Vehicle Wireless Network Security Using Hashed SSID Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for securely connecting a device to a single access point in a vehicle while preventing malicious users from detecting and connecting to a wireless network published on a vehicle.

Innovation Solution

The system generates and broadcasts a hidden and hashed SSID unique to the vehicle, using encrypted wireless network configurations based on vehicle-specific data, allowing only authorized mobile devices to connect by generating a validated Secure Connection Packet (SCP) and passphrase.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a wireless network is published on a vehicle with a standard SSID, then mobile devices can easily connect to the network, but malicious users can detect and connect to the network unauthorizedly

Engineering Contradiction:
Improveease of connectionVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the SSID from a plain text identifier to a hashed version using cryptographic functions (SHA-1, MD5). This parameter change ensures that the SSID cannot be reverse-engineered to obtain the passphrase, while still allowing authorized devices with the correct hashing algorithm to connect. The hashed SSID is displayed to users, and when they enter it along with the hashed passphrase, the system verifies the hash matches before granting access.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces a hashing algorithm as an intermediary between the SSID and the connection verification process. Instead of directly comparing plain text SSIDs and passphrases, the system hashes both the displayed SSID and the user input, then compares the hashed versions. This intermediary layer prevents malicious users from obtaining the actual passphrase through SSID detection, while still enabling legitimate connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a hidden SSID is used to prevent unauthorized access, then malicious users cannot detect the network, but authorized users also cannot easily find and connect to the network

Engineering Contradiction:
Improveunauthorized accessVSAvoidease of connection
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent changes the SSID parameter from hidden to visible (hashed), allowing users to see and enter it for connection. The hashed SSID appears in the list of available networks, making it visible to users who need to connect. When users enter the hashed SSID and hashed passphrase, the system verifies the hash match, providing both visibility and security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a copy of the SSID in hashed form that can be displayed and entered by users. Instead of hiding the SSID completely, the system provides a transformed copy (hashed SSID) that users can interact with. This copied hashed version enables connection functionality while the underlying security mechanism (hashing) prevents unauthorized access.

Inventive Principle:
Principle #26Copying

3Device complexity

If standard wireless authentication is used, then connection setup is simple, but the security protocol is vulnerable to detection and exploitation

Engineering Contradiction:
Improveauthentication complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent changes the authentication parameters from plain text SSID and passphrase to hashed versions. The authentication process still follows standard wireless protocols, but the parameters being verified are hashed versions. This maintains relative simplicity in the authentication flow while dramatically improving security reliability through cryptographic hashing.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes the mechanical/security system of plain text verification with a cryptographic hashing system. Instead of directly comparing text strings, the system uses hash functions (SHA-1, MD5) to transform the SSID and passphrase into fixed-length hash values for comparison. This substitution maintains the simplicity of the authentication flow while providing robust security against detection and exploitation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250016851A1Secure Wireless Networks For Vehicle Assigning Authority
Publication Date: 2025.01.09 PLATFORM SCIENCE INC
  • US20250016851A1 patent drawing
  • US20250016851A1 patent drawing
  • US20250016851A1 patent drawing

AI summary

A system and method (600) of securely and accurately connecting mobile devices (110) to wireless networks in vehicles (210) for a predetermined work assignment by using encrypted wireless network configurations based on vehicle specific data is disclosed herein. The system comprises a vehicle (210) comprising an on-board computer (232) with a memory (231) having a vehicle identification number (233), a connector plug (235), and an motorized engine (234), a connected vehicle device (130) comprising a processor, a WiFi radio, a BLUETOOTH radio, a memory, and a connector for mating with the connector plug of the vehicle (210), and a mobile device (110) comprising a graphical user interface (335), a processor (310), a WiFi radio (307), a BLUETOOTH radio (306), and a cellular network interface (308).