Personal-Public SSID Provisioning for Single-Use Internet Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SSID technology is susceptible to unauthorized access and security breaches due to its public nature, leading to potential interception of sensitive data by malicious actors through brute force attacks or data packet monitoring.

Innovation Solution

Implementing a Personal-Public (PP) SSID connection that is single-device, single-use, password-protected, unadvertised, and encrypted, with optional expiration based on time, usage, or location, using a credential server to manage and terminate the connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SSID broadcasting is used to notify users of available networks, then ease of connection is improved, but network security deteriorates due to public visibility enabling brute force attacks

Engineering Contradiction:
Improveease of connectionVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements temporary SSIDs that are generated for short durations and automatically expire after use or a set time period. These disposable SSIDs replace permanent broadcasted SSIDs, allowing users to connect easily while limiting the window for security attacks. The temporary nature means even if compromised, the vulnerability lifespan is minimized.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system dynamically generates and manages SSIDs with varying lifecycles based on usage patterns and security requirements. Instead of static SSID configurations, the patent employs dynamic creation of temporary access credentials that adapt to connection needs, improving both ease of connection and security through automated lifecycle management.

Inventive Principle:
Principle #15Dynamics

2Reliability

If hidden SSIDs are used to improve network security, then resistance to discovery is improved, but ease of connection deteriorates requiring manual entry

Engineering Contradiction:
Improvenetwork securityVSAvoidease of connection
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a credential server as an intermediary that manages temporary SSID distribution. This mediator automatically provides hidden SSIDs to authorized users through authenticated channels, eliminating the need for manual entry while maintaining security. The credential server acts as the intermediary between the hidden network and users, streamlining the connection process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service connection by automatically provisioning temporary SSIDs to users through the credential server based on their authentication status. Users don't need to manually configure or enter SSIDs; the system automatically provides the necessary credentials, improving ease of connection while maintaining the hidden SSID security model.

Inventive Principle:
Principle #25Self-service

3Reliability

If password protection is implemented on broadcasted SSIDs, then network security is improved, but susceptibility to brute force attacks worsens

Engineering Contradiction:
Improvenetwork securityVSAvoidbrute force attack susceptibility
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces permanent password-protected SSIDs with temporary SSIDs that have limited lifecycles. Even if attackers attempt brute force attacks, the target SSID expires or changes after a short period, rendering extended attack efforts ineffective. This disposable approach maintains security while eliminating the persistent target that brute force attacks exploit.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system implements periodic regeneration of temporary SSIDs, creating a rotating credential system. Instead of a static password that remains vulnerable indefinitely, the SSIDs are periodically updated and expired, creating moving targets that reduce the effectiveness of brute force attacks over time.

Inventive Principle:
Principle #19Periodic action

4Ease of operation

If permanent SSID connections are maintained for continuous access, then ease of operation is improved, but vulnerability lifespan increases enabling longer attack windows

Engineering Contradiction:
Improvecontinuous accessVSAvoidvulnerability lifespan
Core Design Contradiction:
Ease of operationVSDuration of action of moving object

Solution Approach 1:

The patent implements temporary SSIDs with defined lifecycles that automatically expire after use or a set duration. This replaces permanent connection credentials with short-lived ones, maintaining ease of operation for authorized users while dramatically reducing the vulnerability lifespan available to attackers. The disposable nature ensures that compromised credentials become invalid quickly.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system automatically discards expired temporary SSIDs and can issue new credentials when needed. This automated credential rotation discards old vulnerable connections and recovers access through new temporary SSIDs, maintaining continuous access for legitimate users while eliminating long-term vulnerability windows that permanent SSIDs create.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS12432215B2Establishing a personal-public service set identifier connection between a personal device and the internet
Publication Date: 2025.09.30 KYNDRYL INC
  • US12432215B2 patent drawing
  • US12432215B2 patent drawing
  • US12432215B2 patent drawing

AI summary

Embodiments are directed to techniques for secure network connectivity. The techniques including a system having a credential server storing a Personal-Public (PP) Service Set. Identifier (SSID) profile configured according to registration information provided from a personal computing device. The system further including a Wireless Access Point (WAP) communicatively coupled to the credential server and configured to implement a PP SSID connection using the PP SSID profile to create a single-device, single-use, password-protected, unadvertised, and encrypted networking channel between the personal computing device and the Internet.