Physical Layer Rogue Device Detection via Signal Variance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security measures are inadequate in detecting Man-in-the-Middle attacks and Denial of Service attacks, as they rely on protocol-specific techniques that can be bypassed by rogue devices inserted in network links, and do not effectively prevent data capture or modification.

Innovation Solution

A method and system for detecting rogue network devices at the physical layer by analyzing characteristics such as clock frequency noise and jitter, using Synchronous Ethernet (SyncE) to identify mismatches indicative of unauthorized devices, and switching traffic to secure links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional Layer 2 security measures (IEEE 802.1x Port Based Network Access Control) are used to prevent rogue devices, then direct connection to network ports is blocked, but Man-in-the-Middle attacks where users splice rogue devices into active links remain undetected

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidrogue device detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent transitions detection from Layer 2 (data link layer) to Layer 1 (physical layer) by monitoring physical characteristics such as signal quality, noise floor, and electromagnetic properties of the transmission medium. This dimensional shift enables detection of rogue devices even when they are spliced into active links transparently, as the physical layer characteristics change when an unauthorized device is introduced into the physical medium.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If data encryption and port authentication are used to secure network communications, then data protection is improved, but rogue users can eventually crack encryption and authentication mechanisms

Engineering Contradiction:
Improvedata securityVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces software-based security mechanisms (encryption and authentication protocols) with physical layer detection mechanisms. Instead of relying on cryptographic strength that can be brute-forced, the system uses physical measurements (signal characteristics, noise analysis, electromagnetic properties) to detect the presence of rogue devices. This substitution fundamentally changes the security approach from information-theoretic security to physical security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If Layer 2 security measures are implemented to prevent rogue connections, then direct port access is blocked, but Denial of Service attacks by rogue devices modifying and generating packets remain possible

Engineering Contradiction:
Improveconnection securityVSAvoidpacket modification capability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent detects rogue devices at the physical layer by monitoring changes in physical characteristics (signal quality, noise floor, electromagnetic interference) caused by packet generation and modification activities. This physical layer detection enables the system to identify DoS attacks and packet injection attempts before they affect network operations, providing early warning and prevention capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11985148B2Physical layer rogue device detection
Publication Date: 2024.05.14 CIENA CORP
  • US11985148B2 patent drawing
  • US11985148B2 patent drawing
  • US11985148B2 patent drawing

AI summary

Systems and methods for detecting a rogue network device at a physical layer include monitoring physical layer characteristics of a wired link at both a first network device and a second network device; determining whether there are detectable variances in the physical layer characteristics; and detecting a rogue network device inserted on the link based on the detectable variances.