Wireless Network Intruder Detection via Sniffer-Monitored Nonce Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks, such as those using the Z-Wave protocol, are vulnerable to attacks during the key exchange process, where an intruder can capture and decode the encryption key, leading to potential unauthorized control of secure devices.

Innovation Solution

A method and system that utilize a sniffer to detect unauthorized NONCE-GET and NONCE-REPORT signals, alerting the master controller to transmit a new NONCE-GET, thereby preventing unauthorized access and restoring the secure state of the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the encryption key is exchanged only during a learn-in process, then the key exchange is simplified and efficient, but the system becomes vulnerable to attacks where intruders can capture and decode the encryption key

Engineering Contradiction:
Improvekey exchange efficiencyVSAvoidencryption key security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by sending a NONCE-GET signal before the actual key exchange. This preliminary signal allows the master controller to detect potential intruders who might be attempting to capture the encryption key during the learn-in process, thereby preventing security vulnerabilities while maintaining efficient key exchange

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by having the master controller monitor for NONCE-REPORT signals in response to the NONCE-GET. When an unauthorized NONCE-REPORT is detected (one that does not match the expected response), the master controller can identify and prevent intruder attempts, thus maintaining security during the efficient key exchange process

Inventive Principle:
Principle #23Feedback

2Reliability

If a sniffer is added to detect unauthorized signals, then the security detection capability is improved, but the device complexity increases

Engineering Contradiction:
Improveintruder detection capabilityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the sniffer functionality with the existing master controller by integrating the signal detection capability into the controller's existing architecture. This allows the master controller to monitor for NONCE-GET and NONCE-REPORT signals without requiring a completely separate detection system, thereby improving intruder detection while minimizing the increase in device complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The master controller is designed to perform multiple functions: it not only manages the key exchange process but also simultaneously monitors for unauthorized signals using the sniffer capability. This multi-functionality allows the same device to handle both key exchange and security detection, reducing the need for additional separate components

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11463454B2Systems and method to address the security vulnerability in wireless networks
Publication Date: 2022.10.04 KIDDE FIRE PROTECTION LLC
  • US11463454B2 patent drawing
  • US11463454B2 patent drawing
  • US11463454B2 patent drawing

AI summary

A method of operating a secure wireless network between a master controller and a secure device is provided. The method comprising: detecting at least one of a NONCE-GET and a NONCE-REPORT using a sniffer configured to detect wireless signals from a selected wireless protocol; determining that the NONCE-GET was not transmitted by a master controller or that the NONCE-REPORT was not in response to a NONCE-GET transmitted by the master controller, the master controller being in electronic communication with the sniffer; and transmitting a new NONCE-GET to the secure device from the master controller.