Self-Organized Network Access Using Trust Chains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network access systems face challenges in balancing secure access for trusted users with open access to all, while preventing malicious users from exploiting bandwidth and accessing private data, especially in community-wide networks, without requiring a separate authentication server.

Innovation Solution

A self-organized network access system that uses instant messaging buddy lists to determine trust relationships, allowing access based on pre-established trust groups, with optional broadcast of instant messaging addresses and investigation of chain of trust relationships to grant access levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless network access is opened to all users within range, then network accessibility and convenience are improved, but security risks and bandwidth abuse by malicious users increase

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity risks and bandwidth abuse
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism using existing instant messaging buddy lists as a trust verification system. The access point owner's buddy list serves as an intermediary database to determine whether requesting users are trusted, eliminating the need for direct key distribution while maintaining security. This intermediary trust verification system allows open access for trusted users while blocking untrusted users without requiring a separate authentication server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If wireless network access is restricted to trusted users only, then security is improved, but network accessibility and convenience for transient users deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork accessibility for transient users
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent makes the existing instant messaging buddy list system serve multiple functions: it continues to manage trusted contacts for private communications while simultaneously serving as an authentication mechanism for wireless network access. This multi-functional use of the buddy list eliminates the need for separate authentication infrastructure, making security verification convenient for both permanent and transient users without requiring new key distribution processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If authentication keys are distributed to users for security, then access control is improved, but convenience and security against key distribution chains deteriorate

Engineering Contradiction:
Improveaccess controlVSAvoidconvenience of access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent extracts the authentication verification function from the traditional key distribution model and relocates it to the existing buddy list infrastructure. Instead of distributing cryptographic keys that users must manually input and protect, the system extracts trust verification to the access point owner's buddy list, which automatically verifies user identity without requiring key distribution. This eliminates the security risks and inconvenience associated with key management while maintaining access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7788707B1Self-organized network setup
Publication Date: 2010.08.31 SPRINT SPECTRUM LLC
  • US7788707B1 patent drawing
  • US7788707B1 patent drawing
  • US7788707B1 patent drawing

AI summary

A second user requests access to a wireless access point, such as a WiFi connection, provided by a first user. To determine whether the first user should be provided with access, the second user identifies a chain of trust relationships between the first and second users. The chain of trust relationships is established by determining if, for example, the first user is in an instant messaging buddy list of the second user, or if there is an intermediate user who both trusts the first user and is trusted by the second user. If a chain of trust relationships between the first and second users exists and is not too attenuated, the second user provides the first user with network access.