Dynamic Credential Generation for Secure Wireless Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public wireless hotspots are insecure due to unencrypted over-the-air traffic, making user data vulnerable to hackers, and existing security solutions like VPNs are cumbersome and focused on individual user protection rather than network security, while also facing challenges in managing access with shared passwords.

Innovation Solution

A system that dynamically generates user-specific access credentials for each user through an encrypted connection, allowing secure association with a wireless network without pre-shared passwords, using a combination of open and secure wireless networks with network-level encryption and a credential database for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an open wireless network is provided for convenient customer access, then ease of operation is improved, but security is worsened due to unencrypted over-the-air traffic

Engineering Contradiction:
Improvecustomer access convenienceVSAvoiddata security vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The wireless network is segmented into two distinct networks: an open network for initial access and a secure network for protected communication. This segmentation allows customers to easily connect to the open network without passwords while preventing unauthorized access to the secure network, thus resolving the contradiction between ease of access and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A captive portal system acts as an intermediary between the open and secure networks. It receives customer authentication information, validates credentials, and dynamically generates access credentials that bridge the two networks. This intermediary enables convenient access while maintaining security by controlling the transition from open to secure network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a captive portal system with shared password is used for access control, then security is improved, but ease of operation is worsened due to password management complexity

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidpassword management
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

Access credentials are made dynamic rather than static. The system dynamically generates unique access credentials for each customer based on their authentication information. These credentials automatically expire after a predetermined time period, eliminating the need for manual password management and reducing security risks associated with shared passwords.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables self-service authentication where customers provide their own authentication information (such as hotel room numbers or reservation details) at the captive portal. The system automatically verifies credentials and generates access tokens without requiring staff intervention, simplifying the access control process while maintaining security.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If network-level encryption is implemented on the wireless access point, then security is improved, but device complexity is worsened requiring hardware upgrades

Engineering Contradiction:
Improveover-the-air encryptionVSAvoidaccess point configuration
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The security encryption function is moved from the wireless access point to the customer's own device through the captive portal system. The portal establishes encrypted connections with customers' devices and manages security credentials, eliminating the need to modify access point hardware or configuration. This approach provides network-level encryption while maintaining compatibility with existing access point infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10805797B2Enabling secured wireless access using user-specific access credential for secure SSID
Publication Date: 2020.10.13 GUEST TEK INTERACTIVE ENTERTAINMENT
  • US10805797B2 patent drawing
  • US10805797B2 patent drawing
  • US10805797B2 patent drawing

AI summary

A hotspot provides an open wireless network and a secure wireless network. The open wireless network has no network-level encryption and allows open association therewith. The secure wireless network employs network-level encryption and requires authentication of a received access credential from a client device before allowing association therewith. A system for authorizing the client device for secured access at the hotspot includes an access controller configured to establish an encrypted connection between the client device and a login portal of the hotspot over the open wireless network, and to store a user-specific access credential transmitted via the encrypted connection as a valid access credential in a credential database. The credential database is accessed by wireless access points of the hotspot to authenticate the received access credential from the client device in response to a request from the client device to associate with the secure wireless network.