Dynamic VNF Partitioning for Secure Wi-Fi Pass-Through
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current community Wi-Fi networks using WPA2 pass-through are vulnerable to spoofing and data tampering, especially when residential gateways are connected to range extenders, as data traffic can be sent in clear text, compromising security even after authentication.
Innovation Solution
Implementing a dynamic functional partitioning of Virtual Network Functions (VNFs) to create a secure WPA2 pass-through interface between the service provider network and user equipment, ensuring data remains unmodified and encrypted through the residential gateway, using a service provider network device to virtualize authentication and encryption protocols, and managing partitions based on communication latency to optimize security and load balancing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If WPA2 pass-through is implemented in community Wi-Fi networks, then authentication security is improved, but data traffic can still be sent in clear text through range extenders, compromising security
Solution Approach 1:
The patent segments the network function by separating the residential gateway's Wi-Fi access point functionality from the service provider's network. The residential gateway only handles local Wi-Fi authentication, while the service provider's virtual access point handles encryption and data protection, preventing clear text data transmission through range extenders.
Solution Approach 2:
The patent introduces a virtual access point as an intermediary between the residential gateway and the service provider network. This virtual access point receives encrypted data from the residential gateway and forwards it through the service provider network, ensuring data remains encrypted even when passing through range extenders.
2Reliability
If functional partitioning of VNFs is implemented, then security is improved by maintaining data integrity, but system complexity increases
Solution Approach 1:
The patent segments network functions into distinct VNFs: a residential gateway VNF for Wi-Fi access and authentication, and a service provider VNF for encryption and data protection. This segmentation maintains data integrity while organizing complexity into manageable, independent functional modules.
Solution Approach 2:
The patent implements dynamic functional partitioning where the service provider can dynamically adjust the degree of virtualization based on network conditions. The system can adapt between different partitioning configurations (e.g., full virtualization vs. hybrid mode) to balance security requirements with operational simplicity.
3Productivity
If dynamic partition configuration is used, then load balancing is improved, but management complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where the system monitors network conditions, latency, and load distribution. Based on this feedback, the dynamic partition configuration automatically adjusts data paths and resource allocation to optimize load balancing without requiring manual intervention.
Solution Approach 2:
The patent changes operational parameters such as encryption keys, data paths, and virtual connection parameters dynamically based on network conditions. This allows the system to optimize load distribution by adjusting parameters like routing decisions and resource allocation without changing the fundamental architecture.
Data Source
AI summary
A network device or system can operate to enable a security pass-through with a user equipment (UE) and further define various virtual functions between a physical access point (pAP) and a virtual AP (vAP) based on one or more communication link parameters (e.g., latency). The security pass-through can be an interface connection that passes through a computer premise equipment (CPE) or wireless residential gateway (GW) without the CPE or GW modifying or affecting the data traffic such as by authentication or security protocol. The SP network device can receive traffic data from a UE through or via the security pass-through from a UE of a community Wi-Fi network at a home, residence, or entity network.


