Closed Wi-Fi Hotspot Network Encryption Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wi-Fi hotspot networks are vulnerable to security attacks due to the transmission of connection information in clear text, which allows intruders to extract SSID and security type information, leading to brute-force, DoS, and evil twin attacks.

Innovation Solution

A method and system for creating a closed Wi-Fi hotspot network by transmitting encryption keys to station devices over in-band or out-of-band communication mediums, encrypting management frames with these keys, preventing intruders from eavesdropping and performing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If connection information is transmitted in clear text in beacon frames, then station devices can easily retrieve and connect to the Wi-Fi hotspot network, but the network becomes vulnerable to security attacks by intruders

Engineering Contradiction:
Improveease of connectionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the SSID and connection information from the beacon frame, preventing intruders from easily retrieving network details. Instead of including SSID in the beacon frame, the system uses a hidden SSID mechanism where the SSID is not broadcast, thus extracting the vulnerable information element from the transmission medium while maintaining connection capability for authorized devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a hidden SSID and alternative connection information distribution method. Rather than direct clear-text transmission of SSID in beacon frames, the system uses an intermediate approach where connection details are distributed through secure channels or alternative methods, mediating between the need for connectivity and security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hidden SSID feature is used to remove SSID from beacon frames, then some protection is provided, but the SSID remains exposed in other management frames such as probe frames and association frames

Engineering Contradiction:
Improvesecurity protectionVSAvoidexposure of connection information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the information distribution process into different channels and stages. Instead of relying on a single beacon frame transmission, the system divides connection information distribution across multiple secure interactions, including probe request/response sequences and association processes, where SSID is protected or obfuscated in each segment rather than exposed in clear text.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by pre-establishing secure communication channels or pre-shared keys before actual connection information is transmitted. The system prepares encrypted or protected versions of connection details in advance, so that when probe frames or association frames are exchanged, the SSID and connection information are already secured through preliminary encryption or protection mechanisms.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12081967B2Methods, access point device and station device for closed Wi-Fi hotspot network
Publication Date: 2024.09.03 SAMSUNG ELECTRONICS CO LTD
  • US12081967B2 patent drawing
  • US12081967B2 patent drawing
  • US12081967B2 patent drawing

AI summary

Disclosed herein is a method, an Access Point (AP) device for creating a closed Wireless Fidelity (Wi-Fi) hotspot network, and a method, a station device for connecting to the closed Wi-Fi hotspot network. The AP device receives a first input for creating the closed Wi-Fi hotspot network, transmits an encryption key to the station device, which is present within a predefined region, over an in-band communication medium or an out-of-band communication medium, and creates the closed Wi-Fi hotspot network by communicating management frames in cipher text with the station device. The station device receives the encryption key and the management frames from the AP device; and transmits a connection request to the AP device for connecting to the closed Wi-Fi hotspot network. The communication of the management frames in the cipher text provides improved security against attacks associated with Wi-Fi hotspot networks.