WLAN Credential Storage in Network Settings for Seamless Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for authenticating electronic devices on open WLAN networks require frequent re-login due to temporary authentication sessions and lack of secure credential storage, with browser-managed credentials being vulnerable to third-party access and not associated with specific networks.

Innovation Solution

Storing website credentials in a network settings space, such as a WLAN profile, and using a website credential API to manage authentication, allowing automatic re-login and secure storage of credentials within a secure network layer, separate from browser applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credentials are stored in browser data storage space, then authentication process is simple, but credentials are vulnerable to being spoofed by third party applications

Engineering Contradiction:
Improveauthentication processVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts credential storage from the browser application layer and places it in the device's secure network settings space. The browser no longer manages credentials directly, but instead communicates them to the network settings which stores them securely. This separation removes credentials from the vulnerable browser storage environment while maintaining the authentication workflow.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If browser manages credentials independently, then browser operation is simple, but credentials are not associated with specific WLAN networks

Engineering Contradiction:
Improvebrowser operationVSAvoidnetwork-specific credential association
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent merges credential storage with WLAN network profiles in the device's network settings. Instead of storing credentials generically in the browser, the system associates credentials with specific network identifiers (SSID, BSSID) in the network settings space. This allows the device to automatically select and use appropriate credentials when connecting to specific WLAN networks, while the browser continues to operate independently.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If authentication session is temporary, then security is improved, but frequent re-login is required

Engineering Contradiction:
Improveauthentication securityVSAvoidre-login time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by automatically retrieving and submitting stored credentials when the device reconnects to a WLAN network, before the user needs to manually re-authenticate. The system monitors network connection status and automatically performs re-authentication using credentials pre-stored in the network settings, eliminating the need for user intervention while maintaining secure temporary sessions.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If credentials are stored in network settings space, then credential security is improved, but device complexity increases

Engineering Contradiction:
Improvecredential securityVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary communication interface between the browser application and the network settings space. This intermediary mechanism allows the browser to submit credentials to network settings without requiring complex integration. The network settings acts as a secure vault that receives, stores, and retrieves credentials through standardized interfaces, simplifying the overall architecture while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10735954B2Method and device for facilitating authentication over a wireless network
Publication Date: 2020.08.04 MALIKIE INNOVATIONS LTD
  • US10735954B2 patent drawing
  • US10735954B2 patent drawing
  • US10735954B2 patent drawing

AI summary

One method for allowing and controlling access to an open WLAN network is through the use of a secure website such as a Hotspot or Captive Portal landing page that the device must “log in” to in order to have access to the network. Credentials for a Captive Portal or Hotspot landing page (or other websites) are conventionally managed by a browser application and stored in a browser data storage space. According to some aspects of the disclosure, an electronic device obtains credentials for a website, such as a Captive Portal or Hotspot landing page. The credentials are stored in a network settings space on the electronic device. The credentials may be stored in a WLAN profile. The device may automatically log in to a webpage using the credentials, which may facilitate seamless connectivity.