Dynamic Wake-Up Pattern Authentication for Secure LAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wake-on LAN systems lack secure mechanisms to ensure that only trusted sources can awaken sleeping computers, making them vulnerable to unauthorized wake-up events.

Innovation Solution

Implementing a dynamically modifiable password system based on a seed value, where the management console and client system generate passwords that change periodically, ensuring only trusted sources can awaken the system by matching the wake-up pattern with the dynamically modifiable passwords in a pattern wake list.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a constant power source is provided to the network controller to enable wake-up functionality, then the system can receive and decode wake-up packets, but the system becomes vulnerable to unauthorized wake-up events and security threats

Engineering Contradiction:
Improvewake-up functionalityVSAvoidunauthorized wake-up events
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security verification by comparing received wake-up patterns against a pre-stored list of authorized patterns in the network controller before triggering a wake-up event. This preliminary action ensures that only authenticated wake-up signals can activate the system, preventing unauthorized wake-up events while maintaining reliable wake-up functionality for legitimate sources

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism (pattern matching and verification process) between the wake-up packet reception and system activation. This intermediary layer acts as a security gatekeeper that validates the authenticity of wake-up signals, allowing the system to maintain constant power readiness while blocking unauthorized access attempts

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If static passwords are used in wake-up packets, then the implementation is simple, but the security is weak and vulnerable to replay attacks

Engineering Contradiction:
Improvepassword implementationVSAvoidsecurity against replay attacks
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent transforms static passwords into dynamic, time-varying authorization patterns that automatically expire and need to be refreshed. The network controller and management console generate new wake-up patterns periodically using cryptographic key pairs, ensuring that previously captured patterns become invalid. This dynamic approach maintains security against replay attacks while keeping the implementation manageable through automated key rotation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements periodic regeneration of wake-up authorization patterns at defined intervals. Both the management console and network controller synchronize to generate new cryptographic key pairs and corresponding wake-up patterns periodically, ensuring that static patterns do not remain valid indefinitely. This periodic refresh mechanism prevents replay attacks while maintaining a structured, predictable security update schedule

Inventive Principle:
Principle #19Periodic action

3Reliability

If the network controller continuously monitors all packets, then wake-up packets can be reliably detected, but energy consumption increases during sleep mode

Engineering Contradiction:
Improvewake-up packet detectionVSAvoidenergy consumption in sleep mode
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential wake-up detection functionality from the full network protocol stack and implements it in a simplified manner in the network controller during sleep mode. The controller monitors only specific wake-up pattern bytes rather than fully processing all network packets, enabling reliable wake-up detection while minimizing energy consumption by keeping the majority of the system in a low-power state

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8214914B2Securing wakeup network events
Publication Date: 2012.07.03 INTEL CORP
  • US8214914B2 patent drawing
  • US8214914B2 patent drawing
  • US8214914B2 patent drawing

AI summary

In an embodiment, a method is provided. The method of this embodiment provides receiving a packet having a wake-up pattern, and waking up if the wake-up pattern corresponds to one of a number of dynamically modifiable passwords on a pattern wake list, each of the dynamically modifiable passwords being based, at least in part, on a seed value.