Virtualized Wireless Access Point for Secure Communication and Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks are inherently more vulnerable to attacks than wired networks, making them susceptible to attacks on connected wired networks, necessitating robust security mechanisms for secure operation.

Innovation Solution

An apparatus comprising a volatile memory, non-volatile memory, and electronic circuits configured to operate as a wireless access point with integrated virtual machines for wireless network authentication and VPN servers, fully contained in volatile memory, to authenticate and encrypt data transmissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless networks are used to provide network access, then ease of operation and accessibility are improved, but vulnerability to attacks and security risks worsen

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments network functions into separate virtual machines (authentication server, VPN server, firewall) that run in isolated environments. This segmentation allows the wireless access point to maintain ease of operation while limiting the impact of potential attacks to specific virtual machine instances rather than the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multiple intermediary security layers including authentication servers that verify device legitimacy, VPN servers that encrypt data transmissions, and firewalls that filter malicious traffic. These intermediaries stand between the wireless network and internal systems, maintaining accessibility while blocking attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security mechanisms are added to protect against attacks, then network security is improved, but device complexity worsens

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The wireless access point device performs multiple functions by running several virtual machines simultaneously - authentication, VPN encryption, and firewall services - all within a single device. This multi-functionality approach improves network security without requiring multiple separate devices, thus managing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses virtual machine instances that are software copies of security service templates. These virtual machine images can be deployed and replicated across the device, providing robust security mechanisms through software rather than requiring complex hardware configurations for each security function.

Inventive Principle:
Principle #26Copying

3Reliability

If virtual machines are used to provide security services, then network security is improved, but memory resource consumption worsens

Engineering Contradiction:
Improvesecurity service capabilityVSAvoidmemory resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements virtual machines nested within the wireless access point device, with each virtual machine containing specific security services. This nesting allows multiple security functions to share the device's memory resources through virtualization, providing comprehensive security while managing memory consumption through resource pooling and allocation.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12418511B2Method and apparatus for secure communication and routing
Publication Date: 2025.09.16 VERTEX AEROSPACE LLC
  • US12418511B2 patent drawing
  • US12418511B2 patent drawing
  • US12418511B2 patent drawing

AI summary

An apparatus is provided, comprising: a volatile memory; a non-volatile memory; a first electronic circuit that is configured to operate as a wireless access point, the first electronic circuit including a wireless controller for accessing a wireless network; and a second electronic circuit that is operatively coupled to the first electronic circuit, the second electronic circuit including at least one processor configured to execute: (i) a first virtual machine that includes a wireless network authentication server, and (ii) a second virtual machine that includes a virtual private network (VPN) server, wherein the wireless network authentication server is configured to authenticate devices that attempt to join the wireless network; wherein the VPN server is arranged to encrypt data that is received at the apparatus to produce encrypted data, and forward the encrypted data to the wireless controller for transmission over the wireless network.