WiFi Router Temporary Virtual Access Points for Device Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Many WiFi routers are insecure due to unchanging default passwords, lack of device isolation, and infrequent password changes on guest networks, leading to potential virus transmission among connected devices.
Innovation Solution
Implementing a system that creates temporary and permanent virtual access points based on user authentication, allowing devices to connect securely, with temporary access points expiring after a set period and restricting communication to isolate devices from others.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single shared WiFi network is used to connect multiple devices, then network coverage and accessibility are improved, but security and device isolation deteriorate
Solution Approach 1:
The patent divides a single WiFi network into multiple virtual access points (VAPs), each serving as an isolated network segment. Devices are assigned to specific VAPs based on authentication credentials, creating logical segmentation that maintains network accessibility while preventing cross-device communication and virus transmission between segments.
Solution Approach 2:
The patent introduces virtual access points as intermediary layers between devices and the core network infrastructure. These VAPs act as mediators that control and restrict device-to-device communication, allowing devices to access network resources while blocking direct peer-to-peer connections that could transmit viruses.
2Ease of operation
If default passwords are used for WiFi routers, then ease of setup is improved, but security deteriorates
Solution Approach 1:
The patent implements preliminary security measures by requiring authentication credentials during the initial device connection process, even before full network access is granted. The system pre-establishes security policies and credential verification mechanisms that prevent unauthorized access from the outset, rather than relying solely on default router passwords.
Solution Approach 2:
The patent enables devices to self-authenticate and self-assign to appropriate virtual access points by presenting credentials during connection. The system automatically verifies credentials and places devices in appropriate network segments without requiring manual configuration or changing of router passwords, maintaining ease of use while improving security.
3Ease of operation
If guest networks use static passwords, then ease of connection is improved, but security deteriorates due to infrequent password changes
Solution Approach 1:
The patent transforms static guest network passwords into dynamic, temporary credentials that are automatically generated and assigned. Each device receives a unique, time-limited credential that expires after a predetermined period or after use, eliminating the need for manual password changes while maintaining connection simplicity for users.
Solution Approach 2:
The patent implements disposable, single-use or time-limited authentication credentials for guest devices. These temporary credentials are inexpensive to generate and automatically expire after use or a set time period, providing strong security without requiring users to remember or manually change passwords.
4Reliability
If all devices are isolated in separate virtual access points, then security is improved, but network functionality and device communication deteriorate
Solution Approach 1:
The patent creates a multi-functional virtual access point system where each VAP can independently serve different purposes (guest access, device isolation, secure communication zones) while the overall system provides universal network access. The gateway device coordinates between multiple VAPs to enable necessary communication while maintaining isolation where required.
Solution Approach 2:
The patent implements asymmetric network architecture where communication permissions are not uniformly applied but are instead tailored to each VAP and device pair. The system allows asymmetric communication patterns - some devices can communicate freely within their VAP, while cross-VAP communication is restricted or requires special authorization, enabling both isolation and functionality.
Data Source
AI summary
Mechanisms (which can include systems, methods, and media) for securing WiFi routers and devices connected to them are provided. In some embodiments, mechanisms for securing a WiFi router comprise: receiving a first request to form a first connection between a first device and the WiFi router; determining whether a first portal can be presented in connection with the first device; and in response to determining that the first portal cannot be presented in connection with the first device: creating a first temporary virtual access point using the WiFi router; and connecting the first device to the WiFi router using the first temporary virtual access point.


