Wireless Discovery Cluster Verification Against Rogue Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems, such as Wi-Fi Aware, are vulnerable to malicious devices manipulating discovery protocols, leading to potential man-in-the-middle attacks and unauthorized connections.

Innovation Solution

A device equipped with a processor that detects and compares cluster identities and discovery window timings with other devices, executing a security process to ensure intended connections by aborting or warning against mismatched clusters and requiring additional security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a discovery protocol is used to enable automatic device discovery and connection setup, then ease of operation is improved, but security is worsened due to vulnerability to malicious device manipulation

Engineering Contradiction:
Improveautomatic device discoveryVSAvoidconnection security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification of device identity and cluster membership before establishing a connection. The verifying device checks whether the discovered device belongs to the same cluster and has valid timing parameters before proceeding with connection setup, preventing malicious devices from establishing unauthorized connections

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cluster identity and timing parameters as intermediary verification mechanisms. These parameters act as mediators that enable automatic discovery while ensuring security by verifying that both devices belong to the same legitimate cluster before allowing connection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cluster identity verification is implemented to prevent malicious connections, then security is improved, but device complexity increases due to additional verification steps

Engineering Contradiction:
Improveconnection securityVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cluster identity and timing parameters serve multiple functions simultaneously: they enable automatic device discovery, establish cluster membership verification, and provide timing synchronization. This multi-functionality reduces the need for separate verification mechanisms, thereby limiting the increase in device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If timing parameters are monitored to detect malicious devices, then measurement precision is improved, but use of energy increases due to continuous monitoring requirements

Engineering Contradiction:
Improvediscovery window timing detectionVSAvoidcontinuous monitoring
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

Instead of continuous monitoring, the system uses periodic timing parameters associated with discovery windows. The verifying device checks timing parameters at specific periodic intervals defined by the discovery window structure, achieving accurate detection of malicious devices while reducing energy consumption compared to continuous monitoring

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12513504B2Device for wireless communication with other devices
Publication Date: 2025.12.30 KONINKLIJKE PHILIPS NV
  • US12513504B2 patent drawing
  • US12513504B2 patent drawing
  • US12513504B2 patent drawing

AI summary

A device arranged for wireless communication according to a communication protocol has a processor to execute a connection sequence according to a discovery protocol. The connection sequence includes determining a current cluster identity and a current discovery window timing used by the device. Next, at least one other device within wireless range is detected, while further determining a detected cluster identity and a detected discovery window timing of the detected other device. Then it is detected whether the detected device is operating in a different cluster than the device by comparing the current cluster identity with the detected cluster identity or comparing the current discovery window timing with the detected discovery window timing. Finally, upon detecting said different cluster, a security process is executed, which may warn the user or abort the connection sequence. Thereby, a malicious device trying to manipulate the connection sequence is detected.