Wireless Intrusion Prevention via Intermediary Security Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network security systems are often too complex and expensive for many providers to implement effectively, as they require additional sensors to monitor and prevent attacks, leaving them vulnerable to intrusions and data theft.

Innovation Solution

An intrusion detection and prevention system that sits between the receiver and the MAC element of a wireless network device, analyzing traffic for compliance with rules and preventing unauthorized or malicious traffic from reaching the MAC element, thereby enhancing security without the need for additional sensors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional sensors are deployed to monitor wireless traffic for attacks, then detection capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security element as an intermediary component positioned between the receiver and MAC element. This security element acts as a mediator that inspects wireless traffic and enforces security policies without requiring additional external sensors, thereby improving detection capability while avoiding increased system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security element performs multiple functions including traffic inspection, policy enforcement, and attack prevention within a single integrated component. This multi-functional approach consolidates what would otherwise require multiple separate sensors and systems, improving detection capability without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If additional sensors are deployed to monitor wireless traffic for attacks, then detection capability is improved, but implementation cost increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security element serves as a cost-effective intermediary that provides comprehensive security functionality without requiring expensive additional hardware sensors. By reusing existing receiver and MAC element infrastructure and adding only the security element, the solution improves detection capability while controlling implementation costs

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security element performs self-contained security functions including traffic analysis, policy evaluation, and attack prevention without requiring external sensor infrastructure. This self-service capability eliminates the need for costly additional sensors while maintaining high detection capability

Inventive Principle:
Principle #25Self-service

3Reliability

If security sensors are added to the network, then attack detection is improved, but system complexity increases

Engineering Contradiction:
Improveattack detectionVSAvoidoverlay network complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security element acts as an intermediary embedded within the existing device architecture rather than requiring a separate overlay network. This approach improves attack detection while avoiding the complexity of managing additional network layers and coordinating multiple sensors

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security element merges security functionality with the existing receiver and MAC element infrastructure. By combining these functions within the same device rather than adding separate sensors and overlay networks, the solution improves attack detection without increasing overall system complexity

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10171421B2Intrusion prevention and detection in a wireless network
Publication Date: 2019.01.01 WIFI SECURITIES LTD
  • US10171421B2 patent drawing
  • US10171421B2 patent drawing
  • US10171421B2 patent drawing

AI summary

The invention provides an intrusion detection and prevention system and computer program which, when operated or executed by a security element (7) situated between a receiver (3) and a media access control (MAC) element (5) of a device (1) of a wireless network, performs the steps of receiving wireless traffic from the receiver of the device, and detecting that MAC element the traffic is allowed according to one or more rules and passing the traffic to the MAC element of the device, or detecting that the traffic is not allowed according to the one or more rules and preventing the traffic from passing to the MAC element of the device.