Vehicle Wireless Network Security Using Hashed SSID Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for securely connecting a device to a single access point in a vehicle while preventing malicious users from detecting and connecting to a wireless network published on a vehicle.
Innovation Solution
The system generates and broadcasts a hidden and hashed SSID unique to the vehicle, using encrypted wireless network configurations based on vehicle-specific data, allowing only authorized mobile devices to connect by generating a validated Secure Connection Packet (SCP) and passphrase.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a wireless network is published on a vehicle with a standard SSID, then mobile devices can easily connect to the network, but malicious users can detect and connect to the network unauthorizedly
Solution Approach 1:
The patent transforms the SSID from a plain text identifier to a hashed version using cryptographic functions (SHA-1, MD5). This parameter change ensures that the SSID cannot be reverse-engineered to obtain the passphrase, while still allowing authorized devices with the correct hashing algorithm to connect. The hashed SSID is displayed to users, and when they enter it along with the hashed passphrase, the system verifies the hash matches before granting access.
Solution Approach 2:
The patent introduces a hashing algorithm as an intermediary between the SSID and the connection verification process. Instead of directly comparing plain text SSIDs and passphrases, the system hashes both the displayed SSID and the user input, then compares the hashed versions. This intermediary layer prevents malicious users from obtaining the actual passphrase through SSID detection, while still enabling legitimate connections.
2Object-affected harmful factors
If a hidden SSID is used to prevent unauthorized access, then malicious users cannot detect the network, but authorized users also cannot easily find and connect to the network
Solution Approach 1:
The patent changes the SSID parameter from hidden to visible (hashed), allowing users to see and enter it for connection. The hashed SSID appears in the list of available networks, making it visible to users who need to connect. When users enter the hashed SSID and hashed passphrase, the system verifies the hash match, providing both visibility and security.
Solution Approach 2:
The patent creates a copy of the SSID in hashed form that can be displayed and entered by users. Instead of hiding the SSID completely, the system provides a transformed copy (hashed SSID) that users can interact with. This copied hashed version enables connection functionality while the underlying security mechanism (hashing) prevents unauthorized access.
3Device complexity
If standard wireless authentication is used, then connection setup is simple, but the security protocol is vulnerable to detection and exploitation
Solution Approach 1:
The patent changes the authentication parameters from plain text SSID and passphrase to hashed versions. The authentication process still follows standard wireless protocols, but the parameters being verified are hashed versions. This maintains relative simplicity in the authentication flow while dramatically improving security reliability through cryptographic hashing.
Solution Approach 2:
The patent substitutes the mechanical/security system of plain text verification with a cryptographic hashing system. Instead of directly comparing text strings, the system uses hash functions (SHA-1, MD5) to transform the SSID and passphrase into fixed-length hash values for comparison. This substitution maintains the simplicity of the authentication flow while providing robust security against detection and exploitation.
Data Source
AI summary
A system and method (600) of securely and accurately connecting mobile devices (110) to wireless networks in vehicles (210) for a predetermined work assignment by using encrypted wireless network configurations based on vehicle specific data is disclosed herein. The system comprises a vehicle (210) comprising an on-board computer (232) with a memory (231) having a vehicle identification number (233), a connector plug (235), and an motorized engine (234), a connected vehicle device (130) comprising a processor, a WiFi radio, a BLUETOOTH radio, a memory, and a connector for mating with the connector plug of the vehicle (210), and a mobile device (110) comprising a graphical user interface (335), a processor (310), a WiFi radio (307), a BLUETOOTH radio (306), and a cellular network interface (308).


