Location-Specific WPA2 Credential System for Public Wi-Fi Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public Wi-Fi hotspots pose security risks due to unsecured access points, exposing network traffic to interception, particularly in crowded areas, where sensitive information can be captured by network sniffers or rogue access points.

Innovation Solution

Implementing a location-specific Wi-Fi Protected Access-2 (WPA2) credential system that uses beacons to encrypt network traffic and restrict access, ensuring only authorized devices within a defined network-access boundary can connect, thereby preventing unauthorized intrusion and data capture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public Wi-Fi access is provided without restrictions, then ease of operation is improved, but network security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements location-specific WPA2 credentials that are generated and transmitted based on the UE's geographic location relative to the network-access boundary. Different credentials are used for different locations, allowing public access within the boundary while maintaining security through location-based authentication. This resolves the contradiction by making access easy (public within boundary) while ensuring security (location-verified authentication).

Inventive Principle:
Principle #3Local quality

2Reliability

If network access is restricted to authorized devices, then network security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically determines the UE's location, verifies it against the network-access boundary, and provides the appropriate WPA2 credential without manual intervention. The UE simply needs to be within the boundary and request access; the system handles credential generation, verification, and transmission automatically. This maintains security through boundary verification while preserving ease of operation through automated credential distribution.

Inventive Principle:
Principle #25Self-service

3Reliability

If location-based credential transmission is implemented, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The AP performs multiple functions: it acts as a standard Wi-Fi access point, a location verification system, a credential generation server, and a boundary enforcement mechanism. By consolidating these functions into the existing AP infrastructure rather than requiring separate systems, the patent improves security through location-based credentials while minimizing the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10206110B1Techniques for network security
Publication Date: 2019.02.12 GEN DIGITAL INC
  • US10206110B1 patent drawing
  • US10206110B1 patent drawing
  • US10206110B1 patent drawing

AI summary

Techniques are described for network security. One method includes identifying a network-access boundary associated with a network for a location, generating a credential for the network based at least in part on the identified network-access boundary, receiving a request from a user equipment (UE) to access the network associated with the location, and transmitting the credential associated with the network based at least in part on the network-access boundary.