RF Fingerprinting for Unauthorized Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control systems face challenges in pre-emptively detecting unauthorized access by malicious users, as masking device identities is simple and difficult to distinguish based on software-defined characteristics of mobile computing devices, especially in wireless network environments.

Innovation Solution

Implementing a communication fingerprint monitor that analyzes unique transient characteristics of communication signals from mobile devices to generate a fingerprint, comparing it to authorized fingerprints to grant or restrict access, and detecting unauthorized behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-defined characteristics (MAC address, IP address) are used to identify mobile computing devices, then device identification is simple and straightforward, but unauthorized users can easily mask their device identities and gain unauthorized access

Engineering Contradiction:
Improvedevice identificationVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-defined identification mechanisms (MAC addresses, IP addresses) with hardware-based electromagnetic fingerprinting. The electromagnetic fingerprint is derived from the unique physical characteristics of the device's radio frequency circuitry, making it impossible to mask or spoof through software modifications. This substitution of identification methodology resolves the contradiction by maintaining ease of operation while dramatically improving security reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the identification parameter from mutable software-defined addresses to immutable electromagnetic characteristics. The electromagnetic fingerprint captures unique physical properties of the device's hardware components, such as oscillator frequencies and signal transmission characteristics, which cannot be altered without physically changing the hardware. This parameter change ensures that identification remains both simple and secure.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If physical access control systems are implemented to restrict access to authorized locations, then unauthorized physical access is prevented, but users can bypass these controls by using mobile computing devices to access networks from unrestricted locations

Engineering Contradiction:
Improvephysical access controlVSAvoidnetwork access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges physical access control with network access control by integrating electromagnetic fingerprint verification into both systems. The same hardware-based identification mechanism is used to authenticate devices for both physical entry to restricted areas and network connectivity. This integration ensures that a device can only access the network when physically located in authorized areas, eliminating the bypass vulnerability while maintaining flexible wireless access for authorized users.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The electromagnetic fingerprint acts as an intermediary that links physical location verification with network access authorization. Instead of treating physical and network access as separate control systems, the patent uses the unique electromagnetic characteristics of each device as a common identifier that both systems verify. This intermediary mechanism ensures that network access is inherently tied to authorized physical locations, preventing bypass attempts while preserving wireless access flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If traditional network access control methods are used, then authorized users can access the network from any location, but the system cannot pre-emptively detect or prevent malicious behavior from unauthorized devices

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoidmalicious behavior detection
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary action by performing electromagnetic fingerprint verification before granting network access. Rather than detecting malicious behavior after it occurs, the system pre-emptively identifies and blocks unauthorized devices by comparing their electromagnetic fingerprints against an authorized database. This preliminary verification prevents malicious users from even establishing network connections, making detection unnecessary while maintaining full access flexibility for authorized devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms that continuously monitor electromagnetic fingerprints of devices attempting to access the network. The system compares each device's fingerprint against authorized profiles and provides immediate feedback by either granting or denying access. This real-time feedback loop enables the system to detect and prevent malicious behavior before it can affect the network, while maintaining seamless access for authorized users who receive positive feedback.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9420464B2Technologies for controlling network access based on electronic device communication fingerprints
Publication Date: 2016.08.16 INTEL CORP
  • US9420464B2 patent drawing
  • US9420464B2 patent drawing
  • US9420464B2 patent drawing

AI summary

Technologies for monitoring network access and/or usage include mobile computing devices in communication with network devices to facilitate access to a network. Communication signals are transmitted from one of the mobile computing devices and received by a remote computing device (e.g., a network device). Transients of characteristics of the communication signals received during a power-on sequence of the mobile computing device are analyzed to generate a communication fingerprint corresponding to the communication signal. The network device then compares the communication fingerprint to authorized communication fingerprints to determine whether to grant network access to the mobile computing device corresponding to the communication fingerprint. Additionally, granted network access may be monitored to determine whether any unauthorized use is being performed by the mobile computing device. Further, network access may then be restricted if unauthorized use is detected.