Wireless Terminal Security via External Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network systems for BYOD (Bring Your Own Device) environments face challenges in ensuring only secure terminals connect to the in-company network without increasing costs, as current solutions require complex VLAN divisions or risk fraudulent setups.

Innovation Solution

A wireless network system incorporating a terminal management device that communicates with wireless terminals via a different network to determine compliance with a security policy, preventing unauthorized connections and eliminating the need for a quarantine VLAN, thus reducing costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a quarantine VLAN is used to check security policy compliance, then security is improved, but system complexity and initial setup costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security policy determination function from the network infrastructure (VLAN system) and relocates it to a separate terminal management device. This allows security checking to occur outside the wireless network system, eliminating the need for quarantine VLANs while maintaining security compliance verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The terminal management device acts as an intermediary between the wireless terminal and the wireless relay device. It determines security policy compliance and provides connection information to authorized terminals, mediating the connection process without requiring complex network segmentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If terminal setup is not verified before connection, then connection speed is improved, but security is compromised due to fraudulent setups

Engineering Contradiction:
Improveconnection speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The terminal management device performs security policy determination and connection information provision in advance, before the terminal attempts to connect to the wireless relay device. This preliminary security check ensures compliance is verified upfront, allowing direct connection without subsequent quarantine processes.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If periodic quarantine processes are implemented, then security is improved, but energy consumption of terminals increases

Engineering Contradiction:
ImprovesecurityVSAvoidterminal energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Security policy determination is performed once in advance before connection, eliminating the need for periodic quarantine processes. The terminal connects directly after receiving connection information, avoiding repeated security checks that would consume additional energy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10575177B2Wireless network system, terminal management device, wireless relay device, and communications method
Publication Date: 2020.02.25 YAMAHA CORP
  • US10575177B2 patent drawing
  • US10575177B2 patent drawing
  • US10575177B2 patent drawing

AI summary

Provided is a technology for allowing only a wireless terminal satisfying a security policy to be connected to an in-company network without causing a significant increase in costs. The terminal management device including a determination part communicating with a wireless terminal via a different communication network from the wireless network system, and determining whether or not the wireless terminal satisfies a predetermined security policy, and a connection information transmission part transmitting connection information for connection to the wireless relay device to the wireless terminal which is determined to satisfy the security policy by the determination part is provided in a wireless network system that includes a wireless access point device constituting an in-company network and connecting a wireless terminal for which predetermined connection information has been set.