Wireless Authentication via Isolated Security Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks face security threats and network congestion when security keys are shared, allowing unauthorized access by multiple devices.

Innovation Solution

A method that generates a security key for authentication with an access point in infrastructure mode and switches to ad hoc communication mode to broadcast network information, determining approved devices and sending authentication requests on their behalf without sharing the security key, encrypting challenge text to authenticate devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the security key is shared with the guest mobile device, then the guest can access the wireless network, but the likelihood of unauthorized access and network congestion increases

Engineering Contradiction:
Improveease of network accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into two distinct phases: a setup phase where the host device establishes security credentials with the access point, and a guest phase where the host device acts as an intermediary to authenticate guest devices without sharing the actual security key. This segmentation allows the security key to remain confined to the host device while still enabling guest access through controlled delegation of authentication capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The host device serves as an intermediary between guest devices and the access point. Instead of directly sharing the security key with guests, the host device receives authentication requests from guests, processes them using its stored security credentials, and forwards authenticated guests to the network. This intermediary role eliminates the need for key distribution while maintaining ease of guest access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the security key is not shared, then network security is maintained, but guests cannot access the wireless network

Engineering Contradiction:
Improvenetwork securityVSAvoidease of network access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The host device acts as a mediator that bridges the gap between security requirements and guest access needs. The host device stores the security key securely and uses it to authenticate guests on their behalf, allowing guests to access the network without ever receiving the actual security key. This maintains network security while providing convenient guest access through the host's intermediary authentication services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The host device provides self-service authentication capabilities to guests. Instead of manually sharing keys or configuring each guest device individually, the host device automatically processes authentication requests from guests using its stored credentials, enabling guests to connect to the network independently while the host device manages the security aspects automatically.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple devices are allowed to access the network, then network utility is improved, but network congestion and security threats increase

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidnetwork congestion
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback control where the host device monitors and manages guest device connections. The host device receives authentication requests, verifies them against its security credentials, and selectively grants or denies access based on authentication success. This feedback mechanism allows multiple authorized devices to access the network while maintaining control over connection quality and security, preventing unauthorized devices from contributing to network congestion.

Inventive Principle:
Principle #23Feedback

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This method allows secure access to wireless networks without disclosing the security key, reducing unauthorized access and network congestion by controlling device authentication through an intermediary station.

Implementation Method 1

The processor is further configured to encrypt the challenge text based on the security key to generate encrypted challenge text. The security key is isolated from the second station.

Methodology Applied
Scientific EffectEncryption:

Data Source

PatentUS11496898B2Wireless network authentication using isolated security key
Publication Date: 2022.11.08 SCURRY CHRISTOPHER MICHAEL
  • US11496898B2 patent drawing
  • US11496898B2 patent drawing
  • US11496898B2 patent drawing

AI summary

A method includes generating, at a first station, a security key that is usable for authentication with an access point associated with a wireless network. The method includes switching from an infrastructure mode to an ad hoc communication mode, and while in the ad hoc communication mode, broadcasting a beacon frame and receiving a request, from a second station, to join the wireless network. The method includes determining that the second station is an approved device and sending a first authentication request to the access point on behalf of the second station. The method includes receiving a first authentication response, including challenge text, from the access point. The method includes encrypting the challenge text based on the security key and sending the encrypted challenge text as part of a second authentication request to the access point to authenticate the second station with the access point.