Wireless Credential Provisioning via Temporal Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless network authentication mechanisms, such as those specified in 802.11, are inadequate in preventing unauthorized access and are cumbersome to administer, especially for immobile devices like wireless printers, as they rely on shared secret keys and require manual credential provisioning.

Innovation Solution

A credential provisioning system that automates the process by initiating a waiting period after a button press, allowing the wireless supplicant to implicitly prove its identity through association requests, and then uses encrypted messages, such as SSL, to securely provide credentials without requiring manual intervention from administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If shared key authentication is used to secure wireless network access, then network security is improved, but the credential provisioning process becomes cumbersome and requires manual administrator intervention

Engineering Contradiction:
Improvenetwork securityVSAvoidcredential provisioning process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The wireless supplicant automatically proves its identity by associating with the authenticator and receiving credentials without requiring manual configuration by network administrators. The system enables self-provisioning where the supplicant autonomously completes the authentication and credential receipt process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authenticator initiates a waiting period before credential provisioning, during which the supplicant must successfully associate and prove its identity. This preliminary verification step ensures that only authorized devices receive credentials, maintaining security while automating the process.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If open authentication is used to simplify access, then ease of operation is improved, but network security deteriorates as any device can connect

Engineering Contradiction:
Improveauthentication processVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authenticator acts as an intermediary between the supplicant and the network, mediating the authentication process. It receives association requests from supplicants during the waiting period, verifies their identity, and selectively provisions credentials only to authorized devices, thus maintaining security while enabling automated access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If power limitation is applied during credential provisioning to enhance security, then network security is improved, but adaptability deteriorates for immobile devices like wireless printers

Engineering Contradiction:
Improvenetwork securityVSAvoidcompatibility with immobile devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of limiting credential provisioning by physical distance or power constraints, the system introduces a temporal dimension through a waiting period. Authorization is determined by successful association and identity proofing within this time window, enabling immobile devices like wireless printers to receive credentials without requiring physical proximity constraints.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If manual credential provisioning is required to maintain security, then network security is improved, but device complexity and administrative burden increase

Engineering Contradiction:
Improvenetwork securityVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system eliminates manual administrator intervention by enabling supplicants to automatically prove their identity and receive credentials through automated authentication procedures. The authenticator autonomously manages the waiting period, verification, and credential provisioning without human involvement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authenticator monitors association requests during the waiting period and uses this feedback to determine whether to provision credentials. Successful association within the waiting period triggers automatic credential provisioning, creating a closed-loop automated system that reduces administrative complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7555783B2Wireless network credential provisioning
Publication Date: 2009.06.30 CISCO TECHNOLOGY INC
  • US7555783B2 patent drawing
  • US7555783B2 patent drawing
  • US7555783B2 patent drawing

AI summary

A credential provisioning technique is provided that is secure yet easy to administer. A credential provisioner such as a network AP is configured to leave a secure mode of operation and allow open authentication with a wireless supplicant. After open authentication is established, the wireless supplicant requests credential provisioning. In response, the credential provisioner supplies the supplicant with an encrypted password. To prevent unauthorized access, the supplicant again requests credential provisioning but also proves knowledge of the encrypted password. At least one credential is supplied to the wireless supplicant in response to the proof only if a waiting period expires with just one request for credential provisioning being received by the credential provisioner.