Encrypted SSID System for Secure IoT Network Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless Local Area Networks (WLAN) are vulnerable to attacks due to the broadcasting of Service Set Identifiers (SSIDs), which can expose private information and pose connectivity challenges for devices without screens, such as IoT devices, as they require manual input of SSID and password.
Innovation Solution
Implementing an encrypted SSID system where communication devices and access points use a public key for encrypted SSID names, with a private key generated and transmitted to decrypt the SSID, allowing secure and automatic connection for legitimate devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If SSID is broadcasted openly, then network discoverability is improved, but security is worsened due to exposure to attacks
Solution Approach 1:
The patent introduces an encrypted version of the SSID as an intermediary between the open broadcast requirement and security protection. The access point transmits both the encrypted SSID (visible to all) and the plain SSID (protected). The encrypted SSID acts as a mediator that allows devices to discover the network while preventing attackers from obtaining the actual network identifier through packet sniffing.
Solution Approach 2:
The patent applies different quality treatments to different parts of the SSID transmission system. The plain SSID is protected and only transmitted under specific conditions (when a device requests connection), while the encrypted SSID is broadcast openly. This local differentiation allows the system to simultaneously achieve discoverability and security by treating different representations of the SSID differently.
2Object-affected harmful factors
If SSID is hidden, then security is improved, but ease of operation is worsened for devices without screens
Solution Approach 1:
The patent enables devices to automatically obtain and use the plain SSID without requiring manual user input. When a device transmits a connection request containing the encrypted SSID, the access point automatically provides the corresponding plain SSID. This self-service mechanism eliminates the need for users to manually enter SSIDs, making hidden SSID networks as easy to connect to as open networks.
3Object-affected harmful factors
If encryption is implemented, then security is improved, but device complexity is worsened due to key management
Solution Approach 1:
The patent changes the parameter of SSID representation from plain text to encrypted form. By transforming the SSID into an encrypted version that can be broadcast safely, the system achieves security enhancement without requiring complex key management infrastructure. The encryption/decryption process is integrated into the existing connection establishment protocol, minimizing additional complexity.
Data Source
AI summary
A communication device is provided including a transceiver configured to receive and transmit signals and processing circuitry configured to: control the transceiver to obtain, from an access point, a first service set identifier (SSID) including an encrypted second SSID of the access point; (ii) transmit, to the access point, access information related to the first SSID; (iii) receive, from the access point, a private key; and (iv) obtain the second SSID of the access point by applying the private key to the first SSID.


