Wireless Access Point Virtual Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Home networks using shared key authentication mechanisms like WPA-PSK are vulnerable to attacks such as evil twin, KRACK, and Dragonblood, which compromise device and network security by allowing unauthorized access and data extraction.
Innovation Solution
A home gateway that provides unique credentials to each device based on its capabilities, dividing the wireless access point into multiple virtual networks with different security protocols (802.1X for secure devices and WPA-PSK for IoT devices) to enhance security and enforce device-specific policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If shared key authentication mechanisms (WPA-PSK) are used for wireless access, then ease of operation is improved, but security reliability deteriorates due to vulnerability to evil twin, KRACK, and Dragonblood attacks
Solution Approach 1:
The patent divides the wireless network into multiple virtual networks (VLANs), each with its own authentication mechanism. Secure devices use 802.1X authentication in one VLAN while IoT devices use WPA-PSK in another VLAN, segmenting the authentication methods to apply the right security level to the right device type without compromising overall network accessibility
Solution Approach 2:
Different authentication protocols are applied to different device categories within the network. The system identifies device types and applies localized authentication quality - strong 802.1X for secure devices and simpler WPA-PSK for IoT devices - optimizing both security and ease of operation for each device type
2Reliability
If multiple authentication protocols are implemented simultaneously, then security reliability is improved, but device complexity increases
Solution Approach 1:
The access point automatically identifies device types and selects appropriate authentication protocols without manual configuration. The system self-manages the complexity by detecting whether a device is secure or IoT-type and automatically applying the correct authentication method, eliminating the need for users to manually configure authentication settings
Solution Approach 2:
The wireless access point is designed to handle multiple authentication protocols (802.1X and WPA-PSK) simultaneously, making it universal enough to support both secure devices and IoT devices. This multi-functionality allows a single access point to serve diverse device types with different security requirements without requiring separate authentication systems
3Reliability
If unique credentials are provided to each device, then security reliability is improved, but ease of operation deteriorates due to increased authentication overhead
Solution Approach 1:
The system provides different credential management approaches for different device types. Secure devices receive unique credentials through 802.1X authentication, while IoT devices use shared credentials through WPA-PSK. This localized quality approach ensures security where needed while maintaining ease of operation for IoT devices that don't require individual credential management
Data Source
AI summary
There is disclosed computer-implemented system and method of providing a wireless access point (WAP), including dividing the WAP into at least two virtual networks, wherein a first virtual network is for devices that authenticate using a first authentication protocol and a second virtual network is for devices that authenticate using a second authentication protocol, wherein the second authentication protocol is more secure than the first authentication protocol; and onboarding devices to the WAP, and assigning the devices to the at least two virtual networks according to the authentication protocols they use to authenticate to the WAP.


