Network Authorization via Device Identification and Consult Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access methods require users to input usernames and passwords, which can be inconvenient and pose security risks, especially for temporary access scenarios where users need to access networks without memorizing credentials, and current solutions like Wi-Fi Protected Setup (WPS) have limited application scope and potential security vulnerabilities.

Innovation Solution

A method and system for network authorization that involves a network access device sending a consult message to a server to determine access permissions, allowing a master control device to authorize access without requiring usernames or passwords, by generating and sending an instruction notification based on user input, enabling or denying network access accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password are used for network access, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the password input requirement from the network access process. Instead of requiring users to input passwords, the system uses device identification (such as MAC address) to automatically identify terminal devices and authorize access based on pre-configured device lists, eliminating the need for password entry while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements self-service authentication where terminal devices are automatically identified and authorized without user intervention. The network access device automatically compares device identifiers against the authorized device list and grants access without requiring users to manually enter credentials, making the process convenient while secure

Inventive Principle:
Principle #25Self-service

2Ease of operation

If username and password are shared for temporary access, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments network access authorization by device identifier. Instead of sharing a single password, the system maintains a list of authorized devices with unique identifiers. Each device is individually authorized and tracked, allowing temporary access for specific devices without compromising overall network security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authorized device list as an intermediary between the user and network access control. This list serves as a mediator that automatically determines whether a connecting device should be granted access, eliminating the need to share passwords while maintaining secure access control

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If WPS is used for network setup, then ease of operation is improved, but adaptability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidapplication scope
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authorized device list mechanism that can work with any terminal device regardless of whether it supports WPS. The system uses device identification and list-based authorization that is compatible with diverse devices including smartphones, tablets, computers, and IoT devices, greatly expanding application scope beyond WPS-enabled devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9749324B2System, device and method for network authorization based on no password or random password
Publication Date: 2017.08.29 BEIJING QIHOOD TECHNOLOGY CO LTD
  • US9749324B2 patent drawing
  • US9749324B2 patent drawing
  • US9749324B2 patent drawing

AI summary

Disclosed are a system, device and method for network authorization based on no password or a random password, the device comprising: a memory having instructions stored thereon; at least one processor to execute the instructions to cause: obtaining information carried in a consult message by accessing a server, wherein the consult message is generated and sent to the server by a network access device upon reception of a connection establishment request message, and the consult message comprises network communication address information identifying uniquely the master control device and information of whether a terminal device is allowed to access a network; generating an instruction notification comprising instruction information according to user input information, wherein the instruction information comprises physical address information of the terminal device and information of whether allowing the terminal device to access the network; and sending the instruction notification so that the network access device, according to the instruction information, performing a network access operation upon determining that the terminal device is allowed to access the network, or performing a network access rejecting operation upon determining that the terminal device is prohibited to access the network.