Wi-Fi Network Authentication via Bidirectional Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public WI-FI networks lack a robust access authentication mechanism, making users vulnerable to phishing and unauthorized access, which compromises their information security when accessing these networks.

Innovation Solution

A dual-channel authentication system where a terminal requests access verification information from an associated authentication center and then uses this information to authenticate the WI-FI network by verifying if the accessed network can interconnect with a trusted authentication center, ensuring the network's authenticity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unidirectional authentication is used for public WI-FI network access, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent inverts the traditional unidirectional authentication model by implementing bidirectional authentication. The terminal not only authenticates to the network but also verifies the network's authenticity through the associated authentication center, ensuring both sides validate each other before access is granted.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The associated authentication center serves as an intermediary that facilitates mutual authentication between the terminal and the WI-FI network. It verifies the terminal's identity and also authenticates the network's legitimacy, enabling secure access without compromising ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If open access mode is used in phishing networks, then adaptability is improved, but harmful factors increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidharmful factors
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the terminal receives authentication information from the WI-FI network and verifies it against the associated authentication center. This feedback loop enables the terminal to detect phishing networks by comparing authentication responses, thereby identifying harmful networks while maintaining adaptability to legitimate networks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The associated authentication center acts as a trusted intermediary that provides verification services. It mediates between the terminal and the WI-FI network, validating the network's authenticity and preventing terminals from connecting to phishing networks, thus reducing harmful factors while preserving network adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If bidirectional authentication is implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The associated authentication center provides multi-functional services including terminal authentication, network verification, and authentication information management. By consolidating these functions in a single intermediary system, the patent achieves bidirectional authentication without proportionally increasing terminal device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The associated authentication center serves as a centralized intermediary that handles the complexity of bidirectional authentication protocols. It manages the authentication information distribution and verification processes, allowing terminals to achieve high security reliability without implementing complex authentication logic locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10743180B2Method, apparatus, and system for authenticating WIFI network
Publication Date: 2020.08.11 HUAWEI TECH CO LTD
  • US10743180B2 patent drawing
  • US10743180B2 patent drawing
  • US10743180B2 patent drawing

AI summary

A method, an apparatus, and a system for authenticating a WI-FI network, where a terminal sends, to an associated authentication center when the WI-FI network exists in an area in which the terminal is located, a request message that carries a user identifier, receives access verification information allocated to a user represented by the first user identifier from the associated authentication center, sends, to a WI-FI authentication center, a login request that carries the access verification information, receives authentication information obtained and fed back by the WI-FI authentication center carrying a user identifier corresponding to the access verification information, and determines that the WI-FI network is a secure network when the user identifier carried in the authentication information is the same as the user identifier carried in the request message.