Secure Wi-Fi Hotspot Credential Provisioning via OMA-DM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The process of establishing subscription with a service provider for Wi-Fi network access is not user-friendly, lacks standardization, and poses security risks due to varying credential types and network security levels, with current online sign-up mechanisms exposing users to potential theft of credit card and personal information.
Innovation Solution
Implementing a standardized secure online sign-up and provisioning process using the Open Mobile Alliance Device-Management (OMA-DM) protocol, which allows for secure credential provisioning suitable for different types of credentials (username/password, SIM-type, and certificate-based) across both open and secure 802.11-based networks, enabling automatic and secure connectivity through a device-management protocol as a transport mechanism.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current online sign-up mechanisms are used, then users can register for Wi-Fi network access, but users are exposed to security risks such as theft of credit card and personal information
Solution Approach 1:
The patent introduces a device management protocol as an intermediary layer between the user and the Wi-Fi network authentication system. This protocol mediates the credential provisioning process by establishing secure channels and using trusted service providers to handle sensitive operations, thereby protecting users from direct exposure to security vulnerabilities in traditional sign-up mechanisms
Solution Approach 2:
The system enables automatic credential provisioning where the device management protocol autonomously handles the subscription establishment process. The user's device automatically receives and configures credentials without manual intervention, eliminating the need for users to directly interact with vulnerable web forms and reducing exposure to security risks
2Ease of operation
If standardized credential provisioning is implemented, then the process becomes simpler and more user-friendly, but supporting multiple credential types (username/password, SIM-type, certificate-based) increases system complexity
Solution Approach 1:
The device management protocol is designed as a universal framework that can provision multiple types of credentials (username/password, SIM-type, certificate-based) through a single standardized interface. This multi-functional approach allows the system to handle diverse credential requirements while maintaining a consistent, user-friendly process, as the protocol automatically adapts to the specific credential type needed
3Reliability
If secure networks (802.1x enabled) are used, then network security is improved, but access is prohibited to non-registrants which reduces ease of operation
Solution Approach 1:
The system performs preliminary credential provisioning through the device management protocol before the user attempts to access the secure Wi-Fi network. By pre-establishing credentials and configuring the device in advance, the system ensures that users can seamlessly connect to 802.1x secured networks without encountering access barriers, thus maintaining both security and ease of operation
Data Source
AI summary
Embodiments of a mobile device and method for secure on-line sign-up and provisioning of credentials for Wi-Fi hotspots are generally described herein. In some embodiments, the mobile device may be configured to establish a transport-layer security (TLS) session with a sign-up server through a Wi-Fi Hotspot to receive a certificate of the sign-up server. When the certificate is validated, the mobile device may be configured to exchange device management messages with the sign-up server to sign-up for a Wi-Fi subscription and provisioning of credentials, and retrieve a subscription management object (MO) that includes a reference to the provisioned credentials for storage in a device management tree. The credentials are transferred/provisioned securely to the mobile device. In some embodiments, an OMA-DM protocol may be used. The provisioned credentials may include certificates in the case of certificate-based credentials, machine-generated credentials such as username/password credentials, or SIM-type credentials.


