Dynamic Credential Generation for Secure Wireless Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public wireless hotspots are insecure due to unencrypted over-the-air traffic, making user data vulnerable to hackers, and existing security solutions like VPNs are cumbersome and focused on individual user protection rather than network security, while also facing challenges in managing access with shared passwords.
Innovation Solution
A system that dynamically generates user-specific access credentials for each user through an encrypted connection, allowing secure association with a wireless network without pre-shared passwords, using a combination of open and secure wireless networks with network-level encryption and a credential database for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If an open wireless network is provided for convenient customer access, then ease of operation is improved, but security is worsened due to unencrypted over-the-air traffic
Solution Approach 1:
The wireless network is segmented into two distinct networks: an open network for initial access and a secure network for protected communication. This segmentation allows customers to easily connect to the open network without passwords while preventing unauthorized access to the secure network, thus resolving the contradiction between ease of access and security.
Solution Approach 2:
A captive portal system acts as an intermediary between the open and secure networks. It receives customer authentication information, validates credentials, and dynamically generates access credentials that bridge the two networks. This intermediary enables convenient access while maintaining security by controlling the transition from open to secure network access.
2Object-affected harmful factors
If a captive portal system with shared password is used for access control, then security is improved, but ease of operation is worsened due to password management complexity
Solution Approach 1:
Access credentials are made dynamic rather than static. The system dynamically generates unique access credentials for each customer based on their authentication information. These credentials automatically expire after a predetermined time period, eliminating the need for manual password management and reducing security risks associated with shared passwords.
Solution Approach 2:
The system enables self-service authentication where customers provide their own authentication information (such as hotel room numbers or reservation details) at the captive portal. The system automatically verifies credentials and generates access tokens without requiring staff intervention, simplifying the access control process while maintaining security.
3Object-affected harmful factors
If network-level encryption is implemented on the wireless access point, then security is improved, but device complexity is worsened requiring hardware upgrades
Solution Approach 1:
The security encryption function is moved from the wireless access point to the customer's own device through the captive portal system. The portal establishes encrypted connections with customers' devices and manages security credentials, eliminating the need to modify access point hardware or configuration. This approach provides network-level encryption while maintaining compatibility with existing access point infrastructure.
Data Source
AI summary
A hotspot provides an open wireless network and a secure wireless network. The open wireless network has no network-level encryption and allows open association therewith. The secure wireless network employs network-level encryption and requires authentication of a received access credential from a client device before allowing association therewith. A system for authorizing the client device for secured access at the hotspot includes an access controller configured to establish an encrypted connection between the client device and a login portal of the hotspot over the open wireless network, and to store a user-specific access credential transmitted via the encrypted connection as a valid access credential in a credential database. The credential database is accessed by wireless access points of the hotspot to authenticate the received access credential from the client device in response to a request from the client device to associate with the secure wireless network.


