LAN Switch Security via Encrypted Backhaul and Node Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing LANs using network switches connected via wired Ethernet links face security issues as they are not inherently secure, allowing eavesdropping and requiring higher network layer encryption, which can prevent workstation connections.

Innovation Solution

A method and device for securing LANs by detecting wired connections to network switches, establishing secure connections with filtering rules, and managing nodes using encryption and filtering to ensure secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Volume of moving object

If network switch is connected via wired Ethernet link to extend LAN coverage, then wireless communication range is increased, but security is compromised allowing eavesdropping

Engineering Contradiction:
Improvewireless communication rangeVSAvoideavesdropping risk
Core Design Contradiction:
Volume of moving objectVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network into a secure backhaul subnetwork (using encrypted wireless links between nodes) and a less secure fronthaul network (wired connections to stations). By separating these functions and applying different security measures to each segment, the system maintains extended coverage while protecting sensitive data transmission paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption layer at the node level that mediates between the unencrypted wired fronthaul connections and the secure backhaul network. This intermediary mechanism (encryption/decryption at nodes) allows wired stations to access the network without exposing the entire network to eavesdropping risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption is applied to the routing subnetwork to prevent eavesdropping, then security is improved, but workstation connection capability deteriorates

Engineering Contradiction:
Improveeavesdropping protectionVSAvoidworkstation connection capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies different security qualities to different parts of the network: encrypted wireless links for the backhaul subnetwork (where nodes communicate) and unencrypted wired connections for the fronthaul network (where stations connect). This local differentiation allows the system to provide eavesdropping protection where needed while maintaining workstation compatibility where required.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The network is segmented into two functional zones: a secure backhaul subnetwork using encryption for node-to-node communication, and an accessible fronthaul network using unencrypted wired links for station connections. This segmentation resolves the contradiction by providing encryption only where it serves security purposes without interfering with workstation connectivity.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If secure connections are established between nodes using encryption, then data transmission security is improved, but network complexity increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidnetwork configuration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where nodes automatically generate and manage their own encryption keys and secure connections with neighboring nodes without requiring manual configuration. This automation reduces network complexity while maintaining strong encryption, as the system manages its own security infrastructure autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary key management mechanism that facilitates automatic key exchange and certificate distribution between nodes. This intermediary layer simplifies the complexity of establishing secure connections by providing automated protocols for key generation, exchange, and management, reducing the burden on network administrators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4113900B1Method and device for securing a local network comprising a network switch to which a station is connected by a wired link
Publication Date: 2026.04.01 SAGEMCOM BROADBAND SAS
  • EP4113900B1 patent drawingFigure 1a
  • EP4113900B1 patent drawingFigure 1b
  • EP4113900B1 patent drawingFigure 2

AI summary

The present invention relates to a method and device for securing a local area network comprising nodes (Ext1, Ext2, Ext3) allowing for wireless communication coverage extension in order to increase the range of the local area network by coordinating several access points integrated into the nodes, the nodes being interconnected by means of a routing subnetwork, each node of the routing subnetwork emitting at least one wireless network called the front-end network, the method comprising the steps of: detecting a connection of a station (STA6a) via a wired link to a network switch (SW23a) included in the local area network, said network switch being connected to the routing subnetwork by a wired link, establishing secure connections between each node if the connection of the station via a wired link to the network switch is detected,Management of network nodes connected to the network switch with filtering rules applied to data received by the nodes.