Wireless Access Point Virtual Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home networks using shared key authentication mechanisms like WPA-PSK are vulnerable to attacks such as evil twin, KRACK, and Dragonblood, which compromise device and network security by allowing unauthorized access and data extraction.

Innovation Solution

A home gateway that provides unique credentials to each device based on its capabilities, dividing the wireless access point into multiple virtual networks with different security protocols (802.1X for secure devices and WPA-PSK for IoT devices) to enhance security and enforce device-specific policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If shared key authentication mechanisms (WPA-PSK) are used for wireless access, then ease of operation is improved, but security reliability deteriorates due to vulnerability to evil twin, KRACK, and Dragonblood attacks

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the wireless network into multiple virtual networks (VLANs), each with its own authentication mechanism. Secure devices use 802.1X authentication in one VLAN while IoT devices use WPA-PSK in another VLAN, segmenting the authentication methods to apply the right security level to the right device type without compromising overall network accessibility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different authentication protocols are applied to different device categories within the network. The system identifies device types and applies localized authentication quality - strong 802.1X for secure devices and simpler WPA-PSK for IoT devices - optimizing both security and ease of operation for each device type

Inventive Principle:
Principle #3Local quality

2Reliability

If multiple authentication protocols are implemented simultaneously, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access point automatically identifies device types and selects appropriate authentication protocols without manual configuration. The system self-manages the complexity by detecting whether a device is secure or IoT-type and automatically applying the correct authentication method, eliminating the need for users to manually configure authentication settings

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The wireless access point is designed to handle multiple authentication protocols (802.1X and WPA-PSK) simultaneously, making it universal enough to support both secure devices and IoT devices. This multi-functionality allows a single access point to serve diverse device types with different security requirements without requiring separate authentication systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If unique credentials are provided to each device, then security reliability is improved, but ease of operation deteriorates due to increased authentication overhead

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system provides different credential management approaches for different device types. Secure devices receive unique credentials through 802.1X authentication, while IoT devices use shared credentials through WPA-PSK. This localized quality approach ensures security where needed while maintaining ease of operation for IoT devices that don't require individual credential management

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250048099A1Wireless access point with multiple security modes
Publication Date: 2025.02.06 MCAFEE LLC
  • US20250048099A1 patent drawing
  • US20250048099A1 patent drawing
  • US20250048099A1 patent drawing

AI summary

There is disclosed computer-implemented system and method of providing a wireless access point (WAP), including dividing the WAP into at least two virtual networks, wherein a first virtual network is for devices that authenticate using a first authentication protocol and a second virtual network is for devices that authenticate using a second authentication protocol, wherein the second authentication protocol is more secure than the first authentication protocol; and onboarding devices to the WAP, and assigning the devices to the at least two virtual networks according to the authentication protocols they use to authenticate to the WAP.