Server-Based Network Credential Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for connecting computing devices to secure wireless networks require user input and lack robust security measures, particularly against man-in-the-middle attacks, and do not facilitate automatic setup.
Innovation Solution
A server-based setup process that enables automatic connection of computing devices to secure data networks without user input, using mutual authentication and digital signatures to secure the connection, and restricting data traffic through hidden open networks to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If WPS or other connection techniques are used, then a secure wireless network connection can be established, but user input is required at the computing device and/or wireless access point
Solution Approach 1:
A server acts as an intermediary between the computing device and the wireless access point. The server receives connection requests from the computing device, retrieves credentials for the target network, and provides them back to the device. This eliminates the need for users to manually input credentials at either the device or access point, while the server automates the credential retrieval and distribution process.
2Reliability
If traditional connection techniques are used, then connection can be established, but security measures are insufficient against man-in-the-middle attacks
Solution Approach 1:
The server performs preliminary authentication and credential retrieval before the computing device attempts to connect to the wireless network. The server verifies the computing device's authorization and obtains the correct network credentials in advance, ensuring that only authenticated devices receive credentials. This preliminary security check prevents man-in-the-middle attacks by establishing trust before the actual network connection is made.
3Productivity
If manual connection setup is used, then connection can be established, but the process is time-consuming and inefficient
Solution Approach 1:
The computing device autonomously initiates the connection process by sending a request to the server. The server automatically retrieves the appropriate credentials from its database and provides them to the device without requiring user intervention. This self-service mechanism eliminates manual configuration steps and significantly reduces the time required to establish a network connection.
Data Source
AI summary
Techniques for providing a credential of a secure data network to a computing device are described. In an example, a system stores an association between the computing device and a user account. The user account is also associated with a credential of the secure data network. The system receives a certificate of the computing device and determines the association between the computing device and the user account based on the certificate. Further, the system authenticates the computing device based on the association being determined to send to the computing device data, where this data is verified based on a private key of the system. The system receives a request of the computing device for the credential based on the data and sends the credential to the computing device.


