Secure Network Connection via Public Key Operation Value Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wi-Fi network setups are complex, and users often fail to configure security parameters, leading to vulnerable networks due to the complexity of existing secure connection methods, which results in poor network connection efficiency and user experience.
Innovation Solution
A secure connection method that involves acquiring and using a public key operation value through a preset-algorithm operation, reducing the amount of information exchanged and improving security by encrypting and decrypting public key information using private keys, and optionally incorporating random password information for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a complete public key (1536 bits) is used for secure connection, then security is improved, but the amount of information exchanged increases and connection efficiency deteriorates
Solution Approach 1:
The patent extracts only the necessary portion of the public key (public key operation value) rather than transmitting the complete public key. This is achieved by performing a preset-algorithm operation on the public key to generate a condensed representation that retains security properties while reducing data volume, thereby resolving the contradiction between security and connection efficiency
Solution Approach 2:
The patent changes the parameter representation from the complete public key (1536 bits) to a public key operation value obtained through preset-algorithm operation. This parameter transformation maintains the essential security function while significantly reducing the information exchange requirements, thus improving connection efficiency without compromising security
2Reliability
If complete public key information is exchanged, then security is ensured, but the complexity of the connection procedure increases
Solution Approach 1:
The patent extracts only the essential public key operation value needed for secure connection establishment, eliminating the need to exchange and process complete public key information. This extraction approach simplifies the connection procedure while maintaining security through the use of the condensed public key representation
Solution Approach 2:
The patent segments the public key information into two parts: the public key operation value (transmitted and verified) and the complete public key (kept locally for decryption). This segmentation allows the connection procedure to use only the essential segmented portion, reducing complexity while preserving security through the retained complete key
3Quantity of substance
If out-of-band channel bandwidth is limited, then hardware constraints are reduced, but the amount of information that can be exchanged is restricted
Solution Approach 1:
The patent transforms the public key parameter into a condensed public key operation value through preset-algorithm operation, enabling efficient transmission over limited out-of-band channels. This parameter change allows the same security level to be achieved with significantly reduced data transmission requirements, matching the constrained channel bandwidth
Solution Approach 2:
The patent extracts the essential security-critical portion of the public key that can be transmitted through the limited out-of-band channel, separating it from the complete public key that remains local. This extraction enables secure connection establishment despite the bandwidth constraints of the out-of-band channel
Data Source
AI summary
A secure connection method for a network device includes: acquiring a public key operation value of a second device in an out-of-band manner; sending public key information of a first device to the second device; receiving public key information of the second device that is sent by the second device, and decrypting the public key information of the second device by using a private key of the first device, to obtain the public key of the second device; and performing a preset-algorithm operation on the public key of the second device to obtain a copy of the public key operation value of the second device, and after the copy of the public key operation value of the second device matches the public key operation value of the second device, accepting received connection information sent by the second device.


