Access Point Virtual Network Segmentation for Mixed Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless LANs face security challenges when connecting communication apparatuses with different security levels, as automatic setup methods like WPS can lower the overall security level if a device with a low security level, such as WEP, attempts to connect to a network using a higher security method like AES, leading to connection rejections.

Innovation Solution

A communication apparatus is equipped with a confirmation unit to identify the encryption method requested by a connecting device and a formation unit to create a separate network using the requested encryption method if it differs from the existing network's method, allowing devices with lower security levels to connect without compromising the overall network security by forming a new network with matching encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automatic wireless parameter setup and security level setup are implemented using WPS, then ease of operation is improved, but security level deteriorates because the overall security level lowers when a communication apparatus with low security level connects

Engineering Contradiction:
Improveease of operationVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access point divides the wireless network into multiple virtual networks (VLANs) based on security levels. Each virtual network uses a specific encryption method (WEP, TKIP, or AES), allowing devices with different security capabilities to connect to appropriate networks while maintaining overall network security through segmentation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a communication apparatus with low security level (e.g., WEP) sends a connection request to a wireless LAN set with high security level (e.g., AES), then connection is rejected, but this prevents security level deterioration

Engineering Contradiction:
Improvesecurity levelVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The access point creates separate virtual networks for different security levels, allowing WEP devices to connect to the WEP virtual network while AES devices connect to the AES virtual network, thus maintaining both security and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point is designed to support multiple encryption methods (WEP, TKIP, AES) simultaneously through different virtual networks, making it universal enough to accommodate devices with varying security capabilities while maintaining high security standards for each network type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple virtual networks with different encryption methods are formed, then adaptability is improved by allowing low security level devices to connect, but device complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access point segments the wireless network into multiple virtual networks based on security levels, allowing it to handle diverse security requirements through a systematic division approach that manages complexity through organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point acts as an intermediary that manages multiple encryption methods and virtual networks, shielding users from the complexity of security configuration while providing adaptability through automated network selection and assignment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9900771B2Communication apparatus and control method
Publication Date: 2018.02.20 CANON KK
  • US9900771B2 patent drawing
  • US9900771B2 patent drawing
  • US9900771B2 patent drawing

AI summary

This invention allows connection of an apparatus with a low security level without lowering the security level of a network even when such apparatus issues a connection request. This invention is directed to an access point which makes wireless communications with a station using an encryption method (AES). Upon reception of a connection request message including information indicating an encryption method (WEP) that can be used by a station, the access point checks if the encryption method (WEP) recognized based on the received connection request message is different from the encryption method (AES). When it is determined that the two encryption methods are different, the access point launches a controller which makes wireless communications with the station using that encryption method (WEP).