Token-Based Wi-Fi Access Mediation for Retail Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing Wi-Fi access in retail environments either require frequent password changes for staff or make access details visible to non-customers, failing to effectively limit access to only approved customers.

Innovation Solution

A method and system that identifies users, generates a token with quality of service data, and provides a unique output, such as a QR code, which contains time-limited access terms, ensuring only approved customers can access the Wi-Fi network without additional staff intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access details are kept secret until requested, then security is improved, but staff must manually manage and update credentials frequently

Engineering Contradiction:
ImprovesecurityVSAvoidstaff management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically generates and manages access tokens for customers without requiring staff intervention. The token generation process is automated, eliminating the need for staff to manually create, distribute, and update access credentials while maintaining security through automated token validation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An automated intermediary system (the token generation and validation system) is introduced between the customer and the network access control. This intermediary automatically handles the authentication process, generating unique tokens and validating them without requiring staff to manually manage credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access details are displayed inside premises, then ease of access for customers is improved, but non-customers can still access the network

Engineering Contradiction:
Improvecustomer access easeVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access information is segmented into two parts: a publicly visible element (the display showing access is available) and a private element (the actual token credentials). The token itself can be displayed but is designed to be difficult to access or copy, separating the public announcement function from the private authentication function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent mentions that the output can be in a form that is difficult to access, such as a QR code or dynamically generated display that changes or becomes inaccessible to unauthorized viewing. The token display can be designed to appear visible but remain functionally inaccessible to non-customers.

Inventive Principle:
Principle #32Color changes

3Device complexity

If uniform access is provided to all users, then system simplicity is improved, but customer experience and commercial offering are reduced

Engineering Contradiction:
Improveaccess control simplicityVSAvoidcustomer experience differentiation
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

Different quality of service parameters are applied to different users based on their customer status, purchase history, or membership level. The same network infrastructure is used, but the access tokens contain user-specific quality parameters such as bandwidth allocation, access duration, or feature restrictions that differentiate the customer experience.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10135884B2Access to a computer network
Publication Date: 2018.11.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10135884B2 patent drawing
  • US10135884B2 patent drawing
  • US10135884B2 patent drawing

AI summary

A system for mediating access to a computer network comprises the steps of identifying a user who wishes to access the computer network, obtaining quality of service data specific to the user, generating a token comprising the quality of service data and providing an output derived from the token to the user. Optionally, the system can further comprise receiving a request from the user for access to the computer network and providing access to the computer network to the user according to the token.