Wireless Device Credential Association via Cloud Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in associating unassociated devices with access points, preventing them from communicating with cloud computing systems without initial credentials, which limits access and functionality.

Innovation Solution

A method where devices broadcast frames indicating credentials and payloads, access points relay these to cloud computing systems for validation, and upon successful validation, devices associate with access points to enable communication through them.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices require initial credentials to associate with access points, then security is improved, but device complexity and ease of operation worsen due to the need for pre-provisioning credentials

Engineering Contradiction:
ImprovesecurityVSAvoidease of association
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cloud computing system performs preliminary credential generation and validation before the device needs to associate with the access point. The system pre-establishes the credential relationship between the device and cloud, allowing the device to present this pre-established credential during association without requiring prior manual credential provisioning on the device itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cloud computing system acts as an intermediary that bridges the device and access point during the association process. Instead of the device directly negotiating credentials with the access point (which would require pre-provisioning), the cloud computing system receives the credential from the device, validates it, and facilitates the association, thereby simplifying the device's operation while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If devices broadcast credentials for association, then ease of operation is improved, but loss of information worsens due to potential credential exposure

Engineering Contradiction:
Improveease of associationVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts the credential validation function from the device and places it in the cloud computing system. The device broadcasts a credential, but the critical validation operation is performed remotely by the cloud computing system, which has the authority and security infrastructure to verify credentials without exposing them locally or during transmission to the access point.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud computing system serves as a secure intermediary that receives the credential from the device, validates it in a secure environment, and returns validation results without the access point needing to handle or store the actual credential. This mediator approach allows easy broadcasting while preventing credential exposure in the wireless medium.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20220353683A1Associating devices with access points using credentials
Publication Date: 2022.11.03 QUALCOMM INC
  • US20220353683A1 patent drawing
  • US20220353683A1 patent drawing
  • US20220353683A1 patent drawing

AI summary

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a device may transmit, via a broadcast, a first frame that indicates one or more of a device credential or a payload. The device may receive, from the access point, a second frame that indicates one or more of the payload or an access point credential. The device may associate with the access point based at least in part on the access point credential. The device may perform a communication, to a cloud computing system via the access point, after the device has been associated with the access point. Numerous other aspects are described.