Distributed Security Control for WLAN Anti-Spoofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security control mechanisms in communication systems, particularly in wireless termination devices, are inadequate as they only validate source MAC addresses and do not prevent malicious data packets from being sent using other user equipment's IP addresses, leading to vulnerabilities like DoS attacks, and lack real-time configuration of security parameters, limiting the role of devices closer to user equipment in network security.

Innovation Solution

A distributed security control method involving a network controller that dynamically establishes and configures a security control mechanism for second network devices, such as wireless termination devices, to validate data packets and discard invalid ones, enhancing security by applying network security checking rules and parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If wireless termination device only applies validity checking to source MAC address, then the device complexity is low, but the network security reliability is insufficient

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security control function is segmented between the network controller (which establishes and manages security policies) and the wireless termination device (which executes local validation). This segmentation allows the WTP to perform enhanced security checks including IP address validation and anti-spoofing without requiring full security policy management complexity at the edge device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network controller acts as an intermediary that dynamically provides security configuration parameters (such as valid IP address ranges and binding information) to the wireless termination device. This intermediary approach enables the WTP to perform sophisticated security validation while maintaining relatively simple local logic, as the complex policy management is handled by the controller.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access controller does not provide real-time configuration of security parameters, then the ease of operation is high, but the adaptability of security control is limited

Engineering Contradiction:
Improvesecurity parameter configurationVSAvoidreal-time configuration
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The security control mechanism transitions from static configuration to dynamic real-time configuration. The network controller can update security parameters (IP address bindings, valid ranges, anti-spoofing rules) dynamically based on current network conditions and security threats, and these updates are pushed to wireless termination devices without requiring manual reconfiguration or system restarts.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the network controller monitors network security status and automatically adjusts security parameters accordingly. The controller receives status information from wireless termination devices and user equipment, processes this feedback, and dynamically updates security configurations to respond to emerging threats or changing network conditions in real-time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2317690B1A method and device for distributed security control in communication network system
Publication Date: 2018.12.05 ALCATEL LUCENT SA
  • EP2317690B1 patent drawingFigure 1
  • EP2317690B1 patent drawingFigure 2~3
  • EP2317690B1 patent drawingFigure 4~5

AI summary

With migration of network technology and more and more requirements of user equipment for accessing to Internet, the network security faces more and more severe situation. There is provided a method for distributed security control in communication network system and the device thereof in order to improve security and operatability of network operator. In the method, firstly the network controller establishes a network security control mechanism, which is used for a second network device to check the validity of the data package from the user equipment; secondly, the network controller sends the network security control mechanism to the second network devices; lastly, the second network device checks the validity of the data package from the user equipment according to the network security control mechanism, and discards the data package if the data package is invalid. With the present invention, security and operatability of the communication network may be improved greatly, particularly, the functionality of address anti-spoofing can be implemented in the network with a WLAN architecture in centralized control.