Closed Wi-Fi Hotspot Network Encryption Key Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wi-Fi hotspot networks are vulnerable to security attacks due to the transmission of connection information in clear text, which allows intruders to extract SSID and security type information, leading to brute-force, DoS, and evil twin attacks.
Innovation Solution
A method and system for creating a closed Wi-Fi hotspot network by transmitting encryption keys to station devices over in-band or out-of-band communication mediums, encrypting management frames with these keys, preventing intruders from eavesdropping and performing attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If connection information is transmitted in clear text in beacon frames, then station devices can easily retrieve and connect to the Wi-Fi hotspot network, but the network becomes vulnerable to security attacks by intruders
Solution Approach 1:
The patent extracts the SSID and connection information from the beacon frame, preventing intruders from easily retrieving network details. Instead of including SSID in the beacon frame, the system uses a hidden SSID mechanism where the SSID is not broadcast, thus extracting the vulnerable information element from the transmission medium while maintaining connection capability for authorized devices.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a hidden SSID and alternative connection information distribution method. Rather than direct clear-text transmission of SSID in beacon frames, the system uses an intermediate approach where connection details are distributed through secure channels or alternative methods, mediating between the need for connectivity and security protection.
2Reliability
If hidden SSID feature is used to remove SSID from beacon frames, then some protection is provided, but the SSID remains exposed in other management frames such as probe frames and association frames
Solution Approach 1:
The patent segments the information distribution process into different channels and stages. Instead of relying on a single beacon frame transmission, the system divides connection information distribution across multiple secure interactions, including probe request/response sequences and association processes, where SSID is protected or obfuscated in each segment rather than exposed in clear text.
Solution Approach 2:
The patent applies preliminary action by pre-establishing secure communication channels or pre-shared keys before actual connection information is transmitted. The system prepares encrypted or protected versions of connection details in advance, so that when probe frames or association frames are exchanged, the SSID and connection information are already secured through preliminary encryption or protection mechanisms.
Data Source
AI summary
Disclosed herein is a method, an Access Point (AP) device for creating a closed Wireless Fidelity (Wi-Fi) hotspot network, and a method, a station device for connecting to the closed Wi-Fi hotspot network. The AP device receives a first input for creating the closed Wi-Fi hotspot network, transmits an encryption key to the station device, which is present within a predefined region, over an in-band communication medium or an out-of-band communication medium, and creates the closed Wi-Fi hotspot network by communicating management frames in cipher text with the station device. The station device receives the encryption key and the management frames from the AP device; and transmits a connection request to the AP device for connecting to the closed Wi-Fi hotspot network. The communication of the management frames in the cipher text provides improved security against attacks associated with Wi-Fi hotspot networks.


