WLAN Terminal WPI Service Control for Resource Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security mechanisms for Wireless Local Area Networks (WLANs), such as WEP, consume excessive calculating resources for data security protection at the IP layer or above, which is inefficient and not suitable for applications with high real-time requirements.

Innovation Solution

A security service control method that stops the WPI service between a WLAN terminal and AP when initiating security services at the IP layer or above, allowing for resource savings by removing unnecessary encryption and decryption processes, and selectively reinstates the WPI service as needed based on application requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WPI service (data link layer encryption) is activated, then data security protection is improved, but calculating resources are excessively consumed

Engineering Contradiction:
Improvedata security protectionVSAvoidcalculating resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic control of WPI service activation and deactivation based on real-time security requirements. The control unit determines whether to activate WPI encryption based on the security needs of upper-layer applications, allowing the system to adapt between security and resource consumption states rather than maintaining fixed encryption always-on or always-off

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different security measures to different data traffic types. Instead of uniformly encrypting all data link layer packets, the system selectively activates WPI service only for specific applications or data streams that require enhanced security, while allowing other traffic to bypass encryption to conserve calculating resources

Inventive Principle:
Principle #3Local quality

2Reliability

If WPI service (data link layer encryption) is activated, then data security protection is improved, but application real-time performance deteriorates

Engineering Contradiction:
Improvedata security protectionVSAvoidapplication real-time performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts the security level based on application requirements. When real-time performance is critical, the control unit can deactivate WPI service to reduce processing overhead and improve response time. Conversely, when security is paramount, encryption is activated. This dynamic adaptation resolves the contradiction between security and real-time performance

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Instead of applying full encryption to all data traffic, the patent implements partial encryption only for specific applications or data streams that require it. This selective approach reduces the overall computational burden on the system while still providing security where needed, thereby maintaining better real-time performance for non-critical applications

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8724816B2Security service control method and wireless local area network terminal
Publication Date: 2014.05.13 ZTE CORP
  • US8724816B2 patent drawing
  • US8724816B2 patent drawing
  • US8724816B2 patent drawing

AI summary

A security service control method and a WLAN terminal are provided, and the method includes: stopping a WPI service between a WLAN terminal and an AP when the WLAN terminal creates a security service of an IP layer and/or a layer above the IP layer, wherein the WPI service comprises: encrypting a data link layer message to be transmitted, and decrypting a received data link layer message. After the WPI service is stopped, when the WLAN terminal cancels the security service of the IP layer and/or the layer above the IP layer, the WLAN terminal completes processes of removing association, association, user authentication and key negotiation in turn with the WLAN AP, and uses a session key obtained through the key negotiation to recover the WPI service. The calculating resources can be saved by using the present invention.