Access Point Cryptographic Verification for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks supported by access points face security concerns due to the risk of compromised devices sending false control signals, which can hijack the network and redirect users to unintended content, and existing solutions do not adequately prevent malicious takeovers.

Innovation Solution

A multi-band wireless networking system with cryptographic verification and blockchain-enabled security, using private keys and secure boot mechanisms to authenticate and authorize communications, and a cloud-based coordination system to manage channel selection and firmware updates, ensuring only trusted devices can access and modify network configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless access points communicate using standard protocols (WiFi, Bluetooth), then network coverage and device connectivity are improved, but security vulnerabilities increase due to risk of compromised devices sending false control signals

Engineering Contradiction:
Improvenetwork connectivityVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A cloud server acts as an intermediary between access points, verifying control signals before they are executed. The cloud server receives control signals from access points, verifies their authenticity and authorization, and only permits legitimate signals to modify network configurations, thereby preventing compromised devices from sending false control signals while maintaining standard wireless communication protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where access points send control signals to the cloud server for verification, and the cloud server responds with authorization decisions. This closed-loop feedback ensures that only verified and authorized control signals can modify network configurations, addressing the security vulnerability while preserving network connectivity functionality

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If access points allow flexible configuration and firmware updates, then system adaptability and functionality are improved, but security risks increase due to potential malicious takeovers

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidmalicious takeover risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The cloud server serves as a trusted intermediary that mediates all configuration changes and firmware updates. Before any access point can be reconfigured or updated, the cloud server verifies the authenticity and authorization of the control signal, preventing malicious takeovers while allowing legitimate configuration flexibility and firmware updates

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification of control signals at the cloud server before allowing any configuration changes or firmware updates to be applied to access points. This advance verification ensures that only authorized changes are permitted, preventing malicious takeovers while maintaining system adaptability

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11229023B2Secure communication in network access points
Publication Date: 2022.01.18 NETGEAR INC
  • US11229023B2 patent drawing
  • US11229023B2 patent drawing
  • US11229023B2 patent drawing

AI summary

Disclosed is an access point (AP) for a network that includes security features for interacting with devices on the network. The other devices on the network may be other APs, client devices, or a backend configuration server. The access point includes a private key that is used to verify signals to and from (the private key may be different for different functions). In the case of other APs, the private key is used to verify control signals sent between the APs to identify and prevent a hijacked AP from taking control of the network by sending false control signals. In the case of a client device, the client device may use the subject AP's private key to identify that the subject AP is a trusted member of the network that may receive data. In the case of the backend server, the subject AP may verify configuration updates via use of the private key to prevent loading of malicious firmware.