Dynamic Credential Generation for Secure Wi-Fi Hotspots

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users cannot access RSN-enabled Wi-Fi hotspot networks without valid credentials, and there is no method for on-line sign-up or purchasing a subscription within these networks, as current practices require manual intervention or traditional distribution methods.

Innovation Solution

A method and apparatus that allow users to form a preliminary association with a network access point, create or receive necessary credentials, and establish internet connectivity by using a non-RSN enabled network for sign-up purposes, enabling online subscription creation and credential generation for RSN-enabled networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If RSN enabled networks require 802.1x authentication, then network security is improved, but user accessibility deteriorates because users cannot obtain credentials online

Engineering Contradiction:
Improvenetwork securityVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a captive portal as an intermediary system that mediates between the user and the RSN authentication mechanism. The portal provides a web-based interface where users can obtain credentials without directly interacting with the 802.1x authentication protocol, thus maintaining security while improving accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary credential distribution through the captive portal before the user attempts formal authentication. Users receive credentials in advance via the web interface, which they then use during the 802.1x authentication process, eliminating the need for manual credential configuration

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If captive portal redirect is used for open networks, then user registration is simplified, but it cannot be applied to RSN enabled networks requiring 802.1x authentication

Engineering Contradiction:
Improveuser registrationVSAvoidnetwork type compatibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication system that combines the captive portal interface (effective for open networks) with 802.1x authentication capabilities (required for secure networks). The same portal infrastructure serves both network types, allowing operators to maintain consistent user experience across different security requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual credential distribution is used, then security is maintained, but operational complexity and time consumption increase

Engineering Contradiction:
Improvecredential securityVSAvoidcredential distribution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables users to self-serve by automatically receiving credentials through the captive portal without requiring manual distribution by network operators. Users simply connect to the network, are redirected to the portal, and automatically obtain the credentials needed for authentication, eliminating manual intervention

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2617222B1Dynamic account creation with secured hotspot network
Publication Date: 2019.07.24 NOKIA TECHNOLOGIES OY
  • EP2617222B1 patent drawingFigure 1
  • EP2617222B1 patent drawingFigure 2
  • EP2617222B1 patent drawingFigure 3

AI summary

At least one network access point transmits a beacon transmission. A user device receiving it determines it does not have credentials necessary to attach with a secure network access point of the at least one network access point, and so forms a preliminary association with the at least one network access point. During the preliminary association, the user device receives or creates credentials necessary to associate with the secure network access point, and then forms an association with the secure network access point using the received or created credentials and obtains internet connectivity via the secure network access point. In one embodiment there is a non-secure network access point which transmits a beacon using the same SSID as the secure network access point, and the preliminary association is with the non-secure network access point. In another embodiment there is only the secure network access point.