Network Gateway Security-Flaw Detection for Automatic Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing password transmission in wireless networks are vulnerable to security breaches, such as unauthorized terminals intercepting sensitive data during Bluetooth Low Energy (BLE) communications, and existing solutions either compromise security or user experience.

Innovation Solution

A detection device that monitors message destinations and analyzes communications only when a new terminal is detected, using identifiers and characteristics to identify and verify legitimate terminals, without decrypting encrypted messages, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If WPS functionality is activated to allow automatic connection without password, then user experience is improved, but security is compromised allowing malicious terminals to connect

Engineering Contradiction:
Improveautomatic connectionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a detection device as an intermediary that monitors communications between terminals and the network termination equipment. This mediator detects whether a terminal is malicious by analyzing communication patterns and identifying security flaws, thereby enabling automatic connection while maintaining security through active surveillance and intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If password is broadcast automatically via BLE to improve user experience, then manual entry is eliminated, but security is compromised allowing interception of sensitive data

Engineering Contradiction:
Improveautomatic password sharingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The detection device continuously monitors BLE communications and provides feedback about the security status of password broadcasting. When a security flaw is detected or a malicious terminal is identified, the system can alert users or interrupt the password sharing process, creating a feedback loop that maintains security while enabling convenient automatic connection.

Inventive Principle:
Principle #23Feedback

3Reliability

If manual password entry is required for each terminal to ensure security, then security is maintained, but user experience deteriorates due to tedious process

Engineering Contradiction:
ImprovesecurityVSAvoidconnection process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables terminals to self-register and connect automatically through WPS or password broadcasting mechanisms. The detection device autonomously monitors and identifies malicious terminals, freeing users from manual password entry while maintaining security through automated surveillance and threat detection.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If detection device monitors all communications to detect security flaws, then security detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity flaw detectionVSAvoidmonitoring system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection device focuses its monitoring efforts on specific local conditions and patterns that indicate security flaws, rather than analyzing all communications uniformly. By targeting specific suspicious patterns and behaviors in terminal communications, the system achieves effective security detection with reduced computational complexity and resource requirements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4173250B1Method and device for detecting a security flaw
Publication Date: 2025.08.06 ORANGE SA
  • EP4173250B1 patent drawingFigure 1~2
  • EP4173250B1 patent drawingFigure 3~4
  • EP4173250B1 patent drawingFigure 5~6

AI summary

The security flaw (FS) allows a sensitive datum (MDP) to be recovered, the method being implemented by a device (BX) of network-gateway type holding the sensitive datum, said sensitive datum (MDP) allowing a network terminal to connect to said device (BX), and comprising steps of: - analysing (E300) messages sent by at least a first terminal (T) of the network administrated by the device, which terminal is referred to as the terminal known by said device, to another terminal (CAM); - the device detecting (E500) a said security flaw (FS) if it detects (E400) the presence of the sensitive datum (MDP) in a said message.