Device-Specific WPA Password Authentication for Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device identification methods in computer networks are vulnerable to behavioral anomalies, such as MAC address changes, which can lead to misidentification and security breaches, especially in networks with high device turnover and unencrypted public connections.

Innovation Solution

Implementing a method that uses unique Wi-Fi Protected Access (WPA) passwords or passphrases for each device to generate a unique identifier, reducing reliance on MAC addresses and behavioral data, and employing a database to manage and enforce these identifiers, ensuring secure device identification and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MAC address and behavioral data are used for device identification, then device identification can be implemented, but the system becomes vulnerable to behavioral anomalies such as MAC address changes

Engineering Contradiction:
Improvedevice identification reliabilityVSAvoidvulnerability to behavioral anomalies
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the device identification problem from reliance on behavioral characteristics (MAC addresses, network behavior) and creates a separate, independent identification mechanism using device-specific passwords. This separates the identification function from the vulnerable behavioral data, allowing the system to maintain identification capability while eliminating vulnerability to MAC address changes and behavioral anomalies.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces device-specific passwords as an intermediary element between the device and the identification system. Instead of directly identifying devices through their behavioral characteristics, the system uses these password intermediaries that are uniquely assigned to each device. This intermediary layer provides a stable, anomaly-resistant identification mechanism that doesn't depend on device behavior or network characteristics.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If public networks use unencrypted connections for ease of access, then network accessibility is improved, but security is compromised

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by requiring devices to authenticate with device-specific passwords before gaining network access. This pre-authentication step ensures that only authorized devices can connect to the network, establishing security before the connection is established. The system can then provide easy access to authenticated devices while maintaining security controls, resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If device identification relies on behavioral data, then identification can be performed, but the system becomes susceptible to misidentification and security breaches

Engineering Contradiction:
Improveidentification efficiencyVSAvoididentification accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent creates a copy-based identification system where each device has a device-specific password that serves as a unique identifier copy. Instead of analyzing complex behavioral patterns to identify devices, the system uses these password copies that are uniquely assigned to each device. This approach maintains identification efficiency while dramatically improving accuracy, as the password copy is a direct, unambiguous representation of device identity rather than an inference from behavior.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11843946B2Device-specific wireless access point password authentication
Publication Date: 2023.12.12 CUJO LLC
  • US11843946B2 patent drawing
  • US11843946B2 patent drawing
  • US11843946B2 patent drawing

AI summary

There is provided a method that comprises receiving one or more unique passwords for identifying respective one or more user devices of the wireless local area network; associating the one or more unique passwords with the respective one or more user devices and storing the one or more unique passwords to a database; in response to receiving, at an access point of the wireless local area network, a connection request from a user device, requesting, from the user device, a unique password of the user device; and identifying the user device based on the unique password.