VoWiFi Security Protection via MAC Verification and Packet Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VoWiFi technologies lack effective security measures to prevent network attacks such as ARP attacks and cannot ensure secure communication environments, especially in areas with unstable network coverage.

Innovation Solution

A wireless network-based voice communication security protection method that allows users to choose between a user-side self-check interface and a telecommunications provider-side detection interface to assess network security, using MAC address verification and packet monitoring to detect potential threats and automatically switch connections or change packet sizes to prevent attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VoWiFi is used for network calls, then communication convenience is improved, but network security is worsened due to lack of detection mechanisms

Engineering Contradiction:
Improvecommunication convenienceVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security detection before allowing VoWiFi calls to proceed. The detection interface checks network security status in advance, and only allows calls to proceed if the network is deemed safe, preventing potential security breaches before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback mechanism where the detection interface continuously monitors network security status and provides feedback to the call processing system. This feedback loop enables real-time security assessment and dynamic decision-making about whether to allow VoWiFi calls.

Inventive Principle:
Principle #23Feedback

2Device complexity

If no security detection is implemented, then device complexity is reduced, but vulnerability to ARP attacks increases

Engineering Contradiction:
Improvesystem simplicityVSAvoidARP attack vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The detection interface acts as an intermediary component between the network and the call processing system. It sits in the communication path, performing security checks and filtering out malicious packets like ARP attacks, while maintaining a relatively simple overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If MAC address verification is performed, then network security is improved, but packet processing time increases

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs MAC address verification selectively rather than on every single packet. The detection interface verifies security status at key decision points (before allowing VoWiFi calls, when detecting anomalies), rather than continuously validating every packet, thus balancing security with processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11388134B2Wireless network-based voice communication security protection method
Publication Date: 2022.07.12 NAT CHENG KUNG UNIV
  • US11388134B2 patent drawing
  • US11388134B2 patent drawing

AI summary

A wireless network-based voice communication security protection method, which enables VoWiFi (Voice over Wi-Fi) to verify and prevent potential risks in communication, and secures the environment of network communications that can be verified by a user device. A real-time user interface indicates security and quality of the current network call and provides advice on when to cancel a call. A telecommunications provider side interface checks if the user's network communication environment is safe, and provides real-time recommendations to the user regarding the security status of the call. The user device side self-check interface and the telecommunications provider side detection interface simultaneously detect whether or not the user's network communication environment is secure.