Gateway Pairing Method for Secure Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Wi-Fi pairing methods, such as PIN, PBC, and NFC, are either insecure or cumbersome, requiring user manipulation on both the communication device and the residential gateway, which complicates secure network access and configuration.
Innovation Solution
A method where a gateway acts as a wireless access point for two secure Wi-Fi networks, allowing communication devices to pair with the second network without user intervention, using pre-configured authentication data stored in the device, which enhances security and simplifies the pairing process by eliminating the need for user manipulation on both the device and the gateway.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If WPS PIN pairing procedure is used, then pairing security is improved, but ease of operation deteriorates due to user intervention requirements
Solution Approach 1:
The gateway pre-generates a unique pairing identifier for each communication device before the actual pairing process. This preliminary action eliminates the need for users to manually enter PIN codes or press buttons during pairing, as the identifier is automatically provided to the communication device, thereby improving ease of operation while maintaining security through pre-configured authentication credentials
2Ease of operation
If PBC pairing procedure is used, then ease of operation is improved, but pairing security deteriorates due to systematic pairing authorization
Solution Approach 1:
Instead of using a universal push-button configuration that grants systematic authorization to any device, the invention implements localized pairing identifiers that are unique to each communication device. The gateway generates and assigns specific pairing identifiers to individual devices, ensuring that authorization is device-specific rather than blanket authorization, thereby maintaining ease of operation while improving pairing security
3Ease of operation
If NFC pairing procedure is used, then ease of operation is improved for portable devices, but adaptability deteriorates for mains-powered remote devices
Solution Approach 1:
The invention creates a universal pairing mechanism that works across all types of communication devices regardless of their form factor or power source. By using automatically provided pairing identifiers that can be transmitted through various channels (display screens, printed labels, digital communications), the system achieves multi-functionality that accommodates both portable devices and mains-powered devices installed remotely, eliminating the restrictiveness of NFC proximity requirements
4Adaptability or versatility
If multiple secure WLANs are maintained simultaneously, then adaptability is improved, but resource usage increases
Solution Approach 1:
The gateway implements periodic activation of secure WLANs based on pairing requests. Instead of maintaining all secure WLANs continuously active, the gateway activates specific WLANs on-demand when pairing requests are received, and deactivates them after successful pairing or after a predetermined period. This periodic action reduces energy consumption and resource usage while maintaining network availability when needed
Data Source
Figure 1A~1B
Figure 1C~2
Figure 3
AI summary
A gateway manages a first secure wireless local area network and a second secure wireless local area network. The gateway interconnects the second secure wireless local area network and a wide area network, such that each device paired with the second secure wireless local area network can access services offered via the wide area network. The gateway detects (404) a first pairing attempt, with the first secure wireless local area network, using first authentication data. The gateway verifies (405) with a provisioning server that the first pairing is effected by a device associated with a same user as the gateway, and verifies that the first authentication data correspond to the expected authentication data. In the case of positive verification, the gateway transmits (408), via the first secure wireless local area network, second authentication data and a network identifier of the second secure wireless local area network, for the purpose of pairing (409) with the second secure wireless local area network.