Online Signup Server for Wi-Fi Hotspot Credential Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The process of signing up for and connecting to a Wi-Fi hotspot is not user-friendly, lacking a standardized mechanism for secure online signup and credential provisioning across different types of credentials and networks.

Innovation Solution

Implementing a system that uses device management protocols like OMA-DM and SOAP-XML to enable secure online signup and credential provisioning for Wi-Fi hotspots, integrating with cellular network backend components to facilitate seamless Wi-Fi offloading, utilizing a captive portal with anonymous EAP-TLS authentication and certificate enrollment processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a standardized mechanism is implemented for secure online signup, then the ease of operation is improved, but the device complexity increases due to integration of multiple protocols and authentication mechanisms

Engineering Contradiction:
Improvesignup processVSAvoidauthentication system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an Online Signup Server as an intermediary component that mediates between the wireless device and the network infrastructure. This server handles the complex authentication logic, credential provisioning, and coordination between EAP-TLS authentication, certificate enrollment, and device management protocols, thereby simplifying the user interface while managing the underlying complexity centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Online Signup Server is designed as a universal platform that handles multiple credential types (username/password, certificates, SIM-based credentials), supports various device management protocols (OMA-DM, SOAP-XML), and integrates with different network infrastructures (cellular backend, Wi-Fi networks). This multi-functional design consolidates diverse authentication mechanisms into a single standardized interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple types of credentials are provisioned, then the adaptability is improved, but the device complexity increases due to management of different credential formats and protocols

Engineering Contradiction:
Improvecredential typesVSAvoidcredential management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The Online Signup Server implements a universal credential management system that can provision and manage multiple types of credentials (username/password, X.509 certificates, SIM-based credentials) through a standardized interface. The server automatically selects and processes the appropriate credential type based on device capabilities and network requirements, eliminating the need for devices to implement complex multi-protocol credential management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service credential provisioning where the device automatically receives and configures appropriate credentials based on its capabilities and the selected authentication method. The Online Signup Server automatically enrolls certificates, provisions credentials, and configures device settings without requiring manual user intervention for each credential type, thereby simplifying credential management while maintaining versatility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2939490B1Secure on-line signup and provisioning of wireless devices
Publication Date: 2020.09.30 INTEL CORP
  • EP2939490B1 patent drawingFigure 1
  • EP2939490B1 patent drawingFigure 2
  • EP2939490B1 patent drawingFigure 3

AI summary

Embodiments of a mobile device and method for secure online sign-up and provisioning of credentials for Wi-Fi hotspots are generally described herein. In some embodiments, provisioning occurs using a service set identifier (SSID) to associate with a hotspot and retrieve a virtual LAN (VLAN) identifier. The VLAN identifier is used to complete the signup and provisioning process. In some embodiments, a hotspot may implement a primary SSID and a dependent SSID. The mobile device associates with the hotspot using the dependent SSID to perform the secure online signup and provisioning process. Once credentials are obtained using the signup and provisioning process, the device can connect to the hotspot using the primary SSID and the already provisioned credentials. The provisioned credentials may include certificates, username/password, or SIM-type credentials.