Wireless LAN Intrusion Detection via Location Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless local area networks face challenges in detecting unauthorized access or attempted access, particularly due to the lack of encryption for network management/control signals, which allows intruders to replicate and manipulate signals, making it difficult to differentiate between legitimate and unauthorized signal sources.

Innovation Solution

A method is implemented in a wireless local area data communications system where access points detect and locate signal sources, comparing the source location to a database of authorized locations for signals such as association requests, beacon signals, and management/control signals, triggering an alarm for inconsistencies, thereby identifying potential intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network management/control signals are transmitted without encryption to maintain signal clarity and protocol compliance, then signal interoperability and standard compliance are improved, but security against signal replication and unauthorized access deteriorates

Engineering Contradiction:
Improvesignal interoperabilityVSAvoidsignal replication vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces location information as an intermediary verification mechanism. Instead of encrypting the management signals themselves (which would break interoperability), the system adds a location-based verification layer that mediates between signal clarity and security. Access points verify the location of transmitting devices before accepting management signals, allowing unencrypted signals to maintain compatibility while location verification prevents unauthorized replication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional signal-based access control is used without location verification, then system simplicity and ease of operation are maintained, but detection of unauthorized access and intrusion detection capability deteriorate

Engineering Contradiction:
Improveaccess control simplicityVSAvoidunauthorized access detection
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary location verification before allowing network access or management signal transmission. By checking the location of a device against authorized location data before permitting it to send or receive management signals, the system prevents unauthorized access before it can occur, rather than detecting it after the fact. This maintains operational simplicity while adding security.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If location-based verification is added to wireless network access control, then security against unauthorized access and intrusion detection are improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidaccess control system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where access points continuously monitor the location of associated devices and verify it against authorized location data. When a device's location changes or becomes inconsistent with authorized data, the system provides feedback by alerting network administrators or terminating the connection. This automated feedback loop provides robust security without requiring complex manual verification procedures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7426383B2Wireless LAN intrusion detection based on location
Publication Date: 2008.09.16 SYMBOL TECHNOLOGIES LLC
  • US7426383B2 patent drawing
  • US7426383B2 patent drawing

AI summary

A intrusion detection method is disclosed for use in a wireless local area data communications system, wherein mobile units communicate with access points, and wherein the system is arranged to locate transmitters using signals transmitted by the transmitters. A database relating authorized transmitters to location is maintained. Selected signals are detected at the access points and location data corresponding to the selected signals for use in locating a source of the signals is recorded. The source location is determined using the location data, and the source location is compared to a corresponding location in the database. An alarm is signaled if the source location is inconsistent with the corresponding database location.