Network Device Location Inference for Unauthorized Access Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting unauthorized devices in a network is challenging due to the difficulty in distinguishing them from authorized devices, especially when hackers manipulate devices to appear as authorized.

Innovation Solution

The solution involves authorized devices on a second network providing assistance to identify unauthorized devices by exchanging information, such as MAC addresses and account details, to determine the location of a suspect device and verify its authorization status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network access control methods are used, then network security is maintained to some extent, but unauthorized devices can manipulate devices to appear authorized and gain access

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection of unauthorized devices
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a location inference mechanism that acts as an intermediary between device identification and authorization verification. Instead of directly trusting device-provided identification information, the system infers device location through multiple authorized devices and compares it with authorized location information to detect unauthorized devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by continuously monitoring device locations through multiple authorized devices, comparing inferred locations with authorized location information, and using this information to determine whether to grant network access. This creates a closed-loop verification system that adapts to detected anomalies.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If device identification information is collected from multiple authorized devices, then the accuracy of location determination improves, but the complexity of information exchange and processing increases

Engineering Contradiction:
Improvelocation determination accuracyVSAvoidinformation exchange complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the location verification process into distinct components: individual authorized devices independently report device information, a location inference module processes this segmented information separately from each device, and then integrates the results to determine overall device location and authorization status.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal location inference mechanism that can process information from multiple different types of authorized devices (wireless devices, wired devices, mobile devices) through a common information exchange protocol, allowing the same verification process to work across diverse device types without increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If location information is inferred from authorized devices to verify suspect device authorization, then unauthorized devices can be identified more effectively, but the time required for verification increases

Engineering Contradiction:
Improveunauthorized device identificationVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by having authorized devices continuously report their device information and locations in advance, building a database of authorized device patterns before verification is needed. When a suspect device connects, the system can quickly compare against pre-collected location information from multiple authorized devices rather than gathering information from scratch.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10078746B2Detecting unauthorized devices
Publication Date: 2018.09.18 COMCAST CABLE COMM LLC
  • US10078746B2 patent drawing
  • US10078746B2 patent drawing
  • US10078746B2 patent drawing

AI summary

Methods and systems are disclosed that, in some aspects, provide for receiving a provisioning request from a requesting device, and identifying one or more other devices proximate to or co-located with the requesting device. The methods and systems may include determining a location and other information of the one or more other devices and using the information to determine a location of and other information related to the requesting device. It may be determined whether to grant the provisioning request based on the determined location of the requesting device.