WiFi Router Temporary Virtual Access Points for Device Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Many WiFi routers are insecure due to unchanging default passwords, lack of device isolation, and infrequent password changes on guest networks, leading to potential virus transmission among connected devices.

Innovation Solution

Implementing a system that creates temporary and permanent virtual access points based on user authentication, allowing devices to connect securely, with temporary access points expiring after a set period and restricting communication to isolate devices from others.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single shared WiFi network is used to connect multiple devices, then network coverage and accessibility are improved, but security and device isolation deteriorate

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidvirus transmission risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides a single WiFi network into multiple virtual access points (VAPs), each serving as an isolated network segment. Devices are assigned to specific VAPs based on authentication credentials, creating logical segmentation that maintains network accessibility while preventing cross-device communication and virus transmission between segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual access points as intermediary layers between devices and the core network infrastructure. These VAPs act as mediators that control and restrict device-to-device communication, allowing devices to access network resources while blocking direct peer-to-peer connections that could transmit viruses.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If default passwords are used for WiFi routers, then ease of setup is improved, but security deteriorates

Engineering Contradiction:
Improverouter setup simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary security measures by requiring authentication credentials during the initial device connection process, even before full network access is granted. The system pre-establishes security policies and credential verification mechanisms that prevent unauthorized access from the outset, rather than relying solely on default router passwords.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables devices to self-authenticate and self-assign to appropriate virtual access points by presenting credentials during connection. The system automatically verifies credentials and places devices in appropriate network segments without requiring manual configuration or changing of router passwords, maintaining ease of use while improving security.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If guest networks use static passwords, then ease of connection is improved, but security deteriorates due to infrequent password changes

Engineering Contradiction:
Improveconnection simplicityVSAvoidpassword security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static guest network passwords into dynamic, temporary credentials that are automatically generated and assigned. Each device receives a unique, time-limited credential that expires after a predetermined period or after use, eliminating the need for manual password changes while maintaining connection simplicity for users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements disposable, single-use or time-limited authentication credentials for guest devices. These temporary credentials are inexpensive to generate and automatically expire after use or a set time period, providing strong security without requiring users to remember or manually change passwords.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Reliability

If all devices are isolated in separate virtual access points, then security is improved, but network functionality and device communication deteriorate

Engineering Contradiction:
Improvedevice isolation securityVSAvoiddevice communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a multi-functional virtual access point system where each VAP can independently serve different purposes (guest access, device isolation, secure communication zones) while the overall system provides universal network access. The gateway device coordinates between multiple VAPs to enable necessary communication while maintaining isolation where required.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements asymmetric network architecture where communication permissions are not uniformly applied but are instead tailored to each VAP and device pair. The system allows asymmetric communication patterns - some devices can communicate freely within their VAP, while cross-VAP communication is restricted or requires special authorization, enabling both isolation and functionality.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS11937085B2Methods, systems, and media for creating temporary virtual access points using WiFi routers when portals cannot be presented
Publication Date: 2024.03.19 MCAFEE LLC
  • US11937085B2 patent drawing
  • US11937085B2 patent drawing
  • US11937085B2 patent drawing

AI summary

Mechanisms (which can include systems, methods, and media) for securing WiFi routers and devices connected to them are provided. In some embodiments, mechanisms for securing a WiFi router comprise: receiving a first request to form a first connection between a first device and the WiFi router; determining whether a first portal can be presented in connection with the first device; and in response to determining that the first portal cannot be presented in connection with the first device: creating a first temporary virtual access point using the WiFi router; and connecting the first device to the WiFi router using the first temporary virtual access point.