Wireless LAN Controller Detecting Unauthorized Access Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems for wireless communication face challenges in preventing illegal access points from connecting to the network, as existing methods like WEP and MAC Address Filtering are inadequate, and bidirectional authentication requires additional infrastructure and is labor-intensive.

Innovation Solution

A network security system that includes a client and a controller, where the client scans electromagnetic waves to detect access points and dispatches identification information to the controller, which compares this information with a permission list to identify and locate non-registered access points, enhancing network security by detecting and estimating the installation areas of unauthorized access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WEP encryption is used to prevent illegal connections, then data security is improved, but the system becomes vulnerable if the key is illegally obtained

Engineering Contradiction:
Improvedata securityVSAvoidvulnerability to key theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic key generation through 802.1x authentication, where WEP keys are regenerated for each session between client and access point. This dynamic approach ensures that even if one key is compromised, it cannot be used for subsequent sessions, thereby resolving the vulnerability to key theft while maintaining data security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary authentication through 802.1x handshake before establishing WEP key protection. This preliminary action of authenticating users and generating session-specific keys prevents illegal connections before they can exploit static key vulnerabilities

Inventive Principle:
Principle #10Preliminary action

2Reliability

If MAC Address Filtering is used to inhibit unauthorized accesses, then network access control is improved, but MAC addresses can be forged relatively easily

Engineering Contradiction:
Improvenetwork access controlVSAvoidMAC address forgery
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces static MAC address filtering with dynamic 802.1x authentication that verifies user identity and device authorization through cryptographic handshakes. This dynamic authentication mechanism cannot be easily forged like static MAC addresses, thereby improving network access control reliability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system introduces an authentication server as an intermediary that mediates between clients and access points. This intermediary verifies credentials and manages authorization, preventing direct MAC address forgery attacks by adding a layer of cryptographic verification

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If bidirectional authentication is implemented between computer and access point, then security is improved, but additional authentication servers and extensive setup time are required

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing 802.1x authentication infrastructure already deployed in enterprise networks, making the security solution universally applicable without requiring additional specialized authentication servers. The existing RADIUS servers and authentication mechanisms are utilized for their multi-functionality

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables automatic authentication and key generation through 802.1x protocols, where clients and access points self-configure security parameters without manual intervention. This self-service capability reduces setup time and complexity while maintaining bidirectional authentication security

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If access points are illegally installed on the network, then network coverage is improved, but data can be illegally obtained and users can be taken over

Engineering Contradiction:
Improvenetwork coverageVSAvoidillegal data access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements monitoring mechanisms that detect unauthorized access points by analyzing authentication requests and network traffic patterns. When an illegal access point is detected, the system provides feedback to administrators and can automatically isolate the threat, preventing illegal data access while allowing legitimate network coverage expansion

Inventive Principle:
Principle #23Feedback

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This system effectively enhances network security by accurately detecting and locating unauthorized access points, improving the prevention of illegal connections and reducing the need for extensive authentication setups.

Implementation Method 1

the client scans electromagnetic waves within frequency bands permitted to be used for wireless communication, and dispatches to the controller identification information on access points detected as a result of the scan

Methodology Applied
Scientific EffectElectromagnetic wave scanning: Electromagnetic Induction

Data Source

PatentUS7639640B2Network security system, computer, access point recognizing method, access point checking method, program, storage medium, and wireless LAN device
Publication Date: 2009.12.29 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US7639640B2 patent drawing
  • US7639640B2 patent drawing
  • US7639640B2 patent drawing

AI summary

In a network security system, clients search for neighbor access points (APs) in order to establish wireless connections to a LAN. As a result of the search, each of the clients dispatches a list of access points obtained to a controller. The controller detects non-registered access points by comparing a list of previously registered access points with the lists dispatched by the clients.