Secure Ad Hoc Network Access via Out-of-Band Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Wi-Fi Direct services face challenges in user experience, security, and capability negotiation, particularly in forming ad-hoc networks between devices, especially those without display or input mechanisms, such as IoT devices, due to the need for user interaction during security setup and the lack of a central certificate authority.

Innovation Solution

A secure ad-hoc network access system that uses out-of-band discovery via QR codes to encode device information like public keys and Wi-Fi MAC addresses, and modifies protocols to remove user verification steps, utilizing Device Provisioning Protocol (DPP) for secure key verification, enabling device-to-device connection without PIN or push button authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user verification steps (PIN or push button authentication) are required during security setup, then security is improved, but user experience and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts and removes the user verification step (PIN entry or push button authentication) from the security setup process. Instead, it uses out-of-band discovery mechanisms where device information including public keys are exchanged automatically through alternative channels (QR codes, NFC, or other discovery protocols), eliminating the need for manual user verification while maintaining security through cryptographic key exchange.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary out-of-band discovery mechanism that mediates the security setup process. This intermediary channel allows devices to exchange verification information (public keys, device identifiers) without requiring direct user interaction during the critical authentication phase, thus improving ease of operation while maintaining security through the intermediary verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If out-of-band discovery via QR codes is used to encode device information, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork setupVSAvoidprotocol implementation
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal out-of-band discovery mechanism that can operate through multiple channels (QR codes, NFC, or other discovery protocols). This multi-functional approach allows the same security setup process to work across different device types and scenarios, improving ease of operation while managing complexity through standardized universal protocols rather than device-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary encoding of device information (public keys, MAC addresses, capability data) into machine-readable formats (QR codes) before the actual connection attempt. This preliminary action prepares all necessary verification data in advance, simplifying the actual connection process and reducing the complexity of real-time computation during network setup.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If devices without display or input mechanisms are supported, then adaptability is improved, but security verification becomes more difficult

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity verification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces mechanical user interaction (display visibility, button pressing, PIN entry) with automated electronic verification mechanisms. Devices without displays or input mechanisms can participate through automated out-of-band discovery where public keys and device identifiers are exchanged through alternative channels (NFC, QR code scanning by paired device, or other machine-to-machine protocols), eliminating the need for traditional mechanical verification interfaces while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of manufacture

If a central certificate authority is not used, then device independence and ease of manufacture are improved, but security establishment becomes more difficult

Engineering Contradiction:
Improvedevice independenceVSAvoidsecurity establishment
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements a self-service security model where each device generates and manages its own cryptographic key pairs (public and private keys) without requiring enrollment with a central certificate authority. Devices independently establish security through mutual verification of their self-generated public keys exchanged during out-of-band discovery, enabling device independence and easier manufacture while maintaining security through decentralized cryptographic authentication.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10932311B2Secure ad hoc network access
Publication Date: 2021.02.23 INTEL CORP
  • US10932311B2 patent drawing
  • US10932311B2 patent drawing
  • US10932311B2 patent drawing

AI summary

This disclosure describes systems, methods, and apparatuses related to secure ad hoc network access. A device may identify a cryptographic key received from a second device. The device may cause to send a probe request for service information to the second device. The device may identify a probe response including an information element received in the service information from the second device. The device may cause to send a first discovery request seeking to provision the second device. The device may identify a first discovery response from the second device including a configuration method. The device may cause to form an ad hoc wireless network group based on the first discovery response. The device may cause to exchange one or more messages to provide an access for the second device to the ad hoc wireless network group based on the cryptographic key and one or more in-band attributes.