Secure Wi-Fi Credential Provisioning via Encrypted Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices face challenges in automatically authenticating to Wi-Fi access points without exposing authentication credentials to potential security risks, especially when these credentials are managed by an Internet Service Provider (ISP) that needs to provision devices securely.

Innovation Solution

A mobile device establishes a secure channel with a computing system via encryption to receive and decrypt Wi-Fi authentication credentials, generating network information to authenticate and connect to the Wi-Fi access point without user input, using a secure enclave for secure credential management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Wi-Fi authentication credentials are manually entered by the user, then the mobile device can authenticate to the Wi-Fi access point, but the user convenience is reduced and the authentication process becomes time-consuming

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically obtaining and storing Wi-Fi authentication credentials from the computing system before the user needs to connect. The mobile device receives encrypted credentials via secure channel, decrypts them, and stores them for automatic authentication, eliminating the need for manual entry at the time of connection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device is configured to automatically authenticate to Wi-Fi access points using stored credentials without requiring user intervention. The device autonomously manages the authentication process by selecting and providing the appropriate credentials when connecting to known networks.

Inventive Principle:
Principle #25Self-service

2Extent of automation

If Wi-Fi authentication credentials are automatically obtained from the computing system, then the authentication process is automated, but security risks increase if credentials are exposed during transmission or storage

Engineering Contradiction:
Improveauthentication automationVSAvoidsecurity
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

A secure channel acts as an intermediary mechanism between the computing system and the mobile device for transmitting credentials. The secure channel uses encryption to protect credentials during transmission, and the credentials are further protected by being stored in an encrypted form in the device's secure storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different parts of the credential management system have different security properties. The credentials are encrypted during transmission via secure channel, stored encrypted in secure storage, and only decrypted in the secure enclave when needed for authentication. This localized security approach ensures credentials are protected throughout their lifecycle.

Inventive Principle:
Principle #3Local quality

3Reliability

If encrypted credentials are transmitted via secure channel, then credential security is enhanced, but the complexity of the authentication setup process increases

Engineering Contradiction:
Improvecredential securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual credential management mechanisms with automated cryptographic systems. Instead of users manually entering and managing credentials, the system uses automated secure channel establishment, encrypted transmission, secure storage, and automatic decryption processes to manage credentials.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250211987A1Secure access point authentication credential generation in a mobile device
Publication Date: 2025.06.26 CHARTER COMM OPERATING LLC
  • US20250211987A1 patent drawing
  • US20250211987A1 patent drawing
  • US20250211987A1 patent drawing

AI summary

A mobile device establishes a secure channel protected via encryption with a computing system. The mobile device receives, from the computing system via the secure channel, encrypted Wi-Fi authentication credentials for a Wi-Fi access point that is associated with the mobile device and that implements a network. The mobile device decrypts the encrypted Wi-Fi authentication credentials to generate decrypted Wi-Fi authentication credentials. The mobile device generates, based on the decrypted Wi-Fi authentication credentials, network information to enable the mobile device to authenticate to the Wi-Fi access point without user input and thereby connect to the network.