Local Area Network Security Assessment via Reference Server Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security methods, such as VPNs, often require unnecessary resource utilization and performance degradation by always being enabled, even in secure local area networks, and users may not want to use additional security mechanisms on trusted networks like their home LAN.

Innovation Solution

An electronic device determines the security of the local area network by checking for a legitimate reference server with a preconfigured hostname and address, and only uses additional secure techniques like VPN if the network does not meet the security condition, thereby optimizing resource utilization and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional security mechanisms like VPN are always enabled, then network security is improved, but resource utilization increases and network performance degrades

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic security mechanism activation based on real-time network environment assessment. The electronic device evaluates whether additional security mechanisms like VPN should be activated by checking for the presence and responsiveness of reference servers, then adjusts security measures accordingly. This dynamic approach allows the system to optimize between security and performance by activating security mechanisms only when the network environment warrants them.

Inventive Principle:
Principle #15Dynamics

2Reliability

If additional security mechanisms like VPN are always enabled, then network security is improved, but resource utilization increases

Engineering Contradiction:
Improvenetwork securityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing security mechanisms selectively rather than continuously. The system performs a partial security assessment by checking for reference servers and only activates additional security measures when specifically needed. This partial approach reduces resource consumption by avoiding unnecessary security operations in trusted network environments while maintaining adequate security posture.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security assessment is performed by checking reference server responsiveness, then false positives from unresponsive servers are reduced, but measurement precision requirements increase

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidhostname matching precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the electronic device sends test packets to reference servers and evaluates their responsiveness. The system uses this feedback to determine whether the network environment is trustworthy. Additionally, the device performs hostname verification by comparing received hostnames against expected values, creating a multi-layered feedback loop that enhances security assessment reliability while managing measurement precision requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240372862A1Determining security of local area network
Publication Date: 2024.11.07 BLACKBERRY LTD
  • US20240372862A1 patent drawing
  • US20240372862A1 patent drawing
  • US20240372862A1 patent drawing

AI summary

Systems, methods, and software can be used to determine whether a local area network (LAN) is secure. In some aspects, a method includes: determining, by an electronic device that is connected to a local area network (LAN), whether the LAN meets a security condition, wherein the determining whether the LAN meets a security condition comprises: determining whether an Internet Protocol (IP) address of a reference server in a security list is included in a range indicated by a subnet mask of the LAN; and determining whether a hostname of a device at the IP address matches a hostname corresponding to the reference server in the security list; and determining whether to initiate a secured network connection based on whether the LAN meets the security condition.