Network Access Management Module for Secure Guest Terminal Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for sharing access to a private wireless communication network are insecure due to the transmission of sensitive data and prone to configuration errors, and they do not allow access for unconfigured terminals, while also requiring subscription to a telecommunications operator for Wi-Fi access.

Innovation Solution

A method using network access management modules associated with host and guest users, facilitated by a social network, to securely share access configuration information directly, eliminating the need for sensitive data transmission and allowing access without prior configuration or operator subscription, using identification information and generating specific authentication parameters for enhanced security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If configuration information is explicitly provided to the guest user, then the guest user can manually configure their terminal, but this transmits sensitive data insecurely and requires manual entry which is error-prone

Engineering Contradiction:
Improvemanual configuration capabilityVSAvoidsecurity and accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary that stores configuration information and automatically transmits it to the terminal. The server mediates between the user and the terminal, eliminating the need for direct transmission of sensitive data to the guest user and automated the configuration process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The terminal automatically obtains configuration information from the server without requiring manual entry by the guest user. The system performs self-configuration by having the terminal query the server for the appropriate configuration data based on the user's identity.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If existing methods are used, then access can be shared, but they do not allow access for terminals that are not already configured to access another network

Engineering Contradiction:
Improveaccess flexibilityVSAvoidconfiguration requirement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The configuration information is pre-stored on the server before the guest user needs to access the network. This preliminary preparation allows the terminal to obtain ready-made configuration data without requiring prior configuration or existing network access credentials.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authentication credentials are shared between users, then access can be granted, but this creates security vulnerabilities with malicious users or impersonators

Engineering Contradiction:
Improveaccess sharing capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent generates unique configuration information for each specific user-terminal combination. Instead of sharing general authentication credentials, each user receives customized configuration data that is locally valid for their specific terminal, preventing unauthorized use by malicious users or impersonators.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2871876B1Technique for configuring secure access by a guest terminal to a host network
Publication Date: 2020.09.23 ORANGE SA
  • EP2871876B1 patent drawingFigure 1~3
  • EP2871876B1 patent drawingFigure 4

AI summary

A method for configuring network access to allow network access to at least one guest terminal associated with a guest user, said method being implemented by a first network access management module associated with a host user, and comprising the following steps: - receiving from a terminal associated with the host user an offer to share network access intended for the guest user, said users being connected via a social network; - obtaining from a second network access management module associated with said guest user, the identification information of said guest terminal; - obtaining from the network configuration information allowing access to the network by the guest terminal, following the sending to the network of an access configuration request including said identification information;and - sending configuration information to the second management module, intended for the guest terminal, allowing it access to the network.