Method for dynamically increasing wi-fi security level

EP4690885A1Pending Publication Date: 2026-02-11SOFTATHOME
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2024705684
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-04-04
Filing Date
2024-02-20
Publication Date
2026-02-11

AI Technical Summary

Technical Problem

Current Wi-Fi security protocols, such as WPA2/WPA3, often lead to interoperability issues with older equipment, forcing telecommunications operators to use the least secure mode (WPA2) to maintain connectivity, thereby compromising security levels.

Method used

A method that dynamically adjusts Wi-Fi security protocols between a gateway and stations, starting with a higher security mode like WPA2/WPA3, monitors connectivity, and reverts to a previous protocol if anomalies are detected, ensuring all stations remain connected while maintaining optimal security.

Benefits of technology

This approach allows operators to dynamically increase Wi-Fi security for compatible households while ensuring all equipment maintains connectivity, effectively balancing security and compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024054307_10102024_PF_FP_ABST
    Figure EP2024054307_10102024_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for increasing the security level of a Wi-Fi access point capable of communicating with a plurality of Wi-Fi stations in a communication network, this method comprising the following steps: - identifying a first Wi-Fi security protocol used within the Wi-Fi access point; - activating a second Wi-Fi security protocol; - checking whether at least one Wi-Fi station no longer manages to connect to the Wi-Fi access point, this check being performed by detecting an association anomaly; - transmitting an alert signal in the event of detecting an association anomaly; - maintaining the second Wi-Fi security protocol if no alert signal is transmitted, and - returning to the first Wi-Fi security protocol if an alert signal is transmitted.
Need to check novelty before this filing date? Find Prior Art

Description

Description Title of the invention: Method for dynamically increasing the Wi-Fi security level.

[0001] Technical field

[0002] The present invention relates to a method for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations in a communication network.

[0003] Such a network is, in particular, a home network equipped with a gateway as an access point allowing local equipment to be connected to the Internet.

[0004]

[0005] State of the prior art

[0006] Generally speaking, Wi-Fi is the most widely used medium for transmitting data at home. It is used by a large and growing number of different devices (smartphone, tablet, PC, TV decoder, IOT equipment, etc.) and for a wide variety of uses: email, telephony, “Live” video, “OTT” video, IOT monitoring, etc.

[0007] Wi-Fi technologies are becoming more complex and provide additional tools that allow certain characteristics of the flows to be optimized, while taking into account certain constraints: 802.11e, 802.1 lu, 802.1 lax, OFDMA, . . .

[0008] Similarly, as Wi-Fi technologies evolve rapidly, some existing Wi-Fi equipment may be incompatible with these developments. For a telecom operator deploying new Wi-Fi technology in a home, it is important not to introduce new problems for its customers' Wi-Fi equipment.

[0009]

[0010] Some stations may occasionally have difficulty using a gateway's Wi-Fi network. These difficulties manifest themselves as an inability to establish a Wi-Fi connection. There may be several reasons for this: incompatibility of the Wi-Fi station with a particular Wi-Fi standard or incompatibility with a security mode currently in use by the home gateway.

[0011]

[0012] Security protocols such as WEP (for Wired Equivalent Privacy), WPA (for Wi-Fi Protected Access), and WPA2 provide user authentication, encryption, and data privacy to ensure the security of wireless connections.

[0013]

[0014] Today, some Wi-Fi devices are not compatible with new Wi-Fi security protocols such as WPA2 / WPA3 or WPA3. This forces some telecom operators to use only the most popular security mode (WPA2) for all of their home gateways to avoid interoperability issues. As a result, an operator is unable to offer the best Wi-Fi security for its customers.

[0015]

[0016] Today, when an operator decides to improve its security level by activating a new security protocol, if it does not work, the user must log in manually to reduce the security level.

[0017]

[0018] The present invention aims to dynamically increase the level of Wi-Fi security between Wi-Fi stations and a gateway within a home network.

[0019] Another aim of the invention is to optimize the management of Wi-Fi stations within an access point of the communication network.

[0020]

[0021] Statement of the invention

[0022] At least one of the objectives is achieved with a method for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations in a communication network, this method comprising the following steps: - identification of a first Wi-Fi security protocol used within the Wi-Fi access point, - activation of a second Wi-Fi security protocol, - checking whether at least one Wi-Fi station can no longer connect to the Wi-Fi access point, this check being done by detecting an association anomaly, - emission of an alert signal in the event of detection of an association anomaly, - maintaining the second Wi-Fi security protocol if no alert signal is emitted, - return to the first Wi-Fi security protocol if an alert signal is issued.

[0023]

[0024] The method according to the present invention aims to increase the security level of Wi-Fi access points in a home depending on the Wi-Fi equipment present.

[0025] This way, you can gradually increase the Wi-Fi security mode in a home and check if some Wi-Fi stations are detected as having a connectivity problem. If so, the home gateway will re- duct the security mode to return to optimal connectivity for all Wi-Fi stations, otherwise the access point can use this new security mode.

[0026] With this feature, the operator can dynamically increase the security of Wi-Fi access points in part of its home gateway fleet, only for homes with equipment compatible with the latest standards. This dynamic increase aims to benefit from the highest or most recent level of security while maintaining the access point compatible with all Wi-Fi stations that usually connect to this access point.

[0027] For example, the protocols contemplated by the present invention may include the following protocols: WEP, WPA, WPA2, WPA2 / WPA3 or WPA3.

[0028]

[0029] According to an advantageous characteristic of the invention, if no alert signal is emitted after a predetermined duration, the following steps can be carried out: - activation of a third Wi-Fi security protocol, - checking whether at least one Wi-Fi station can no longer connect to the Wi-Fi access point, this check being done by detecting an association anomaly, - emission of an alert signal in the event of detection of an association anomaly, - maintaining the third Wi-Fi security protocol if no alert signal is emitted, - fallback to the second Wi-Fi security protocol if an alert signal is issued.

[0030]

[0031] The method according to the invention thus makes it possible to dynamically activate several security protocols in succession; each attempt is followed by a verification phase to see if the Wi-Fi stations continue to connect. If there is no connection, the previous protocol is returned to.

[0032] Preferably, the check is initiated as soon as the security level on the access point is changed. This check includes waiting for association from each of the stations that were associated or connected before the security level change.

[0033] The verification duration is configurable, for example a few seconds or several minutes, including 2 min.

[0034] At the end of the verification period, if at least one station is not reconnected, the procedure is canceled and the old security mode is returned.

[0035] If all stations have reconnected before the end of the period, then the new security protocol is maintained.

[0036] The check may consist of only checking whether some Wi-Fi stations, already known by the Wi-Fi access point, manage to connect again. These few Wi-Fi stations can be the Wi-Fi stations that have connected since a predetermined time in the past and / or those that have connected beyond a predetermined number of times.

[0037] For example, the alert signal can only be emitted when, for a given duration, the ratio between the number of Wi-Fi stations that manage to connect and the number of Wi-Fi stations that fail to connect is below a predetermined threshold.

[0038]

[0039] During the verification phase, the present invention advantageously implements association anomaly detection. Various means are used to verify whether a Wi-Fi station is no longer able to connect to the Wi-Fi access point.

[0040] Advantageously, the detection of an association anomaly between a Wi-Fi station and the Wi-Fi access point can comprise the following steps: - each time the Wi-Fi station sends a Wi-Fi standard management frame, called a “Probe Request”, comprising a MAC address and content, the following steps are carried out: - identification of content, - application of a unique identification algorithm to the content in order to generate a unique content identification code, - storage of the unique code within the access point, - check if the Wi-Fi station is associated with the access point, - if not associated, check if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point; - if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point, generation of an alert signal.

[0041]

[0042] With the method according to the invention, a Wi-Fi standard management frame, the "Probe Request", is used. This is used by Wi-Fi stations to identify nearby networks. This is a relevant indicator because during an association attempt, this "Probe Request" is systematically sent by the Wi-Fi station.

[0043] If this Wi-Fi standard management frame is present but if the Wi-Fi station linked to this Wi-Fi standard management frame is not associated with the network access point, then it is considered that there is an interoperability problem between the access point and this Wi-Fi station. The present invention therefore makes it possible to detect the presence of this “Probe Request” by associating it with a Wi-Fi station known to the access point.

[0044] Unique identification could be done using the physical address of the Wi-Fi station, i.e. the MAC address. But since this address, supposedly being unique, is sometimes changing, the present invention provides for the creation of a unique invariable code.

[0045] By retaining only the contents of the “Probe Request”, the random component is removed and the access point is thus able to link the “Probe Request” to a known device on the network.

[0046] Thus, during a next association attempt, the Wi-Fi station will send a "Probe Request", if the unique code calculated from this "Probe Request" is known to the access point and the Wi-Fi station linked to this unique code is not connected, then the access point considers that this Wi-Fi station is unable to associate and raises an alert. If the station manages to connect, then the alert is lifted.

[0047] Checking whether the Wi-Fi station linked to the unique code has already been associated with the access point consists of checking whether the Wi-Fi station has subsequently been associated and then disassociated from the access point, i.e. whether there has already been a successful association before.

[0048] The verification of whether the Wi-Fi station is associated with the access point is carried out immediately, with each “Probe Request” received by the access point.

[0049] With the method according to the invention, if an operator decides to modify a Wi-Fi parameter on an access point, this operator is informed of possible incompatibilities with a client's Wi-Fi equipment, even if the latter uses a random MAC address.

[0050]

[0051] According to an advantageous characteristic of the invention, the unique identification algorithm can be a hash function.

[0052] This function can more precisely be an MD5 cryptographic hash function. Such a function allows you to calculate a unique identifier from digital content. This allows you to distinguish Wi-Fi stations from each other.

[0053]

[0054] According to an advantageous embodiment of the invention, the communication network can comprise several access points including a gateway and at least one repeater, the steps of storing the unique code and verification being carried out within the gateway.

[0055] In this case, the step of checking whether the Wi-Fi station linked to the unique code has already been associated concerns all access points. We check whether the Wi-Fi station has not already been associated with one of the access points.

[0056] According to the invention, a processing unit of the gateway can be configured to carry out the steps of the method according to the invention. The intelligence is in the gateway.

[0057]

[0058] In other words, in a network including repeaters and a home gateway, each time a "Probe Request" is received on one of the network devices, a unique code is calculated and then saved in the home gateway for future comparison.

[0059]

[0060] According to one embodiment of the invention, the content may include a number of antennas of the Wi-Fi station or a maximum frequency band of the Wi-Fi station. These are elements relating to the Wi-Fi capabilities of the equipment. Obviously, the content of the Wi-Fi standard management frame may include other elements than those mentioned.

[0061]

[0062] According to a preferred embodiment of the invention, for communication according to the IEEE 802.11 standard, the content is the “IEEE 802.11 Wireless management” part. In particular, variable information such as the destination address or the source address is not retained.

[0063]

[0064] According to one embodiment of the invention, the communication network may be a home network, the access point comprising an internet connection router.

[0065] Such a router can be, for example, a gateway, a "homegateway" in English, or any other device capable of connecting user equipment to the Internet.

[0066]

[0067] According to another aspect of the invention, a communication network is proposed for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations; this access point being configured to implement a method according to the invention.

[0068]

[0069] The present invention also relates to a computer program product comprising instructions which, when the program is executed by a processing unit in an access point or in a remote server, for example in the cloud, cause the latter to implement the method according to the invention.

[0070]

[0071] Description of figures and embodiments.

[0072] Other advantages and particularities of the invention will appear on reading the detailed description of implementations and embodiments which are in no way limiting, and the following appended drawings:

[0073] [Fig. 1] Figure 1 is a schematic view of a house equipped with an access point in the form of an internet gateway and a user's Wi-Fi stations;

[0074] [Fig. 2] Figure 2 is a flowchart illustrating steps of the method according to the invention;

[0075] [Fig. 3] Figure 3 is a flowchart illustrating steps of a method according to the invention;

[0076] [Fig. 4] Figure 4 is a schematic view illustrating the fields in a Wi-Fi standard management frame of the “Probe Request” type according to the invention;

[0077] [Fig. 5] Figure 5 is a simplified schematic view of frames sent by a Wi-Fi station to an access point; and

[0078] [Fig. 6] Figure 6 is a simplified schematic view of frames sent by a Wi-Fi station to an access point according to the invention.

[0079]

[0080] The embodiments which will be described below are in no way limiting; it will be possible in particular to implement variants of the invention comprising only a selection of characteristics described below isolated from the other characteristics described, if this selection of characteristics is sufficient to confer a technical advantage or to differentiate the invention compared to the state of the prior art. This selection comprises at least one preferably functional characteristic without structural details, or with only a part of the structural details if this part alone is sufficient to confer a technical advantage or to differentiate the invention compared to the state of the prior art.

[0081]

[0082] Figure 1 is a schematic view illustrating a house 1 equipped with an access point 2 which is a gateway allowing access to the Internet 3 via a wired connection 4 based on coaxial cable or optical fiber.

[0083] The access point 2 comprises a processing unit 7, such as a microcontroller for example, for implementing the method according to the invention and a Wi-Fi module 8 for wireless communication with equipment. The invention also provides an embodiment in which the processing unit implementing the invention, alternatively to the processing unit 7 or in a complementary manner, is a remote server 9. Such a remote server can control several processing units arranged in different residences.

[0084] In Figure 1, home devices can connect wired or wirelessly to access point 2 to access the Internet 3.

[0085] In the example of Figure 1, there is a television 5 and a Wi-Fi station such as a mobile phone 6 of the “smartphone” type, both connected to the gateway 2 wirelessly by Wi-Fi. When the television 5 is in operation, a digital television service is notably activated between the television 5 and the access point 2.

[0086] The mobile phone 6 is able to connect to the gateway 2 to access the Internet by implementing different types of services: web, download, telephony, etc.

[0087] The combination of access point 2, television 5 and mobile phone 6 forms a home network in which communications take place according to a secure protocol. This secure protocol prevents unauthorized external connection to the wireless network and encrypts the data exchanged.

[0088] The access point 2 comprises conventional hardware and software means for serving as an access point and repeater between equipment and the Internet and further comprises one and / or the other a computer program product for implementing the method according to the invention.

[0089] Wi-Fi security protocols are evolving and new protocols are emerging to improve security.

[0090] Figure 2 is a schematic view of a flowchart illustrating a dynamic security enhancement sequence according to the invention.

[0091] A first step 10 is distinguished which is the start of a procedure according to the invention consisting in particular of noting that the access point 2 is capable of communicating according to the WPA2 protocol.

[0092] In step 11, the processing unit 7 activates a security protocol change from the WPA2 protocol to the WPA2 / WPA3 protocol. At this time, the access point 2 can only communicate according to the WPA2 / WPA3 protocol.

[0093] In step 12, we check whether Wi-Fi stations already known to the access point are able to connect or not. If one or more Wi-Fi stations are no longer able to connect to the access point which is now in WPA2 / WPA3, the processing unit 7 then commands the activation of the previous protocol which is the WPA2 protocol. The security increase process ends there. A new attempt can be made later.

[0094] In other words, during verification, we wait to see if each of the stations that were associated or connected before the change in security level will be able to associate again.

[0095] The verification time is, for example, 2 minutes. This time can be configured depending on the number of Wi-Fi stations that were associated before the security protocol change.

[0096] On the other hand, in step 12, if all the Wi-Fi stations manage to connect to the access point which is now in WPA2 / WPA3, the processing unit 7 then commands in step 13 an activation of another WPA3 security protocol considered superior to the WPA2 / WPA3 protocol. The access point can then communicate only according to the WPA3 protocol.

[0097] In step 14, we check whether Wi-Fi stations already known to the access point are able to connect or not. If one or more Wi-Fi stations are no longer able to connect to the access point which is now in WPA3, the processing unit 7 then commands the activation of the previous protocol which is the WPA2 / WPA3 protocol. The security increase process ends there. A new attempt can be set up later.

[0098] On the other hand, in step 14, if all the Wi-Fi stations manage to connect to the access point which is now in WPA3, the processing unit 7 maintains the WPA3 protocol and the improvement process thus ends in step 15.

[0099]

[0100] We will now describe the verification process if at least one Wi-Fi station can no longer connect to the Wi-Fi access point during a change of security protocol, this verification being done by detecting an association anomaly.

[0101] In Figure 1, when for example the mobile phone 6 is activated, it tries to identify nearby Wi-Fi access points. When an access point is identified, an association attempt follows.

[0102]

[0103] Figure 3 is a flowchart illustrating steps for implementing the association anomaly detection steps according to the invention.

[0104] There is a step 16 during which the Wi-Fi station transmits a Wi-Fi standard management frame, called "Probe Request". This frame is received by the access point 2 which is a home gateway to the Internet. The frame includes a MAC address and content.

[0105] Figure 4 shows a screenshot of the frame. A first part is distinguished, which is the header of the frame, and a second part is the content according to the invention. The first part includes fields located between “type / Subtype:” and “[FCS Status: Unverified]”. The content according to the invention includes all the characteristics entered in the fields ranging from “Tagged parameters” to “Tag: Vendor Specific: Broadcom”.

[0106] In step 17 in Figure 3, the access point identifies the content according to the invention. A digital file is then created. An MD5 hash is then applied to this digital file in step 18 so as to obtain a unique code 19.

[0107] In step 20, the unique code is saved within the gateway.

[0108] In step 21, we check whether the Wi-Fi station, i.e. phone 6, is associated with access point 2.

[0109] If so, "yes," nothing happens at step 23.

[0110] If the answer is negative, the "no", then in step 22 we check whether the unique code is known in the access point and whether the Wi-Fi station linked to this unique code has already been associated with the access point. We thus try to find out whether, in the past, the telephone 6 has already been associated at least once with the access point 2. [OR I] If no, nothing happens at step 23.

[0112] If the answer is "yes", an alert signal is generated in step 24, for example via the internet to a remote server of the operator. This alert signal can advantageously remain local to the gateway but can also be propagated in the home network or in the cloud through a secure tunnel (MQTT) in both cases.

[0113] When the alert signal is local, it can be a software signal sent to a gateway application for corrective actions to be implemented, and / or a message sent on the local network to other network equipment, such as a Wi-Fi repeater.

[0114] Figure 5 shows an embodiment according to the prior art. Figure 5a illustrates a first association of the Wi-Fi station with the access point. Figure 5b illustrates a second association of the Wi-Fi station with the access point at a later time.

[0115] Figure 5a concerns a first phase during which a Wi-Fi station transmits a “Probe Request” frame at a time t0. This frame obviously includes the MAC address of the Wi-Fi station. In a second phase, during an association attempt, at a time t1, the Wi-Fi station also transmits the same MAC address. In such a situation where the Wi-Fi station uses the same MAC address between the “Probe Request” and its association, it is easy for the access point to detect the presence of this equipment.

[0116] Figure 5b concerns a second phase during which a Wi-Fi station transmits a “Probe Request” frame at a time t0. This frame obviously includes the MAC address of the Wi-Fi station. In a second phase, during an association attempt, at a time t1, the Wi-Fi station transmits a MAC address different from that sent in the “Probe Request”. In such a situation, the fact that the Wi-Fi station uses a different MAC address between the “Probe Request” and its association prevents the link between the “Probe Request” and the association from being made.

[0117] The MAC address is notably different by manufacturer implementation to mask its presence and avoid identification of the station.

[0118] It is therefore necessary to remove the random component of the "Probe Request" due to the fact that the MAC address is sometimes different.

[0119] The MAC address can be random, but the data contained in the "Probe Request" need not be. By separating the two sets and creating, for example, an MD5 hash of the contents, we obtain a unique code for the Wi-Fi station, as we will see in Figure 6.

[0120]

[0121] Figure 6 shows an embodiment according to the invention. Figure 6a illustrates a first association of the Wi-Fi station with the access point. Figure 6b illustrates a second association of the Wi-Fi station with the access point. a later time.

[0122] Figure 6a concerns the same steps as in Figure 5a with the addition here of the calculation of the unique code at time t0 when receiving the “Probe Request” frame. During the association attempt, at time t1, the Wi-Fi station also transmits the same MAC address. In such a situation where the Wi-Fi station uses the same MAC address between the “Probe Request” and its association, it is easy for the access point to detect the presence of this equipment.

[0123]

[0124] Figure 6b concerns the same steps as in Figure 5b with the addition here of the calculation of the unique code at time t0 during the transmission of the “Probe Request” frame. In the same way, we consider the case where, during the association attempt, at time t1, the Wi-Fi station transmits a MAC address different from that sent in the “Probe Request”. With the present invention, if the association is not carried out, the unique code is used to identify the Wi-Fi station and to note that this Wi-Fi station had already associated in the past during the phase described in Figure 6a.

[0125]

[0126] Thus, with the method according to the invention, any anomaly in the connection of a Wi-Fi station to an access point is detected. This detection makes it possible to validate or not the upgrades of the security protocols.

[0127]

[0128] Of course, the invention is not limited to the examples just described. Many modifications can be made to these examples without departing from the scope of the present invention as described.

[0129]

Claims

Claims

1. Method for increasing the security level of a WiFi access point capable of communicating with several WiFi stations in a communication network, this method comprising the following steps: - identification of a first Wi-Fi security protocol used within the Wi-Fi access point, - activation of a second Wi-Fi security protocol, - checking whether at least one Wi-Fi station can no longer connect to the Wi-Fi access point, this check being done by detecting an association anomaly, - emission of an alert signal in the event of detection of an association anomaly, - maintaining the second Wi-Fi security protocol if no alert signal is emitted, - return to the first Wi-Fi security protocol if an alert signal is issued.

2. Method according to claim 1, characterized in that if no alert signal is emitted after a predetermined duration, carrying out the following steps: - activation of a third Wi-Fi security protocol, - checking whether at least one Wi-Fi station can no longer connect to the Wi-Fi access point, this check being done by detecting an association anomaly, - emission of an alert signal in the event of detection of an association anomaly, - maintaining the third Wi-Fi security protocol if no alert signal is emitted, - fallback to the second Wi-Fi security protocol if an alert signal is issued.

3. Method according to claim 1 or 2, characterized in that the detection of association anomaly between a Wi-Fi station and the Wi-Fi access point comprises the following steps: - each time the Wi-Fi station sends a Wi-Fi standard management frame, called a “Probe Request”, comprising a MAC address and content, the following steps are carried out: - identification of content, - application of a unique identification algorithm to the content in order to generate a unique content identification code, - storage of the unique code within the access point, - check if the Wi-Fi station is associated with the access point, - if not associated, check if the unique code is known in the access point and whether the Wi-Fi station linked to this unique code has already been associated with the access point; - if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point, generation of an alert signal.

4. Method according to claim 3, characterized in that the unique identification algorithm is a hash function.

5. Method according to claim 3 or 4, characterized in that the unique identification algorithm is a cryptographic hash function MD 5.

6. Method according to any one of claims 3 to 5, characterized in that the communication network comprises several access points including a gateway and at least one repeater, the steps of storing the unique code and verification being carried out within the gateway.

7. Method according to any one of claims 3 to 6, characterized in that the content comprises a number of antennas of the Wi-Fi station.

8. Method according to any one of claims 3 to 7, characterized in that the content comprises a maximum frequency band of the Wi-Fi station.

9. Method according to any one of claims 3 to 8, characterized in that for a communication according to the IEEE 802.11 standard, the content is the “IEEE 802.11 Wireless management” part.

10. Method according to any one of the preceding claims, characterized in that the communication network is a home network, the access point comprising an internet connection router.

11. Communication network for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations, the communication network comprising a Wi-Fi access point, characterized in that the access point is configured to implement a method according to any one of the preceding claims.

12. Computer program product comprising instructions which, when the program is executed by a processing unit in an access point or in a remote server, cause the latter to implement the method according to any one of claims 1 to