Secure Wi-Fi Credential Provisioning via Encrypted Channel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices face challenges in automatically authenticating to Wi-Fi access points without exposing authentication credentials to potential security risks, especially when these credentials are managed by an Internet Service Provider (ISP) that needs to provision devices securely.
Innovation Solution
A mobile device establishes a secure channel with a computing system via encryption to receive and decrypt Wi-Fi authentication credentials, generating network information to authenticate and connect to the Wi-Fi access point without user input, using a secure enclave for secure credential management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Wi-Fi authentication credentials are manually entered by the user, then the mobile device can authenticate to the Wi-Fi access point, but the user convenience is reduced and the authentication process becomes time-consuming
Solution Approach 1:
The system performs preliminary actions by automatically obtaining and storing Wi-Fi authentication credentials from the computing system before the user needs to connect. The mobile device receives encrypted credentials via secure channel, decrypts them, and stores them for automatic authentication, eliminating the need for manual entry at the time of connection.
Solution Approach 2:
The mobile device is configured to automatically authenticate to Wi-Fi access points using stored credentials without requiring user intervention. The device autonomously manages the authentication process by selecting and providing the appropriate credentials when connecting to known networks.
2Extent of automation
If Wi-Fi authentication credentials are automatically obtained from the computing system, then the authentication process is automated, but security risks increase if credentials are exposed during transmission or storage
Solution Approach 1:
A secure channel acts as an intermediary mechanism between the computing system and the mobile device for transmitting credentials. The secure channel uses encryption to protect credentials during transmission, and the credentials are further protected by being stored in an encrypted form in the device's secure storage.
Solution Approach 2:
Different parts of the credential management system have different security properties. The credentials are encrypted during transmission via secure channel, stored encrypted in secure storage, and only decrypted in the secure enclave when needed for authentication. This localized security approach ensures credentials are protected throughout their lifecycle.
3Reliability
If encrypted credentials are transmitted via secure channel, then credential security is enhanced, but the complexity of the authentication setup process increases
Solution Approach 1:
The patent replaces manual credential management mechanisms with automated cryptographic systems. Instead of users manually entering and managing credentials, the system uses automated secure channel establishment, encrypted transmission, secure storage, and automatic decryption processes to manage credentials.
Data Source
AI summary
A mobile device establishes a secure channel protected via encryption with a computing system. The mobile device receives, from the computing system via the secure channel, encrypted Wi-Fi authentication credentials for a Wi-Fi access point that is associated with the mobile device and that implements a network. The mobile device decrypts the encrypted Wi-Fi authentication credentials to generate decrypted Wi-Fi authentication credentials. The mobile device generates, based on the decrypted Wi-Fi authentication credentials, network information to enable the mobile device to authenticate to the Wi-Fi access point without user input and thereby connect to the network.


