Network Access Token Controller for Home IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home Wi-Fi networks lack control over access, as they rely on a single passphrase shared across all clients, allowing unauthorized access when shared with guests, and there is no mechanism to revoke previous passphrases for future access.

Innovation Solution

Implementing a system where a controller device generates dynamically generated tokens for accessory devices, allowing secure network access without sharing the traditional password, with features like token-based authentication, expiration dates, and revocation mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single passphrase is shared across all clients for network access, then ease of operation is improved, but network security deteriorates because the owner cannot control individual access or revoke it

Engineering Contradiction:
Improvenetwork accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the single shared passphrase into multiple individual credentials. Each accessory device receives its own unique credential (such as a device-specific password or cryptographic key) that is separately managed and can be individually revoked. This allows the owner to control access on a per-device basis while maintaining ease of operation for each device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by providing customized credentials tailored to each accessory device. Instead of a uniform passphrase for all devices, each device receives credentials specifically configured for it, enabling differentiated access control. The owner can grant or revoke access for specific devices without affecting others, achieving both security and operational flexibility.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If a passphrase is shared with a guest, then ease of operation is improved for guest access, but network security deteriorates because the guest can share it with others without consent

Engineering Contradiction:
Improveguest accessVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments guest access into individual device-specific credentials rather than a shared passphrase. Each guest device receives its own unique credential that cannot be easily shared or transferred to other devices. This maintains ease of operation for legitimate guests while preventing unauthorized access by limiting credential portability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential management system that acts as a mediator between the network owner and guest devices. This intermediary (such as a controller or authentication server) issues and manages device-specific credentials, enabling controlled guest access while preventing unauthorized sharing. The intermediary can also revoke credentials if misuse is detected.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the network is reconfigured with a new SSID/passphrase to revoke previous access, then network security is improved, but device complexity increases due to reconfiguring all network devices

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork reconfiguration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network access control into individual device credentials rather than a single network-wide passphrase. This allows the owner to revoke or update credentials for specific devices without reconfiguring the entire network or affecting other devices. Security can be improved locally for individual devices without causing system-wide reconfiguration complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic credential management where individual device credentials can be independently updated, revoked, or renewed without static network-wide reconfiguration. This dynamic approach allows selective security updates for specific devices or time periods without requiring all network devices to be reconfigured, reducing overall system complexity.

Inventive Principle:
Principle #15Dynamics

4Reliability

If device-specific credentials are generated and managed for each accessory, then network security is improved through controlled access, but device complexity increases due to credential generation and management

Engineering Contradiction:
Improvenetwork securityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credential management system that handles multiple functions through a single mechanism. The same system generates device-specific credentials, distributes them to accessories, tracks their usage, and revokes them when needed. This multi-functional approach consolidates what would otherwise be separate complex processes into a unified system, reducing overall complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables self-service credential management where accessory devices automatically receive and configure their own device-specific credentials without manual intervention. The credentials are provisioned automatically during device pairing or initialization, and the system autonomously manages their lifecycle including renewal and revocation. This automation reduces the operational complexity of managing individual device credentials.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11483708B2Network access tokens for accessories
Publication Date: 2022.10.25 APPLE INC
  • US11483708B2 patent drawing
  • US11483708B2 patent drawing
  • US11483708B2 patent drawing

AI summary

A controller device within a home network (or any suitable network) can be configured to manage network access tokens for various accessory devices within the home network. These network access tokens can be used by the accessory devices to access the home network without needing the network owner's network password. The network access tokens can be revocable and/or for a limited time. The controller device can generate the network access tokens, and can provide them to the accessory devices (or other user devices) as well as to an access device on the home network. Once the access device is provisioned with the accessory device's network access token, the router can control whether the accessory device is to be granted access to the home network and for how long.