WLAN Access Point Security Alerts via Signal Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless Local Area Networks (WLANs) face security vulnerabilities due to complex user setup processes and the use of standard/printed PINs, making them prone to security attacks, as intruders can exploit known passwords and interfere with configuration processes.

Innovation Solution

A WLAN access point and end-point devices equipped with a transceiver, controller, and security unit that measure characteristics of connection request messages and interfering signals, generating security alerts to inhibit unauthorized access by measuring time correlations and signal magnitudes, and communicating alerts through visual, audible notifications or network management centers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If push button configuration or PIN configuration is used to simplify user setup, then ease of operation is improved, but security is worsened due to use of standard/printed PINs that make devices prone to security attacks

Engineering Contradiction:
Improveuser setup processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security checks by measuring characteristics of connection request messages and interfering signals before completing the configuration process. The security unit measures time correlations and signal magnitudes in advance to detect potential attacks, allowing the system to prevent unauthorized access before it can compromise the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security unit continuously monitors connection requests and interfering signals, providing feedback about security conditions. When suspicious activity is detected (such as unusually quick response times or high signal magnitudes), the system generates security alerts and can inhibit the configuration process, creating a feedback loop that maintains security while allowing legitimate operations.

Inventive Principle:
Principle #23Feedback

2Device complexity

If users select simple keys to reduce configuration complexity, then ease of operation is improved, but security is worsened making devices more prone to security attacks

Engineering Contradiction:
Improveconfiguration complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The security unit acts as an intermediary between the configuration process and potential attacks. It measures characteristics of connection requests and interfering signals, using time correlation and signal magnitude analysis to distinguish between legitimate simple configuration operations and malicious attacks, thereby protecting the system even when simple keys are used.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system measures characteristics of connection requests and interfering signals to detect attacks, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security unit performs self-service by autonomously measuring characteristics of connection requests and interfering signals, calculating time correlations, and generating security alerts without requiring external intervention. The system monitors itself and automatically responds to detected threats, reducing the need for complex external security infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7929513B2Wireless local area network access points, end-point communication devices, and computer program products that generate security alerts based on characteristics of interfering signals and/or connection messages
Publication Date: 2011.04.19 BELLSOUTH INTELLECTUAL PROPERTY CORPORATION(US)
  • US7929513B2 patent drawing
  • US7929513B2 patent drawing
  • US7929513B2 patent drawing

AI summary

A wireless local area network access point (WAP) includes a transceiver, a controller, and a security unit. The transceiver communicates messages with an end-point communication device through a wireless air interface in a defined frequency band. The controller receives through the transceiver a connection request message containing a password from the end-point communication device, authenticates the received password, and responds to the authentication by transmitting through the transceiver to the end-point communication device an encryption key as a connection response message. The security unit generates a security alert based on measured characteristics of one or more received connection request messages and/or based on measured characteristics of interfering signals in the defined frequency band.