Wireless Device Privacy via Credential Source Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless devices broadcasting network names (SSIDs) are susceptible to eavesdropping, leading to privacy concerns and potential spoofing attacks, as users often manually input or remember multiple network credentials, which can reveal personal information and compromise security.
Innovation Solution
Implementing a system where wireless devices obtain network information records from trusted credential sources, including docking stations, short-range wireless devices, or servers, which provide SSIDs and access credentials along with usage policies that specify when, where, and how to use these networks, such as geofencing and time-based conditions, to enhance privacy and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless devices broadcast network names (SSIDs) to locate and join networks, then network connectivity and convenience are improved, but privacy is compromised and devices become susceptible to eavesdropping and spoofing attacks
Solution Approach 1:
The patent extracts the harmful SSID broadcasting function from the network connection process. Instead of devices broadcasting their known network names, the system uses background scanning to detect networks and matches them against stored credentials without exposing the device's network knowledge to potential eavesdroppers.
Solution Approach 2:
The patent introduces an intermediary matching process between network detection and credential usage. The device scans for networks, compares detected SSIDs against a stored database of known networks, and only uses credentials when there's a match - this intermediary step prevents direct exposure of credential information while maintaining connectivity functionality.
2Ease of operation
If wireless devices persistently store network information records including SSIDs and access credentials to automatically join known networks, then ease of operation is improved, but security is worsened as credentials may be exposed
Solution Approach 1:
The patent applies local quality by differentiating between types of network information storage. Known network SSIDs are stored in a accessible database for matching purposes, while access credentials are stored separately with restricted access. The system only retrieves credentials when a specific matching condition is met, rather than having universal access to all stored information.
Solution Approach 2:
The patent performs preliminary matching of detected networks against stored known networks before attempting to use credentials. This preliminary action ensures that credentials are only used when there's a verified match, preventing unauthorized or accidental credential exposure while maintaining automatic joining functionality for legitimate networks.
3Adaptability or versatility
If wireless devices perform active scanning by broadcasting beacon signals to detect hidden networks, then network detection capability is improved, but the device exposes its own identity and known networks to eavesdroppers
Solution Approach 1:
The patent uses copying by having the device broadcast beacon signals containing only the SSID of the hidden network being searched for, not the device's own identity or other known networks. This allows the device to detect hidden networks through active scanning while minimizing information exposure by copying only the necessary network identifier in the broadcast.
Data Source
AI summary
A wireless device can obtain a network information record from another device operating as a credential source. The network information record can include network access information for a wireless network (e.g., SSID and password) and a usage policy specifying conditions under which the wireless device should search for the wireless network (e.g., temporal and/or spatial conditions). The wireless device can implement the usage policy by searching for the wireless network only when the conditions are satisfied. In some instances, the network access information can include instructions for dynamically generating time-varying network access information, and the wireless device can use the instructions to generate network access information during a search for wireless networks.


