Network Authorization via Device Identification and Consult Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access methods require users to input usernames and passwords, which can be inconvenient and pose security risks, especially for temporary access scenarios where users need to access networks without memorizing credentials, and current solutions like Wi-Fi Protected Setup (WPS) have limited application scope and potential security vulnerabilities.
Innovation Solution
A method and system for network authorization that involves a network access device sending a consult message to a server to determine access permissions, allowing a master control device to authorize access without requiring usernames or passwords, by generating and sending an instruction notification based on user input, enabling or denying network access accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If username and password are used for network access, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent extracts the password input requirement from the network access process. Instead of requiring users to input passwords, the system uses device identification (such as MAC address) to automatically identify terminal devices and authorize access based on pre-configured device lists, eliminating the need for password entry while maintaining security
Solution Approach 2:
The system implements self-service authentication where terminal devices are automatically identified and authorized without user intervention. The network access device automatically compares device identifiers against the authorized device list and grants access without requiring users to manually enter credentials, making the process convenient while secure
2Ease of operation
If username and password are shared for temporary access, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent segments network access authorization by device identifier. Instead of sharing a single password, the system maintains a list of authorized devices with unique identifiers. Each device is individually authorized and tracked, allowing temporary access for specific devices without compromising overall network security
Solution Approach 2:
The patent introduces an authorized device list as an intermediary between the user and network access control. This list serves as a mediator that automatically determines whether a connecting device should be granted access, eliminating the need to share passwords while maintaining secure access control
3Ease of operation
If WPS is used for network setup, then ease of operation is improved, but adaptability deteriorates
Solution Approach 1:
The patent implements a universal authorized device list mechanism that can work with any terminal device regardless of whether it supports WPS. The system uses device identification and list-based authorization that is compatible with diverse devices including smartphones, tablets, computers, and IoT devices, greatly expanding application scope beyond WPS-enabled devices
Data Source
AI summary
Disclosed are a system, device and method for network authorization based on no password or a random password, the device comprising: a memory having instructions stored thereon; at least one processor to execute the instructions to cause: obtaining information carried in a consult message by accessing a server, wherein the consult message is generated and sent to the server by a network access device upon reception of a connection establishment request message, and the consult message comprises network communication address information identifying uniquely the master control device and information of whether a terminal device is allowed to access a network; generating an instruction notification comprising instruction information according to user input information, wherein the instruction information comprises physical address information of the terminal device and information of whether allowing the terminal device to access the network; and sending the instruction notification so that the network access device, according to the instruction information, performing a network access operation upon determining that the terminal device is allowed to access the network, or performing a network access rejecting operation upon determining that the terminal device is prohibited to access the network.


