Encrypted SSID System for Secure IoT Network Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless Local Area Networks (WLAN) are vulnerable to attacks due to the broadcasting of Service Set Identifiers (SSIDs), which can expose private information and pose connectivity challenges for devices without screens, such as IoT devices, as they require manual input of SSID and password.

Innovation Solution

Implementing an encrypted SSID system where communication devices and access points use a public key for encrypted SSID names, with a private key generated and transmitted to decrypt the SSID, allowing secure and automatic connection for legitimate devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If SSID is broadcasted openly, then network discoverability is improved, but security is worsened due to exposure to attacks

Engineering Contradiction:
Improvenetwork discoverabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encrypted version of the SSID as an intermediary between the open broadcast requirement and security protection. The access point transmits both the encrypted SSID (visible to all) and the plain SSID (protected). The encrypted SSID acts as a mediator that allows devices to discover the network while preventing attackers from obtaining the actual network identifier through packet sniffing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different quality treatments to different parts of the SSID transmission system. The plain SSID is protected and only transmitted under specific conditions (when a device requests connection), while the encrypted SSID is broadcast openly. This local differentiation allows the system to simultaneously achieve discoverability and security by treating different representations of the SSID differently.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If SSID is hidden, then security is improved, but ease of operation is worsened for devices without screens

Engineering Contradiction:
Improvesecurity protectionVSAvoidconnection complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent enables devices to automatically obtain and use the plain SSID without requiring manual user input. When a device transmits a connection request containing the encrypted SSID, the access point automatically provides the corresponding plain SSID. This self-service mechanism eliminates the need for users to manually enter SSIDs, making hidden SSID networks as easy to connect to as open networks.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If encryption is implemented, then security is improved, but device complexity is worsened due to key management

Engineering Contradiction:
Improvesecurity enhancementVSAvoidencryption system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent changes the parameter of SSID representation from plain text to encrypted form. By transforming the SSID into an encrypted version that can be broadcast safely, the system achieves security enhancement without requiring complex key management infrastructure. The encryption/decryption process is integrated into the existing connection establishment protocol, minimizing additional complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240430669A1Encrypted Service Set Identifier
Publication Date: 2024.12.26 VESTEL ELEKTRONIK SANAYI & TICARET ANONIM SIRKETI
  • US20240430669A1 patent drawing
  • US20240430669A1 patent drawing
  • US20240430669A1 patent drawing

AI summary

A communication device is provided including a transceiver configured to receive and transmit signals and processing circuitry configured to: control the transceiver to obtain, from an access point, a first service set identifier (SSID) including an encrypted second SSID of the access point; (ii) transmit, to the access point, access information related to the first SSID; (iii) receive, from the access point, a private key; and (iv) obtain the second SSID of the access point by applying the private key to the first SSID.