Wireless LAN Cipher Key Setting via Automatic Terminal Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless LAN security systems face challenges in simplifying the addition of new terminals while preventing cipher key leakage, particularly in public spaces where manual registration and key setting are cumbersome and insecure, especially when dealing with multiple users and varying cipher systems.

Innovation Solution

A cipher key setting system where the terminal transmits adaptable cipher systems to the access point, which narrows and selects suitable cipher systems and keys based on a predetermined security policy, allowing secure and automatic key setting without manual intervention, and enables terminals to automatically adapt to changes in cipher systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual registration of MAC addresses and setting of WEP keys is performed, then security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The terminal automatically transmits its MAC address and receives the WEP key from the access point without manual intervention. The access point automatically registers the MAC address and generates/distributes the WEP key, eliminating the need for manual configuration while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of configuring security settings is replaced with an automatic wireless communication-based system. The terminal and access point exchange authentication information and cipher keys through wireless signals, substituting manual configuration operations with automated electronic processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If WEP key is transmitted by wireless to simplify terminal setting, then ease of operation is improved, but security deteriorates due to potential interception

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access point performs preliminary actions by generating the WEP key and preparing authentication information before wireless transmission to the terminal. This preliminary preparation ensures that the key distribution process is controlled and secure from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access point acts as an intermediary that controls the secure distribution of WEP keys to terminals. It mediates the authentication process by verifying terminal MAC addresses and distributing cipher keys through a controlled mechanism, preventing direct peer-to-peer key exposure that could be intercepted.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple cipher systems are supported to improve adaptability, then adaptability is improved, but device complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access point is designed with multi-functionality to support multiple cipher systems (WEP, TKIP, AES). It can adaptively select and switch between different encryption methods based on terminal capabilities and security requirements, providing universal compatibility across diverse devices while maintaining a unified system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7742602B2Cipher key setting system, access point, wireless LAN terminal, and cipher key setting method
Publication Date: 2010.06.22 BUFFALO CORP LTD
  • US7742602B2 patent drawing
  • US7742602B2 patent drawing
  • US7742602B2 patent drawing

AI summary

The invention intends to achieve new additions of terminals that use a wireless LAN with a simple process, while preventing leakage of data indicating cipher keys. The access point is notified of the cipher systems adaptable to the terminals. The access point narrows the cipher systems adaptable to itself, sets the cipher keys and notifies them, and also determines the station IDs for the cipher keys each. Thereafter, when the access point modifies the cipher systems based on the security policy, the access point adopts the station IDs corresponding to the cipher systems each. Therefore, the terminals specify the cipher systems based on the station IDs, and perform wireless communications by using the cipher keys notified in advance.