Secure Wi-Fi Hotspot Credential Provisioning via OMA-DM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The process of establishing subscription with a service provider for Wi-Fi network access is not user-friendly, lacks standardization, and poses security risks due to varying credential types and network security levels, with current online sign-up mechanisms exposing users to potential theft of credit card and personal information.

Innovation Solution

Implementing a standardized secure online sign-up and provisioning process using the Open Mobile Alliance Device-Management (OMA-DM) protocol, which allows for secure credential provisioning suitable for different types of credentials (username/password, SIM-type, and certificate-based) across both open and secure 802.11-based networks, enabling automatic and secure connectivity through a device-management protocol as a transport mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current online sign-up mechanisms are used, then users can register for Wi-Fi network access, but users are exposed to security risks such as theft of credit card and personal information

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a device management protocol as an intermediary layer between the user and the Wi-Fi network authentication system. This protocol mediates the credential provisioning process by establishing secure channels and using trusted service providers to handle sensitive operations, thereby protecting users from direct exposure to security vulnerabilities in traditional sign-up mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automatic credential provisioning where the device management protocol autonomously handles the subscription establishment process. The user's device automatically receives and configures credentials without manual intervention, eliminating the need for users to directly interact with vulnerable web forms and reducing exposure to security risks

Inventive Principle:
Principle #25Self-service

2Ease of operation

If standardized credential provisioning is implemented, then the process becomes simpler and more user-friendly, but supporting multiple credential types (username/password, SIM-type, certificate-based) increases system complexity

Engineering Contradiction:
Improveuser-friendlinessVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The device management protocol is designed as a universal framework that can provision multiple types of credentials (username/password, SIM-type, certificate-based) through a single standardized interface. This multi-functional approach allows the system to handle diverse credential requirements while maintaining a consistent, user-friendly process, as the protocol automatically adapts to the specific credential type needed

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure networks (802.1x enabled) are used, then network security is improved, but access is prohibited to non-registrants which reduces ease of operation

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary credential provisioning through the device management protocol before the user attempts to access the secure Wi-Fi network. By pre-establishing credentials and configuring the device in advance, the system ensures that users can seamlessly connect to 802.1x secured networks without encountering access barriers, thus maintaining both security and ease of operation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10341328B2Secure on-line sign-up and provisioning for Wi-Fi hotspots using a device-management protocol
Publication Date: 2019.07.02 MEDIATEK INC
  • US10341328B2 patent drawing
  • US10341328B2 patent drawing
  • US10341328B2 patent drawing

AI summary

Embodiments of a mobile device and method for secure on-line sign-up and provisioning of credentials for Wi-Fi hotspots are generally described herein. In some embodiments, the mobile device may be configured to establish a transport-layer security (TLS) session with a sign-up server through a Wi-Fi Hotspot to receive a certificate of the sign-up server. When the certificate is validated, the mobile device may be configured to exchange device management messages with the sign-up server to sign-up for a Wi-Fi subscription and provisioning of credentials, and retrieve a subscription management object (MO) that includes a reference to the provisioned credentials for storage in a device management tree. The credentials are transferred/provisioned securely to the mobile device. In some embodiments, an OMA-DM protocol may be used. The provisioned credentials may include certificates in the case of certificate-based credentials, machine-generated credentials such as username/password credentials, or SIM-type credentials.