Secure Tunnel Switching for Compromised Wireless Access Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless access points and small cells deployed at customer premises in 5G networks are vulnerable to tampering and communication security breaches, leading to potential service disruptions and inability to access telecommunication services unless an alternate network is available.

Innovation Solution

Establishing a secure tunnel with an untrusted link between a wireless access point and a gateway device, allowing communication to continue through the access point as a transparent relay, while keeping payload traffic indecipherable to the access point, and switching back to a trusted link when security is restored.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a wireless access point is deployed at customer premises, then service coverage and accessibility are improved, but security vulnerability increases

Engineering Contradiction:
Improveservice coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The communication path is segmented into multiple hops (endpoint device -> wireless access point -> intermediate device -> gateway device). By introducing an intermediate device that establishes an indirect communication path, the system segments the direct link and allows secure tunneling even when the wireless access point is compromised, thus maintaining security while preserving service coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediate device is introduced as a mediator between the wireless access point and the gateway device. This intermediary establishes a secure tunnel that bypasses the untrusted wireless access point for critical communications, allowing the system to maintain security through the intermediary while still utilizing the wireless access point for basic connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of stationary object

If a secure tunnel is established through an untrusted wireless access point, then continuous service provision is improved, but communication security deteriorates

Engineering Contradiction:
Improveservice continuityVSAvoidcommunication security
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The communication path is divided into segments where the secure tunnel is established between the intermediate device and gateway device, while the wireless access point only handles local wireless communications. This segmentation allows the secure portion to bypass the untrusted access point for critical data, maintaining both service continuity and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The intermediate device acts as a mediator that establishes a secure tunnel to the gateway device, bypassing the untrusted wireless access point for secure communications. This intermediary ensures that sensitive payload traffic never passes through the compromised access point, maintaining security while allowing continuous service through the access point's wireless functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the wireless access point is taken out of service when compromised, then security is improved, but service availability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the communication functions: the wireless access point continues to provide wireless connectivity and basic networking services, while the intermediate device handles secure tunneling to the gateway. This segmentation allows the access point to remain operational for service availability while security-critical communications use the separate secure path.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The intermediate device serves as a mediator that enables the wireless access point to remain in service while securing communications. The intermediary establishes an alternative secure path to the gateway device, allowing the compromised access point to continue providing wireless access without compromising security, thus maintaining both service availability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11395357B2Trust mode switching for wireless access points
Publication Date: 2022.07.19 AT&T MOBILITY II LLC
  • US11395357B2 patent drawing
  • US11395357B2 patent drawing
  • US11395357B2 patent drawing

AI summary

Devices, computer-readable media, and methods are disclosed for establishing a secure tunnel having a path that includes an untrusted link between a wireless access point and a gateway device. For example, a processor may detect a security event associated with a wireless access point that is in communication with a gateway device of the telecommunication network via a trusted link, establish a secure tunnel between the gateway device and an endpoint device that is accessing the telecommunication network via the wireless access point and the gateway device, and transport payload traffic between the endpoint device and the gateway device via the secure tunnel. A path of the secure tunnel may include an untrusted link between the wireless access point and the gateway device. In addition, the payload traffic that is transported via the secure tunnel may be indecipherable by the wireless access point.