Wireless Quarantine via SSID Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional quarantine network systems fail to effectively quarantine terminals infected with computer viruses and those with low security levels within a wireless LAN environment, allowing potential virus transmission between such terminals.

Innovation Solution

A quarantine network system comprising a first and second wireless LAN access point, along with a server apparatus that switches terminals between these access points based on security status, restricting the number of connectable terminals and preventing communication between infected and low-security terminals by changing the SSID, thereby isolating them.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a VLAN is allocated to every terminal and a layer-2 intelligent switch is used to quarantine terminals, then terminals can be quarantined individually, but this method only works in cable-LAN environments and cannot be applied to wireless LAN environments

Engineering Contradiction:
Improvequarantine capabilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a wireless LAN access point as an intermediary device between terminals and the network. The access point receives quarantine instructions from the server and controls terminal access to the network by switching SSIDs, enabling individual terminal quarantine in wireless environments without requiring complex infrastructure changes at the terminal level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical VLAN configuration approach (requiring cable-LAN and layer-2 switches) with a wireless-based control mechanism. By using wireless LAN access points and SSID switching, the system achieves similar quarantine functionality without the physical infrastructure constraints of traditional VLAN-based approaches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If multiple terminals are allowed to connect to the quarantine network simultaneously, then network resources are efficiently utilized, but infected terminals can communicate with low-security terminals causing cross-infection

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidcross-infection risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic control of terminal access to the quarantine network. The server issues time-dependent or condition-dependent quarantine instructions to the access point, allowing the access point to dynamically switch SSIDs and control which terminals can connect to the quarantine network at any given time, preventing cross-infection while maintaining resource utilization.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where the server monitors terminal security states and sends quarantine instructions to the access point accordingly. The access point executes these instructions and can report back on connection status, enabling the server to adjust quarantine measures based on real-time network conditions and terminal security states.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8984634B2Quarantine network system, server apparatus, and program
Publication Date: 2015.03.17 NEC CORP
  • US8984634B2 patent drawing
  • US8984634B2 patent drawing
  • US8984634B2 patent drawing

AI summary

A quarantine network system 100 quarantines terminals 30 and 31 connected to a network via a wireless communication. The quarantine network system 100 is provided with an access point 20 for a business NW used for connection to a business network, an access point 21 for a quarantine NW which is used for connection to a network for quarantining and restricts the number of terminals connectable thereto, and an NW switching performance server 10 transmitting to the terminal a command which makes the terminal switch SSID of an access point which the terminal uses for wireless communication, in accordance with the situation.