BLE Beacon Credential Provisioning for Guest Wi-Fi Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in efficiently sharing WiFi or Internet network access credentials with guests, as existing methods are time-consuming and expose owners to potential unauthorized access or theft of credentials.

Innovation Solution

Implementing a system that uses Bluetooth Low Energy (BLE) beacons to automatically detect and authorize guest devices, transmitting encrypted network access credentials only when the guest is within range and revoking them upon disconnection, with the option for administrators to remotely manage access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual credential sharing methods are used, then guests can access the network, but the process is time-consuming and security risks increase

Engineering Contradiction:
ImproveGuest network access processVSAvoidTime required for credential sharing
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring the network access control system and storing credential information before guests arrive. When a guest checks in via the mobile application, the system has already prepared the authentication mechanisms and can rapidly provision access without manual intervention, thus reducing the time required for credential sharing while maintaining security controls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing guests to autonomously check in through a mobile application without requiring manual credential distribution from network administrators. Guests can independently complete the check-in process, receive their access credentials, and connect to the network automatically, significantly reducing both the time required and the operational burden on administrators.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If access credentials are shared manually, then guests can connect to the network, but the risk of unauthorized access and credential theft increases

Engineering Contradiction:
ImproveNetwork access provisioningVSAvoidUnauthorized access and credential theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system introduces a mobile application as an intermediary between guests and the network access control system. This intermediary securely transmits credentials through encrypted communication channels, eliminates the need for manual credential sharing, and provides audit trails for all access operations. The intermediary layer protects against unauthorized access and credential theft while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces manual mechanical processes of credential distribution (such as physically writing down passwords or sharing WPS pins) with automated electronic credential provisioning through the mobile application. This substitution eliminates human error, prevents credential theft through manual handling, and provides secure, traceable access control while maintaining user-friendly operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If traditional credential distribution methods are used, then guests can access the network, but administrative control and monitoring are difficult

Engineering Contradiction:
ImproveGuest check-in efficiencyVSAvoidAccess management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves universality by implementing a multi-functional mobile application that handles multiple operations within a single platform: guest registration, credential distribution, network connection management, and administrative monitoring. This consolidated approach improves productivity by streamlining the check-in process while the centralized digital infrastructure simplifies administrative control and monitoring capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes key parameters of the access management system by transitioning from static, manual credential management to dynamic, automated electronic provisioning. This enables real-time monitoring capabilities, granular access control policies, and centralized administrative oversight without significantly increasing operational complexity for end users. The digital parameter changes allow for scalable deployment and flexible configuration.

Inventive Principle:
Principle #35Parameter changes

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution streamlines guest network access, enhances security by encrypting credentials, and allows administrators to manage access remotely, reducing the risk of unauthorized use and theft.

Implementation Method 1

Users may set up router devices at locations that offer Internet access to user devices (e.g., laptop computers, mobile phones, tablet computers, etc.). For example, WiFi routers establish wireless networks around the router device

Methodology Applied
Scientific EffectBluetooth Low Energy (BLE) transmission:

Implementation Method 2

transmitting encrypted network access credentials only when the guest is within range

Methodology Applied
Scientific EffectEncryption:

Data Source

PatentUS9900774B2Shared network connection credentials on check-in at a user's home location
Publication Date: 2018.02.20 PAYPAL INC
  • US9900774B2 patent drawing
  • US9900774B2 patent drawing
  • US9900774B2 patent drawing

AI summary

There are provided systems and methods for shared network connection credentials on check-in at a user's home location. A user may have a wireless network for accessing the Internet, such as a WiFi router, at a location for the user. The wireless network may be password protected to prevent unauthorized used. However, the user may further provide a beacon at the location for the location for the wireless network that provides short range wireless communications including a check-in option for other users visiting the location. Once the other users have used a device to check-in to the beacon, the beacon may be push the access credentials for the wireless network securely to the other users' devices. The secure access credentials may be configured to be wiped from the other users' devices after user, for example, when the other users' devices disconnect from the wireless network of the beacon.