LAN Switch Security via Encrypted Backhaul and Node Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing LANs using network switches connected via wired Ethernet links face security issues as they are not inherently secure, allowing eavesdropping and requiring higher network layer encryption, which can prevent workstation connections.
Innovation Solution
A method and device for securing LANs by detecting wired connections to network switches, establishing secure connections with filtering rules, and managing nodes using encryption and filtering to ensure secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Volume of moving object
If network switch is connected via wired Ethernet link to extend LAN coverage, then wireless communication range is increased, but security is compromised allowing eavesdropping
Solution Approach 1:
The patent segments the network into a secure backhaul subnetwork (using encrypted wireless links between nodes) and a less secure fronthaul network (wired connections to stations). By separating these functions and applying different security measures to each segment, the system maintains extended coverage while protecting sensitive data transmission paths.
Solution Approach 2:
The patent introduces an intermediary encryption layer at the node level that mediates between the unencrypted wired fronthaul connections and the secure backhaul network. This intermediary mechanism (encryption/decryption at nodes) allows wired stations to access the network without exposing the entire network to eavesdropping risks.
2Object-affected harmful factors
If encryption is applied to the routing subnetwork to prevent eavesdropping, then security is improved, but workstation connection capability deteriorates
Solution Approach 1:
The patent applies different security qualities to different parts of the network: encrypted wireless links for the backhaul subnetwork (where nodes communicate) and unencrypted wired connections for the fronthaul network (where stations connect). This local differentiation allows the system to provide eavesdropping protection where needed while maintaining workstation compatibility where required.
Solution Approach 2:
The network is segmented into two functional zones: a secure backhaul subnetwork using encryption for node-to-node communication, and an accessible fronthaul network using unencrypted wired links for station connections. This segmentation resolves the contradiction by providing encryption only where it serves security purposes without interfering with workstation connectivity.
3Object-affected harmful factors
If secure connections are established between nodes using encryption, then data transmission security is improved, but network complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where nodes automatically generate and manage their own encryption keys and secure connections with neighboring nodes without requiring manual configuration. This automation reduces network complexity while maintaining strong encryption, as the system manages its own security infrastructure autonomously.
Solution Approach 2:
The patent introduces an intermediary key management mechanism that facilitates automatic key exchange and certificate distribution between nodes. This intermediary layer simplifies the complexity of establishing secure connections by providing automated protocols for key generation, exchange, and management, reducing the burden on network administrators.
Data Source
Figure 1a
Figure 1b
Figure 2
AI summary
The present invention relates to a method and device for securing a local area network comprising nodes (Ext1, Ext2, Ext3) allowing for wireless communication coverage extension in order to increase the range of the local area network by coordinating several access points integrated into the nodes, the nodes being interconnected by means of a routing subnetwork, each node of the routing subnetwork emitting at least one wireless network called the front-end network, the method comprising the steps of: detecting a connection of a station (STA6a) via a wired link to a network switch (SW23a) included in the local area network, said network switch being connected to the routing subnetwork by a wired link, establishing secure connections between each node if the connection of the station via a wired link to the network switch is detected,Management of network nodes connected to the network switch with filtering rules applied to data received by the nodes.