Secure Wireless Network Access via Out-of-Band Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network systems face challenges in providing secure access to public networks, as exchanging credentials via wireless communication can be vulnerable to man-in-the-middle attacks, making it difficult to ensure secure and convenient access for users while preventing unauthorized access.

Innovation Solution

A network system that uses an enrollee device to acquire a data pattern via an out-of-band channel representing the network public key, derive a shared key, encode the enrollee public key, and transfer a network access request to a configurator device, which verifies and generates security data to establish secure communication, preventing man-in-the-middle attacks and ensuring secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credentials are exchanged via wireless communication, then network access is enabled, but security is compromised due to man-in-the-middle attacks

Engineering Contradiction:
Improvenetwork accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a configurator device as an intermediary that facilitates secure credential exchange. The configurator acts as a trusted mediator between the enrollee and the network, enabling the enrollee to obtain network access credentials without directly exposing sensitive information over the wireless channel, thus preventing man-in-the-middle attacks while maintaining ease of access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary configuration where the enrollee device is pre-configured with credentials through the configurator before joining the wireless network. This preliminary setup ensures that security credentials are established in advance through a controlled process, eliminating the need for real-time credential exchange over the potentially insecure wireless channel.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple wireless messages are exchanged for credential verification, then security is improved, but communication overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidwireless messages
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the credential verification process from the wireless communication channel and performs it through the configurator intermediary. By taking out the sensitive credential exchange from the wireless medium and handling it through the configurator, the system maintains security while significantly reducing the number of wireless messages required for authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11765172B2Network system for secure communication
Publication Date: 2023.09.19 KONINKLIJKE PHILIPS NV
  • US11765172B2 patent drawing
  • US11765172B2 patent drawing
  • US11765172B2 patent drawing

AI summary

In a network system for wireless communication an enrollee accesses the network via a configurator. The enrollee acquires a data pattern that represents a network public key via an out-of-band channel by a sensor. The enrollee derives a first shared key based on the network public key and the first enrollee private key, and encodes a second enrollee public key using the first shared key, and generates a network access request. The configurator also derives the first shared key, and verifies whether the encoded second enrollee public key was encoded by the first shared key, and, if so, generates security data and cryptographically protects data using a second shared key, and generates a network access message. The enrollee processor also derives the second shared key and verifies whether the data was cryptographically protected and, if so, engages the secure communication based on the second enrollee private key and the security data.