Cloud Credential Distribution for Wireless Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Consumers face difficulties in configuring and securely connecting internet-enabled devices to wireless networks, particularly those without a rich user interface, leading to inconvenience and insecurity in credential distribution.

Innovation Solution

A cloud-based system that authenticates and securely delivers private network credentials to wireless devices, using a credential management system to verify authorized users and encrypt credentials, allowing devices to connect to networks without manual input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual WiFi credential entry is required for device connection, then network security is maintained, but consumer convenience and ease of operation deteriorates

Engineering Contradiction:
Improveease of device connectionVSAvoidcredential distribution security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cloud-based credential management system as an intermediary between the consumer and the device. The system receives credentials from the consumer's authenticated account and automatically distributes them to authorized devices through the cloud, eliminating manual entry while maintaining security through centralized authentication and authorization controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service credential distribution where the cloud management system automatically provisions credentials to devices based on pre-configured authorization rules. Once the consumer authenticates their account and authorizes device access, the system autonomously handles credential generation, distribution, and management without requiring manual intervention for each device connection.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If WiFi credentials are pre-configured in devices, then connection ease is improved, but adaptability to new networks and routers deteriorates

Engineering Contradiction:
Improveconnection easeVSAvoidnetwork compatibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic credential management where the cloud system can update device credentials at any time based on current network conditions. Devices periodically check with the cloud service for updated credentials or authorization changes, allowing seamless adaptation to new routers or network configurations without requiring manual reconfiguration or device recalls.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The cloud-based system provides universal credential management that works across different device types, network configurations, and router models. The standardized cloud interface handles diverse authentication scenarios (WPA2, WPA3, enterprise networks) through a single platform, making the system adaptable to various network environments while maintaining consistent ease of use.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If cloud-based credential distribution is implemented, then ease of device connection is improved, but system complexity increases

Engineering Contradiction:
Improveautomatic credential distributionVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complex credential management functionality from the edge devices and concentrates it in the cloud. Devices only need minimal client software to communicate authentication status and receive credentials, while the complex operations of credential generation, encryption, secure storage, and distribution logic reside in the cloud infrastructure, simplifying device architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary authentication and authorization actions in the cloud before credential distribution. The consumer's account is pre-validated, device authorization is pre-configured, and security policies are pre-established in the cloud management system. This preliminary processing reduces the complexity burden on the distribution phase, as most decision-making and validation occurs beforehand.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10834592B2Securing credential distribution
Publication Date: 2020.11.10 INFINEON TECHNOLOGIES AMERICAS CORP
  • US10834592B2 patent drawing
  • US10834592B2 patent drawing
  • US10834592B2 patent drawing

AI summary

Methods, systems and apparatus for securing credential distribution are disclosed. One method includes receiving, by a wireless device, from a cloud system, that the wireless device is authorized to receive private network credentials, sensing, by the wireless device, a presence of one or more wireless networks, providing, by the wireless device, wireless network information of the sensed presence of the one or more wireless networks to the cloud system, providing, by the wireless device, to the cloud system, a request for private network credentials, wherein the cloud system, receives the private network credentials of the authenticated user, and receiving, by the wireless device, from the cloud system, distribution of the private network credentials, thereby allowing the wireless device to obtain local network access with the private network credentials.