Illegal device detection and blocking device
A portable device monitors wireless networks to detect and block unauthorized devices by comparing MAC addresses with a stored list, addressing the limitations of conventional technologies by enabling advanced detection and blocking of unauthorized devices.
Patent Information
- Application Number
- JP2025534697
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-13
- Filing Date
- 2023-11-27
- Publication Date
- 2026-01-06
AI Technical Summary
Conventional illegal hidden camera blocking devices and wireless LAN intrusion detection technologies fail to detect and block unauthorized devices in advance by monitoring transmission packets or frames, and they are not portable for individual user convenience.
An illegal device detection and blocking device that monitors device information in a wireless network, using a network connection unit, storage means, and a control unit to detect and block unauthorized devices by comparing MAC addresses with a stored MAC list, and communicates via Bluetooth with a user terminal for control and updates.
The device effectively detects and blocks unauthorized devices before illegal activity occurs, being portable and user-friendly for individual use, allowing detection and blocking anywhere.
Smart Images

Figure 2026500295000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a system for detecting unauthorized devices such as unauthorized cameras, and more particularly to a wireless network unauthorized device detection and blocking device and a detection and blocking system including the same, which can monitor devices in a wireless network and block unauthorized devices when detected. [Background technology]
[0002] Recently, security issues have become a hot topic, with malicious actors installing spy chips in computer peripherals to create wired and wireless backdoors and stealing confidential national documents, corporate technical and sales data, and personal information. The act of installing illegal cameras and secretly recording footage to violate personal privacy or illegally distributing the footage has also emerged as a social problem.
[0003] One prior art for preventing such illegal activities is the "AI Algorithm-Based Illegal Hidden Camera Real-Time Blocking and Alarm Device," published in the Korean Intellectual Property Office Patent Publication under Publication No. 10-2021-0009917. In this published patent, an HMM model application prediction unit performs prediction by applying an HMM model that uses a state transition probability matrix A, an emission probability B, and an initial state probability vector π, an illegal device blocking unit blocks illegal hidden cameras in real time by analyzing traffic and using device load based on current, and an illegal video determination unit identifies illegal videos through packet analysis.
[0004] In addition, the "Wireless LAN Intrusion Detection Method and System" disclosed in Publication No. 10-2014-0071776 involves an intrusion detection sensor detecting packets suspected of being attacks from either outside or inside, an intrusion detection AP managing AP-generated frames generated by all APs in the wireless LAN, and a threat management server extracting frames contained in packets suspected of being attacks, and then checking whether the extracted frames are frames present in AP-generated frames to determine whether the packets are attacks. Summary of the Invention [Problem to be solved by the invention]
[0005] Conventional illegal hidden camera blocking devices and wireless LAN intrusion detection technologies either monitor the transmission packets of captured images to detect illegal images or inspect the frames included in the transmission packets, which means that they have the problem of not being able to detect and block illegal devices in advance.
[0006] The present invention has been proposed to solve the above problems, and an object of the present invention is to provide an illegal device detection and blocking device that can detect unauthorized illegal devices by monitoring device information in a wireless network and block the illegal devices in advance before any illegal activity occurs.
[0007] Another object of the present invention is to provide an illegal device detection and blocking apparatus that is portable so that individual users can conveniently detect and block illegal devices anywhere. [Means for solving the problem]
[0008] An illegal device detection and blocking device according to an embodiment of the present invention is an illegal device detection and blocking device that can detect whether illegal devices such as hidden cameras are installed in an existing monitored network and block them, and includes a network connection unit connected to a wireless LAN in the monitored network, a storage means for storing a MAC list, a control unit that receives MAC addresses of devices connected to the network through the network connection unit as input and blocks data transmission from the illegal device if an illegal MAC address is detected, and a wireless communication unit that transmits and receives signals between the control unit and a user terminal, and the control unit includes a packet pattern information collection unit that operates the network connection unit in a monitor mode and acquires MAC addresses of surrounding Wi-Fi devices in the monitored wireless network, and an illegal device detection unit that compares the MAC addresses of the wireless LANs collected in the monitor mode with the MAC addresses registered in the MAC list of the storage means to detect wireless illegal devices, and if a wireless illegal device is detected, notifies the user terminal of the detection fact through the wireless communication unit.
[0009] The control unit may further include an illegal device blocking unit that blocks a wireless illegal device from connecting to an access point by transmitting a de-authentication packet to the wireless network, thereby blocking data transmission from the illegal device.
[0010] The control unit may further include an input / output control unit that, when an illegal device is detected, transmits information about the illegal device to the user terminal through the wireless communication unit, and, when a command from the user terminal is received through the wireless communication unit, acquires a MAC list from the user terminal and processes the MAC list to perform a blocking operation.
[0011] The control unit is paired with a user terminal via Bluetooth, and when it receives a startup command from an app on the user terminal, it can provide various information about the device to the user terminal, transmit and receive various lists such as a MAC list, an access point (AP) list, and a firmware list from the user terminal to the device, and control the device to perform initial setup.
[0012] When the control unit receives an operation command from a user through an application on the user terminal, it activates the network connection unit to start the wireless LAN, checks the firmware version and MAC list version from the version file of the user terminal, and if a new firmware version or a new MAC list version is detected, downloads new firmware data or MAC list data from the user terminal to update the firmware or MAC list, and if the firmware data is updated, it can control the device to reboot and then execute the illegal device detection process.
[0013] The illegal device detection and blocking device is configured to be portable and includes a rechargeable battery, and the wireless communication unit is configured to be able to communicate with a user terminal via Bluetooth communication and can be controlled through a user interface of the user terminal operated by the user. [Effects of the Invention]
[0014] According to an embodiment of the present invention, an illegal device detection and blocking device is used to monitor a wireless internal network and detect unauthorized wireless signals, thereby blocking illegal devices before illegal activity occurs, and can be applied to the security of various wireless communication networks.
[0015] Furthermore, according to an embodiment of the present invention, such an illegal device detection and blocking device can be carried by a general user and controlled in conjunction with a user terminal such as a smartphone, etc. Therefore, the device can be activated anytime and anywhere where the presence of an illegal device is suspected, and the illegal device can be conveniently detected and blocked. [Brief explanation of the drawings]
[0016] [Figure 1] 1 is a block diagram of an illegal device detection and blocking device according to the present invention;
[0017] [Figure 2] 3 is a flowchart of a method for operating the illegal device detection and blocking device according to the present invention.
[0018] [Figure 3] 1 is a schematic diagram illustrating a system including an illegal device detection and blocking apparatus according to an embodiment of the present invention;
[0019] [Figure 4] 1 is a block diagram showing the configuration of an illegal device detection and blocking device according to an embodiment of the present invention;
[0020] [Figure 5] FIG. 10 is a diagram illustrating an example of the operation of an illegal device in a network environment to which an embodiment of the present invention is applied.
[0021] [Figure 6] 1 is a diagram illustrating a detection process of an illegal device detection and blocking apparatus according to an embodiment of the present invention;
[0022] [Figure 7] 1 is a diagram illustrating a blocking process of an illegal device detection and blocking apparatus according to an embodiment of the present invention;
[0023] [Figure 8]3 is a flowchart illustrating the overall operation of an illegal device detection and blocking device and a system including the same according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0024] The present invention and the technical problems achieved by implementing the present invention will become more apparent from the preferred embodiments of the present invention described below. The following examples are merely illustrative for explaining the present invention and are not intended to limit the scope of the present invention.
[0025] FIG. 1 is a block diagram of an illegal device detection and blocking apparatus according to an embodiment of the present invention.
[0026] As shown in FIG. 1, the illegal device detection and blocking device 100 of the present invention comprises a network connection unit 110, a storage unit 120, a control unit 130, and a wireless communication unit 140.
[0027] 1 to 3, the network connection unit 110 connects to a monitored network to acquire a MAC address and blocks devices with the MAC address according to a control command, and the storage means 120 stores the MAC addresses of illegal devices as a MAC list. The illegal device detection and blocking apparatus 100 blocks illegal devices having MAC addresses included in the MAC list. Therefore, the MAC list is a MAC list (block list) of devices to be blocked. The wireless communication unit 140 receives signals from the control unit 130 and transmits them to the user terminal 200, and can transmit signals from the user terminal 200 to the control unit 130.
[0028] A user can carry the illegal device detection and interception device 100 and a user terminal 200 such as a personal smartphone and activate the illegal device detection and interception device 100 at a location where an illegal device is suspected to be present. The illegal device detection and interception device 100 may not have a dedicated user interface. The user terminal 200 can communicate with the illegal device detection and interception device 100 through a short-range communication method such as Bluetooth. Therefore, the user can operate the illegal device detection and interception device 100 using an app on the user terminal 200.
[0029] The storage means may be configured to include volatile memory such as RAM (Random Access Memory), non-volatile memory such as ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), flash memory, or any form of computer-readable recording medium known in the technical field to which the present invention pertains.
[0030] The MAC list is a blocking list that stores the MAC addresses of illegal devices, which corresponds to a type of blacklist when managing devices using blacklists and whitelists. It can be set when manufacturing the illegal device detection and blocking device of the present invention and can be continuously updated by the user terminal 200.
[0031] The control unit 130 receives MAC addresses of devices connected to the monitored network via the network connection unit 110, compares the MAC addresses with those recorded in the MAC list of the storage means 120 to detect illegal devices, and if an illegal device is detected, notifies the user terminal 200 via the wireless communication unit 140, and after receiving a blocking command from the user terminal 200, blocks communication of the illegal device via the network connection unit 110. The control unit 130 may be configured to include a CPU (Central Processing Unit), MPU (Micro Processor Unit), MCU (Micro Controller Unit), GPU (Graphic Processing Unit), or any type of processor known in the technical field of the present invention.
[0032] FIG. 2 is a flowchart illustrating a method for operating an illegal device detection and blocking apparatus according to an embodiment of the present invention.
[0033] Referring to FIG. 2, in the MAC list recording step S1, a "MAC list" of devices that are predicted to be illegal devices is obtained and recorded in the storage means 120.
[0034] In the packet information collection step S2, the illegal device detection and interruption apparatus 100 collects packets present in the monitored network and extracts MAC addresses.
[0035] In the illegal device detection step S3, the illegal device detection and blocking apparatus 100 compares the extracted MAC address with MAC addresses in a stored MAC list to detect illegal devices.
[0036] In the user terminal linking stage S4, the illegal device detection and blocking device 100 uses short-range communication such as Bluetooth to transmit information about the detected illegal device (MAC address, detection distance, etc.) to the user terminal 200, and the user terminal 200 uses short-range communication 15 to transmit an illegal device blocking command to the illegal device detection and blocking device.
[0037] In the illegal device blocking step S5, the illegal device detection and blocking apparatus 100 blocks data transmission from the illegal device.
[0038] The apparatus and method of the present invention can be realized by the following specific examples.
[0039] As shown in FIG. 3, the illegal device detection and blocking system according to an embodiment of the present invention can be configured to include an illegal device detection and blocking device 100 that is installed in a wireless LAN environment 10 and connected to a user terminal 200 via short-range communication 15, and that detects illegal devices present in the wireless LAN 10 and blocks the connection, and a user terminal 200 that controls the illegal device detection and blocking device 100.
[0040] 3, a wireless LAN 10 is a wireless LAN that operates according to the IEEE 802.11 protocol and is also known as WiFi. A legitimate wireless terminal is connected to the wireless LAN, and a wireless illicit device 50 that is a target of monitoring in the present invention may also be connected to the wireless LAN.
[0041] The illegal device detection and blocking device 100 is installed in a wireless LAN 10 environment and connected to a user terminal 200 via short-range communication 15. The device detects illegal devices present in the wireless LAN 10 and reports the detection to the user terminal 200, and can block the illegal devices 50 in accordance with a blocking command from the user terminal 200. In an embodiment of the present invention, the illegal devices 50 are devices recorded in a MAC list, and after transmitting the MAC address of the device to the user terminal 200 for a judgment, if the device is found to be an illegal device and a blocking command is received, the device is blocked.
[0042] The rogue device detection and blocking apparatus 100 monitors the rogue device 50 in the monitor mode and blocks the rogue device 50 according to a command from the user terminal 200. Here, the monitor mode is an operation mode of a wireless LAN in which a WiFi terminal can collect all wireless frames received through an antenna even if the WiFi terminal is not connected to an access point.
[0043] In addition, the illegal device detection and blocking apparatus 100 scans the network and then transmits the MAC address and detection distance of the device to the user terminal 200 so that the device can be registered in the DB 210 .
[0044] The user terminal 200 is equipped with a database 210, which can store a version file that stores the firmware (F / W) version and MAC list version information of the illegal device detection and blocking device 100, as well as the MAC list and firmware (F / W) data.
[0045] The user terminal 200 can register various information about the illegal device detection and blocking apparatus 100 in the database 210. That is, the user terminal 200 can have a function for displaying a detected MAC list, a function for checking the MAC list of a suspicious device and then blocking it, and a function for registering and updating the MAC list, and a function for uploading a version file, a firmware file, and a MAC list file.
[0046] The user terminal 200 can connect to another external server (not shown) via a mobile communication network and download a MAC list file, firmware file, etc. This external server may be operated by a company that sells the illegal device detection and interception device 100 or another service provider. This company may also provide an app stored on the user terminal 200. This external server may register users who install the illegal device detection and interception device 100 as members and provide an administrator mode screen, a member information management screen, a member device management screen, etc. The searched MAC list may record sensitivity, data volume, suspiciousness, etc. Here, a "suspicious device" refers to a device that the illegal device detection and interception device 100 has determined to be a possible illegal device according to a predetermined procedure. The user terminal 200 may notify the user of the suspicious device reported by the illegal device detection and interception device 100 through the app, or may notify an external server. As a result, if the suspicious device is ultimately determined to be an illegal device according to the user's instructions or the instructions of the external server, the suspicious device can be registered in the MAC list and blocked.
[0047] The block list (MAC list) may be prepared on an external server by a company that sells the illegal device detection and blocking device 100 or another service provider. These companies may select and collect MAC addresses that are mainly used by companies that manufacture illegal devices, and provide them as a block list.
[0048] FIG. 4 is a block diagram showing the configuration of an illegal device detection and blocking apparatus according to an embodiment of the present invention.
[0049] As shown in Figure 4, the illegal device detection and blocking device 100 of an embodiment of the present invention is composed of a network connection unit 110, a control unit 130 consisting of a packet pattern information collection unit 131, an illegal device detection unit 132, an illegal device blocking unit 133, and an input / output control unit 134, a storage means 120 in which a MAC list 122 is stored, and a wireless communication unit 140.
[0050] Referring to FIG. 4, the network connection unit 110 is for connecting to the wireless LAN 10 to be monitored and acquiring the MAC addresses of devices present on the wireless network.
[0051] The packet pattern information collection unit 131 operates in monitor mode via the network connection unit 110 and collects MAC addresses of surrounding Wi-Fi devices while not connected to an AP. The illegal device detection unit 132 compares the MAC addresses of the wireless LAN collected in monitor mode with the MAC addresses registered in the MAC list 122 of the storage means, and detects illegal wireless devices 50.
[0052] When an illegal wireless device 50 is detected by the illegal device detection unit 132, the illegal device blocking unit 133 transmits a de-authentication packet to block the operation of the illegal wireless device. Here, de-authentication means blocking the device using a disassociation frame (subtype: 1010) or a deauthentication frame (subtype: 1100), which are types of IEEE 802.11 management frames.
[0053] The input / output control unit 134 communicates with the user terminal 200 and can process operations such as updating the MAC list 122 in the storage unit 120 and updating firmware. That is, when an illegal device 50 is detected, the input / output control unit 134 transmits information about the illegal device 50 to the user terminal 200 via the wireless communication unit 140, and when a command is received from the user terminal 200 via the wireless communication unit 140, the input / output control unit 134 processes the command. For example, when a blocking command is received, the input / output control unit 134 can obtain the MAC list from the user terminal 200 and perform a blocking operation. Also, when a version file update command (firmware version or MAC list version) is received, the input / output control unit 134 receives and updates the MAC list data or firmware data.
[0054] The wireless communication unit 140 is a communication means for communicating with the user terminal 200, and in the embodiment of the present invention, can communicate with the user terminal 200 via short-range communication 15 (Bluetooth).
[0055] Figure 5 is a diagram showing an example of the operation of an illegal device in a network environment to which an embodiment of the present invention is applied, Figure 6 is a diagram for explaining the detection process of an illegal device detection and blocking device in an embodiment of the present invention, and Figure 7 is a diagram for explaining the blocking process of an illegal device detection and blocking device in an embodiment of the present invention.
[0056] 5, an example of a network environment to which an embodiment of the present invention is applied is shown, in which wireless illicit cameras 50-1 and 50-2 are connected to an access point 11 via a wireless LAN 10, an illicit device detection / blocking device 100 monitors the wireless network 10, and an illicit device viewing device 70 is connected via the Internet 40. The illicit device detection / blocking device 100 is connected to a user terminal 200 via short-range communication 15.
[0057] When the illegal cameras are operating in this state, as shown in Fig. 5, the illegal videos taken by the wireless illegal cameras 50-1 and 50-2 are transmitted to the AP 11 via the wireless LAN 10, and the illegal videos transmitted to the AP 11 are then transmitted to the illegal video viewing terminal 70 via the Internet 40. This makes it possible to view the illegal videos on the illegal video viewing device 70.
[0058] 6, the illicit device detection and interception device 100 is switched to the monitor mode, receives wireless packets from devices connected to the wireless LAN 10, extracts the MAC addresses, and detects the wireless illicit cameras 50-1 and 50-2 by comparing the MAC addresses with those in the MAC list 122. When the wireless illicit cameras 50-1 and 50-2 are detected, the illicit device 100 transmits de-authentication packets to the wireless LAN 10, as shown in FIG.
[0059] FIG. 8 is a flowchart illustrating the overall operation of the illegal device detection and blocking device and the system including the same according to an embodiment of the present invention.
[0060] When a user who has installed the illegal device detection and interception device 100 according to an embodiment of the present invention starts an application on the user terminal 200, the user terminal 200 is paired with the illegal device detection and interception device 100. The user terminal 200 is provided with various information such as the product serial number to the illegal device detection and interception device 100, and transmits various lists such as a MAC list, an AP list, and a firmware list to the illegal device detection and interception device 100 to perform initial setup (S11).
[0061] When an operation command or a reset command is transmitted from the user terminal 200 to the illegal device detection and interception apparatus 100, the illegal device detection and interception apparatus 100 activates the network connection unit 110 and starts up the wireless LAN (S12).
[0062] Next, the firmware version and MAC list version are checked from the version file of the user terminal 200 in step S13.
[0063] If a new firmware version or a new MAC list version is detected, the illegal device detection and blocking device 100 can download new firmware data or MAC list data from the user terminal 200 and update the firmware or MAC list (S14). When the firmware data is updated, the entire process can be restarted by rebooting.
[0064] As described above, after checking for updates to the MAC list and firmware version at the initial stage of operation, the illegal device detection and interception device 100 operates in WiFi monitor mode, receives wireless packets from devices connected to the wireless LAN 10, extracts the MAC address, compares it with the MAC address in the MAC list to detect illegal wireless devices, and if a wireless illegal device is detected, transmits the information to the user terminal 200 (S16-S19). When the user terminal 200 receives suspicious device information from the illegal device detection and interception device 100, it registers the suspicious device in the MAC list and transmits an illegal device interception command to the illegal device detection and interception device 100 according to a predetermined procedure. After receiving the interception command from the user terminal 200, the illegal device detection and interception device 100 transmits a de-authenticate packet to the wireless LAN 10 to intercept the illegal wireless device (S20-S22). More specifically, in a wireless LAN, the illegal device detection and blocking device 100 captures a MAC address in monitor mode, then checks whether an illegal device exists in address 2 and address 3 of the MAC header, and if an illegal device is detected, transmits the MAC address of the suspicious device to the user terminal 200 via the mobile communication network 30.
[0065] Most ordinary individuals carry a user terminal 200 such as a smartphone. If an individual carries an illegal device detection and blocking device 100 that can be linked to the user terminal 200, the illegal device 50 can be detected and blocked. The illegal device detection and blocking device 100 can be manufactured in a portable palm-sized size. In addition, a ring-shaped strap can be attached to one side of the illegal device detection and blocking device 100, making it easy for users to carry.
[0066] A user can turn on / off the power of the illegal device detection and interception device 100 or instruct the illegal device detection and interception device 100 to detect illegal devices through an application installed on the user terminal 200. The user terminal 200 can display information about suspicious devices received from the illegal device detection and interception device 100 to the user, and can receive commands from the user and send a blocking command to the illegal device detection and interception device 100.
[0067] In this embodiment, the illegal device detection and interruption device 100 is not equipped with a user interface, and an example is shown in which the device utilizes the interface of the user terminal 200 connected via short-range communication 15. However, it is also possible to provide a user interface by providing an input / output means in the illegal device detection and interruption device 100, or to configure the device 100 not to have a user interface and to automatically execute all of the above processes without user intervention by simply starting up the illegal device detection and interruption device 100.
[0068] Although the present invention has been described above with reference to one embodiment shown in the drawings, those skilled in the art will recognize that various modifications and equivalent alternative embodiments are possible.
Claims
1. An illegal device detection and blocking device that can detect whether an illegal device such as a hidden camera is installed in an existing monitored network and block it, a network connection unit connected to a wireless LAN of a monitored network; a storage means for storing the MAC list; a control unit that receives MAC addresses of devices connected to the network via the network connection unit, and blocks data transmission from illegal devices when an illegal MAC address is detected; a wireless communication unit that transmits and receives signals between the control unit and a user terminal; The control unit a packet pattern information collecting unit that operates the network connection unit in a monitor mode and acquires MAC addresses of peripheral Wi-Fi devices that exist in the monitored wireless network; and an illegal device detection unit that detects illegal wireless devices by comparing the MAC addresses of the wireless LAN collected in monitor mode with the MAC addresses registered in the MAC list of the storage means, and notifies the user terminal of the detection via the wireless communication unit when an illegal wireless device is detected.
2. The control unit The rogue device detection and blocking device of claim 1, further comprising an rogue device blocking unit that blocks data transmission from the rogue device by sending a de-authentication packet to the wireless network and blocking the rogue device from connecting to the access point.
3. The control unit The illegal device detection and blocking device of claim 2, further comprising an input / output control unit that, when an illegal device is detected, transmits illegal device information to a user terminal via the wireless communication unit, and, when a command from the user terminal is received via the wireless communication unit, acquires a MAC list from the user terminal and processes it to perform a blocking operation.
4. The control unit The illegal device detection and blocking device of claim 2 is paired with a user terminal via Bluetooth, and when it receives a startup command from an app on the user terminal, it provides various information about the device to the user terminal and controls the device to perform initial configuration by having the user terminal send various lists such as a MAC list, AP list, and firmware list to the device.
5. The control unit When it receives an activation command from the user through the app on the user's device, it activates the network connection unit to start the wireless LAN, Check the firmware version and MAC list version from the version file of the user device, If a new firmware version or a new MAC list version is detected, the new firmware data or MAC list data is downloaded from the user terminal to update the firmware or MAC list, 3. The illegal device detection and blocking device according to claim 2, wherein when firmware data is updated, control is performed so that illegal device detection processing is executed after rebooting.
6. The illegal device detection and blocking device includes a rechargeable battery and is configured to be portable; The wireless communication unit is configured to be able to communicate with a user terminal via Bluetooth communication; The illegal device detection and blocking device according to claim 1, which is controllable through a user interface of a user terminal operated by a user.
Citation Information
Patent Citations
Method for blocking wireless mobile terminal from accessing illegal AP
CN113473471A
WIRELESS INTRUSION PREVENTION SYSTEM AND METHOD OF OPERATION - Patent application
JP2024520585A
3D imaging device with digital micromirror device and operating method thereof
KR1020220037938A
Method and network element for improved access to communication networks
US20170187703A1
Wireless intrusion prevention system and operating method therefor
WO2022255619A1