Wireless Network Security via BPL Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Shared data communication networks, such as those in aircraft or buildings, face security concerns as they are often used by unrelated parties, potentially allowing unauthorized access and interference with critical systems.
Innovation Solution
Implementing separate wireless systems with distinct routers and utilizing broadband-over-power line technology to isolate and secure different parts of the network, such as the cabin and flight deck, by using BPL units to transmit signals over electrical conductors, ensuring independent communication paths with unique addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a shared data communication network is used to provide wireless access to multiple users, then cost effectiveness and convenience are improved, but security and protection against unauthorized access deteriorate
Solution Approach 1:
The patent divides the shared network into multiple isolated virtual networks (VLANs) using routers with unique addresses. Each VLAN segments the network traffic so that passengers in different vehicles cannot access each other's data or systems, while still allowing each vehicle to share its own network resources. This resolves the contradiction by maintaining network sharing capability within each segment while preventing unauthorized cross-access between segments.
Solution Approach 2:
The patent introduces routers as intermediary devices between different network segments. These routers act as mediators that control and manage traffic flow between VLANs, enforcing security policies and preventing direct access between unrelated parties. The routers with unique addresses serve as controlled intermediaries that enable safe network sharing while blocking unauthorized access attempts.
2Ease of operation
If wireless access is provided throughout the building or vehicle, then convenience is improved, but the risk of hacking and unauthorized interference increases
Solution Approach 1:
The patent implements segmentation by creating separate VLANs for different vehicles or zones, each with its own router. This allows wireless access to be provided throughout each vehicle independently, maintaining convenience for users while isolating potential hacking attempts to specific segments. A security breach in one vehicle's network cannot spread to other vehicles due to the VLAN isolation.
Solution Approach 2:
The patent applies local quality by assigning unique router addresses and configuring security policies specific to each vehicle or zone. Each local network segment has customized security settings and access controls tailored to its specific requirements, allowing wireless access convenience locally while maintaining differentiated security measures to address local hacking risks.
3Device complexity
If critical systems are connected to the same network as passenger entertainment, then cost effectiveness is improved, but system reliability and safety deteriorate
Solution Approach 1:
The patent segments the network into separate VLANs - one for critical flight deck systems and another for passenger entertainment. This segmentation allows a single physical network infrastructure to support both functions while preventing entertainment system attacks from reaching critical flight systems. The segmentation maintains infrastructure simplicity while dramatically improving critical system safety through logical isolation.
4Device complexity
If a single network address is used for the entire system, then device complexity is reduced, but security and access control capability worsen
Solution Approach 1:
The patent uses segmentation to create multiple VLANs, each with its own router address. While this increases addressing complexity slightly, it provides robust security by allowing granular access control policies to be applied to each segment. The segmented addressing scheme enables precise control over which devices can communicate with which segments, dramatically improving access control security compared to a single flat network.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances physical security by isolating network components, preventing unauthorized access and reducing the risk of interference, thereby improving the overall security of shared data communication systems.
Implementation Method 1
Data may then travel over the electrical conductor simultaneously with electrical power transfer regardless of whether the power line is used for transmission of power or not
Data Source
AI summary
A shared data communications system includes a network file server and two routers, each with its own address. A first router provides wireless access to a first part of the system. A second router provides wireless access to a second part of the same, shared system via the technique known as broadband-over-power line (BPL). In the second part, a first BPL unit is carried by the proximal end of an electrical conductor for receiving and sending signals between it and distal, second BPL unit on the same electrical conductor. The use of separate routers with different addresses and a power line to transmit and receive data to confine the wireless portion of the second part of the system to a smaller area increase the physical security of wireless communications with the second part, making it less likely data communications taking place in the second part will be accessed by others.


