WPA2 Pass-Through Virtualization for Community Wi-Fi Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Community Wi-Fi networks face vulnerabilities in data security, particularly when using WPA2 pass-through, as residential gateways can decrypt and modify data traffic, allowing potential spoofing and tampering, especially with range extenders connected via Ethernet, compromising the security of guest subscribers.
Innovation Solution
Implementing a WPA2 pass-through interface that enables secure, end-to-end encryption from the service provider network to user equipment (UE) without modification by the residential gateway, using virtualization techniques to manage and secure data traffic, ensuring it remains unaltered and encrypted throughout the process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If WPA2 pass-through is used to enable community Wi-Fi access, then internet access for guests is provided, but data security is compromised because the residential gateway can decrypt and modify traffic
Solution Approach 1:
The patent extracts the WPA2 encryption function from the residential gateway and relocates it to the service provider network. By removing this critical security function from the untrusted gateway environment, the system eliminates the ability of the gateway to decrypt and modify traffic while still enabling guest access through the community Wi-Fi network
Solution Approach 2:
The patent introduces a virtual access point (vAP) as an intermediary between the guest device and the residential gateway. The vAP, controlled by the service provider, establishes a secure WPA2 connection with the guest device and tunnels traffic through the gateway without allowing decryption or modification, thus mediating between the need for gateway passage and the need for security
2Reliability
If the residential gateway processes WPA2 encryption, then data traffic can be encrypted, but the gateway can also decrypt and modify the traffic
Solution Approach 1:
The patent extracts the WPA2 encryption and decryption functions from the residential gateway and implements them in the service provider network instead. This extraction removes the gateway's ability to process encryption, thereby eliminating both the encryption capability and the harmful decryption/modification capability in one action
Solution Approach 2:
The patent creates a virtual copy of the access point functionality (vAP) that replicates the WPA2 security functions without relying on the residential gateway. This virtual copy performs encryption and decryption in the service provider network, providing security without giving the gateway any processing capability over the traffic
3Area of stationary object
If range extenders are connected via Ethernet to the residential gateway, then network coverage is extended, but security vulnerabilities increase due to potential spoofing and tampering
Solution Approach 1:
The patent extracts the security-critical WPA2 processing functions from the residential gateway (where range extenders connect) and relocates them to the service provider network. This extraction removes the gateway's ability to process encryption, thereby eliminating the security vulnerabilities that arise from gateway-based processing while range extenders maintain their network coverage function
Solution Approach 2:
The patent introduces the virtual access point (vAP) as an intermediary that establishes secure WPA2 connections directly with client devices, including those connected through range extenders. This intermediary approach ensures that traffic is encrypted end-to-end through the service provider network, preventing spoofing and tampering at the gateway level while maintaining extended network coverage
Data Source
AI summary
A service provider (SP) network device or system can operate to enable a WiFi protected access 2 (WPA2) pass-through with a user equipment (UE) and further define various partitions between a physical access point (pAP) and a virtual AP (vAP) according to one or more virtual network functions (VNFs). The WPA2 pass-through can be an interface connection that passes through a computer premise equipment (CPE) or wireless residential gateway (GW) without the CPE or GW modifying or affecting the data traffic. One such partition, can include security functions, including authentication and authorization being initially at the CPE, while other network functions of the community WiFi network are virtualized and moved to the SP network. The SP network device can receive traffic data from a UE through or via the WPA 2 pass-through from a UE of a community Wi-Fi network at a home, residence, or entity network.


