Masked SSID Beacon Broadcast for Secure Multi-Level Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network access points are vulnerable to unauthorized access due to the lack of encryption in SSID broadcasts, which can lead to security breaches, especially in peer-to-peer networks where multiple applications with varying security requirements are supported from a single infrastructure.

Innovation Solution

The method involves masking the true SSID in beacon frames and broadcasting a masked version, allowing only authorized devices to retrieve the true SSID, enabling secure multi-level network access through the use of virtual SSIDs, shared keys, signature and SSID pairs, public key infrastructure, and hash functions to define access levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SSID broadcast is enabled for network discovery, then network accessibility is improved, but security is worsened because SSIDs can be sniffed in plain text

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a masking intermediary layer between the true SSID and the broadcast signal. A masking algorithm processes the true SSID to generate a masked version for broadcast, while maintaining the ability to retrieve the original SSID through authorized devices that possess the masking key or algorithm, thus protecting the true SSID from plain text sniffing

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the SSID parameter by applying masking algorithms that change the visible form of the SSID in broadcasts. The true SSID is converted into a masked representation through cryptographic or hashing functions, allowing network discovery while preventing direct identification of the true network identifier

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple SSIDs are supported on a single access point to enable flexible deployment, then adaptability is improved, but device complexity is worsened

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidaccess point complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent enables a single access point to function as multiple virtual access points by implementing multiple SSID support. The access point is designed to handle multiple SSID configurations, each representing a different virtual network or service level, allowing diverse applications (public Internet access, inventory control, etc.) to coexist on one hardware platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the single access point into multiple virtual access points, each associated with a specific SSID and access level. This logical segmentation allows different network zones or services to be maintained independently while sharing the same physical infrastructure, reducing the need for multiple separate access points

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If SSID broadcast is disabled to prevent snooping, then security is improved, but network discoverability is worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork discoverability
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses a masking intermediary that allows SSID broadcast to continue while protecting the true SSID. Authorized devices with the masking key can retrieve the true SSID from the masked broadcast, while unauthorized devices cannot, thus maintaining both security and discoverability simultaneously

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary masking of the SSID before broadcast, preparing the protected version in advance. This preliminary action ensures that the SSID is always protected when broadcast, eliminating the need to completely disable broadcasting while maintaining security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8166309B2System and method for a secure multi-level network access mechanism using virtual service set identifier broadcast
Publication Date: 2012.04.24 INFOSYS LTD
  • US8166309B2 patent drawing
  • US8166309B2 patent drawing

AI summary

A method, system, and computer program product for network management, including masking a true service set identifier (SSID) in beacon frame; and broadcasting the beacon frame with the masked true SSID, whereby an authorized device retrieve the true SSID from the broadcast beacon frame.