Access Point P2P Service Control via Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless networks face challenges in controlling and managing peer-to-peer (P2P) wireless connections, particularly in environments requiring high security and efficient bandwidth usage, as P2P communications can bypass infrastructure and lead to security hazards and inefficient bandwidth allocation.

Innovation Solution

An access point system that controls P2P wireless transmissions by determining whether devices or services are prohibited within its range and blocking or redirecting them through the infrastructure, using techniques such as spoofing MAC addresses, sending ambiguous messages, or relaying traffic to enforce compliance with security and quality of service policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If P2P wireless connections are allowed for direct communication between devices, then communication efficiency and user convenience are improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improvedirect communication capabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The access point acts as an intermediary between P2P devices, receiving service advertisement messages and service request messages, determining whether to allow connections based on security policies, and forwarding approved messages between devices. This mediator approach enables direct P2P communication while maintaining infrastructure control over security and bandwidth management

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access point implements a feedback mechanism by monitoring P2P communication attempts, evaluating them against security policies and bandwidth conditions, and providing control decisions (allow or block) back to the communication flow. This feedback loop ensures security requirements are met while enabling P2P communication when appropriate

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If P2P communications are permitted, then device connectivity and service access are enhanced, but bandwidth allocation efficiency deteriorates

Engineering Contradiction:
Improveservice accessibilityVSAvoidbandwidth utilization
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The access point dynamically evaluates bandwidth conditions and adjusts P2P communication permissions in real-time. When bandwidth is available, P2P connections are permitted to enhance service accessibility. When bandwidth resources are constrained, the access point blocks P2P communications to preserve bandwidth for infrastructure traffic, creating a dynamic adaptation to changing network conditions

Inventive Principle:
Principle #15Dynamics

3Reliability

If cross connection is strictly forbidden to prevent security hazards, then security control is improved, but legitimate P2P communication capability deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidP2P communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The access point applies different security control policies to different P2P communication scenarios. Rather than uniformly blocking all cross connections, it evaluates each service advertisement and service request message individually, applying security policies locally to specific device pairs and service types. This enables legitimate P2P communications to proceed while blocking only those that violate security requirements

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9661497B2Control and enhancement of direct wireless service communications
Publication Date: 2017.05.23 CISCO TECHNOLOGY INC
  • US9661497B2 patent drawing
  • US9661497B2 patent drawing
  • US9661497B2 patent drawing

AI summary

An access point is configured to control peer-to-peer wireless transmission in an area around the access point. The access point receives a message from a service providing device advertising a service. The access point receives another message from a service using device requesting the service. The access point determines whether the service using device or the service is prohibited in the area controlled by the access point. Responsive to a determination that the service using device is prohibited, the access point blocks the service using device from receiving the service. Responsive to a determination that the service is prohibited, the access point blocks the service providing device from providing the service.