Service-Configurable Wi-Fi Security Entity for Endpoint Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices in Wi-Fi peer-to-peer networks lack the ability to independently configure security settings, leading to vulnerabilities such as data exposure when connecting with devices that do not support encryption, as the security configuration is dictated by the access point or one of the connected devices.

Innovation Solution

A system that enables service-configurable wireless connections by allowing service endpoints to manage the security configuration of Wi-Fi connections, accommodating the security requirements of both local and remote service endpoints through a service-configurable security mechanism, which can establish and configure secure datapaths over Wi-Fi connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the access point or connected device dictates the security configuration of the Wi-Fi network, then the network can be established with a unified security setting, but applications with different security requirements cannot be accommodated, leading to potential data exposure

Engineering Contradiction:
Improvesecurity configuration adaptabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security configuration control from the network layer to the application layer. Each application can now have its own service endpoint that independently configures security settings for its datapath, rather than all applications sharing a single network-level security configuration. This allows sensitive applications to enforce encryption while non-sensitive applications can use simpler configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing different security configurations for different applications (service endpoints) within the same network. The service-configurable security entity enables each service endpoint to have customized security parameters tailored to its specific security requirements, rather than applying a uniform security policy across all services.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If a unified security configuration is enforced across all applications, then network establishment is simplified, but applications with specific security requirements cannot configure their own settings, compromising their security

Engineering Contradiction:
Improvenetwork establishmentVSAvoidapplication-specific security configuration
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a service-configurable security entity as an intermediary between the application layer and the network layer. This intermediary receives security requirements from service endpoints and translates them into appropriate Wi-Fi connection configurations, enabling applications to have customized security settings without complicating the overall network establishment process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension of control by introducing service-level security configuration above the traditional network-level configuration. This creates a hierarchical structure where both network-wide and application-specific security settings can coexist, allowing simplified network establishment while accommodating diverse application requirements.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If service endpoints can independently configure security settings, then applications with different security requirements can be accommodated, but the complexity of security configuration management increases

Engineering Contradiction:
Improveservice-specific security configurationVSAvoidsecurity configuration management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling service endpoints to autonomously declare their security requirements and configure their own datapath security settings. The service-configurable security entity automatically processes these declarations and establishes appropriate security configurations without requiring manual intervention or complex centralized management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces dynamic security configuration where security settings can be adjusted at the service level based on specific application requirements. The system dynamically creates and manages separate security configurations for different service endpoints, allowing the security architecture to adapt flexibly to diverse application needs without static, rigid configuration management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10015151B2Method and apparatus for enabling service-configurable wireless connections
Publication Date: 2018.07.03 APPLE INC
  • US10015151B2 patent drawing
  • US10015151B2 patent drawing
  • US10015151B2 patent drawing

AI summary

The disclosed embodiments provide a system that enables service-configurable wireless connections. During operation, a local service endpoint of a service runs on a wireless device. The local service endpoint sends a request to establish a datapath with another service endpoint on another device. Meanwhile, the wireless device's service discovery module discovers a remote endpoint for the service on a remote device. In response to the request, the wireless device's service-configurable security entity configures a Wi-Fi connection's security configuration, thereby enabling the local endpoint to establish a datapath between the local endpoint and the remote endpoint over the Wi-Fi connection.