Secure Access Point Configuration via Mobile Device Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access points (APs) are often vulnerable to security breaches due to default passwords not being changed by users, allowing intruders to perform malicious actions.

Innovation Solution

Implementing a system that securely associates APs with mobile devices using proximity-based networks, enabling secure configuration and management through a mobile device, which acts as a key to unlock AP settings and facilitate changes, thereby enhancing security by eliminating the need for default passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the AP uses default password for configuration access, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveconfiguration accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary secure association between the mobile device and AP before allowing configuration access. The mobile device establishes a secure connection in advance, and only then is the AP unlocked for configuration. This eliminates the need for default passwords while maintaining ease of operation through automated secure authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device acts as an intermediary between the user and the AP configuration process. Instead of directly accessing the AP with a password, the user interacts with the mobile device application, which then securely communicates with the AP. This intermediary layer provides both ease of operation and enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the AP is fully open and accessible, then ease of operation is improved, but vulnerability to malicious actions is worsened

Engineering Contradiction:
Improveconfiguration accessVSAvoidmalicious actions
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The AP accessibility dynamically changes based on the secure association state. The AP transitions from a locked state (not accessible) to an unlocked state (accessible for configuration) only after successful secure association with the mobile device. Once configuration is complete, the AP can be re-locked. This dynamic state management provides both ease of operation when needed and protection against malicious actions when not needed.

Inventive Principle:
Principle #15Dynamics

3Reliability

If proximity-based network association is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidassociation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure association process is automated and self-service oriented. The mobile device application automatically detects the AP, initiates the secure association process, and manages the configuration access without requiring manual password entry or complex user intervention. This automation maintains security while minimizing the perceived complexity for the user.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9998923B2Systems, methods and computer-readable storage media facilitating access point management via secure association of an access point and a mobile device
Publication Date: 2018.06.12 CHENGDU SKSPRUCE TECH
  • US9998923B2 patent drawing
  • US9998923B2 patent drawing
  • US9998923B2 patent drawing

AI summary

Access point (AP) management via secure association between APs and mobile devices is facilitated. A method comprises: associating the device with an AP that is locked, wherein the associating is performed via a proximity-based network facilitating communication based on the device and the AP being within a defined distance of one another; unlocking the AP employing a key associated with the device, wherein the unlocking the AP comprises facilitating access to one or more configuration settings of the AP via the device; and enabling a service of the AP and a corresponding service of the device to facilitate change of at least one of the one or more configuration settings via the device. In one embodiment, the associating the device with the AP comprises performing exchange of information between the device and the AP for secure pairing between the device and the AP.