Ad Hoc Network Security via Decoy Beacon Disruption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ad hoc wireless networks increase network security vulnerability as they are often configured without authentication or encryption, allowing hackers to gain access to the main corporate network, and are difficult to control without direct station management.

Innovation Solution

A network security system detects and disrupts ad hoc networks by sending decoy information, such as beacon frames with advanced timestamps, to prevent stations from communicating with each other, effectively fragmenting the network and preventing data exchange without requiring direct control over the stations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ad hoc networks are configured without authentication or encryption to enable direct communication between stations, then ease of operation is improved, but network security deteriorates

Engineering Contradiction:
Improveease of configurationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an access point as an intermediary device that mediates all communications between stations in the ad hoc network. The access point monitors and controls traffic, implementing security policies without requiring direct configuration changes on stationary devices. This resolves the contradiction by maintaining ease of operation at stations while centralizing security enforcement at the access point.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If direct control over stations is required to disable ad hoc networks to enforce security policy, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access point serves as an intermediary that enforces security policies without requiring direct control or configuration changes on individual stations. By centralizing control at the access point, the system achieves security policy enforcement while avoiding the complexity of managing control mechanisms across multiple distributed stations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access points are used as manageable choke-points for network security, then network security is improved, but adaptability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork configuration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The access point is designed to perform multiple functions: it serves as a security enforcement point for ad hoc networks, a traffic monitor, and a policy enforcement mechanism. This multi-functionality allows the system to maintain security while adapting to different ad hoc network configurations and requirements, resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8428516B2Wireless ad hoc network security
Publication Date: 2013.04.23 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8428516B2 patent drawing
  • US8428516B2 patent drawing
  • US8428516B2 patent drawing

AI summary

Providing network security includes detecting network traffic associated with an ad hoc network that includes a first station and a second station, and preventing data sent by the first station from reaching the second station.