Mobile Network Extender Locking to Host Router

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile network extenders, when stolen, can be used to gain unauthorized access to private networks, making them vulnerable to malware attacks due to their exposed location.

Innovation Solution

Implementing a security protection mechanism that locks the mobile network extender to a host router via a secure encrypted channel, using a secret session key or cross-reference security pass, preventing unauthorized reconnection and ensuring exclusive use with the authorized host router.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Illumination intensity

If the extender is mounted in a high location for good cellular signal reception, then the wireless link quality is improved, but the extender becomes vulnerable to theft and unauthorized access

Engineering Contradiction:
Improvecellular signal reception qualityVSAvoidtheft risk and unauthorized access
Core Design Contradiction:
Illumination intensityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by implementing security measures before theft or unauthorized access can occur. The extender is pre-configured with security credentials and authentication mechanisms that actively prevent unauthorized connection attempts, countering the vulnerability created by its exposed high-location mounting.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism between the extender and any attempting router. This intermediary security layer verifies credentials and authorized relationships, preventing direct unauthorized access even when the extender is physically stolen from its high-location mounting.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the extender is made accessible for potential reconnection, then network availability is improved, but unauthorized routers can reconnect and compromise network security

Engineering Contradiction:
Improvenetwork availabilityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system changes the parameter of connection authorization by implementing dynamic authentication based on authorized router relationships. Instead of simple physical accessibility, the extender uses credential verification and authorized relationship tracking to control reconnection, maintaining network availability for legitimate devices while blocking unauthorized access.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements feedback mechanisms where the extender continuously verifies router credentials and authorized relationships before allowing connection. This feedback loop ensures that only authenticated, authorized routers can reconnect, maintaining both network availability and security through ongoing verification rather than static access control.

Inventive Principle:
Principle #23Feedback

3Reliability

If security authentication is implemented, then unauthorized access is prevented, but the reconnection process becomes more complex

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidreconnection process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies preliminary action by pre-establishing authorized relationships and security credentials during initial router pairing and configuration. This preliminary setup stores authentication data and authorized router information in advance, so that subsequent reconnections can verify credentials without complex real-time authentication processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by storing copies of security credentials, authorized relationships, and authentication data in the extender's memory. These copied security parameters enable rapid verification of router authenticity without requiring complex real-time authentication, simplifying the reconnection process while maintaining strong security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11310664B2Security protection to prevent unauthorized use of mobile network extenders
Publication Date: 2022.04.19 CISCO TECHNOLOGY INC
  • US11310664B2 patent drawing
  • US11310664B2 patent drawing
  • US11310664B2 patent drawing

AI summary

In one illustrative example, a mobile network extender has a network interface configured to connect with a host router and a cellular modem configured to provide a wireless link for communications via a cellular mobile network. In a pairing process, the extender may establish a secure encrypted channel with the router via the network interface. In a locking process, the extender may receive information from the router and verify the information. Upon verification, the extender may be set in a locked state in which the extender is logically locked to the router. The extender may also receive and store a secret session key from the router, and permit the router to acquire the extender for communications. In the locked state, the extender may permit or deny subsequent router acquisition upon router reconnection based on verifying, using the secret session key, authentication data received via the network interface.