Token-Based WiFi Access via Telephony Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge is to facilitate seamless data offloading and rerouting from cellular networks to WiFi hotspots, which is hindered by security measures like WPA and WEP that require encryption keys, making it difficult for mobile devices to access secured WiFi networks.

Innovation Solution

The implementation of Wi-Fi Protected Setup (WPS) protocol allows mobile devices to obtain configuration data, including encryption keys, through a token provided by a network provider, enabling secure access to WiFi networks by modifying access control lists and using multiple encryption keys for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures like WPA or WEP are implemented to secure WiFi networks, then network security is improved, but ease of access for mobile devices deteriorates due to requirement of encryption keys

Engineering Contradiction:
Improvenetwork securityVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system (access control server, registrar, and token-based authentication mechanism) that mediates between the mobile device and the secured WiFi network. The server system handles the complex authentication and key distribution processes, allowing mobile devices to access secured networks without needing to manually manage encryption keys, thus resolving the contradiction between security and ease of access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automatic detection and connection to WiFi hotspots is enabled, then data offloading efficiency is improved, but security vulnerability increases due to potential unsecured networks

Engineering Contradiction:
Improvedata offloading efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the mobile device receives authentication status and network availability information from the access control server. The server provides feedback about which WiFi networks are secure and available, allowing the mobile device to make informed connection decisions automatically, thus achieving both efficient data offloading and maintained security

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple encryption keys are used for secure communication, then network security is improved, but device complexity increases due to key management requirements

Engineering Contradiction:
Improvenetwork securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the mobile device to perform self-service authentication by automatically receiving and storing encryption keys from the access control server without user intervention. The device autonomously manages its own key storage and usage, eliminating the need for complex manual key management while maintaining strong security through multiple encryption keys

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9967748B2Network access via telephony services
Publication Date: 2018.05.08 AT&T INTELLECTUAL PROPERTY I L P
  • US9967748B2 patent drawing
  • US9967748B2 patent drawing
  • US9967748B2 patent drawing

AI summary

A method includes receiving a token at a first device via a second device. The token is received by the second device from a computing system responsive to a request for access to a first wireless network secured with a network encryption key. The request is sent from the second device via a second wireless network. The computing system generates and sends the token to the second device and to a registration device in response to a determination that a user account associated with the second device permits access to the first wireless network. The method includes sending, from the first device to the registration device via the first wireless network, a hash value based on the token. Responsive to the hash value matching a second hash value generated by the registration device, the method includes receiving configuration data to enable the first device to access the first wireless network.