Secure Wi-Fi Pairing via Hidden Network Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Wi-Fi pairing methods, such as WPS, are inadequate for secure and easy pairing of stations (STA) with access points (AP), especially for users who are not tech-savvy, as they require excessive user intervention and third-party equipment.

Innovation Solution

A method for associating a Wi-Fi station with a Wi-Fi access point using a second Wi-Fi network not advertised by the access point, where security information is transmitted through this second network to secure the association with the first network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DPP (Device Provisioning Protocol) is used to ensure strong authentication and increase security level, then security is improved, but user operation complexity increases excessively requiring specific mobile application installation and third-party equipment

Engineering Contradiction:
Improvesecurity levelVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses a hidden Wi-Fi network as an intermediary channel to exchange security information between the station and access point. This mediator enables secure authentication without requiring third-party equipment or complex user operations, as the security data is automatically exchanged through the hidden network before the visible network association is established.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs security information exchange in advance through the hidden network before the station associates with the visible network. By preliminarily establishing secure authentication credentials through the hidden channel, the system eliminates the need for complex user operations during the visible network pairing process.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If WPS (Wi-Fi Protected Setup) is used for pairing, then ease of operation is improved with simple button press, but security level becomes inadequate compared to DPP

Engineering Contradiction:
Improvepairing simplicityVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The hidden Wi-Fi network serves as a secure intermediary channel that automatically exchanges cryptographic keys and security information between the station and access point. This intermediary mechanism provides strong security comparable to DPP while maintaining the simplicity of automatic pairing without requiring third-party equipment or complex user interventions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If security information is exchanged over the first Wi-Fi network, then the association process is simplified, but security is compromised as the network is not yet secure at the time of exchange

Engineering Contradiction:
Improveassociation process complexityVSAvoidsecurity of information exchange
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the Wi-Fi network into two distinct channels: a hidden network for secure security information exchange and a visible network for normal data communication. This segmentation allows security credentials to be exchanged through the hidden channel before the visible network association is established, ensuring that security information is protected during exchange while maintaining a simple overall association process.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250056233A1Methods and devices facilitating secure wi-fi pairing
Publication Date: 2025.02.13 ORANGE SA
  • US20250056233A1 patent drawing
  • US20250056233A1 patent drawing

AI summary

A method for associating a Wi-Fi station with a Wi-Fi access point through a first Wi-Fi network advertised by the access point. The method is implemented by the station and includes: setting up an association (of the station with the access point through a second Wi-Fi network not advertised by the access point; transmitting security information to the access point, through the second network; and setting up an association of the station with the access point through the first network, depending on the security information.