Secure Wireless LAN Access via Mobile Relay Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless LAN access methods are cumbersome and insecure, particularly for public hotspots, as users must manually input lengthy MAC addresses and WEP keys, which are prone to errors and vulnerabilities, and lack robust security measures against eavesdropping and malicious access points.

Innovation Solution

A system that uses a mobile phone to establish a secure connection through a relay server and VPN, where a setting program is downloaded via short-range communication to ensure authentication and encryption over potentially unsecured links, preventing data leakage and tampering by authenticating users and encrypting communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users manually input MAC addresses and WEP keys for wireless LAN access, then registration can be completed, but the process becomes troublesome and error-prone

Engineering Contradiction:
Improveease of registrationVSAvoidtime for input
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent introduces a mobile phone as an intermediary device that automatically transmits the setting program to the information processing device. This mediator eliminates the need for users to manually input MAC addresses and WEP keys, resolving the contradiction by making registration easier while reducing time loss through automated program distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The setting program is prepared in advance on the mobile phone, containing all necessary authentication information and security settings. This preliminary preparation allows the information processing device to be configured automatically without user input during the registration process, improving ease of operation while minimizing time loss.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If WEP keys and SSID are used for wireless LAN security, then basic authentication is provided, but the security system becomes vulnerable to attacks

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the security parameters from traditional WEP keys and SSID to a more robust authentication mechanism using a setting program that implements mutual authentication between the information processing device and the relay server. This parameter change maintains reliability while reducing vulnerability to attacks by using stronger cryptographic methods.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The relay server acts as an intermediary that facilitates secure authentication between the information processing device and the communication network. It verifies the setting program and manages authentication, providing enhanced security while reducing vulnerability compared to direct WEP key authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If robust security measures like IPSec and PPTP are implemented, then security is improved, but user operations become more complicated

Engineering Contradiction:
ImprovesecurityVSAvoidease of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The setting program automatically configures security settings on the information processing device without requiring user intervention. The program self-installs and configures robust security measures like IPSec or PPTP connections, maintaining high reliability while improving ease of operation by eliminating complicated manual setup procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

All security configurations are pre-packaged in the setting program on the mobile phone. When transmitted to the information processing device, the program automatically applies robust security measures without requiring the user to understand or configure complex security parameters, thus maintaining security while simplifying operations.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If public wireless LAN access points are used for convenience, then accessibility is improved, but security against eavesdropping and malicious intercepts deteriorates

Engineering Contradiction:
ImproveaccessibilityVSAvoideavesdropping risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The relay server serves as a trusted intermediary between the information processing device and the communication network through the public wireless LAN. It establishes secure authenticated connections that protect against eavesdropping and malicious intercepts, maintaining accessibility to public hotspots while reducing security risks through encrypted and authenticated communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The setting program performs preliminary authentication and establishes security protections before data transmission begins. By pre-configuring secure connection parameters and authenticating with the relay server, the system prevents eavesdropping and malicious intercepts from succeeding, allowing safe use of public access points.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS7283820B2Secure communication over a medium which includes a potentially insecure communication link
Publication Date: 2007.10.16 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US7283820B2 patent drawing
  • US7283820B2 patent drawing
  • US7283820B2 patent drawing

AI summary

In an information processing system, a mobile phone obtains a setting program which makes security settings for ensuring security of communication by performing authentication with a communication destination on an unsecured communication link, from a registration server through a secure, first communication link; an information processing device executes the setting program obtained from the mobile phone to make security settings, communicates with a relay server through an unsecured, second communication link; the registration server receives access from the mobile phone through the first communication link, authenticates a user, and sends the setting program to the mobile phone; the relay server authenticates an information processing device in response to a connection request from the information processing device, makes security settings, and relays access from the information processing device to a communication network through the second communication link.