Secure Anonymous WLAN Access via Intercepted HTTPS Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses face administrative challenges in securing wireless local area networks (WLANs) for guest access, as traditional authentication methods are not applicable to guests, and existing solutions fail to provide secure, anonymous access while preventing eavesdropping.

Innovation Solution

A separate guest WLAN is established, using an access point with a web server, packet filter, and redirector to intercept URL access requests, generate and securely communicate a security key, and set it on both the access point and client device via HTTPS, enabling secure anonymous access without user authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (user name/password, hardware tokens, biometrics) are used for WLAN access, then network security is improved, but device complexity and administrative overhead increase due to guest account management and token retrieval

Engineering Contradiction:
Improvenetwork securityVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication step from the WLAN access process. Instead of requiring users to present credentials before accessing the network, the system allows direct access and extracts only the necessary security key generation and distribution through a web-based interface, eliminating the need for traditional authentication databases and token management

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a web server as an intermediary between the WLAN access point and users. This intermediary handles security key distribution through HTTPS connections, replacing the need for traditional authentication mechanisms while maintaining security. The web server acts as a mediator that provides secure access without requiring user credentials or administrative overhead

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a separate guest WLAN is provided with anonymous access, then ease of operation is improved, but network security deteriorates due to lack of user authentication and unencrypted traffic

Engineering Contradiction:
Improveanonymous accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary security key generation and distribution before actual WLAN data transmission begins. The access point intercepts HTTPS requests, generates security keys in advance, and distributes them through the web server before users need to access the network, ensuring security is established prior to usage

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the security parameter from traditional authentication credentials to dynamically generated security keys. Instead of using static user accounts or hardware tokens, the system generates ephemeral security keys for each user session, maintaining security while enabling anonymous access without traditional authentication requirements

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If all guest network traffic is sent un-encrypted to maintain simplicity, then ease of manufacture is improved, but loss of information increases due to eavesdropping vulnerabilities

Engineering Contradiction:
Improvenetwork configuration simplicityVSAvoideavesdropping risk
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent implements self-service security where the access point automatically intercepts HTTPS requests, generates security keys, and configures encryption parameters without requiring manual administrative configuration. The system serves itself by automatically establishing secure connections through the web server interface, maintaining simplicity while ensuring encrypted traffic

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual security configuration mechanisms with automated web-based key distribution. Instead of requiring administrators to manually configure encryption settings or manage security policies, the system uses HTTPS web interactions to automatically distribute security keys and establish encrypted connections, substituting mechanical configuration with automated digital processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8285992B2Method and apparatuses for secure, anonymous wireless LAN (WLAN) access
Publication Date: 2012.10.09 THOMSON LICENSING SA
  • US8285992B2 patent drawing
  • US8285992B2 patent drawing
  • US8285992B2 patent drawing

AI summary

A method and system for providing secure, anonymous access to a wireless local area network, including configuring an access point to drop packets except packets exhibiting an URL access protocol like HTTP and HTTPS, intercepting a URL access request by an access point from a mobile device via a web browser, re-directing the URL access request to a web server by the access point generating a security key by one of the access points and the web server, communicating the generated security key to the said web server securely by the access point or vice versa and setting the security key by the access point is described. A mobile device including means for forwarding a request for secure access to a wireless local area network via a URL access request, means for receiving a mobile code or a signal for displaying a security key and means for setting the security key is also described.