Virtualized Access Point Secure Pairing via Wired Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a secure wireless connection to a virtualized access point is challenging due to the need for complex physical interactions and laborious configuration processes, especially in new network topologies where wireless access points are virtualized in a data center, far from user premises.
Innovation Solution
A method is introduced where a radio equipment controller in the data center receives information items emulating user actions from both the device seeking to connect and the virtualized access point, allowing for a secure wireless connection to be established within a specific time interval, using a wired network connection to simplify the configuration process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical interactions are required on both the wireless device and the virtualized access point for secure connection establishment, then security protection is improved, but the configuration complexity and user effort increase significantly
Solution Approach 1:
The patent introduces a wired network connection as an intermediary channel between the wireless device and the virtualized access point. Instead of requiring direct physical interactions on both wireless devices, the system uses the wired network to transmit information items that represent user actions, thereby mediating the pairing process and reducing complexity while maintaining security
Solution Approach 2:
The patent uses information items that copy or represent user actions performed on one device to emulate the corresponding actions on the other device. When a user performs an action on the wireless device, this action is captured as an information item and transmitted via the wired network to emulate the same action on the virtualized access point, eliminating the need for physical interaction on both devices
2Adaptability or versatility
If the access point is virtualized and located in a data centre far from user premises, then network flexibility and scalability are improved, but the ease of configuration and setup deteriorates
Solution Approach 1:
The wired network connection serves as a mediator that bridges the physical distance between the user's wireless device and the remotely located virtualized access point in the data centre. This intermediary channel enables simple configuration by transmitting pairing information over the existing wired infrastructure, eliminating the need for users to physically access or configure the remote access point
Solution Approach 2:
The patent replaces the mechanical/physical interaction model (where users would need to physically access both devices) with an information-based model. User actions are captured as information items and transmitted electronically via the wired network, substituting physical presence and manual configuration with automated information exchange
3Ease of operation
If simple push button configuration methods are used, then ease of operation is improved, but protection against man in the middle attacks deteriorates
Solution Approach 1:
The wired network connection acts as a secure intermediary channel that provides protection against man-in-the-middle attacks. By transmitting pairing information over this controlled wired channel rather than through wireless air interface, the system maintains the simplicity of push-button configuration while enhancing security against eavesdropping and injection attacks
Data Source
AI summary
In a context of virtualized access points deployment, an access point of a first wireless network is split in a radio equipment deployed at the user premises and a radio equipment controller deployed in a data centre located a few kilometres from the user premises, the radio equipment and the radio equipment controller being interconnected via a wired network connection. In order to establish a secure wireless connection of a device to the virtualized access point in a user-friendly manner, a salient idea is to receive at the radio equipment controller in the data centre a first and a second information items respectively emulating a first action of a user on the first device and a second action of the user on the virtualized access point. The disclosed principles are advantageous as sending the first and the second information items to the radio equipment controller allows to emulate user actions on both the wireless device seeking for joining the first wireless network and the virtualized access point, further allowing to use simple but secure wireless configuration setup protocols, avoiding laborious configurations from users.


