Short-Range Wireless Network Key Configuration via Secure Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security configurations in communication networks are cumbersome, prone to dictionary attacks, and insecure, particularly in push button configurations, where physical access can allow malicious users to associate devices with the network, and manual passphrase/key entry is complex and error-prone.

Innovation Solution

A key carrying device initiates pairing with network devices via short-range communication, determining their registration state and establishing a secure communication channel to transmit network keys, using techniques such as NFC, Elliptic curve Diffie-Hellman, and Advanced Encryption Standard for secure configuration and unregistration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If push button configuration is used, then device association is simplified, but security is compromised allowing unauthorized access

Engineering Contradiction:
Improvedevice associationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a configuration device as an intermediary between the network device and the external environment. This configuration device securely stores network keys and mediates the configuration process by transmitting keys only to authorized network devices through established secure channels, preventing unauthorized access while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary actions by pre-configuring network keys in the configuration device before network device association. The configuration device securely stores network keys and prepares secure communication channels in advance, so that when a network device needs to be configured, the key transmission has already been secured, preventing dictionary attacks and unauthorized access.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual passphrase entry is used, then security is improved, but configuration complexity and error rate increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables self-service by allowing the configuration device to automatically transmit network keys to network devices without requiring manual passphrase entry by users. The system performs key transmission and configuration automatically through secure channels, eliminating manual errors while maintaining strong security through cryptographic key management.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual key entry is used, then security is improved, but configuration time and user effort increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The configuration device acts as an intermediary that automatically manages key transmission. Instead of requiring users to manually enter complex keys, the configuration device securely transmits pre-generated network keys to network devices through established secure channels, dramatically reducing configuration time while maintaining security through automated cryptographic processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary key generation and secure channel establishment before the actual configuration operation. Network keys are pre-configured in the configuration device with proper security measures in place, so that the actual key transmission to network devices is a rapid automated process rather than a time-consuming manual entry process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9100382B2Network security configuration using short-range wireless communication
Publication Date: 2015.08.04 QUALCOMM INC
  • US9100382B2 patent drawing
  • US9100382B2 patent drawing
  • US9100382B2 patent drawing

AI summary

A configuration device is disclosed for configuring a network device in a communication network. The configuration device initiates pairing operations with the network device via a short-range communication connection. The configuration device determines whether the network device is in a registered state or an unregistered state. If the configuration device determines that the network device is in the unregistered state, the configuration device establishes a secure short-range communication channel between the configuration device and the network device. The configuration device transmits a network key to the network device via the secure short-range communication channel for configuring the network device to communicatively connect to the communication network. If the configuration device determines that the network device is in the registered state, the configuration device determines whether to unregister the network device.