Smart Hub Automates Network Credential Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for connecting computing devices to secure computer networks require user input and lack scalability and security, as they do not efficiently manage the addition of multiple devices or rotate credentials effectively.

Innovation Solution

A system that uses a smart hub to establish a temporary network access point, generating a unique credential for each device, which connects to a secure network via a server-verified process, allowing seamless and secure addition of devices without user input and enabling credential rotation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional WPA connection techniques are used requiring user input at each device, then security credentials can be established, but the process becomes complex and difficult to scale when adding multiple devices

Engineering Contradiction:
ImprovescalabilityVSAvoiduser input requirement
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

A gateway device is introduced as an intermediary between the secure network and new computing devices. The gateway manages the credential distribution process by receiving credentials from the secure network and automatically distributing them to new devices, eliminating the need for manual user input at each device while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing new computing devices to automatically obtain credentials through the gateway without requiring user configuration or input. The gateway automatically detects new devices, requests credentials from the secure network, and distributes them, making the process autonomous and scalable.

Inventive Principle:
Principle #25Self-service

2Reliability

If a single shared credential is used for all devices on the secure network, then ease of connection is improved, but security is compromised if the credential is compromised

Engineering Contradiction:
Improvenetwork securityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the credential management by providing each computing device with its own unique credential instead of using a single shared credential for all devices. The gateway manages this segmentation by distributing individual credentials to each device, maintaining network security while isolating the impact of credential compromise to a single device.

Inventive Principle:
Principle #1Segmentation

3Productivity

If manual credential distribution is performed for each device, then security can be maintained, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improvedevice addition speedVSAvoidcredential distribution time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The gateway performs preliminary actions by pre-configuring itself to automatically request and receive credentials from the secure network before new devices need to connect. When a new device is detected, the credential distribution process has already been initiated or is ready to execute immediately, reducing the time required for device addition while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11284258B1Managing access of a computing device to a network
Publication Date: 2022.03.22 AMAZON TECH INC
  • US11284258B1 patent drawing
  • US11284258B1 patent drawing
  • US11284258B1 patent drawing

AI summary

Techniques for connecting computing devices to a network are described. For example, a network access device (NAD) connects to a first network that includes a first access point (AP). The NAD receives, from a computing device, first data identifying a second network to be established for the computing device and sends the first data to a server. The NAD receives back a first credential associated with access to the second network and sets up a second AP to the second network. The second AP is associated with the first credential. The NAD sends, to the computing device, second data indicating that access to the second network is available, generates a second credential associated with access to the first network via the first AP, and sends the second credential to the computing device via the second AP.