Wireless Credential Provisioning via Temporal Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless network authentication mechanisms, such as those specified in 802.11, are inadequate in preventing unauthorized access and are cumbersome to administer, especially for immobile devices like wireless printers, as they rely on shared secret keys and require manual credential provisioning.
Innovation Solution
A credential provisioning system that automates the process by initiating a waiting period after a button press, allowing the wireless supplicant to implicitly prove its identity through association requests, and then uses encrypted messages, such as SSL, to securely provide credentials without requiring manual intervention from administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If shared key authentication is used to secure wireless network access, then network security is improved, but the credential provisioning process becomes cumbersome and requires manual administrator intervention
Solution Approach 1:
The wireless supplicant automatically proves its identity by associating with the authenticator and receiving credentials without requiring manual configuration by network administrators. The system enables self-provisioning where the supplicant autonomously completes the authentication and credential receipt process.
Solution Approach 2:
The authenticator initiates a waiting period before credential provisioning, during which the supplicant must successfully associate and prove its identity. This preliminary verification step ensures that only authorized devices receive credentials, maintaining security while automating the process.
2Ease of operation
If open authentication is used to simplify access, then ease of operation is improved, but network security deteriorates as any device can connect
Solution Approach 1:
The authenticator acts as an intermediary between the supplicant and the network, mediating the authentication process. It receives association requests from supplicants during the waiting period, verifies their identity, and selectively provisions credentials only to authorized devices, thus maintaining security while enabling automated access.
3Reliability
If power limitation is applied during credential provisioning to enhance security, then network security is improved, but adaptability deteriorates for immobile devices like wireless printers
Solution Approach 1:
Instead of limiting credential provisioning by physical distance or power constraints, the system introduces a temporal dimension through a waiting period. Authorization is determined by successful association and identity proofing within this time window, enabling immobile devices like wireless printers to receive credentials without requiring physical proximity constraints.
4Reliability
If manual credential provisioning is required to maintain security, then network security is improved, but device complexity and administrative burden increase
Solution Approach 1:
The system eliminates manual administrator intervention by enabling supplicants to automatically prove their identity and receive credentials through automated authentication procedures. The authenticator autonomously manages the waiting period, verification, and credential provisioning without human involvement.
Solution Approach 2:
The authenticator monitors association requests during the waiting period and uses this feedback to determine whether to provision credentials. Successful association within the waiting period triggers automatic credential provisioning, creating a closed-loop automated system that reduces administrative complexity.
Data Source
AI summary
A credential provisioning technique is provided that is secure yet easy to administer. A credential provisioner such as a network AP is configured to leave a secure mode of operation and allow open authentication with a wireless supplicant. After open authentication is established, the wireless supplicant requests credential provisioning. In response, the credential provisioner supplies the supplicant with an encrypted password. To prevent unauthorized access, the supplicant again requests credential provisioning but also proves knowledge of the encrypted password. At least one credential is supplied to the wireless supplicant in response to the proof only if a waiting period expires with just one request for credential provisioning being received by the credential provisioner.


