Zero-Touch WLAN Connection via Cryptographic Credential Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing zero-touch connection systems for Wireless Local Area Networks (WLANs) are limited in managing secure access for multiple devices, are vulnerable to security compromises, and lack dynamic control over device connections.
Innovation Solution
A method involving cryptographic processing of network identifiers and device identifiers to derive access credentials, allowing User Equipment (UE) to securely connect to a target WLAN without user intervention, using cryptographic functions such as encryption and decryption, and dynamically changing credentials for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access credentials are encoded within broadcast network identifier for zero touch connection, then user input is not required for connection, but the system becomes vulnerable to security compromise
Solution Approach 1:
The system segments the connection process into two distinct phases: a setup phase where credentials are securely established, and a connection phase where pre-shared keys are used. This separation allows zero-touch connection capability while maintaining security by not exposing sensitive credentials during broadcast
Solution Approach 2:
Access credentials are established in advance during a setup phase before the actual connection is needed. The pre-shared keys are configured beforehand, enabling devices to connect automatically without user input while the secure credentials remain protected and are not transmitted during the connection process
2Reliability
If manual identification and credential input is required for each WLAN, then security is maintained, but user burden increases significantly
Solution Approach 1:
The system enables devices to automatically perform the connection process themselves using pre-configured credentials. Devices autonomously identify target WLANs, retrieve their pre-shared keys, and establish connections without requiring user intervention for credential input, thereby reducing user burden while maintaining security
3Extent of automation
If zero touch connection systems are used for multiple devices, then device setup is simplified, but dynamic control over connections is limited
Solution Approach 1:
The system dynamically manages connections by allowing devices to automatically connect to multiple WLANs based on their pre-configured credentials, while network administrators retain the ability to dynamically add, remove, or modify credentials. This enables both automatic connection operation and flexible dynamic control over which devices can connect to which networks
Data Source
AI summary
A telecommunications network comprises: User Equipment (UE); a Wireless Access Point (WAP), identifiable by a network device identifier; a source Wireless Local Area Network (WLAN), provided by means of the WAP and identifiable by means of a source network identifier; and a target WLAN. A method of operating the network comprises: generating a cryptographic output by performing a cryptographic function upon both the source network identifier and the network device identifier; assigning, to the target WLAN, access credentials, wherein said access credentials comprise the cryptographic output; and by means of the UE: identifying the source network identifier and the network device identifier; cryptographically processing the identified source network identifier and the identified network device identifier so as to derive the cryptographic output; and requesting a connection to, or via, the target WLAN using access credentials derived by the UE from said cryptographic output.

