Dynamic Passphrase Display for Secure Wi-Fi Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Wi-Fi networks face challenges in establishing secure connections due to overlapping personal area networks, leading to cumbersome and time-consuming onboarding processes and complex passphrase management.

Innovation Solution

An electronic device that selectively enables secure access to a network by displaying a passphrase associated with a location, allowing preconfigured and dynamic secure connections, independent of other network traffic, using a physical or virtual interface activation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate passphrases are assigned to each electronic device for secure PAN connections, then network security is improved, but device onboarding becomes cumbersome and time-consuming

Engineering Contradiction:
Improvenetwork securityVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-generates and stores multiple passphrases in advance at the network administrator device. When a new device needs to join, the administrator simply selects from pre-prepared passphrases rather than creating new ones during onboarding, significantly reducing setup time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A single passphrase can be shared among multiple electronic devices within the same PAN, eliminating the need for unique passphrases per device. This universal approach simplifies onboarding while the system maintains security through controlled passphrase distribution and revocation capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If each electronic device has a unique passphrase for secure access, then connection security is enhanced, but passphrase management becomes complicated

Engineering Contradiction:
Improveconnection securityVSAvoidpassphrase management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network administrator device serves as an intermediary that centrally manages all passphrases. It generates, distributes, updates, and revokes passphrases for multiple devices, eliminating the need for individual devices to independently manage their own unique passphrases and reducing overall system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables easy revocation of passphrases when devices leave the network or security credentials need updating. The administrator can discard old passphrases and issue new ones, providing simplified lifecycle management while maintaining security through controlled credential rotation

Inventive Principle:
Principle #34Discarding and recovering

3Adaptability or versatility

If multiple overlapping PANs are allowed in a WLAN, then network versatility is improved, but unauthorized access between PANs becomes possible

Engineering Contradiction:
Improvenetwork versatilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Each PAN is assigned a unique passphrase that is locally valid only within that specific PAN. This local quality ensures that security credentials are meaningful only in their intended context, preventing devices from one PAN from accessing another PAN's resources even when physically co-located in the same WLAN

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20220086638A1Reset button for selective secure access to a network
Publication Date: 2022.03.17 RUCKUS IP HOLDINGS LLC
  • US20220086638A1 patent drawing
  • US20220086638A1 patent drawing
  • US20220086638A1 patent drawing

AI summary

An electronic device that selectively enables secure access to a network is described. During operation, the electronic device may receive an access request. For example, the access request may correspond to activation of or a change in a state of: a physical user-interface device in the electronic device; or a virtual icon displayed in a user interface on a display. In response to receiving the access request, the electronic device may display, on the display, information that specifies an identifier of the network (such as a service set identifier or SSID) and a passphrase (such as a dynamic pre-share key or DPSK) associated with a location of the electronic device (such as a hotel room), where the passphrase enables secure access to the network that is proximate to the location. In some embodiments, the information may include a two-dimensional (2D) quick response (QR) code or another type of graphical pattern.