WPA2 Pass-Through Fragmentation for Packet Frame Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In WiFi Protected Access 2 (WPA2) pass-through from a service provider network to a client device, packet frame lengths can exceed the maximum transmission unit size due to tunneling and vAP protocol overheads, leading to potential frame drops and security vulnerabilities, especially when data traffic is tunneled through residential gateways with range extenders, which can compromise data integrity and security.
Innovation Solution
Implementing fragmentation and defragmentation components at the Customer Premise Equipment (CPE) to manage packet frames, ensuring they do not exceed the maximum transmission unit size, and using WPA2 pass-through to establish a secure, end-to-end interface between the service provider network and the client device without modifying or decrypting data traffic at the CPE, thereby maintaining security and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If tunneling and vAP protocol overheads are applied to packet frames, then secure data transmission is enabled, but packet frame lengths exceed maximum transmission unit size causing frame drops
Solution Approach 1:
The patent applies segmentation by dividing large packet frames into smaller fragments that can fit within the maximum transmission unit size. The fragmentation component breaks down oversized frames while the defragmentation component reassembles them at the destination, resolving the contradiction between maintaining secure tunneling overheads and avoiding frame drops due to excessive length.
2Reliability
If WPA2 pass-through is used to establish secure interface, then data integrity is maintained, but packet frames may still exceed MTU size leading to transmission failures
Solution Approach 1:
The patent implements preliminary action by performing fragmentation at the source end before transmission occurs. The fragmentation component proactively breaks down frames that would exceed MTU size, preventing transmission failures before they happen. This ensures both data integrity through WPA2 pass-through and successful transmission by avoiding MTU violations.
3Adaptability or versatility
If data traffic is tunneled through residential gateways with range extenders, then network coverage is extended, but data integrity and security are compromised
Solution Approach 1:
The patent uses fragmentation and defragmentation components as intermediaries that operate transparently across the network path. These components mediate between the need for extended network coverage through range extenders and the requirement for data integrity, ensuring that packet frames are properly sized for transmission while maintaining WPA2 encryption and data integrity throughout the extended network path.
Data Source
AI summary
A service provider (SP) network device or system can enable a WiFi protected access 2 (WPA2) pass-through with a user equipment (UE) and define various partitions between a physical access point (pAP) and a virtual AP (vAP) based on virtual network function(s) (VNFs). The WPA2 pass-through can be an interface connection that passes through a computer premise equipment (CPE) or wireless residential gateway (GW) without modifying the data traffic and also enable different packet sizes, even if the vAP or data VNF at the SP network device is not configured to process the size, by fragmenting and defragmenting at least one of: a packet frame from the UE to the vAP, or from the vAP to the UE based on fragmentation criteria.


