Wireless Terminal Authorization via Multi-Layer Data Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems struggle to accurately detect unauthorized wireless connections, particularly when MAC addresses are spoofed, as they rely on variable values like sequence numbers and received radio wave strength, which can lead to erroneous evaluations.
Innovation Solution
A wireless communication apparatus that acquires and stores information about authorized terminals, including fixed and individual identifier information, to evaluate the authenticity of connected terminals based on the degree of matching between acquired and stored data, even when MAC addresses are spoofed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If variable values like sequence numbers or received radio wave strength are used as evaluation criteria, then the evaluation process is simple, but the detection accuracy of unauthorized terminals deteriorates due to erroneous evaluations
Solution Approach 1:
The patent segments the evaluation process into multiple independent checks: comparing individual identifiers (MAC addresses), comparing fixed information (device type, manufacturer, model), and comparing variable information (sequence numbers, radio wave strength). This segmentation allows the system to use multiple criteria rather than relying on a single variable value, thereby improving detection accuracy while maintaining manageable complexity through structured evaluation.
2Reliability
If MAC address filtering is implemented to allow connections only to authorized terminals, then connection security is improved, but the system becomes vulnerable to spoofing attacks where unauthorized terminals use stolen MAC addresses
Solution Approach 1:
The patent applies preliminary action by storing multiple authorization criteria (individual identifier, fixed information, and variable information characteristics) in advance before actual connection evaluation occurs. When a connection request is received, the system compares the terminal's information against all stored criteria simultaneously. This preliminary preparation of multiple verification points ensures that even if one criterion (like MAC address) is spoofed, other criteria (like fixed device information) can still identify the unauthorized terminal.
3Device complexity
If only individual identifier information is stored and compared, then the storage and evaluation process is simple, but the system cannot detect spoofed MAC addresses of unauthorized terminals
Solution Approach 1:
The patent implements a nested structure where multiple layers of information are stored and compared: the outer layer contains individual identifiers (MAC addresses), the middle layer contains fixed information (device type, manufacturer, model that remain constant for a terminal), and the inner layer contains variable information characteristics. This nested approach allows the system to maintain simplicity at each individual level while achieving high reliability through the combination of all layers, effectively detecting spoofed identifiers by verifying them against the nested information structure.
Data Source
AI summary
A wireless communication apparatus (1) includes an information acquisition unit (10) for acquiring information about a wireless terminal when the wireless terminal is wirelessly connected to the wireless communication apparatus, a storage unit (11) for storing the information about an authorized terminal acquired by the information acquisition unit (10) in association with an individual identifier of the authorized wireless terminal, and an evaluation unit (12) for evaluating as to whether or not the wireless terminal wirelessly connected to the wireless communication apparatus is an authorized wireless terminal. The information includes at least fixed information other than the individual identifier. The evaluation unit (12) makes the evaluation based on a degree of matching between the information about the wireless terminal to be evaluated acquired by the information acquisition unit (10) and the information stored in the storage unit (11).


