Network Access Token Controller for Home IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Home Wi-Fi networks lack control over access, as they rely on a single passphrase shared across all clients, allowing unauthorized access when shared with guests, and there is no mechanism to revoke previous passphrases for future access.
Innovation Solution
Implementing a system where a controller device generates dynamically generated tokens for accessory devices, allowing secure network access without sharing the traditional password, with features like token-based authentication, expiration dates, and revocation mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single passphrase is shared across all clients for network access, then ease of operation is improved, but network security deteriorates because the owner cannot control individual access or revoke it
Solution Approach 1:
The patent segments the single shared passphrase into multiple individual credentials. Each accessory device receives its own unique credential (such as a device-specific password or cryptographic key) that is separately managed and can be individually revoked. This allows the owner to control access on a per-device basis while maintaining ease of operation for each device.
Solution Approach 2:
The patent implements local quality by providing customized credentials tailored to each accessory device. Instead of a uniform passphrase for all devices, each device receives credentials specifically configured for it, enabling differentiated access control. The owner can grant or revoke access for specific devices without affecting others, achieving both security and operational flexibility.
2Ease of operation
If a passphrase is shared with a guest, then ease of operation is improved for guest access, but network security deteriorates because the guest can share it with others without consent
Solution Approach 1:
The patent segments guest access into individual device-specific credentials rather than a shared passphrase. Each guest device receives its own unique credential that cannot be easily shared or transferred to other devices. This maintains ease of operation for legitimate guests while preventing unauthorized access by limiting credential portability.
Solution Approach 2:
The patent introduces an intermediary credential management system that acts as a mediator between the network owner and guest devices. This intermediary (such as a controller or authentication server) issues and manages device-specific credentials, enabling controlled guest access while preventing unauthorized sharing. The intermediary can also revoke credentials if misuse is detected.
3Reliability
If the network is reconfigured with a new SSID/passphrase to revoke previous access, then network security is improved, but device complexity increases due to reconfiguring all network devices
Solution Approach 1:
The patent segments network access control into individual device credentials rather than a single network-wide passphrase. This allows the owner to revoke or update credentials for specific devices without reconfiguring the entire network or affecting other devices. Security can be improved locally for individual devices without causing system-wide reconfiguration complexity.
Solution Approach 2:
The patent implements dynamic credential management where individual device credentials can be independently updated, revoked, or renewed without static network-wide reconfiguration. This dynamic approach allows selective security updates for specific devices or time periods without requiring all network devices to be reconfigured, reducing overall system complexity.
4Reliability
If device-specific credentials are generated and managed for each accessory, then network security is improved through controlled access, but device complexity increases due to credential generation and management
Solution Approach 1:
The patent implements a universal credential management system that handles multiple functions through a single mechanism. The same system generates device-specific credentials, distributes them to accessories, tracks their usage, and revokes them when needed. This multi-functional approach consolidates what would otherwise be separate complex processes into a unified system, reducing overall complexity while maintaining security.
Solution Approach 2:
The patent enables self-service credential management where accessory devices automatically receive and configure their own device-specific credentials without manual intervention. The credentials are provisioned automatically during device pairing or initialization, and the system autonomously manages their lifecycle including renewal and revocation. This automation reduces the operational complexity of managing individual device credentials.
Data Source
AI summary
A controller device within a home network (or any suitable network) can be configured to manage network access tokens for various accessory devices within the home network. These network access tokens can be used by the accessory devices to access the home network without needing the network owner's network password. The network access tokens can be revocable and/or for a limited time. The controller device can generate the network access tokens, and can provide them to the accessory devices (or other user devices) as well as to an access device on the home network. Once the access device is provisioned with the accessory device's network access token, the router can control whether the accessory device is to be granted access to the home network and for how long.


