Cloud Wi-Fi Onboarding via Temporary Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring Wi-Fi enabled devices to connect to a secure Wi-Fi network is cumbersome and prone to security issues due to the need for manual entry of long passphrases, which can be vulnerable to brute-force attacks.

Innovation Solution

A cloud-based Wi-Fi service manager and agent system that allows remote activation, configuration, and monitoring of Wi-Fi networks, enabling devices to connect securely without manual passphrase entry through a user interface, using cloud-based agents installed on access points and devices to manage and configure SSIDs and passphrases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual passphrase entry is used for Wi-Fi connection, then connection security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveconnection securityVSAvoidease of configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A cloud-based service acts as an intermediary between the user and the Wi-Fi network. The service receives connection requests, retrieves credentials from a backend system, and establishes the connection automatically, eliminating the need for users to manually enter passphrases while maintaining security through server-side credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service connection establishment where devices automatically obtain and use credentials without human intervention. The cloud service autonomously manages the connection process by retrieving credentials and configuring devices, making the system serve itself rather than requiring manual user input.

Inventive Principle:
Principle #25Self-service

2Reliability

If long passphrases are used for Wi-Fi security, then connection security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveconnection securityVSAvoidease of configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The complex passphrase management task is extracted from the user interaction flow and handled entirely by the cloud-based service. Users no longer need to input or remember long passphrases; the system extracts this burden by automatically retrieving and managing credentials through the cloud interface.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The manual mechanical process of typing and entering passphrases is replaced by an automated electronic system. The cloud service electronically retrieves and transmits credentials, substituting the manual mechanical interaction with an automated digital process that maintains security without requiring user input.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If existing Wi-Fi configuration techniques are used, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of configurationVSAvoidconnection security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The cloud-based service serves as a secure intermediary that mediates between the simplified user interface and the actual network credentials. This intermediary layer allows easy user operation while maintaining security by keeping credential management centralized and protected on the server side, preventing exposure of actual passphrases.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10057813B1Onboarding and configuring Wi-Fi enabled devices
Publication Date: 2018.08.21 PLUME DESIGN INC
  • US10057813B1 patent drawing
  • US10057813B1 patent drawing
  • US10057813B1 patent drawing

AI summary

A method of activating and configuring a Wi-Fi enabled device to connect with a Wi-Fi Access Point (AP) by a cloud-based Wi-Fi service manager is disclosed. A unique identifier of the Wi-Fi enabled device and a unique identifier of the Wi-Fi AP are received by the cloud-based Wi-Fi service manager. The unique identifier of the Wi-Fi enabled device is used as a seed for a predetermined algorithm to generate a temporary service set identifier (SSID) and a temporary passphrase. The temporary SSID and the temporary passphrase are sent to the Wi-Fi AP for configuring the Wi-Fi AP with the temporary SSID and the temporary passphrase.