Hypervisor-Based Wireless Access Point Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication for mobile computers poses challenges in ensuring secure data access, as the security management systems developed for stationary computers with wired links are not effective for wireless links, where one access point may provide security while others may not.

Innovation Solution

A method for a mobile computer to determine if it has lost connectivity to an access point and, upon roaming to a new access point, assess whether it is authorized for secure communication, allowing or denying access to secure data accordingly, potentially using a hypervisor or network resource.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile computers roam between wireless access points to maintain connectivity, then mobility and productivity are improved, but security control becomes more difficult because different access points have different security authorization levels

Engineering Contradiction:
ImprovemobilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-establishing a list of authorized access points and their security clearance levels before the mobile computer actually roams. The hypervisor continuously monitors connection status and proactively verifies authorization before allowing access to secure data, preventing security breaches before they occur rather than reacting after compromise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where the hypervisor monitors the mobile computer's connection status to access points and compares it against the authorized list. When connectivity is lost or the computer roams to a new access point, the system receives feedback about the current connection state and automatically adjusts access permissions accordingly, ensuring security is maintained throughout the roaming process.

Inventive Principle:
Principle #23Feedback

2Reliability

If the system continuously monitors access point authorization to ensure security, then data security is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile computer's hypervisor performs self-service by autonomously managing its own security clearance status. The hypervisor maintains local knowledge of authorized access points, automatically monitors connection status, and makes decisions about data access without requiring constant intervention from centralized security systems. This distributed self-service approach reduces overall system complexity while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The hypervisor serves multiple functions simultaneously: it manages the mobile computer's connection to access points, maintains security clearance status, monitors for unauthorized roaming, and controls data access permissions. By consolidating these functions into a single multi-functional component, the system achieves effective security monitoring without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7620997B2System and method for controlling network access in wireless environment
Publication Date: 2009.11.17 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US7620997B2 patent drawing
  • US7620997B2 patent drawing
  • US7620997B2 patent drawing

AI summary

When an authenticated wireless computer loses connectivity to a wireless access point of a network and roams to another access point, the wireless computer (e.g., a hypervisor in the computer) determines whether the new access point is authorized for secure communication and if so, releases access to secure data on the network through the new access point.