Bluetooth Access List Control for Unauthorized Connection Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Bluetooth communication systems lack effective security measures to control access between devices, allowing unauthorized connections and limiting desired connections by making devices non-discoverable, which is not desirable.

Innovation Solution

A method and system that configures a restricted access list on computing devices to control access between Bluetooth devices, using identifiers like IP address, MAC address, or device serial number to define permitted devices, and enters a restricted mode to prevent unauthorized modifications and discovery requests, ensuring secure communication only with listed devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Bluetooth devices use conventional security modes (open access or non-discoverable), then security is improved, but either unauthorized connections are allowed or desired connections are limited

Engineering Contradiction:
ImprovesecurityVSAvoidconnection flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the access control mechanism into two distinct components: an access list that identifies authorized devices and a restricted mode that enforces the restrictions. This segmentation allows the system to maintain security while providing controlled flexibility for authorized connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by requiring users to pre-configure an access list with identifiers of authorized devices before entering restricted mode. This advance preparation enables the system to automatically control connections without real-time user intervention, resolving the contradiction between security and connection flexibility.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If devices are set to non-discoverable mode to prevent unauthorized connections, then security is improved, but the ability to establish desired connections deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidconnection establishment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary mechanism - the access list with device identifiers - that mediates between security requirements and connection establishment. Instead of completely hiding devices (non-discoverable mode), the system uses the access list as a mediator to selectively permit connections from authorized devices while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If access control lists are made modifiable to allow flexible device management, then ease of operation is improved, but security deteriorates due to unauthorized modifications

Engineering Contradiction:
Improvedevice managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamics by making the access list modifiable during configuration phase but enforcing restrictions when restricted mode is active. The system dynamically transitions between a flexible configuration state and a secure enforcement state, allowing easy device management during setup while preventing unauthorized modifications during operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2458907B1Method and device for controlling access between wireless communication devices
Publication Date: 2018.06.06 PSION INC
  • EP2458907B1 patent drawingFigure 1
  • EP2458907B1 patent drawingFigure 2
  • EP2458907B1 patent drawingFigure 3

AI summary

The method and system is provided for using an access list stored on a memory of a first computing device, the access list for controlling communication between the first computing device and a plurality of computing devices in a Bluetooth communication network (that is, one capable of short range wireless communication operating in the 2.4 GHz ISM radio frequency band.) In response to a connection request between the first computing device and a second computing device of the plurality of computing devices, the method determines whether the second computing device is on the access list by comparing an identifier of the second computing device provided by the second computing device to the access list to determine if the identifier matches an entry in the access list. Connection between the first computing device and the second computing device is prevented in response to determining that the identifier of the second computing device is not on the access list.