes configuring a Personal-Public (PP) SSID profile based on the registration information by generating a predicted time of a PP SSID request associated with the personal computing device, wherein providing a PP SSID network name and a PP SSID password for the PP SSID profile to the personal computing device occurs within an interval of time prior to the predicted time.

[0015] The foregoing optional aspects of the present disclosure advantageously increase usability and efficiency by predictively provisioning PP SSID connections.

[0016] Further aspects of the present disclosure are directed to a computer-implemented method, the method including connecting a personal computing device to a publicly published service set identifier (SSID). The method further includes providing registration information to an authentication webpage in response to connecting to the publicly published SSID. The method further includes receiving a personal-public (PP) SSID network name and a PP SSID password in response to providing the registration information to the authentication webpage. The method further includes accessing an in-target using the PP SSID connection by establishing a single-device, single-use, password-protected, unpublished, and encrypted networking channel between the personal computing device and the Internet. Additional aspects of the present disclosure are directed to systems and computer program products configured to perform the aforementioned computer-implemented methods.

[0017] Advantageously, the foregoing method improves network security by implementing a PP SSID connection that is a single-device, single-use, password-protected, unpublished, and encrypted networking channel. The single-device networking channel limits the ability of a malicious device to connect to the PP SSID connection. The single-use networking channel limits the amount of time the PP SSID connection is susceptible to compromise by a malicious actor. The password-protected PP SSID connection provides an additional layer of security associated with the PP SSID connection. The unpublished PP SSID connection makes it difficult for a malicious actor to discover the PP SSID connection. The encrypted PP SSID connection renders any data intercepted from the PP SSID connection less valuable or worthless.

[0018] An additional optional aspect of the present disclosure, including a limitation of the above method, includes the PP SSID password comprising a biometric password selected from the group consisting of a voice-based password, a face-based password, a fingerprint-based password, and a gait-based password.

[0019] Advantageously, biometric passwords can be more difficult for malicious actors to forge than traditional passwords, and thus the foregoing optional aspects of the present disclosure further improve network security.

[0020] The above summary is not intended to describe each illustrated embodiment or every implementation of the present disclosure. [Brief description of the drawings]

[0021] The drawings included in this application are incorporated in and form a part of this specification. These drawings illustrate embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure. The drawings are merely illustrative of particular embodiments and are not intended to limit the disclosure. [Figure 1]1 illustrates an example computing environment for generating and using Personal-Public (PP) Service Set Identifiers (SSIDs) in accordance with some embodiments of the present disclosure. [Diagram 2] 1 illustrates an example communication diagram for generating and using a PP SSID according to some embodiments of the present disclosure. [Diagram 3] 1 illustrates a flowchart of an example method for implementing a PP SSID using a credential server according to some embodiments of the present disclosure. [Figure 4] 1 illustrates a flowchart of an example method for generating an enrollment profile according to some embodiments of the present disclosure. [Diagram 5] 1 illustrates a flowchart of an example method for predictively providing a PP SSID, according to some embodiments of the present disclosure. [Figure 6] 1 illustrates a flowchart of an example method for implementing a PP SSID using a wireless access point (WAP) according to some embodiments of the present disclosure. [Figure 7] 1 illustrates a flowchart of an example method for implementing a PP SSID using a personal computing device, according to some embodiments of the present disclosure. [Figure 8A] 1 illustrates an interface functional diagram of a personal computing device requesting a PP SSID according to some embodiments of the present disclosure. [Figure 8B] 1 illustrates an interface functional diagram of a personal computing device using a PP SSID according to some embodiments of the present disclosure. [Figure 9A] 1 illustrates an interface functional diagram of a personal computing device using a near-limit PP SSID in accordance with some embodiments of the present disclosure. [Figure 9B] 1 illustrates an interface functional diagram of a personal computing device having a terminated PP SSID connection according to some embodiments of the present disclosure. [Figure 10]1 illustrates a block diagram of an example PP SSID manager according to some embodiments of the present disclosure. [Figure 11] 1 illustrates a cloud computing environment according to some embodiments of the present disclosure. [Figure 12] 1 illustrates abstraction model layers according to some embodiments of the present disclosure.

[0022] While the present disclosure is amenable to various modifications and alternative forms, specific features thereof have been shown by way of example in the drawings and will be described in detail. It is to be understood, however, that the particular embodiments described are not to be construed in a limiting sense. On the contrary, it is intended to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0023] Aspects of the present disclosure are directed to networks, and more particularly, to network security. Although not limited to such application, embodiments of the present disclosure can be best understood in light of the foregoing context.

[0024] Referring now to FIG. 1, a block diagram of an exemplary computing environment 100 for implementing a Personal-Public (PP) Service Set Identifier (SSID) in accordance with some embodiments of the present disclosure is shown.

[0025] First, a brief description of PP SSIDs. PP SSIDs can be used to create a secure networking channel between a user device and a network (e.g., the Internet, an intranet, or another network). The networking channel of a PP SSID can be one or more of a single-device networking channel, a single-use networking channel, a password-protected networking channel, a private networking channel, an encrypted networking channel, or a provisioned networking channel, or a combination thereof. Thus, PP SSIDs are "public" in the sense that they are provided by a publicly available wireless access point (WAP), such as WAP 108, and "personal" in the sense that each PP SSID is configured to provide secure network access for a single device, such as personal computing device 102.

[0026] Returning to the discussion of FIG. 1, the computing environment 100 includes a personal computing device 102, a wireless access point (WAP) 108, a credential server 114, and a PP SSID manager 122 that are communicatively coupled to each other, directly or indirectly, via a physical networking protocol, a wireless networking protocol, or a combination of a physical networking protocol and a wireless networking protocol.

[0027] The personal computing device 102 can be, but is not limited to, a computer, a desktop, a laptop, a tablet, a smartphone, a mobile phone, a smart device (e.g., smart glasses, a smart appliance, a smart TV, etc.), or another device. The personal computing device 102 is configured to execute an operating system 104 capable of presenting a web browser 106 application, which can be used as an interface to communicate with the Internet 126 via the WAP 108. Although a single personal computing device 102 using a PP SSID connection 124 is shown, in some embodiments, there may be multiple computing devices 102 (e.g., a predefined group, set, or cohort of devices) using a PP SSID connection 124. These embodiments are useful, for example, when one user is accessing the Internet 126 with a smartphone, a tablet, and a laptop. In such an embodiment, each of the smartphone, tablet, and laptop belonging to the same user may use the same PP SSID connection 124. As another example, a group of similar users in similar locations may share a PP SSID connection 124. In such an example, the group of similar users may be employees of the same company working together while traveling on business. However, for ease of discussion, the remainder of this disclosure will discuss a single personal computing device 102 .

[0028] The WAP 108 may be any configuration of hardware and software useful for wirelessly connecting a device (e.g., the personal computing device 102) to a network (e.g., the Internet 126). The WAP 108 may include, for example, a router, an access point, a hotspot, etc. In some embodiments, the WAP 108 may be physically connected to the Internet 126 (e.g., via an Ethernet connection) and may provide wireless access to the Internet 126 using one or more wireless networking protocols 110. The networking protocols 110 may be, but are not limited to, the Institute of Electrical and Electronic Engineers (IEEE) networking protocol 802.1X-2010, published on February 5, 2010, and amended by 802.1Xbx-2014 published on December 22, 2014 and 802.1Xck-2018 published on December 21, 2018, which is an IEEE standard for port-based network access control (PNAC). Networking protocol 110 may be configured for Extensible Authentication Protocol (EAP) 112, which is an authentication framework that may be used in wireless networks and / or point-to-point connections. EAP 112 is a standard defined according to Request for Comments (RFC) 3748 and updated by RFC 5247. As will be appreciated by those skilled in the art, EAP 112 is one example of an authentication protocol and other types of authentication protocols may be used in other embodiments.

[0029] The credential server 114 may be any configuration of hardware and software useful for configuring, generating, storing, or transmitting a PP SSID profile 118 to the personal computing device 102 via the WAP 108, or a combination thereof, to establish a corresponding PP SSID connection 124. The credential server 114 may also monitor the validity limit of the PP SSID profile 118, and upon exceeding the validity limit of the PP SSID profile 118, issue a self-destruction command, delete the out-of-validity PP SSID profile 118, or terminate the corresponding PP SSID connection 124, or a combination thereof.

[0030] The credential server 114 may include a PP SSID configuration engine 116 configured to generate PP SSID profiles that are customized, tailored, or otherwise individualized for individual devices, or combinations thereof, such as a PP SSID profile 118 for the personal computing device 102. The PP SSID configuration engine 116 may use, for example, machine learning, artificial intelligence, deep learning, neural networks, etc., to generate the PP SSID profile 118. The PP SSID profile 118 may include, but is not limited to, a PP SSID network name, a PP SSID password, a PP SSID encryption protocol, a PP SSID authentication protocol, a time-based validity limit (e.g., time, duration, etc.), a usage-based validity limit (e.g., amount of usage, type of usage, etc.), or a location-based validity limit (e.g., geofence), or combinations thereof.

[0031] The credential server 114 may further include an enrollment profile database 120 for storing enrollment profiles of various devices, such as the personal computing device 102. The enrollment profiles in the enrollment profile database 120 may include, for example, a sign-in name, a user name, a personal identifier, a password, a usage history, etc. The information in the enrollment profile database 120 may be used by the PP SSID configuration engine 116 to generate a PP SSID profile 118.

[0032] The PP SSID manager 122 may be any configuration of hardware and software useful for managing PP SSID functionality in one or more of the personal computing device 102, the WAP 108, or the credential server 114, or a combination thereof. The PP SSID functionality may include creating, storing, transmitting, or deleting a PP SSID profile 118, and / or implementing or terminating a PP SSID connection 124. The PP SSID manager 122 may include hardware or software, or both, communicatively coupled to, embedded in, or distributed among one or more of the personal computing device 102, the WAP 108, or the credential server 114, or a combination thereof. As an example, the PP SSID manager 122 may be an application running on the personal computing device 102. As another example, the PP SSID manager 122 may be processor-executable code stored on a tangible storage medium of the WAP 108 or the credential server 114, or both. As another example, the PP SSID manager 122 may be a cloud-based application that can provision PP SSID functionality as needed to one or more of the personal computing device 102, the WAP 108, or the credential server 114, or a combination thereof.

[0033] The PP SSID manager 122 can be useful for establishing a PP SSID connection 124 between the personal computing device 102 and the Internet 126 via the WAP 108. The PP SSID connection 124 can include one or more of the following characteristics: (i) Single Device: A PP SSID connection 124 can be customized according to a PP SSID profile 118 associated with a single personal computing device 102, and this customization can be related to, among other things, the amount of usage, the type of usage, the time of usage, the location of usage (e.g., geofence), the predicted future usage, and the like. The "single device" characteristic has a first advantage of tailorability, which improves usability and efficiency by tailoring the PP SSID connection 124 to the likely usage of the personal computing device 102. The "single device" characteristic has a second advantage of improved security, which relates to being able to discover malicious behavior on the PP SSID connection 124 by identifying attempts at multiple device connections when only single device connections are allowed. However, in some embodiments, the PP SSID connection 124 is configured for a set of devices, rather than for a single device, and the set of devices belongs to a predefined group (e.g., employees of a particular company, guests of a particular hotel, etc.). (ii) Single Use: A PP SSID connection 124 can be associated with a validity limit, which can be based, for example, on location (e.g., inside or outside a geofence), date and / or time, duration of use, type of use, amount of use, etc. The “single use” nature of a PP SSID connection 124 advantageously improves security by terminating the PP SSID connection 124 and creating a new PP SSID connection 124 for a new session, even with the same personal computing device 102. Thus, even if a malicious attacker discovers a PP SSID connection 124, the malicious attacker will have a limited (and perhaps insufficient) time to attempt to compromise the PP SSID connection 124 before the PP SSID connection 124 is terminated and a new PP SSID session is created. (iii) Password Protection: The PP SSID connection 124 can be secured by an authentication protocol using, for example, a password based on the PP SSID profile 118 of the personal computing device 102. The "password protected" nature of the PP SSID connection 124 improves security by reducing the likelihood that the PP SSID connection 124 can be compromised even if the PP SSID network name is discovered. Additionally, two-factor authentication, one-time passwords, biometric passwords, and other password-related security mechanisms can be used to further increase the security of the PP SSID connection 124 as compared to traditional passwords. (iv) Unadvertised: A PP SSID connection 124 may include an unadvertised (e.g., hidden, disguised, etc.) PP SSID network name such that only personal computing devices 102 associated with the PP SSID profile 118 corresponding to the PP SSID connection 124 recognize the PP SSID network name. The “unadvertised” characteristic advantageously improves security by limiting the ability of malicious actors to discover or identify the PP SSID connection 124. (v) Encryption: The PP SSID connection 124 can be further secured by, for example, encryption protocols. The “encrypted” nature of the PP SSID connection 124 improves network security by encrypting data transmitted between the personal computing device 102 and the Internet 126 via the WAP 108. As a result, even if the data is intercepted, the intercepted data is encrypted and of limited, if any, value to a malicious attacker. (vi) Provisioning: A PP SSID connection 124 may be provisioned to a personal computing device 102 when the personal computing device 102 or a login (e.g., employee ID) entered into the personal computing device 102 is associated with a PP SSID provisioning agreement. In these embodiments, the PP SSID provisioning agreement may be a personal PP SSID provisioning agreement (e.g., an individual at a restaurant who desires a secure PP SSID network connection), a provisioning of multiple personal PP SSIDs (e.g., a business with employees distributed across a region or country), or other arrangement, or combination thereof, in which the PP SSID manager 122 provisions one or more personal computing devices 102 with PP SSID functionality according to pre-agreed PP SSID provisioning functionality terms, duration terms, payment terms, usage terms, or other terms or combinations thereof. Advantageously, the "provisioning" characteristic of the PP SSID connection 124 allows for metered use of the PP SSID functionality as needed.

[0034] Accordingly, aspects of the disclosure are generally directed to creating, implementing, or using, or a combination thereof, a PP SSID connection 124 based on a PP SSID profile 118, using a personal computing device 102, a WAP 108, and a credential server 114, where the PP SSID connection 124 may be configured to provide one or more characteristics of single device, single use, password protection, encryption, or provisioning, or a combination thereof, for purposes of improving network security.

[0035] The foregoing block diagrams may include more, fewer, or different components than explicitly shown, or combinations thereof, while remaining within the spirit and scope of the disclosure. Similarly, the components shown in the block diagrams may be separate from one another, combined with one another, integrated with one another, or otherwise communicatively coupled, or combinations thereof, in other arrangements other than that shown in FIG. 1, while remaining within the spirit and scope of the disclosure.

[0036] Referring now to FIG. 2, a communications diagram 200 is shown broadly illustrating various aspects of the present disclosure.

[0037] At time 202, the personal computing device 102 may power up (e.g., switch on, boot, start up, etc.). At interaction 204, the personal computing device 102 may identify and attach to a publicly published SSID via the WAP 108. At interaction 206, the WAP 108 may provide an authentication web page to the personal computing device 102. At interaction 208, the personal computing device 102 may forward registration information (e.g., sign-in, email address, name, etc.) to the WAP 108. At interaction 210, the WAP 108 may provide the registration information to the credential server 114. At interaction 212, the credential server 114 may communicate with the PP SSID configuration engine 116 to generate a PP SSID profile 118 based at least in part on the registration information. At interaction 214, the PP SSID configuration engine 116 may provide information related to the PP SSID profile 118 to the credential server 114. At interaction 216, the credential server 114 can provide the PP SSID profile 118 to the WAP 108. In some embodiments, the WAP 108 can associate a media access control (MAC) address of the personal computing device 102 with the PP SSID profile 118 and store the association in a cache of the WAP 108. In other embodiments, the credential server 114 associates the MAC address of the personal computing device 102 with the PP SSID profile 118 and stores the association in the enrollment profile database 120.

[0038] At interaction 218, the WAP 108 can provide information related to the PP SSID profile 118 (e.g., PP SSID network name, PP SSID password) to the personal computing device 102. At time 220, the personal computing device 102 can establish a PP SSID connection 124, which can include characteristics such as, but not limited to, single device, single use, password protected, private, encrypted, or provisioned, or combinations thereof. In some embodiments, the PP SSID connection 124 cannot be discovered or used by other user devices interacting with the WAP 108. At time 222, the PP SSID configuration engine 116 can monitor the PP SSID connection 124 for an active limit, which can be stored in the PP SSID profile 118, which can include a time-based active limit, a usage-based active limit, or a location-based active limit, or combinations thereof. At interaction 224, the PP SSID configuration engine 116 may detect an out-of-validity limit for the PP SSID connection 124 and issue a self-destruct command associated with the PP SSID connection 124 to the credential server 114, the WAP 108, or the personal computing device 102, or a combination thereof, to terminate the PP SSID connection 124. In some embodiments, the self-destruct command may also cause data associated with the PP SSID connection 124, data generated by the PP SSID connection 124, data generated during use of the PP SSID connection 124, or data associated with the PP SSID profile 118, or a combination thereof, to be deleted, and the deleted data may be deleted from storage, memory, or cache, or a combination thereof, of one or more of the personal computing device 102, the WAP 108, the credential server 114, or the PP SSID configuration engine 116, or a combination thereof.

[0039] The foregoing aspects of Figure 2 may be completed in any order and are not limited to those described. Furthermore, some, all, or none of the foregoing aspects may be completed while remaining within the spirit and scope of the present disclosure.

[0040] 3, a flowchart of an example method 300 for configuring a PP SSID profile 118 is shown, in accordance with some embodiments of the present disclosure. In some embodiments, the method 300 is performed by the credential server 114, or another hardware or software or both configuration.

[0041] In operation 302, the credential server 114 receives registration information from the WAP 108. In some embodiments, the registration information is entered into a main authentication web page associated with the WAP 108 and then transmitted to the credential server 114.

[0042] In operation 304, the credential server 114 determines whether the registration information received in operation 302 matches a registration profile stored in the registration profile database 120. If the registration information matches a registration profile in the registration profile database 120 (304: yes), the method 300 proceeds to operation 308. If the registration information does not match a registration profile in the registration profile database 120 (304: no), the method 300 proceeds to operation 306. In some embodiments, the registration information that matches a registration profile stored in the registration profile database 120 may be associated with the existence of a commercial arrangement (e.g., contractual agreement, terms of service, etc.) for provisioning PP SSID functionality to an existing registration profile. In such an embodiment, the registration information may be, for example, an employee identifier or other login indicating that the registration information is associated with a commercial entity having a commercial arrangement for provisioning of PP SSIDs. As another example, the registration information may be a login of an individual indicating that the individual has a commercial arrangement for provisioning of PP SSIDs.

[0043] In operation 306, the credential server 114 creates a registration profile based on the information received in operation 302. After creating the registration profile in operation 306, the method 300 may return to operation 302 and receive the registration information with a database match in operation 304, or in other embodiments, the method 300 may proceed directly to operation 308. In operation 308, the credential server 114 configures a PP SSID profile 118 based on the registration profile. Configuring the PP SSID profile 118 may include establishing parameters for a single-device, single-use, password-protected, non-public, encrypted, and / or provisioned PP SSID connection 124 based on, customized to, tailored to, or otherwise configured according to the registration profile associated with the personal computing device 102. The configuration of the PP SSID profile 118 can include, for example, a PP SSID network name (e.g., a 32 character identifier, a 32 byte identifier, etc.), a password (e.g., a fingerprint-based password, a voice-based password, a face-based password, a gait-based password, an alphanumeric password, a pattern-based password, etc.), a time-based validity limit (e.g., date and time of validity limit, amount of time until validity limit, etc.), a usage-based validity limit (bandwidth threshold, type of usage, etc.), a location-based validity limit (e.g., inside or outside a geofence around a given location, etc.), or another validity limit parameter. In some embodiments, the PP SSID profile 118 further includes an authentication protocol (e.g., a one-time password (OTP) protocol, a multi-factor authentication protocol, etc.).

[0044] In operation 310 , the credentials server 114 registers a media access control (MAC) address associated with the personal computing device 102 in the PP SSID profile 118 .

[0045] In operation 312, the credential server 114 determines whether the PP SSID profile 118 is out of validity (or invalid). The credential server 114 can determine whether the PP SSID profile 118 is out of validity by comparing the current date and / or time with the validity limit date and / or time. If the current date and / or time is past the validity limit date and / or time, the PP SSID profile 118 is out of validity, otherwise it is not out of validity.

[0046] Alternatively or in addition, operation 312 can compare the usage of the PP SSID connection 124 with the expiration date, and if the cumulative usage using the PP SSID connection 124 exceeds the expiration date (e.g., more than 1 gigabyte of data), then the PP SSID profile 118 is out of bounds, otherwise it is not out of bounds.

[0047] Alternatively or in addition, operation 312 can compare the usage type of the PP SSID connection 124 with usage parameters, and if the usage type does not meet the usage parameters (e.g., less than one data transfer exceeding 1 megabyte in any 10 minutes within the previous 60 minutes), then the PP SSID profile 118 is out of range, otherwise it is not out of range.

[0048] Alternatively or additionally, operation 312 may compare the location of the personal computing device 102 to a geofence associated with the PP SSID profile 118. In such an embodiment, if the personal computing device 102 is outside the geofence, then the PP SSID profile 118 is out of bounds, and otherwise it is not out of bounds.

[0049] If the PP SSID profile 118 is not out of validity limits (312: no), the method 300 returns to operation 312 to continuously, semi-continuously, intermittently, or at predetermined intervals to monitor the validity limits of the PP SSID profile 118. If the credential server 114 determines that the PP SSID profile 118 is out of validity limits or is otherwise invalid (312: yes), the method 300 proceeds to operation 314.

[0050] In operation 314, the credential server 114 issues a self-destruct command to the PP SSID profile 118 and data associated with the PP SSID profile 118. Issuing the self-destruct command may include sending a self-destruct command to the WAP 108 or the personal computing device 102, or both. Issuing the self-destruct command may terminate the PP SSID connection 124. Issuing the self-destruct command may delete data created as a result of using the PP SSID connection 124 (e.g., by deleting data in the cache of the WAP 108 or the personal computing device 102 associated with activity resulting from using the PP SSID connection 124).

[0051] The foregoing operations may be completed in any order and are not limited to those described. Moreover, one may complete one, all, or none of the foregoing operations while remaining within the spirit and scope of the present disclosure.

[0052] 4, a flow chart of an example method 400 for configuring a PP SSID profile 118 is shown, in accordance with some embodiments of the present disclosure. In some embodiments, method 400 is a sub-method of method 300 and is an example of operation 308 of FIG 3. In some embodiments, method 400 is implemented by credential server 114, or by separate hardware or software, or a combination of both.

[0053] In operation 402, the credential server 114 collects location information from the personal computing device 102, which may be based, for example, on data from a PP SSID application running on the personal computing device 102, data manually entered by a user into the personal computing device 102 and sent to the credential server 114, Global Positioning System (GPS) coordinates sent from the personal computing device 102 to the credential server 114, inferred location information based on web browsing history, map use, or the like, or another location source, or a combination thereof.

[0054] In operation 404, the credential server 114 collects context information from the personal computing device 102. The context information may be related to preferred usage (e.g., streaming video, checking email, uploading information, using a personal hotspot, etc.). The context information may also be related to predicted usage, which may be based on historical data from the personal computing device 102 and / or location-related data collected in operation 402. The predicted usage may include a predicted date and time when the next PP SSID connection 124 will be requested by the personal computing device 102. This information may be used to predictively provision a PP SSID profile 118 near the predicted date and time of the next PP SSID connection 124 request (discussed in more detail with respect to FIG. 5).

[0055] It should be noted that while this disclosure is directed to the collection of personal data (location data, contextual data, web browsing history, usage history, etc.), in embodiments, a user may opt-in to any system that collects this personal data. In doing so, the user may be informed of what data is being collected, how the collected data is being used, whether the collected data is encrypted when used, etc. Furthermore, any opt-in system allows the user to opt-out at any time. For any user who chooses to opt-out, any of that user's personal data may be identified and deleted. Furthermore, any personal data may be managed according to rules and regulations that may be established by a company, industry, country, treaty, etc.

[0056] In operation 406, the credential server 114 may perform machine learning on the information collected in operations 402-404. Machine learning algorithms may include, but are not limited to, decision tree learning, association rule learning, artificial neural networks, deep learning, inductive logic programming, support vector machines, clustering, Bayesian networks, reinforcement learning, representation learning, similarity / metric learning, sparse dictionary learning, genetic algorithms, rule-based learning, or other machine learning techniques, or combinations thereof.

[0057] For example, the machine learning algorithm may use one or more of the following exemplary techniques: K-nearest neighbors (KNN), learning vector quantization (LVQ), self-organizing maps (SOM), logistic regression, least squares regression (OLSR), linear regression, stepwise regression, multivariate adaptive regression splines (MARS), ridge regression, lasso regression (least absolute shrinkage and selection operator:LASSO), Elastic Net, Least Angle Regression (LARS), Probabilistic Classifier, Naive Bayes Classifier, Binary Classifier, Linear Classifier, Hierarchical Classifier, Canonical Correlation Analysis (CCA), Factor Analysis, Independent Component Analysis (ICA), Linear Discriminant Analysis (LDA), Multidimensional Scaling (MDS), Nonnegative Matrix Factorization (NMF), Partial Least Squares Regression (PLSR), Principal Component Analysis (PCA), Principal Component Regression (PCR), Sammon Mapping, t-SNE, Bootstrap Aggregation, Ensemble Averaging, Gradient Boosted Decision Tree (GBRT), Gradient Boosting Machine (GBM), Inductive Bias Algorithm, Q-Learning, State-Action-Reward-State-Action (SARSA), Temporal Difference (TD) Learning, Apriori Algorithm, Equivalent Class Transformation (ECLAT) algorithm, Gaussian process regression, gene expression programming, group method of data handling (GMDH), inductive logic programming, instance-based learning, logistic model tree, informative fuzzy network (IFN), hidden Markov model, Gaussian naive Bayes, multinomial naive Bayes, averaged independent dependence estimator (AODE), Bayesian network (BN), classification and regression tree (CART), chi-squared automated interaction detection (CHAID), expectation maximization algorithm, feedforward neural network, logic learning machine, self-organizing map, single-linkage clustering, fuzzy clustering, hierarchical clustering, Boltzmann machine, convolutional neural network, recurrent neural network, hierarchical temporal memory (HTM), or other machine learning techniques or combinations thereof.

[0058] The output of operation 406 includes one or more of a predicted usage period (e.g., predicted availability limit), a predicted usage area (e.g., predicted geofence), a predicted usage amount (e.g., predicted network speed, download amount, upload amount, etc.), a predicted usage type (e.g., email, streaming, web browsing, application usage, data upload / download rates, etc.), or other predictions or combinations thereof.

[0059] In operation 408, the credential server 114 associates a geofence with the PP SSID profile 118. The geofence may be, for example, a room (e.g., a hotel room), a building (e.g., a hotel area), a city area (e.g., a downtown city center), or another geofence.

[0060] In operation 410, the credential server 114 associates a time-based validity limit with the PP SSID profile 118. The validity limit may include a date and / or time when the PP SSID profile 118 goes out of validity and any associated PP SSID connections 124 are terminated. As one example, the validity limit may be associated with a check-out date and check-out time of a hotel that owns the WAP 108 and / or the credential server 114. As another example, the validity limit may be associated with the length of a conference that is renting network use of the WAP 108 and / or the credential server 114.

[0061] In operation 412, the credential server 114 associates access parameters with the PP SSID profile 118. The access parameters may include a PP SSID network name, a PPS SSID password, etc. As an example, the PP SSID password may include a biometric password, where the biometric password is based on face recognition, voice recognition, fingerprint identification, iris recognition, retina recognition, stride recognition, etc. As another example, the PP SSID password may include a numeric password, an alphabetic password, an alphanumeric password, a pattern-based password, etc.

[0062] In operation 414, the credential server 114 outputs the PP SSID profile 118. Outputting the PP SSID profile 118 may include storing the PP SSID profile 118 in the credential server 114, transmitting data associated with the PP SSID profile 118 to the WAP 108, or transmitting data associated with the PP SSID profile 118 to the personal computing device 102, or a combination thereof.

[0063] The foregoing operations may be completed in any order and are not limited to those described. Furthermore, some, all, or none of the foregoing operations may be completed while remaining within the spirit and scope of the present disclosure.

[0064] 5, a flow chart of an example method 500 for predictively configuring a PP SSID profile 118 is shown, in accordance with some embodiments of the present disclosure. In some embodiments, method 500 is a sub-method of method 300 and is an example of operation 308 of FIG. 3. Method 500 may be implemented by the credential server 114, or another hardware or software or both configuration.

[0065] In operation 502, the credential server 114 generates a predicted date and time of a PP SSID request for a given registration profile stored in the registration profile database 120. Operation 502 may include using a machine learning algorithm, such as the machine learning algorithm previously discussed with respect to FIG. 4. In such an embodiment, the input to the machine learning algorithm may be the registration profile or a portion thereof, and the output may be a predicted date and time of the next PP SSID request. In other embodiments, the future PP SSID request may be manually entered by a user updating the registration profile, where the user indicates that they desire a PP SSID connection 124 at a specific date and time in the future (or a recurring date and time in the future, such as every Monday at 11:00 a.m. for a weekly meeting at a hotel conference center).

[0066] In operation 504, the credential server 114 configures (e.g., provisions, generates, creates, etc.) the PP SSID profile 118 for the registration profile from operation 502 within a period (e.g., 1 hour, 5 minutes, etc.) prior to the predicted date and time.

[0067] In operation 506, the credential server 114 provides the personal computing device 102 (via the WAP 108) with the relevant information of the PP SSID profile 118 configured in operation 504, thereby enabling the personal computing device 102 to establish a PP SSID connection 124 within the second period of the predicted date and time using the relevant information of the PP SSID profile 118. The relevant information may include one or more of a PP SSID network name, a PP SSID password, validity limit information, terms of use information, etc.

[0068] The foregoing operations may be completed in any order and are not limited to those described. Furthermore, some, all, or none of the foregoing operations may be completed while remaining within the spirit and scope of the present disclosure.

[0069] 6, a flowchart of an example method 600 for implementing a PP SSID connection 124 is shown, in accordance with various embodiments of the present disclosure. In some embodiments, the method 600 is performed by the WAP 108 or another hardware or software configuration or both.

[0070] In operation 602, the WAP 108 receives registration information from the personal computing device 102. The registration information may include a name, an email, a sign-in name (e.g., a screen name, a username), an alphanumeric identifier, an address, a password (e.g., an alphanumeric password, a personal identification number (PIN), biometric data relating to a fingerprint, face recognition, voice recognition, iris / retina / eye information, or other biometric data or combinations thereof, etc.), context information (e.g., calendar information relating to a planned activity, area, or time, or combinations thereof, etc.), etc. The WAP 108 may receive the registration information based on a user input to the personal computing device 102, the user input being an input to an application, a web page, etc. In some embodiments, the registration information is generated automatically based on, for example, the location of the personal computing device 102, the MAC address of the personal computing device 102, etc.

[0071] In operation 604, the WAP 108 sends the registration information to the credential server 114, which may determine whether the registration information corresponds to an existing registration profile or whether a new registration profile should be created.

[0072] In operation 606, the WAP 108 receives the PP SSID profile 118 from the credential server 114, and in operation 608, the WAP 108 provides information related to the PP SSID profile 118 to the personal computing device 102. Operation 608 may include, for example, sending a PP SSID network name and a PP SSID password to the personal computing device 102 so that a user of the personal computing device 102 can initiate a PP SSID connection 124 with the WAP 108 using the PP SSID network name and the PP SSID password.

[0073] In operation 610, the WAP 108 establishes a PP SSID connection 124 for the personal computing device 102 to access the Internet 126. In some embodiments, operation 610 includes the personal computing device 102 successfully authenticating with the WAP 108 for use of the PP SSID connection 124 using credentials associated with the PP SSID profile 118. In such embodiments, the authentication may be performed on an authentication web page associated with the WAP 108 that is presented to the personal computing device 102.

[0074] In operation 612, the WAP 108 determines whether the PP SSID profile 118 is out of validity. In various embodiments, the WAP 108 determines whether the PP SSID profile 118 is out of validity, or the WAP 108 receives an indication that the PP SSID profile 118 is out of validity from another source (e.g., the credential server 114, the PP SSID configuration engine 116, etc.). The validity of the PP SSID may be related to date, time, location, usage, or other factors, or a combination thereof.

[0075] If the WAP 108 determines that the PP SSID profile 118 is not out of range or if the WAP 108 determines that it has not received information that the PP SSID profile 118 is out of range (612: no), the method 600 returns to operation 610 to maintain the PP SSID connection 124. If the WAP 108 determines that the PP SSID profile 118 is out of range or if the WAP 108 receives an indication that the PP SSID profile 118 is out of range (612: yes), the method 600 proceeds to operation 614.

[0076] In operation 614, the WAP 108 terminates the PP SSID connection 124 and / or deletes data associated with the PP SSID connection 124 or the PP SSID profile 118, or both. In some embodiments, operation 614 includes deleting data from the WAP 108 cache relating to the PP SSID connection 124 or the PP SSID profile 118, or both.

[0077] The foregoing operations may be completed in any order and are not limited to those described. Furthermore, some, all, or none of the foregoing operations may be completed while remaining within the spirit and scope of the present disclosure.

[0078] 7, a flowchart of an example method 700 for using a PP SSID connection 124 on a personal computing device 102 is shown, in accordance with an embodiment of the present disclosure. In some embodiments, the method 700 is implemented by the personal computing device 102, or another hardware or software configuration, or both.

[0079] In operation 702, the personal computing device 102 is turned on (eg, powered on, booted, an application associated with the PP SSID functionality is launched, etc.).

[0080] In operation 704, the personal computing device 102 interfaces with a publicly advertised SSID of a WAP 108 (eg, a hotel guest network, a restaurant guest network, etc.).

[0081] In operation 706, the personal computing device 102 is redirected to an authentication web page of the WAP 108. In operation 708, the personal computing device 102 provides registration information from the personal computing device 102 to the WAP 108.

[0082] In operation 710, the personal computing device 102 receives information regarding the configured PP SSID profile 118 from the WAP 108. In some embodiments, the PP SSID information includes a PP SSID network name or a PP SSID password or both, allowing the personal computing device 102 to initiate a PP SSID connection 124 by entering the PP SSID network name and the PP SSID password into the WAP 108 via an interface of the personal computing device 102.

[0083] In operation 712, the personal computing device 102 accesses the Internet 126 using the PP SSID connection 124. In some embodiments, the personal computing device 102 is the only device accessing the network using the PP SSID connection 124. Further, in some embodiments, other devices cannot see the PP SSID connection 124. Further, in some embodiments, the PP SSID connection 124 is encrypted.

[0084] In operation 714, the personal computing device 102 may determine whether the PP SSID profile 118 is out of validity. In some embodiments, operation 714 includes determining whether a current date and time is past a validity limit date and time. In some embodiments, operation 714 includes determining whether a current location of the personal computing device 102 is outside a predefined geofence associated with the PP SSID profile 118. In some embodiments, operation 714 includes determining whether the personal computing device 102 has received an indication (e.g., from the WAP 108 or the credential server 114) that the PP SSID profile 118 is out of validity.

[0085] If the PP SSID profile 118 is not out of validity limits (714: no), the method 700 returns to operation 712, where the PP SSID connection 124 is maintained. If the PP SSID profile 118 is out of validity limits (714: yes), the method 700 proceeds to operation 716, where the PP SSID connection 124 is terminated. In some embodiments, operation 716 further includes deleting data associated with the PP SSID connection 124 (e.g., deleting data in a cache of the personal computing device 102 that was generated as a result of using the PP SSID connection 124).

[0086] The foregoing operations may be completed in any order and are not limited to those described. Furthermore, some, all, or none of the foregoing operations may be completed while remaining within the spirit and scope of the present disclosure.

[0087] 8A, an interface functional diagram of a device 800 at a first time for requesting a PP SSID session is shown, according to an embodiment of the present disclosure. The device 800 at a first time may include on its display a window of a PP SSID application 802 running on the device 800 at a first time. The PP SSID application 802 may display a public SSID connection 804 being used to connect to the WAP 108. The device 800 at a first time may be directed to an authentication web page 806 associated with the WAP 108. A user of the device 800 at a first time may enter registration information into display fields 808 and submit the registration information to the credential server 114 via the WAP 108 by requesting a PP SSID session using a PP SSID request button 810.

[0088] 8B, an interface functional diagram of a device 812 at a second time for logging into a configured PP SSID channel is illustrated, according to some embodiments of the present disclosure. The device 812 at a second time presents login information 814 received from the credential server 114 via the WAP 108 associated with the configured PP SSID profile 118. The login information 814 may include, for example, a PP SSID network name, a PP SSID password, validity limit information (e.g., validity limit date and time, amount of usage, type of usage, area of ​​usage, etc.), encryption information, etc. The device 812 at the second time may further present a PP SSID login screen 816 that may receive a PP SSID network name 818 and a PP SSID password 820 based on user input. The device 812 at the second time may further include a login to PP SSID session button 822 or other initiation interface element for transmitting login credentials from the PP SSID login screen 816 to the WAP 108 or the credential server 114 or both. Upon successful establishment of the PP SSID connection 124, the device 812 at the second time may display a first indicator 824 of the PP SSID connection 124, which may have any number of patterns, colors, shapes, sizes, etc.

[0089] 9A, an interface functional diagram of a device 900 at a third time for displaying a PP SSID lifetime limit warning is shown, according to some embodiments of the present disclosure. In some embodiments, the device 900 at a third time can include a second indicator 902 that symbolizes the approaching lifetime limit of the PP SSID session, which can be different (e.g., a different color, pattern, shape, etc.) from the first indicator 824 discussed with respect to FIG. 8B. The device 900 at a third time can also display a connection lifetime limit warning 904 and prompt the user to update the connection 906, which can be either to generate a new PP SSID profile 118 for the new PP SSID connection 124 or to extend the lifetime limit of the current PP SSID profile 118 and the corresponding PP SSID connection 124.

[0090] 9B, an interface functional diagram of a device 908 at a fourth time for notifying a user of an out-of-validity PP SSID session is shown, according to some embodiments of the present disclosure. The device 908 at the fourth time may include a third indicator 910 different from the first indicator 824 and the second indicator 902. The third indicator 910 may represent a terminated PP SSID network connection. Additionally, the device 908 at the fourth time may present a connection termination notification 912.

[0091] The diagrams of FIGS. 8A-8B and 9A-9B may include more, fewer, or different features, or combinations thereof, than explicitly shown while remaining within the spirit and scope of the disclosure.

[0092] 10 illustrates a block diagram of an example PP SSID manager 122 according to some embodiments of the present disclosure. The PP SSID manager 122 can be hardware or software or a combination of both configured to manage PP SSID connections. The PP SSID manager 122 can reside in one or more of the personal computing device 102, the WAP 108, or the credential server 114, or a combination thereof.

[0093] In various embodiments, PP SSID manager 122 can perform the methods described in Figures 2-7 or the functions described in Figures 1, 8A-8B, and 9A-9B, or combinations thereof. In some embodiments, PP SSID manager 122 receives instructions for the aforementioned methods and functions by downloading processor-executable instructions from a remote data processing system over network 1050. In other embodiments, PP SSID manager 122 provides instructions for the aforementioned methods and / or functions to a client machine, which performs the methods or portions of the methods based on the instructions provided by PP SSID manager 122.

[0094] The PP SSID manager 122 includes a memory 1025, a storage 1030, an interconnect 1020 (e.g., a BUS), one or more CPUs 1005 (e.g., processors), an I / O device interface 1010, an I / O device 1012, and a network interface 1015.

[0095] Each CPU 1005 retrieves and executes programming instructions stored in memory 1025 or storage 1030. The interconnect 1020 is used to move data, such as programming instructions, between the CPUs 1005, the I / O device interface 1010, the storage 1030, the network interface 1015, and the memory 1025. The interconnect 1020 may be implemented using one or more buses. In various embodiments, the CPUs 1005 may be a single CPU, multiple CPUs, or a single CPU with multiple processing cores. In some embodiments, the CPUs 1005 may be a digital signal processor (DSP). In some embodiments, the CPU 1005 includes one or more 3D integrated circuits (3DICs) (e.g., 3D wafer level packaging (3DWLP), 3D interposer-based integration, 3D stacked IC (3D-SIC), monolithic 3D IC, 3D heterogeneous integration, 3D system-in-package (3DSiP), or package-on-package (PoP) CPU configurations, or combinations thereof). Memory 1025 is included generally representative of random access memory (e.g., static random access memory (SRAM), dynamic random access memory (DRAM), or flash). Storage 1030 is included generally representative of non-volatile memory, such as a hard disk drive, solid state device (SSD), removable memory card, optical storage, or flash memory device. In alternative embodiments, storage 1030 may be replaced by a storage area network (SAN) device, cloud, or other device connected to PP SSID manager 122 via I / O device interface 1010 or to network 1050 via network interface 1015.

[0096] In some embodiments, memory 1025 stores instructions 1060. However, in various embodiments, instructions 1060 are stored partially in memory 1025 and partially in storage 1030, completely in memory 1025, completely in storage 1030, or accessed over network 1050 via network interface 1015.

[0097] The instructions 1060 may be processor-executable instructions for performing any portion or all of any of the methods of Figures 2-7 or any of the functions discussed in Figures 1, 8A-8B, and / or 9A-9B, or a combination thereof.

[0098] In various embodiments, the I / O device 1012 includes an interface capable of presenting information and receiving input. For example, the I / O device 1012 can present information to and receive input from a user interacting with the PP SSID manager 122.

[0099] The PP SSID manager 122 is connected to a network 1050 via a network interface 1015. The network 1050 may include a physical network, a wireless network, a cellular network, or another network.

[0100] Although this disclosure includes detailed descriptions of cloud computing, it is understood that implementation of the teachings described herein is not limited to a cloud computing environment. Rather, embodiments of the invention may be practiced in connection with any other type of computing environment now known or later developed.

[0101] Cloud computing is a model of service delivery for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal administrative effort or interaction with a service provider. The cloud model can include at least five characteristics, at least three service models, and at least four deployment models.

[0102] Its features are as follows. On-Demand Self-Service: Cloud consumers can automatically and unilaterally provision computing capacity, such as server time and network storage, as they need it, without the need for human interaction with the provider of the service. Pervasive Network Access: Functionality is available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin- or thick-client platforms (e.g., cell phones, laptops, and PDAs). Resource Pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources being dynamically allocated and reallocated on demand. Consumers are location independent in that they generally have no control or knowledge of the exact location of the resources they are provided with, although they may be able to identify a location at a higher level of abstraction (e.g., country, state, or data center). Rapid Elasticity: Capabilities can be rapidly provisioned and rapidly scaled out, and rapidly released and rapidly scaled in, rapidly and elastically, sometimes automatically. To the consumer, the capabilities available for provisioning often appear unlimited, and can be purchased in any quantity at any time. Metered Services: Cloud systems automatically control and optimize resource usage by using metering capabilities at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both providers and consumers of the services being used. The service model is as follows: Software as a Service (SaaS): The functionality provided to the consumer is the use of the provider's applications running on a cloud infrastructure. These applications are accessible from a variety of client devices through thin-client interfaces such as web browsers (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or individual application functions, with the expected exception of limited user-specific application configuration settings. Platform as a Service (PaaS): The functionality offered to the consumer is the deployment onto a cloud infrastructure of applications created or acquired by the consumer, generated using programming languages ​​and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but does have control over the deployed applications and, in some cases, the application hosting environment configuration. Infrastructure as a Service (IaaS): The capability provided to a consumer is to provision processing, storage, network, and other basic computing resources on which the consumer can deploy and run any software, which may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but has control over the operating systems, storage, deployed applications, and possibly limited control over network component (e.g., host firewall) selection.

[0103] The deployment model is as follows: Private Cloud: The cloud infrastructure is operated exclusively for an organization. It can be managed by that organization or a third party and can exist on-premise or off-premise. Community Cloud: Infrastructure shared by several organizations to support a specific community with common concerns (e.g., mission, security requirements, policies, and compliance considerations). It can be managed by those organizations or by a third party and can reside on-premise or off-premise. Public Cloud: A cloud infrastructure is a combination of two or more clouds (private, community, or public) that remain unique entities but are tied together by standardized or proprietary technologies that enable data and application portability (e.g., cloud bursting for load balancing between clouds).

[0104] A cloud computing environment is a service oriented approach that focuses on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing is an infrastructure that includes a network of interconnected nodes.

[0105] 11, an exemplary cloud computing environment 50 is shown. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 with which local computing devices used by cloud consumers, such as a personal digital assistant (PDA) or cell phone 54A, a desktop computer 54B, a laptop computer 54C, or an automobile computer system 54N, or combinations thereof, can communicate. The nodes 10 can communicate with each other. They can be physically or virtually grouped (not shown) into one or more networks, such as a private cloud, a community cloud, a public cloud, or a hybrid cloud, or combinations thereof, as described above. This enables the cloud computing environment 50 to provide infrastructure, platform, or software, or combinations thereof, as a service without the cloud consumer having to maintain resources on a local computing device. It will be understood that the types of computing devices 54A-N shown in FIG. 13 are intended as examples only, and that the computing nodes 10 and cloud computing environment 50 can communicate with any type of computerized device via any type of network or network-addressable connection (e.g., using a web browser) or both.

[0106] 12, a set of functional abstraction layers provided by cloud computing environment 50 (FIG. 11) is shown. It should be understood in advance that the components, layers, and functions shown in FIG. 12 are intended to be merely illustrative, and embodiments of the present invention are not limited thereto. As shown, the following layers and corresponding functions are provided:

[0107] Hardware and software layer 60 includes hardware and software components. Examples of hardware components include mainframe 61, RISC (Reduced Instruction Set Computer) architecture based servers 62, servers 63, blade servers 64, storage devices 65, and networks and network components 66. In some embodiments, software components include network application server software 67 and database software 68.

[0108] The virtualization layer 70 provides an abstraction layer that can provide the following examples of virtual entities: virtual servers 71, virtual storage 72, virtual networks including virtual private networks 73, virtual applications and operating systems 74, and virtual clients 75.

[0109] In one example, the management layer 80 may provide the functions described below. Resource provisioning 81 provides dynamic procurement of computing and other resources utilized to execute tasks within the cloud computing environment. Metering and pricing 82 provides cost tracking as resources are utilized within the cloud computing environment and charging or billing for the consumption of these resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, and protection for data and other resources. User portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides allocation and management of cloud computing resources such that required service levels are met. Service level agreement (SLA) planning and fulfillment 85 provides pre-provisioning and procurement of cloud computing resources where future requirements are forecasted according to SLAs.

[0110] The workload layer 90 provides examples of functionality that can utilize a cloud computing environment. Examples of workloads and functionality that can be provided from this layer include mapping and navigation 91, software development and lifecycle management 92, virtual classroom instructional delivery 93, data analytics processing 94, transaction processing 95, and PP SSID management 96.

[0111] The embodiments of the invention may be a system, a method, or a computer program product, or a combination thereof, at any possible level of technical detail of integration. The computer program product may include one or more computer-readable storage media having computer-readable program instructions thereon for causing a processor to perform aspects of the invention.

[0112] A computer readable storage medium may be any tangible device capable of holding and storing instructions for use by an instruction execution device. A computer readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above. A non-exhaustive list of more specific examples of computer readable storage media includes the following: portable computer diskettes, hard disks, random access memory (RAM), read only memory (ROM), erasable programmable read only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read only memory (CD-ROM), digital versatile disk (DVD), memory sticks, floppy disks, mechanically encoded devices such as punch cards or ridge-in-groove structures having instructions recorded thereon, and any suitable combination of the above. As used herein, a computer-readable storage medium should not be construed as a transitory signal per se, such as an electric wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., light pulses through a fiber optic cable), or an electrical signal sent through a wire.

[0113] The computer readable program instructions described herein may be downloaded from a computer readable storage medium into each computing / processing device, or may be downloaded to an external computer or storage device over a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical transmission fiber, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer readable program instructions from the network and transfers the computer readable program instructions for storage in a computer readable storage medium in the respective computing / processing device.

[0114] The computer readable program instructions for carrying out the operations of the present invention may be either assembler instructions, instruction set architecture (ISA) instructions, machine language instructions, machine dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or source or object code written in any combination of one or more programming languages, including object oriented programming languages ​​such as Smalltalk, C++, and conventional procedural programming languages ​​such as the "C" programming language, or similar programming languages. The computer readable program instructions may be executed entirely on the user's computer, partially on the user's computer as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) can execute computer readable program instructions by utilizing state information of the computer readable program instructions to individualize the electronic circuitry to perform aspects of the invention.

[0115] Aspects of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.

[0116] These computer readable program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, whereby the instructions executed by the processor of the computer or other programmable data processing apparatus create means for performing the functions / operations specified in one or more blocks of the flowcharts and / or block diagrams. These computer readable program instructions may also be stored in a computer readable storage medium capable of directing a computer programmable data processing apparatus, or other device, or combination thereof, to function in a particular manner, whereby the computer readable storage medium having instructions stored therein includes an article of manufacture including instructions implementing aspects of the functions / operations specified in one or more blocks of the flowcharts and / or block diagrams.

[0117] The computer program instructions may be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to generate a computer-implemented process, such that the instructions executing on the computer, other programmable apparatus, or other device perform the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0118] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or a subset of instructions, including one or more executable instructions for performing a specified logical function. In some alternative implementations, the functions shown in the blocks may occur in a different order than that shown in the figures. For example, two blocks shown in succession may in fact be executed substantially simultaneously, or these blocks may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0119] It will be appreciated that the process software (e.g., any of the instructions stored in instructions 1060 of FIG. 10 and / or any subset of the methods described with respect to FIGS. 2-7 and / or any of the functions discussed in FIGS. 1, 8A-8B, and 9A-9B) may be deployed by manually loading directly onto the client, server, and proxy computers by loading a storage medium such as a CD, DVD, etc., but the process software may also be automatically or semi-automatically deployed onto computer systems by sending the process software to a central server or central servers. The process software is then downloaded to the client computer that will execute the process software. Alternatively, the process software is sent directly to the client system via email. The process software is then detached or loaded into the directory by executing a set of program instructions that detach the process software to the directory. Another alternative approach is to send the process software directly to a directory on the hard drive of the client computer. If there is a proxy server, the process selects the proxy server code, determines on which computer to place the proxy server code, transmits the proxy server code, and then installs the proxy server code on the proxy computer. The process software is transmitted to the proxy server and then stored on the proxy server.

[0120] Embodiments of the invention may also be provided as part of a service engagement with a client company, non-profit organization, government agency, internal organizational structure, etc. These embodiments may include configuring a computer system to perform some or all of the methods described herein, and deploying software, hardware, and web services to implement them. These embodiments may also include analyzing a client's operations, making recommendations in response to the analysis, building a system that implements a subset of the recommendations, integrating the system into existing processes and infrastructure, metering usage of the system, allocating costs to users of the system, and charging, invoicing (e.g., generating an invoice), or otherwise receiving payment for usage of the system.

[0121] The terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting of the invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural unless the context clearly indicates otherwise. Furthermore, it will be understood that as used herein, the terms "comprise" and / or "comprising" specify the presence of the stated features, integers, steps, operations, elements or components, or combinations thereof, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups or combinations thereof. In the preceding detailed description of exemplary embodiments of various embodiments, reference has been made to the accompanying drawings, in which like numerals represent like elements, which form a part hereof, and in which are shown, by way of example, specific exemplary embodiments in which the various embodiments may be practiced. These embodiments have been described in sufficient detail to enable one skilled in the art to practice them, but other embodiments may be used and logical, mechanical, electrical, and other changes may be made without departing from the scope of the various embodiments. In the preceding description, numerous specific details have been set forth in order to provide a thorough understanding of the various embodiments. However, various embodiments may be practiced without these specific details, and in other instances, well-known circuits, structures and techniques have not been shown in detail so as not to obscure the embodiments.

[0122] Different instances of the word "embodiment" as used herein do not necessarily refer to the same embodiment, but may. Any data and data structures shown or described herein are merely examples, and other embodiments may use different amounts of data, types of data, fields, numbers and types of fields, field names, numbers and types of rows, records, entries, or organization of data. Also, any data may be combined with logic, so that separate data structures may not be necessary. Thus, the foregoing detailed description should not be construed in a limiting sense.

[0123] The description of various embodiments has been presented for illustrative purposes, but is not intended to be exhaustive or to limit the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terms used in this specification have been selected to best explain the principles of the embodiments, practical applications, or improvements of the technology over the technology found in the market, or to enable those skilled in the art to understand the embodiments disclosed herein.

[0124] To further illustrate aspects of the present disclosure, several variations of the present disclosure will now be described.

[0125] A first variation relates to a system including a credential server that stores a personal-public (PP) service set identifier (SSID) profile configured according to registration information provided by a personal computing device, and further includes a wireless access point (WAP) communicatively coupled to the credential server and configured to implement a PP SSID connection using the PP SSID profile, creating a single-device, single-use, password-protected, private, and encrypted networking channel between the personal computing device and the Internet.

[0126] A second variation based on the first variation further includes that the PP SSID profile is associated with an availability limit, and the PP SSID connection is configured to be terminated according to the availability limit.

[0127] A third variation based on the second variation further includes that the effective limit is selected from the group consisting of time, amount of usage, and type of usage.

[0128] A fourth variation based on the second or third variation further includes that the validity limit is based on a location of the personal computing device and a geofence defined in the PP SSID profile, and the PP SSID connection is terminated when the personal computing device is outside the geofence.

[0129] A fifth variation relates to a computer-implemented method including receiving, at a credential server, registration information from a wireless access point (WAP) in response to the personal computing device connecting to a publicly advertised service set identifier (SSID) provided by the WAP. The method further includes configuring, by the credential server, a personal-public (PP) SSID profile based on the registration information. The method further includes providing, via the WAP, to the personal computing device, a PP SSID network name and a PP SSID password of the PP SSID profile, the PP SSID profile enabling the personal computing device to establish a PP SSID connection between the personal computing device and the Internet, the PP SSID profile including a single-device, single-use, password-protected, private, and encrypted networking channel.

[0130] A sixth variation based on the fifth variation further includes associating a media access control (MAC) address of the personal computing device with the PP SSID profile.

[0131] A seventh variation based on the fifth or sixth variation further includes, in response to determining that the registration information is not associated with a profile in the registration profile database, creating a registration profile associated with the registration information.

[0132] An eighth variation based on the fifth, sixth, or seventh variation further includes determining that the PP SSID profile is out of validity and terminating the PP SSID connection in response to determining that the PP SSID profile is out of validity.

[0133] A ninth variation based on the eighth variation further includes determining that the PP SSID profile is out of validity limit, the determining that the current time is after the validity limit time associated with the PP SSID profile.

[0134] A tenth variation based on the eighth or ninth variation further includes that determining that the PP SSID profile is outside a validity limit includes determining that the current location is outside a geofence associated with the PP SSID profile.

[0135] An eleventh variation based on any of the fifth to tenth variations includes where configuring a personal-public (PP) SSID profile based on the registration information further includes receiving location information about the personal computing device, receiving context information about the personal computing device, performing machine learning on the location information and context information to generate a predicted usage area and a predicted usage time associated with the personal computing device, associating a geofence with the PP SSID profile based on the predicted usage area, associating a validity limit for the PP SSID profile based on the predicted usage time, and outputting the PP SSID profile with the geofence and validity limit.

[0136] A twelfth variation based on any of the fifth through eleventh variations includes where configuring a personal-public (PP) SSID profile based on the registration information further includes generating a predicted time of a PP SSID request associated with the personal computing device, and where providing the PP SSID network name and PP SSID password of the PP SSID profile to the personal computing device occurs within a period of time prior to the predicted time.

[0137] A thirteenth variation is directed to a computer program product including a computer-readable storage medium having program instructions embodied therein, the program instructions executable by a processor causing the processor to perform a method including receiving, at a credential server, from a wireless access point (WAP) registration information from the personal computing device in response to the personal computing device connecting to a publicly advertised service set identifier (SSID) provided by the WAP. The method further includes configuring, by the credential server, a personal-public (PP) SSID profile based on the registration information. The method further includes providing, via the WAP, to the personal computing device, a PP SSID network name and a PP SSID password of the PP SSID profile, the PP SSID profile enabling the personal computing device to establish a PP SSID connection between the personal computing device and the Internet, the PP SSID connection including a single-device, single-use, password-protected, unpublished, and encrypted networking channel.

[0138] A fourteenth variation based on the thirteenth variation further includes determining that the PP SSID profile is out of validity limits, and terminating the PP SSID connection in response to determining that the PP SSID profile is out of validity limits.

[0139] A fifteenth variation based on the fourteenth variation further includes that determining that the PP SSID profile is out of validity limit includes determining that the current time is after the validity limit time associated with the PP SSID profile.

[0140] A sixteenth variation based on the fourteenth or fifteenth variation further includes that determining that the PP SSID profile is outside a validity limit includes determining that the current location is outside a geofence associated with the PP SSID profile.

[0141] A seventeenth variation based on any of the thirteenth to sixteenth variations includes where configuring a personal-public (PP) SSID profile based on the registration information further includes receiving location information about the personal computing device, receiving context information about the personal computing device, performing machine learning on the location information and context information to generate a predicted usage area and a predicted usage time associated with the personal computing device, associating a geofence with the PP SSID profile based on the predicted usage area, associating a validity limit for the PP SSID profile based on the predicted usage time, and outputting the PP SSID profile with the geofence and validity limit.

[0142] An eighteenth variation based on any of the thirteenth to seventeenth variations includes where configuring a personal-public (PP) SSID profile based on the registration information further includes generating a predicted time of a PP SSID request associated with the personal computing device, and providing the PP SSID network name and PP SSID password of the PP SSID profile to the personal computing device includes occurring within a period of time prior to the predicted time.

[0143] A nineteenth variation relates to a system including a processor and a computer-readable storage medium storing program instructions, the processor configured to execute the program instructions to cause the processor to perform a method including receiving, at a credential server, from a wireless access point (WAP) registration information from the personal computing device in response to the personal computing device connecting to a publicly advertised service set identifier (SSID) provided by the WAP, the method further including configuring, by the credential server, a personal-public (PP) SSID profile based on the registration information, the method further including providing, via the WAP, to the personal computing device, a PP SSID network name and a PP SSID password of the PP SSID profile, the PP SSID profile enabling the personal computing device to establish a PP SSID connection between the personal computing device and the Internet, the PP SSID profile including a single-device, single-use, password-protected, unpublished, and encrypted networking channel.

[0144] A twentieth variation based on the nineteenth variation further includes the program instructions being downloaded into the computer-readable storage medium from a remote data processing system.

[0145] A twenty-first variation relates to a computer-implemented method that includes connecting a personal computing device to a publicly published service set identifier (SSID). The method further includes providing registration information to an authentication web page in response to connecting to the publicly published SSID. The method further includes receiving a personal-public (PP) SSID network name and a PP SSID password in response to providing the registration information to the authentication web page. The method further includes accessing an in-target using the PP SSID connection by establishing a single-device, single-use, password-protected, unpublished, and encrypted networking channel between the personal computing device and the Internet.

[0146] A twenty-second variation based on the twenty-first variation further includes displaying, on the personal computing device, an indicator regarding the PP SSID connection.

[0147] A twenty-third variation based on the twenty-second variation further includes displaying a connection lifetime limit warning on the personal computing device at a time within a period of time prior to a lifetime limit associated with the PP SSID connection.

[0148] A twenty-fourth variation based on the twenty-second or twenty-third variation further includes displaying, on the personal computing device, a connection termination warning in response to a location of the personal computing device within a boundary of a geofence associated with the PP SSID profile.

[0149] A 25th variation, based on any of the 21st through 24th variations, further includes that the PP SSID password comprises a biometric password selected from the group consisting of a voice-based password, a face-based password, a fingerprint-based password, and a gait-based password.

Claims

1. a credential server that stores a Personal-Public (PP) Service Set Identifier (SSID) profile configured according to registration information provided by the personal computing device; a wireless access point (WAP) communicatively coupled to the credential server, the WAP configured to implement a PP SSID connection by using the PP SSID profile, creating a single-device, single-use, password-protected, private, and encrypted networking channel between the personal computing device and the Internet; Including, the PP SSID profile is configured as a PP SSID profile having a geofence and an availability limit by associating a geofence and an availability limit with the PP SSID profile based on a predicted area of ​​use, and a predicted time, amount, or type of use, or a combination thereof, associated with the personal computing device, the predicted area, and a combination thereof, generated by performing machine learning on location information for the personal computing device and contextual information for the personal computing device. system.

2. The system of claim 1 , wherein the PP SSID connection is configured to be terminated according to the validity limit.

3. The system of claim 1 or claim 2, wherein the PP SSID connection is terminated when the personal computing device is outside the geofence.

4. 1. A computer-implemented method comprising: receiving, at a credential server, from a wireless access point (WAP) registration information from the personal computing device in response to the personal computing device connecting to a publicly advertised service set identifier (SSID) provided by the WAP; configuring, by the credential server, a personal-public (PP) SSID profile based on the registration information; receiving location information regarding the personal computing device; receiving contextual information regarding the personal computing device; performing machine learning on the location information and the context information to generate a predicted area of ​​use, and a predicted time of use, amount of use, or type of use, or a combination thereof, associated with the personal computing device; Associating a geofence with the PP SSID profile based on the predicted area of ​​use; associating an availability limit with the PP SSID profile based on the predicted time of use, the predicted amount of use, or the predicted type of use, or a combination thereof; and outputting the PP SSID profile having the geofence and the validity limit. The above configuration, providing, via the WAP, a PP SSID network name and a PP SSID password of the PP SSID profile to the personal computing device, the PP SSID profile enabling the personal computing device to establish a PP SSID connection between the personal computing device and the Internet, the PP SSID connection comprising a single-device, single-use, password-protected, private, and encrypted networking channel; A method comprising:

5. The method of claim 4 , further comprising associating a media access control (MAC) address of the personal computing device with the PP SSID profile.

6. The method of claim 4 or claim 5, further comprising, in response to determining that the registration information is not associated with a profile in an registration profile database, creating an registration profile associated with the registration information.

7. determining that the PP SSID profile is outside the validity limits; in response to determining that the PP SSID profile is outside the validity limit, terminating the PP SSID connection. The method of any one of claims 4 to 6, further comprising:

8. 8. The method of claim 7, wherein determining that the PP SSID profile is outside the validity limit comprises determining that a current time is after a time of the validity limit associated with the PP SSID profile.

9. determining that a current location of the personal computing device is outside the geofence associated with the PP SSID profile; and terminating the PP SSID connection in response to determining that a current location of the personal computing device is outside the geofence.

10. configuring the Personal-Public (PP) SSID profile based on the registration information; generating a predicted time for a PP SSID request associated with said personal computing device; Further comprising: providing the PP SSID network name and the PP SSID password of the PP SSID profile to the personal computing device occurs within a period of time prior to the predicted time; A method according to any one of claims 4 to 9.

11. A computer program comprising program instructions causing a computer to carry out a method according to any one of claims 4 to 10.

12. 12. A computer readable storage medium having stored thereon the computer program of claim 11.

13. A processor; a computer readable storage medium storing program instructions; wherein the processor executes the program instructions to: receiving, at a credential server, from a wireless access point (WAP) registration information from the personal computing device in response to the personal computing device connecting to a publicly advertised service set identifier (SSID) provided by the WAP; configuring, by the credential server, a personal-public (PP) SSID profile based on the registration information; receiving location information regarding the personal computing device; receiving contextual information regarding the personal computing device; performing machine learning on the location information and the context information to generate a predicted area of ​​use, and a predicted time of use, amount of use, or type of use, or a combination thereof, associated with the personal computing device; Associating a geofence with the PP SSID profile based on the predicted area of ​​use; associating an availability limit with the PP SSID profile based on the predicted time of use, the predicted amount of use, or the predicted type of use, or a combination thereof; and outputting the PP SSID profile having the geofence and the validity limit. The above configuration, providing, via the WAP, a PP SSID network name and a PP SSID password of the PP SSID profile to the personal computing device, the PP SSID profile enabling the personal computing device to establish a PP SSID connection between the personal computing device and the Internet, the PP SSID connection comprising a single-device, single-use, password-protected, private, and encrypted networking channel; configured to cause the processor to perform a method including: system.

14. 14. The system of claim 13, wherein the program instructions are downloaded into the computer readable storage medium from a remote data processing system.

15. 1. A computer-implemented method comprising: Connecting a personal computing device to a publicly announced Service Set Identifier (SSID); providing registration information to an authentication web page in response to connecting to the publicly published SSID; receiving a personal-public (PP) SSID network name and a PP SSID password in response to providing the registration information to the authentication web page; accessing the Internet using a PP SSID connection by establishing a single-device, single-use, password-protected, private, and encrypted networking channel between the personal computing device and the Internet; Including, a PP SSID profile used for the PP SSID connection is configured as a PP SSID profile having a geofence and an availability limit by associating a geofence and an availability limit with the PP SSID profile based on a predicted area of ​​use, and a predicted time, amount, or type of use associated with the personal computing device, the predicted area, and a combination thereof, generated by performing machine learning on location information related to the personal computing device and contextual information related to the personal computing device; method.

16. Displaying an indicator on the personal computing device regarding the PP SSID connection. The method of claim 15 further comprising:

17. displaying a connection availability limit warning on the personal computing device at a time within a period prior to the availability limit associated with the PP SSID profile.

20. The method of claim 16, further comprising:

18. displaying, on the personal computing device, a connection termination warning in response to a location of the personal computing device within a boundary of the geofence associated with the PP SSID profile.

18. The method of claim 16 or claim 17, further comprising:

19. 19. The method of any one of claims 15 to 18, wherein the PP SSID password comprises a biometric password selected from the group consisting of a voice-based password, a face-based password, a fingerprint-based password, and a gait-based password.

Citation Information

Patent Citations

  • System and method for selecting a wireless network

    JP2010541429A

  • Method and apparatus for wlan device pairing

    JP2017536046A

  • Centralized access point provisioning system and method of operation

    JP2018538748A