WPAN Firewall Access Control Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless Personal Area Networks (WPANs) lack robust security mechanisms to prevent unauthorized access and data transfer, leading to security shortcomings that deter entities from adopting these technologies.

Innovation Solution

Implementing firewall functionality in WPAN-capable devices to control access to resources through low-level access control measures, monitoring, and logging activities, with configuration options via user control interfaces or Application Programming Interfaces (APIs), to regulate both incoming and outgoing communications and secure sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If WPAN connection is established without access control measures, then communication between devices is enabled, but unauthorized access and data theft become possible

Engineering Contradiction:
ImproveWPAN connection establishmentVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements access control measures that are established before WPAN connections are made. The system pre-defines allowed sets of accesses for each device, and the firewall component automatically enforces these rules before any unauthorized communication can occur, preventing security breaches rather than responding to them after the fact.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a firewall component as an intermediary layer between WPAN devices. This firewall monitors and controls all communication requests passing through the WPAN network, acting as a mediator that allows legitimate traffic while blocking unauthorized access attempts, thus maintaining both connectivity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If physical access control is not implemented, then device portability is maintained, but unauthorized users can establish WPAN connections and transfer data

Engineering Contradiction:
Improvedevice portabilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a self-service security mechanism where each WPAN-enabled device automatically performs access control verification. When a connection request is received, the device's firewall component autonomously checks whether the requesting device is in the allowed set, eliminating the need for manual physical verification while maintaining security against unauthorized access.

Inventive Principle:
Principle #25Self-service

3Device complexity

If no monitoring mechanism is implemented, then system complexity is reduced, but security incidents cannot be detected or logged

Engineering Contradiction:
Improvesecurity mechanismVSAvoidsecurity monitoring capability
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism through comprehensive logging of all WPAN communication activities. The system records connection attempts, data transfers, and access control decisions, providing continuous feedback about network security status. This information can be used for security analysis, auditing, and improving future access control policies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2316230B1System and method for a WPAN firewall
Publication Date: 2017.12.27 SYMBOL TECHNOLOGIES LLC
  • EP2316230B1 patent drawingFigure 1
  • EP2316230B1 patent drawingFigure 2
  • EP2316230B1 patent drawingFigure 3

AI summary

Systems and methodologies for implementing Wireless Personal Area Network (WPAN) security are provided herein. As disclosed herein, firewall functionality can be implemented for a WPAN-capable device to control access to resources of the device over a WPAN. In one example, a WPAN protocol can be extended to include low-level access control measures that enable analysis of communication requests to and/or from a device prior to acting on the requests. As described herein, a WPAN firewall associated with a device can be configured to block, monitor, and/or log respective resource accesses to and/or from a WPAN. WPAN firewall functionality as described herein can be configured using mechanisms such as an Application Programming Interface (API) and/or a user control interface. Additionally, lateral regulation of security policies for a WPAN and one or more other networks utilized by a device can be provided.