Wireless Access Point Security System for Passenger Vehicles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commercial passenger vehicles' wireless access points are vulnerable to security attacks, such as unauthorized APs mimicking authorized ones, which can steal sensitive information or disrupt service, and existing systems fail to effectively detect and prevent these attacks.

Innovation Solution

A dedicated wireless AP system that monitors beacon frames and other wireless activity to detect anomalies, generates security alerts, and logs malicious activity, allowing for real-time detection and prevention of attacks, including spoofing, deauthentication, and malformed frame attacks, while minimizing disruption to regular AP functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless AP provides entertainment and Internet access to passengers, then passenger satisfaction and service quality improve, but the system becomes vulnerable to security attacks and malicious activities

Engineering Contradiction:
Improveservice qualityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the wireless network monitoring into multiple independent components: beacon frame rate monitoring, deauthentication frame detection, data frame analysis, and security alert generation. Each component operates independently to detect specific attack types, allowing the system to maintain comprehensive security coverage while reducing the complexity of any single detection mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary security assessments by continuously monitoring beacon frame rates and comparing them against baseline values before actual attacks occur. This proactive approach allows the system to detect anomalies and generate security alerts before malicious activities can fully compromise the network, preventing rather than merely responding to attacks.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If the wireless AP monitors all wireless frames for security threats, then detection accuracy improves, but computational load and processing time increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational load
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent applies different monitoring intensities to different types of wireless frames based on their security relevance. Management frames (beacon frames) receive intensive monitoring with rate comparison against baselines, while other frames are monitored for specific attack patterns like deauthentication sequences. This localized quality approach ensures high detection accuracy for critical threats while reducing unnecessary processing of benign traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts monitoring parameters such as beacon frame rate thresholds and comparison windows based on network conditions and detected attack patterns. By changing these parameters adaptively, the system maintains high detection accuracy while optimizing computational resource usage to prevent overload during normal operation versus attack scenarios.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If the system generates security alerts for all suspicious activities, then security response time improves, but false positives increase and system reliability decreases

Engineering Contradiction:
Improvesecurity response timeVSAvoidfalse positive rate
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system incorporates feedback mechanisms where security alerts are generated based on multiple correlated indicators rather than single events. For example, it monitors sequences of deauthentication frames, compares beacon frame rates against baselines, and analyzes patterns in data frames. This multi-factor feedback approach reduces false positives by requiring convergence of multiple suspicious indicators before triggering alerts, thereby improving reliability while maintaining rapid response capability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11418956B2Passenger vehicle wireless access point security system
Publication Date: 2022.08.16 PANASONIC AVIONICS CORP
  • US11418956B2 patent drawing
  • US11418956B2 patent drawing
  • US11418956B2 patent drawing

AI summary

Techniques are described to detect and/or prevent malicious wireless attacks and/or suspicious wireless activity related to a wireless network in a commercial passenger vehicle. For example, an access point located in the commercial passenger vehicle receives a set of wireless beacon frames from a first wireless device, makes a first determination of a first beacon frame rate of the set of wireless beacon frames, receives a second beacon frame after a first beacon frame, makes a second determination of a second beacon frame rate of the second beacon frame relative to the first beacon frame, makes a third determination that a second wireless device is impersonating the first wireless device upon comparing the first beacon frame rate to the second beacon frame rate, and sends, upon making the third determination, a security alert message to an external input/output (I/O) device in the commercial passenger vehicle.