Wireless Beacon Credential Distribution for Secure Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Administrators of secure wireless networks face challenges in managing access credentials for guests and users with varying security clearance levels, as existing solutions do not effectively prevent unauthorized usage or provide differentiated access levels without revealing sensitive information.
Innovation Solution
Implementing a system that uses wireless beacons, such as Bluetooth Low Energy (BLE) or LTE Direct, to provide access credentials to users, where administrative devices determine access rights and levels based on user identity verification, location, and actions, allowing for secure and differentiated network access without exposing credentials to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access credentials are provided to users for wireless network access, then network accessibility is improved, but credential security deteriorates as users may retain and misuse credentials on return visits
Solution Approach 1:
The system performs preliminary actions by providing access credentials only for the current visit duration. The credentials are automatically revoked when the user leaves the geographic area, preventing reuse on return visits. This resolves the contradiction by enabling easy access during the visit while maintaining security against future misuse.
Solution Approach 2:
The access credential validity is made dynamic rather than static. Credentials are tied to both time and geographic location, automatically becoming invalid when the user leaves the predefined area. This dynamic approach allows network accessibility during the visit while preventing credential security breaches on subsequent visits.
2Ease of manufacture
If uniform access credentials are provided to all users, then ease of distribution is improved, but differentiated access control deteriorates as all users gain equal network permissions
Solution Approach 1:
The system applies local quality by assigning different access permission levels to different users through customized access profiles. Each profile contains specific network resource permissions tailored to the user's needs. This allows easy credential distribution while implementing differentiated access control, as each user receives credentials with appropriate local permissions for their role.
3Measurement precision
If manual credential management is used for each user, then access control precision is improved, but system complexity deteriorates due to individual credential distribution and management
Solution Approach 1:
The system implements self-service by automatically generating, distributing, and revoking access credentials based on user check-in/check-out data. The geographic fencing and credential management are handled automatically without manual intervention. This maintains precise access control while eliminating the complexity of manual credential distribution and management for each user.
Solution Approach 2:
The system uses feedback from user check-in/check-out actions to automatically adjust credential validity. When users check out or leave the geographic area, the system receives feedback and automatically revokes credentials. This maintains precise access control based on actual user presence while reducing system complexity through automated feedback-driven management.
4Loss of information
If credentials remain visible to users after distribution, then user awareness of access is improved, but unauthorized usage risk deteriorates as users can share or misuse credentials
Solution Approach 1:
The system confirms user awareness of network access through preliminary confirmation actions during check-in, but credentials are designed to be non-transferable and automatically revoked upon leaving the area. This maintains user awareness of their active access while preventing unauthorized usage through automatic revocation and non-transferable credential design.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There are provided systems and methods for using a wireless beacon to provide access credentials to a secure network. A network access device, such as a WiFi router, may provide a secure wireless network requiring access credentials to access the network. For example, the network may be password protected to prevent unauthorized used. Additionally, the network may have various levels of use, such as access depending on a security clearance for a user or data transfer and usage rates. Each of the various levels of use may require a separate access credential. A wireless beacon may be configured to connect to user devices that are near or within an area covered by the network. The connection between a user device and the beacon may be utilized to determine the proper access credential for the user device and push the access credential to the user device.