Temporary Wireless Network for Secure Credential Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securely joining devices to a wireless network are prone to security flaws, such as brute force attacks, and are often cumbersome or time-consuming for users, requiring manual entry of security keys or temporary wired connections.

Innovation Solution

A method is introduced where a new device joins a secure wireless network by establishing a temporary wireless network with a second device already on the network, using a shared secret key, either through physical proximity methods like 2D barcodes, near-field communications, or light/audio signals, to transfer credentials securely without exposing them to open networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional methods are used to join devices to a secure wireless network, then network security may be compromised due to brute force attacks and exposure of credentials over open networks, but the joining process becomes more secure using a temporary wireless network with shared secret keys

Engineering Contradiction:
Improvenetwork securityVSAvoidjoining process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a temporary wireless network as an intermediary channel between the new device and the existing device. This intermediary allows secure credential transfer without exposing credentials to the open target network, thus resolving the contradiction between security and complexity by providing a controlled communication path.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary authentication and credential transfer through the temporary network before the new device joins the target network. This preliminary action ensures that security credentials are exchanged in a controlled environment, preventing brute force attacks and credential exposure while maintaining a straightforward joining process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual entry of security keys is required, then network security is maintained, but the process becomes time-consuming and cumbersome for users

Engineering Contradiction:
Improvenetwork securityVSAvoidjoining time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables the new device to automatically obtain security credentials through the temporary wireless network without requiring manual key entry by the user. The existing device serves the credentials automatically, eliminating the time-consuming manual process while maintaining security through the controlled temporary network channel.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If credentials are transferred over open wireless networks, then the joining process is simplified, but security is compromised due to potential interception and brute force attacks

Engineering Contradiction:
Improvejoining process simplicityVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the credential transfer process into two distinct phases: first, secure credential exchange through the temporary wireless network; second, joining the target network with obtained credentials. This segmentation isolates the vulnerable credential transfer from the open target network, maintaining simplicity while ensuring security through physical separation of the sensitive operation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2901649B1Securely joining a secure wireless communications network
Publication Date: 2018.06.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2901649B1 patent drawingFigure 1
  • EP2901649B1 patent drawingFigure 2A~2C
  • EP2901649B1 patent drawingFigure 3

AI summary

Securely joining a secure wireless communications network is described, for example, where a printer or other device is securely added to a home wireless network. In various embodiments, a temporary wireless network is established between a new joiner device and a second wireless communications device which is already a member of a secure home wireless network. In an example, the temporary wireless network is set up using a secret key known to the new joiner device and the second wireless communications device by virtue of physical proximity. In various examples, the secure, temporary wireless network is used to transfer credentials of the secure home network to the new joiner device which then joins the home network. In an example the temporary wireless network is cancelled once the new joiner device becomes a member of the secure home (or other) wireless network.