WPA2 Pass-Through Fragmentation for Packet Frame Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In WiFi Protected Access 2 (WPA2) pass-through from a service provider network to a client device, packet frame lengths can exceed the maximum transmission unit size due to tunneling and vAP protocol overheads, leading to potential frame drops and security vulnerabilities, especially when data traffic is tunneled through residential gateways with range extenders, which can compromise data integrity and security.

Innovation Solution

Implementing fragmentation and defragmentation components at the Customer Premise Equipment (CPE) to manage packet frames, ensuring they do not exceed the maximum transmission unit size, and using WPA2 pass-through to establish a secure, end-to-end interface between the service provider network and the client device without modifying or decrypting data traffic at the CPE, thereby maintaining security and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tunneling and vAP protocol overheads are applied to packet frames, then secure data transmission is enabled, but packet frame lengths exceed maximum transmission unit size causing frame drops

Engineering Contradiction:
Improvesecure data transmissionVSAvoidpacket frame length
Core Design Contradiction:
ReliabilityVSLength of moving object

Solution Approach 1:

The patent applies segmentation by dividing large packet frames into smaller fragments that can fit within the maximum transmission unit size. The fragmentation component breaks down oversized frames while the defragmentation component reassembles them at the destination, resolving the contradiction between maintaining secure tunneling overheads and avoiding frame drops due to excessive length.

Inventive Principle:
Principle #1Segmentation

2Reliability

If WPA2 pass-through is used to establish secure interface, then data integrity is maintained, but packet frames may still exceed MTU size leading to transmission failures

Engineering Contradiction:
Improvedata integrityVSAvoiddata transmission success rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by performing fragmentation at the source end before transmission occurs. The fragmentation component proactively breaks down frames that would exceed MTU size, preventing transmission failures before they happen. This ensures both data integrity through WPA2 pass-through and successful transmission by avoiding MTU violations.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If data traffic is tunneled through residential gateways with range extenders, then network coverage is extended, but data integrity and security are compromised

Engineering Contradiction:
Improvenetwork coverageVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses fragmentation and defragmentation components as intermediaries that operate transparently across the network path. These components mediate between the need for extended network coverage through range extenders and the requirement for data integrity, ensuring that packet frames are properly sized for transmission while maintaining WPA2 encryption and data integrity throughout the extended network path.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10785683B2Native fragmentation in WiFi protected access 2 (WPA2) pass-through virtualization protocol
Publication Date: 2020.09.22 MAXLINEAR INC
  • US10785683B2 patent drawing
  • US10785683B2 patent drawing
  • US10785683B2 patent drawing

AI summary

A service provider (SP) network device or system can enable a WiFi protected access 2 (WPA2) pass-through with a user equipment (UE) and define various partitions between a physical access point (pAP) and a virtual AP (vAP) based on virtual network function(s) (VNFs). The WPA2 pass-through can be an interface connection that passes through a computer premise equipment (CPE) or wireless residential gateway (GW) without modifying the data traffic and also enable different packet sizes, even if the vAP or data VNF at the SP network device is not configured to process the size, by fragmenting and defragmenting at least one of: a packet frame from the UE to the vAP, or from the vAP to the UE based on fragmentation criteria.