Dynamic SSID Generation for Wireless Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication networks using service set identifiers (SSIDs) are vulnerable to attacks, such as spoofing and distributed denial of service, as they broadcast static SSIDs, making it difficult to secure the network effectively against malicious activities.

Innovation Solution

Implementing dynamically generated SSIDs, where access points broadcast beacons without SSIDs, and user devices request association, allowing the access point to generate a unique SSID for each device, which is then transmitted and used for secure association, and verified to prevent unauthorized access and deauthentication attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If static SSIDs are broadcast for network identification, then network discoverability is improved, but network security deteriorates due to spoofing and DDOS attacks

Engineering Contradiction:
Improvenetwork discoverabilityVSAvoidspoofing attacks
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by transitioning from static SSIDs to dynamic SSIDs that change over time. The access point generates a new SSID for each association request, making the network identifier constantly changing rather than fixed. This resolves the contradiction by maintaining network discoverability through dynamic beacon broadcasts while preventing spoofing attacks since attackers cannot predict or replicate changing SSIDs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of the SSID from static to dynamic by generating unique SSIDs based on association request timestamps and random values. Each association request receives a different SSID, transforming the network identifier from a constant parameter to a variable parameter that changes with each connection attempt, thereby securing the network while maintaining discoverability.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If SSIDs are hidden to prevent attacks, then network security is improved, but network usability deteriorates as devices cannot discover the network

Engineering Contradiction:
Improveattack preventionVSAvoidnetwork usability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies preliminary action by broadcasting beacons that indicate the presence of a wireless network without revealing the actual SSID. The access point prepares and transmits beacon frames containing network availability information but omits the specific network identifier, allowing devices to discover that a network exists while preventing attackers from obtaining the SSID for spoofing purposes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where the access point acts as a mediator that provides network discovery functionality without exposing the SSID. The beacon frames serve as an intermediary signal that confirms network presence and invites association requests, while the actual SSID is only generated and provided during the association process itself, thus balancing security and usability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If unique dynamic SSIDs are generated for each device, then network security is improved, but system complexity increases due to dynamic SSID generation and management

Engineering Contradiction:
Improvespoofing preventionVSAvoidSSID generation complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies self-service by implementing automatic SSID generation at the access point without requiring external configuration or management. The access point autonomously generates unique SSIDs using timestamps and random values from incoming association requests, and automatically manages the lifecycle of these SSIDs including generation, transmission to authorized devices, and expiration, thereby reducing manual complexity while maintaining high security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback by using information from the association request itself (such as device MAC address and timestamp) to generate the SSID. The access point receives the association request, extracts relevant parameters, uses them to create a unique SSID, and feeds this SSID back to the requesting device. This feedback mechanism ensures each device receives a customized SSID without requiring complex external configuration systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10412083B2Dynamically generated SSID
Publication Date: 2019.09.10 SONICWALL US HOLDINGS INC
  • US10412083B2 patent drawing
  • US10412083B2 patent drawing
  • US10412083B2 patent drawing

AI summary

A plurality of beacons that do not include any service set identifiers may be broadcast from an access point. A request concerning association with the access point may be sent wirelessly from a user device and received at the access point. A unique service set identifier (SSID) for the requesting user device may be generated, and information regarding the unique SSID may be transmitted to the requesting user device. A subsequent association request from the requesting user device may include the unique SSID.