Wireless Access Method Using Personal Identification Number Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless access technologies require complex and time-consuming processes to establish an encrypted connection between terminal devices and access points, especially for IoT devices lacking a visual input user interface, which reduces efficiency and makes it difficult to select service set identifiers and enter passwords.
Innovation Solution
A wireless access method that involves an access point obtaining a personal identification number from a terminal device, broadcasting a beacon with vendor-specific information, and performing authentication and key calculations to generate and transmit encrypted keys, allowing for a simplified association and key negotiation stage through fewer message exchanges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex association and key negotiation stages are used to establish encrypted connection, then connection security is improved, but establishment time and process complexity increase
Solution Approach 1:
The access point pre-stores the personal identification number in its database before the terminal device needs to connect. This preliminary storage eliminates the need for real-time password entry and authentication challenges, allowing the terminal device to directly use its stored PIN for authentication, thereby reducing connection establishment time while maintaining security.
Solution Approach 2:
The terminal device uses its own pre-stored personal identification number to authenticate itself directly with the access point without requiring user intervention or complex authentication challenges. The device performs self-authentication using its inherent identifier, simplifying the connection process and reducing establishment time while ensuring secure encrypted connection.
2Reliability
If complex association and key negotiation stages are used to establish encrypted connection, then connection security is improved, but process complexity increases
Solution Approach 1:
The invention extracts the essential authentication function from the complex Wi-Fi association and key negotiation process. By using the personal identification number stored in the access point database as the core authentication mechanism, the system simplifies the overall process while maintaining security, eliminating unnecessary complexity in the association and key negotiation stages.
Solution Approach 2:
The personal identification number serves multiple functions: it acts as the authentication credential, the basis for key derivation, and the identifier for the terminal device. This multi-functionality reduces the need for separate authentication and key establishment mechanisms, simplifying the overall process complexity while ensuring secure encrypted connection.
3Ease of operation
If IoT device lacks visual input user interface, then device simplicity is improved, but ability to select service set identifier and enter password deteriorates
Solution Approach 1:
The terminal device performs self-identification using its pre-stored personal identification number without requiring any user input or visual interface interaction. The device automatically authenticates itself with the access point using its inherent identifier, enabling seamless connection for IoT devices without visual input capabilities.
Solution Approach 2:
The access point acts as an intermediary that stores and verifies the personal identification number. Instead of requiring the terminal device to display or input a password, the access point mediates the authentication process by comparing the terminal device's stored PIN with the expected value, enabling secure connection without visual interface requirements.
Data Source
AI summary
A wireless access method includes the following steps. An access point obtains a personal identification number of a terminal device and broadcasts a beacon. The access point performs a terminal device authentication on a vendor specific information element of a probe request from the terminal device according to the personal identification number. When the terminal device authentication is successful, the access point performs a key calculation according to the personal identification number and the probe request to generate a pairwise transient key, a key encryption key and a group transient key and uses the key encryption key to encrypt a pre-shared key and the group transient key. The access point transmits a probe response to the terminal device. The access point installs the pairwise transient key and the group transient key to establish an encrypted transmission.


