Device Credential Provisioning for Secure Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In BYOD environments, existing authentication schemes are inadequate for securing access to wireless networks, particularly for Android-based smartphones, which are susceptible to 'man-in-the-middle' attacks due to automatic acceptance of digital certificates without user verification, compromising network security.

Innovation Solution

A system and method for provisioning unique device credentials that involves device fingerprinting, generating digital certificates, and providing credentials based on device type, including certificate-based or username/password authentication, to ensure secure network access for diverse electronic devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificate authentication is used for Android-based smartphones, then network security is compromised because devices automatically accept certificates without user verification, but if certificate-based authentication is avoided, then secure access cannot be provisioned for these devices

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies different authentication methods based on device type: certificate-based authentication for devices that support it (iOS, Windows) and username/password authentication for Android devices. This local differentiation resolves the contradiction by tailoring the authentication approach to each device's security capabilities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the authentication parameter from certificate-based to username/password-based specifically for Android devices. This parameter change allows Android devices to be authenticated securely without requiring them to implement certificate verification, thus maintaining both security and device compatibility.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual device registration by network administrator is implemented, then network security control is maintained, but then registration process becomes labor intensive and causes unreasonable waiting time for guests

Engineering Contradiction:
Improveaccess control securityVSAvoidregistration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service registration where devices automatically register with the network by providing their device information. The authentication server automatically provisions credentials without requiring manual administrator intervention, thus maintaining security control while dramatically improving registration efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary automatic registration and credential provisioning before the user needs network access. Devices are pre-authenticated and given credentials in advance, eliminating the need for manual administrator registration and reducing waiting time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If unique device credentials are provisioned for all device types, then network security is enhanced and man-in-the-middle attacks are reduced, but then the authentication system must support multiple authentication protocols increasing system complexity

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication system that can handle multiple authentication protocols (certificate-based and username/password) through a single authentication server. This multi-functional approach provides secure credentials for all device types without requiring separate authentication systems for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system segments the credential provisioning process into device-specific pathways: one pathway for certificate-based authentication and another for username/password authentication. This segmentation allows the system to maintain multiple protocols while managing complexity through structured separation of authentication methods.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9049184B2System and method for provisioning a unique device credentials
Publication Date: 2015.06.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9049184B2 patent drawing
  • US9049184B2 patent drawing
  • US9049184B2 patent drawing

AI summary

According to one embodiment of the invention, a method for controlling access to a network comprises a first operation of determining a type of electronic device to join the network. Then, unique device credentials are sent to the electronic device. These unique device credentials are used in authenticating the electronic device, and the format of the unique device credentials is based on the type of electronic device determined.