Wireless Access Point Dynamic Access Rule Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In public wireless environments, managing access between devices securely is challenging due to security risks from random clients connecting to the same network, making it difficult to allow communication while preventing hacking and ensuring efficient access control.

Innovation Solution

Implementing a system where a wireless access point requests and applies access rules from a remote server to control IP and MAC address access, allowing or denying network packets based on dynamically updated rules, and enabling automatic device discovery while filtering communication to ensure secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If clients are allowed to communicate freely over a LAN in public wireless environments, then network accessibility and device discovery are improved, but security risks increase due to potential hacking and unauthorized access

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an access point as an intermediary device that mediates all communication between wireless clients. The access point intercepts, inspects, and controls network packets, allowing it to enforce access policies and prevent direct peer-to-peer communication that would expose clients to security risks while maintaining the ability to allow legitimate communication through the intermediary

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If access control restrictions are implemented to prevent hacking, then security is improved, but network flexibility and ease of reconfiguration deteriorate due to manual configuration requirements

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where the access point can modify access policies in real-time based on current network conditions, client identities, and security requirements. The system transitions from static manual configuration to dynamic automated policy enforcement, allowing the network to adapt flexibly to changing circumstances while maintaining security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The access point monitors network traffic and client behavior, using this feedback to automatically adjust access control decisions. The system continuously evaluates packet content, client credentials, and network state to dynamically enforce appropriate access policies without requiring manual reconfiguration

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If manual reconfiguration is used to enable client communication, then access control precision is improved, but operational complexity and difficulty of implementation increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidoperational complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The access point performs self-service by automatically authenticating clients, inspecting packets, and enforcing access policies without requiring manual administrator intervention. The system autonomously manages access control precision through automated credential verification, packet filtering, and policy enforcement mechanisms

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11218488B2Access enforcement at a wireless access point
Publication Date: 2022.01.04 JUNIPER NETWORKS INC
  • US11218488B2 patent drawing
  • US11218488B2 patent drawing
  • US11218488B2 patent drawing

AI summary

A first set of access rules is received from an access configuration service. The first set of access rules specifies addresses of devices authorized for a first user. A second set of access rules is received from the access configuration service. The second set of the access rules specifies addresses of devices authorized for a second user. At a wireless access point, a network packet associated with the first user is received. The first set of access rules is applied to filter the network packet.