Dynamic Wake-Up Pattern Authentication for Secure LAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wake-on LAN systems lack secure mechanisms to ensure that only trusted sources can awaken sleeping computers, making them vulnerable to unauthorized wake-up events.
Innovation Solution
Implementing a dynamically modifiable password system based on a seed value, where the management console and client system generate passwords that change periodically, ensuring only trusted sources can awaken the system by matching the wake-up pattern with the dynamically modifiable passwords in a pattern wake list.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a constant power source is provided to the network controller to enable wake-up functionality, then the system can receive and decode wake-up packets, but the system becomes vulnerable to unauthorized wake-up events and security threats
Solution Approach 1:
The patent implements preliminary security verification by comparing received wake-up patterns against a pre-stored list of authorized patterns in the network controller before triggering a wake-up event. This preliminary action ensures that only authenticated wake-up signals can activate the system, preventing unauthorized wake-up events while maintaining reliable wake-up functionality for legitimate sources
Solution Approach 2:
The patent introduces an intermediary authentication mechanism (pattern matching and verification process) between the wake-up packet reception and system activation. This intermediary layer acts as a security gatekeeper that validates the authenticity of wake-up signals, allowing the system to maintain constant power readiness while blocking unauthorized access attempts
2Ease of manufacture
If static passwords are used in wake-up packets, then the implementation is simple, but the security is weak and vulnerable to replay attacks
Solution Approach 1:
The patent transforms static passwords into dynamic, time-varying authorization patterns that automatically expire and need to be refreshed. The network controller and management console generate new wake-up patterns periodically using cryptographic key pairs, ensuring that previously captured patterns become invalid. This dynamic approach maintains security against replay attacks while keeping the implementation manageable through automated key rotation
Solution Approach 2:
The patent implements periodic regeneration of wake-up authorization patterns at defined intervals. Both the management console and network controller synchronize to generate new cryptographic key pairs and corresponding wake-up patterns periodically, ensuring that static patterns do not remain valid indefinitely. This periodic refresh mechanism prevents replay attacks while maintaining a structured, predictable security update schedule
3Reliability
If the network controller continuously monitors all packets, then wake-up packets can be reliably detected, but energy consumption increases during sleep mode
Solution Approach 1:
The patent extracts only the essential wake-up detection functionality from the full network protocol stack and implements it in a simplified manner in the network controller during sleep mode. The controller monitors only specific wake-up pattern bytes rather than fully processing all network packets, enabling reliable wake-up detection while minimizing energy consumption by keeping the majority of the system in a low-power state
Data Source
AI summary
In an embodiment, a method is provided. The method of this embodiment provides receiving a packet having a wake-up pattern, and waking up if the wake-up pattern corresponds to one of a number of dynamically modifiable passwords on a pattern wake list, each of the dynamically modifiable passwords being based, at least in part, on a seed value.


