Dynamic VNF Partitioning for Secure Wi-Fi Pass-Through

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current community Wi-Fi networks using WPA2 pass-through are vulnerable to spoofing and data tampering, especially when residential gateways are connected to range extenders, as data traffic can be sent in clear text, compromising security even after authentication.

Innovation Solution

Implementing a dynamic functional partitioning of Virtual Network Functions (VNFs) to create a secure WPA2 pass-through interface between the service provider network and user equipment, ensuring data remains unmodified and encrypted through the residential gateway, using a service provider network device to virtualize authentication and encryption protocols, and managing partitions based on communication latency to optimize security and load balancing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WPA2 pass-through is implemented in community Wi-Fi networks, then authentication security is improved, but data traffic can still be sent in clear text through range extenders, compromising security

Engineering Contradiction:
Improveauthentication securityVSAvoiddata tampering vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network function by separating the residential gateway's Wi-Fi access point functionality from the service provider's network. The residential gateway only handles local Wi-Fi authentication, while the service provider's virtual access point handles encryption and data protection, preventing clear text data transmission through range extenders.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtual access point as an intermediary between the residential gateway and the service provider network. This virtual access point receives encrypted data from the residential gateway and forwards it through the service provider network, ensuring data remains encrypted even when passing through range extenders.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If functional partitioning of VNFs is implemented, then security is improved by maintaining data integrity, but system complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidVNF partitioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network functions into distinct VNFs: a residential gateway VNF for Wi-Fi access and authentication, and a service provider VNF for encryption and data protection. This segmentation maintains data integrity while organizing complexity into manageable, independent functional modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic functional partitioning where the service provider can dynamically adjust the degree of virtualization based on network conditions. The system can adapt between different partitioning configurations (e.g., full virtualization vs. hybrid mode) to balance security requirements with operational simplicity.

Inventive Principle:
Principle #15Dynamics

3Productivity

If dynamic partition configuration is used, then load balancing is improved, but management complexity increases

Engineering Contradiction:
Improveload balancingVSAvoidpartition management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the system monitors network conditions, latency, and load distribution. Based on this feedback, the dynamic partition configuration automatically adjusts data paths and resource allocation to optimize load balancing without requiring manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes operational parameters such as encryption keys, data paths, and virtual connection parameters dynamically based on network conditions. This allows the system to optimize load distribution by adjusting parameters like routing decisions and resource allocation without changing the fundamental architecture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250016666A1Dynamic functional partitioning for security pass-through virtual network function (VNF)
Publication Date: 2025.01.09 QUANTEFI CORP
  • US20250016666A1 patent drawing
  • US20250016666A1 patent drawing
  • US20250016666A1 patent drawing

AI summary

A network device or system can operate to enable a security pass-through with a user equipment (UE) and further define various virtual functions between a physical access point (pAP) and a virtual AP (vAP) based on one or more communication link parameters (e.g., latency). The security pass-through can be an interface connection that passes through a computer premise equipment (CPE) or wireless residential gateway (GW) without the CPE or GW modifying or affecting the data traffic such as by authentication or security protocol. The SP network device can receive traffic data from a UE through or via the security pass-through from a UE of a community Wi-Fi network at a home, residence, or entity network.