Secure Network Provisioning Device for Seamless Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of secure network access procedures hinders casual networking, as existing methods require elaborate configurations and often involve insecure credential sharing, which compromises security and is cumbersome for devices accessing new networks.

Innovation Solution

A secure network provisioning device that connects to a security authority to acquire and manage network profiles, allowing seamless secure network access by switching between acquisition and gateway modes, enabling secure connections without requiring manual configuration on client devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure network access procedures are implemented with proper security mechanisms, then network security is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A portable networking device acts as an intermediary between client devices and secure networks. This device pre-acquires network profiles and credentials from security authorities, then provides them to client devices through direct connections. The intermediary handles the complexity of security configuration, allowing casual users to access secure networks without dealing with complex security mechanisms directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The portable networking device performs preliminary actions by acquiring network profiles and credentials from security authorities before client devices need to access the network. This pre-acquisition process handles the complex configuration work in advance, so when client devices connect to the portable device, they receive ready-to-use network access information without needing to undergo complex configuration procedures themselves.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If network access credentials are shared locally to enable casual networking, then ease of operation is improved, but security is compromised

Engineering Contradiction:
Improvenetwork access convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The portable networking device serves as a secure intermediary that manages network credentials. Instead of users directly sharing sensitive credentials like passwords and encryption keys, the portable device holds these credentials securely and provides network access through controlled connections. This eliminates the security risks of credential sharing while maintaining the convenience of local access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The portable networking device creates secure copies of network profiles and credentials from the security authority. These copies are stored in the portable device's memory and can be provided to multiple client devices as needed. The original credentials remain secure in the authorized system, while the portable device holds validated copies that enable convenient access without exposing the master credentials.

Inventive Principle:
Principle #26Copying

3Reliability

If network profiles are acquired from security authorities, then network security is maintained, but configuration time and complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The portable networking device performs the time-consuming task of acquiring network profiles from security authorities in advance, before client devices need to access the network. This preliminary acquisition process is done once when the portable device connects to the security authority, and the resulting profiles can then be quickly distributed to multiple client devices without repeating the lengthy authentication and configuration process each time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The configuration process is segmented into two distinct phases: (1) The portable networking device acquires network profiles from the security authority in a preliminary step, and (2) Client devices quickly connect to the portable device to receive pre-prepared network access information. This segmentation separates the time-consuming security authentication from the quick local connection process, reducing overall configuration time for end users.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7769995B2System and method for providing secure network access
Publication Date: 2010.08.03 ADEIA TECHNOLOGIES INC
  • US7769995B2 patent drawing
  • US7769995B2 patent drawing
  • US7769995B2 patent drawing

AI summary

Secure network access is provided by connecting a secure network provisioning device to a security authority, acquiring one or more network profiles, configuring one or more network interfaces of the secure network provisioning device with data corresponding to attributes of the acquired network profiles, switching the secure network provisioning device from an acquisition mode to a gateway mode, and connecting the secure network provisioning device to a client device. The secure network provisioning device includes a first set of network communication interfaces requiring configuration blocks to enable access to associated networks, a second set of network communication interfaces free from a requirement for configuration prior to network access, a communication interface gateway module configured to gate network traffic between network communication interfaces and a network profile acquisition module configured to acquire network profiles containing data required to configure the communication interfaces of the first set.