Wireless Connection Request Blocking via Device Name and Intrinsic Info Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems like Wi-Fi Direct, unauthorized users can spoof authorized users by matching their identification information, leading to potential security risks and unauthorized connections, as existing authentication methods do not adequately differentiate between legitimate and spoofed devices.

Innovation Solution

An information processing apparatus with a receiving unit for wireless connection requests, a connecting unit for establishing connections, and determining units to verify the consistency of device names and intrinsic information, where if the names match but intrinsic information does not, the connection is rejected, preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless connection authentication is simplified to allow easy connection, then ease of operation is improved, but security is worsened allowing unauthorized spoofing connections

Engineering Contradiction:
Improveease of connectionVSAvoidconnection security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification by comparing device names and apparatus intrinsic information (such as MAC addresses) before establishing a wireless connection. This preliminary action identifies potential spoofing attempts by detecting inconsistencies between the displayed device name and the actual device identifier, preventing unauthorized connections before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary verification mechanism that acts as a mediator between the connection request and the connection establishment. This intermediary layer compares multiple identification parameters (device name and intrinsic information) to validate the authenticity of the connecting device, adding a security checkpoint without requiring complex user authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If device identification is based on single parameter matching, then ease of operation is improved, but measurement precision is worsened causing inability to distinguish spoofed devices

Engineering Contradiction:
Improveauthentication simplicityVSAvoiddevice identification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The device identification process is segmented into multiple independent verification steps: first comparing the device name parameter, then comparing the apparatus intrinsic information parameter. This segmentation allows the system to evaluate each parameter separately and combine the results, achieving high identification accuracy while maintaining operational simplicity through automated multi-parameter comparison

Inventive Principle:
Principle #1Segmentation

3Reliability

If multi-parameter verification is implemented to prevent spoofing, then connection security is improved, but device complexity is worsened

Engineering Contradiction:
Improveconnection securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service verification by automatically comparing the device name and apparatus intrinsic information without requiring user intervention. The information processing apparatus autonomously executes the multi-parameter comparison, identifies mismatches indicating spoofing attempts, and rejects unauthorized connections, thereby achieving enhanced security without increasing operational complexity for the user

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11340849B2Information processing apparatus, information processing method, and storage medium, that include a wireless connection request blocking feature
Publication Date: 2022.05.24 CANON KK
  • US11340849B2 patent drawing
  • US11340849B2 patent drawing
  • US11340849B2 patent drawing

AI summary

When establishing a connection with an external apparatus for wireless communication, an information processing apparatus suppresses the connection establishment based on an unauthorized connection request, by determining whether or not information showing a name of the external apparatus included in each of a plurality of received wireless connection requests in a state capable of accepting the wireless connection request is the same, determining whether or not apparatus intrinsic information included in each of the plurality of received wireless connection requests in the state capable of accepting the wireless connection request is the same, and shifting, in a case where it is determined that the information showing the name of the external apparatus is the same and it is determined that the apparatus intrinsic information is not the same, the information processing apparatus to a state incapable of accepting the wireless connection request.