NFC-Based WiFi Profile Management for Secure Guest Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current WiFi network management for guests is insecure when no authentication is used and inconvenient when security mechanisms are employed, as it requires frequent password changes, affecting user experience and network safety.

Innovation Solution

Implementing a system that uses NFC devices to automatically obtain and update WiFi profile data, allowing secure and convenient connections by reading NFC tags or peer devices, eliminating the need for manual authentication and frequent password entry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If no security mechanism is used for guest WiFi access, then ease of connection is improved, but network security deteriorates

Engineering Contradiction:
Improveease of connectionVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication actions before WiFi connection is established. Guest users are authenticated through mobile devices using NFC technology, and authentication results are cached before actual WiFi connection occurs. This allows secure authentication to be completed in advance while maintaining ease of connection during actual WiFi access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces mobile devices as intermediary carriers between authentication servers and WiFi access points. The mobile device stores authentication results and acts as a mediator that presents authenticated user identity to the access point, eliminating the need for direct password transmission and improving both security and connection ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If frequent password changes are implemented, then network security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidease of operation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs authentication actions in advance and caches the results in mobile devices before actual WiFi connection is needed. This preliminary authentication eliminates the need for users to manually enter passwords during connection, maintaining ease of operation while enabling frequent security updates through the authentication server.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service authentication where mobile devices automatically present authenticated user identity to access points without requiring manual password entry. The authentication process is handled automatically by the system and mobile device, eliminating manual password re-entry while maintaining security through server-based authentication updates.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If manual authentication is required for WiFi connection, then network security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidease of connection
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

Mobile devices serve as intermediary carriers that store authentication results and automatically present authenticated user identity to WiFi access points. This intermediary approach eliminates the need for manual authentication at the access point while maintaining security through server-based authentication, significantly improving connection ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service authentication where the mobile device automatically handles authentication presentation to the access point without requiring manual user input. The authenticated mobile device automatically provides its identity credentials, eliminating manual authentication steps while maintaining network security through server validation.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides a secure and user-friendly method for managing WiFi connections by automatically obtaining and updating WiFi profiles via NFC, enhancing network security and user convenience by reducing the burden of frequent password changes.

Implementation Method 1

a client security application obtains a WiFi profile of a WiFi network via a near-field communication (NFC) device of the WiFi client device

Methodology Applied
Scientific EffectNear Field Communication:

Data Source

PatentUS10362608B2Managing wireless client connections via near field communication
Publication Date: 2019.07.23 FORTINET INC
  • US10362608B2 patent drawing
  • US10362608B2 patent drawing
  • US10362608B2 patent drawing

AI summary

Systems and methods for automatically obtaining WiFi profile data from an NFC device are provided. According to one embodiment, a client security application obtains a WiFi profile of a WiFi network via a near-field communication (NFC) device of the WiFi client device and establishes a WiFi connection with the WiFi network using the WiFi profile.