Access Point Virtual Network Segmentation for Mixed Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless LANs face security challenges when connecting communication apparatuses with different security levels, as automatic setup methods like WPS can lower the overall security level if a device with a low security level, such as WEP, attempts to connect to a network using a higher security method like AES, leading to connection rejections.
Innovation Solution
A communication apparatus is equipped with a confirmation unit to identify the encryption method requested by a connecting device and a formation unit to create a separate network using the requested encryption method if it differs from the existing network's method, allowing devices with lower security levels to connect without compromising the overall network security by forming a new network with matching encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If automatic wireless parameter setup and security level setup are implemented using WPS, then ease of operation is improved, but security level deteriorates because the overall security level lowers when a communication apparatus with low security level connects
Solution Approach 1:
The access point divides the wireless network into multiple virtual networks (VLANs) based on security levels. Each virtual network uses a specific encryption method (WEP, TKIP, or AES), allowing devices with different security capabilities to connect to appropriate networks while maintaining overall network security through segmentation.
2Reliability
If a communication apparatus with low security level (e.g., WEP) sends a connection request to a wireless LAN set with high security level (e.g., AES), then connection is rejected, but this prevents security level deterioration
Solution Approach 1:
The access point creates separate virtual networks for different security levels, allowing WEP devices to connect to the WEP virtual network while AES devices connect to the AES virtual network, thus maintaining both security and adaptability.
Solution Approach 2:
The access point is designed to support multiple encryption methods (WEP, TKIP, AES) simultaneously through different virtual networks, making it universal enough to accommodate devices with varying security capabilities while maintaining high security standards for each network type.
3Adaptability or versatility
If multiple virtual networks with different encryption methods are formed, then adaptability is improved by allowing low security level devices to connect, but device complexity increases
Solution Approach 1:
The access point segments the wireless network into multiple virtual networks based on security levels, allowing it to handle diverse security requirements through a systematic division approach that manages complexity through organization.
Solution Approach 2:
The access point acts as an intermediary that manages multiple encryption methods and virtual networks, shielding users from the complexity of security configuration while providing adaptability through automated network selection and assignment.
Data Source
AI summary
This invention allows connection of an apparatus with a low security level without lowering the security level of a network even when such apparatus issues a connection request. This invention is directed to an access point which makes wireless communications with a station using an encryption method (AES). Upon reception of a connection request message including information indicating an encryption method (WEP) that can be used by a station, the access point checks if the encryption method (WEP) recognized based on the received connection request message is different from the encryption method (AES). When it is determined that the two encryption methods are different, the access point launches a controller which makes wireless communications with the station using that encryption method (WEP).


