Method for dynamically increasing the Wi-Fi security level.
The method dynamically adjusts Wi-Fi security protocols in home networks by identifying and upgrading to new protocols while checking for connection issues, using unique identification codes to ensure seamless compatibility and security enhancement.
Patent Information
- Application Number
- FR2023003361
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-04-04
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2043-04-04
AI Technical Summary
Existing Wi-Fi networks face issues with interoperability and security protocol compatibility, leading to connectivity problems and suboptimal security levels due to the use of outdated security protocols like WPA2 to accommodate all devices, preventing operators from offering the best security for their customers.
A method that dynamically increases Wi-Fi security by identifying the current protocol, activating a new protocol, checking for connection anomalies, and sending alerts if devices cannot connect, reverting to previous protocols if necessary, using unique identification codes based on Wi-Fi management frames to detect association anomalies.
Enables secure protocol upgrades for compatible devices while maintaining connectivity for all stations, ensuring a gradual and reliable increase in security levels without disrupting existing equipment.
Smart Images

Figure 00000015_0000 
Figure 00000016_0000 
Figure 00000017_0000
Abstract
Description
Title of the invention: Method for dynamically increasing the Wi-Fi security level. Technical field
[0001] The present invention relates to a method for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations in a communication network.
[0002] Such a network is in particular a home network equipped with a gateway as an access point allowing local equipment to be connected to the Internet.
[0003] State of the prior art
[0004] Generally speaking, Wi-Fi is the most widely used medium for transmitting data at home. It is used by a large and growing number of different devices (smartphone, tablet, PC, TV decoder, IOT equipment, etc.) and for a wide variety of uses: email, telephony, “Live” video, “OTT” video, IOT monitoring, etc.
[0005] Wi-Fi technologies are becoming more complex and provide additional tools that allow certain characteristics of the flows to be optimized, while taking into account certain constraints: 802.11e, 802.1 lu, 802.11ax, OFDMA, etc.
[0006] Similarly, as Wi-Fi technologies evolve very quickly, some Wi-Fi equipment already on the market is sometimes incompatible with these developments. For a telecommunications operator deploying new Wi-Fi technology in a home, it is important not to introduce new problems for its customers' Wi-Fi equipment.
[0007]
[0008] Some stations may sometimes have difficulty using a gateway's Wi-Fi network. These difficulties manifest themselves by an inability to establish a Wi-Fi connection, the reasons for which can be multiple: incompatibility of the Wi-Fi station with a particular Wi-Fi standard or even incompatibility with a security mode currently in use by the home gateway.
[0009]
[0010] Security protocols such as WEP (for "Wired Equivalent Privacy"), WPA (for "Wi-Fi Protected Access") and WPA2, enable user authentication as well as data encryption and confidentiality to ensure the security of wireless connections.
[0012] Today, some Wi-Fi devices are not compatible with new Wi-Fi security protocols such as WPA2 / WPA3 or WPA3. This forces some telecommunications operators to use only the most widespread security mode (WPA2) for all of these home gateways in order to avoid interoperability problems. As a result, an operator is not able to offer the best Wi-Fi security for its customers.
[0013]
[0014] Today, when an operator decides to improve its security level by activating a new security protocol, if it does not work, the user must log in manually to reduce the security level.
[0015]
[0016] The present invention aims to dynamically increase the level of Wi-Fi security between Wi-Fi stations and a gateway within a home network.
[0017] Another aim of the invention is to optimize the management of Wi-Fi stations within an access point of the communication network.
[0018] Statement of the invention
[0019] At least one of the objectives is achieved with a method for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations in a communication network, this method comprising the following steps: - identification of a first Wi-Fi security protocol used within the Wi-Fi access point, - activation of a second Wi-Fi security protocol, - checking whether at least one Wi-Fi station can no longer connect to the Wi-Fi access point, this checking being done by detecting an association anomaly, - sending an alert signal if an association anomaly is detected, - maintaining the second Wi-Fi security protocol if no alert signal is sent, - return to the first Wi-Fi security protocol if an alert signal is emitted.
[0020]
[0021] The method according to the present invention aims to increase the security level of Wi-Fi access points in a home depending on the Wi-Fi equipment present.
[0022] Thus, a gradual increase in the Wi-Fi security mode can be carried out in a home and check whether certain Wi-Fi stations are detected as having a connectivity problem. If this is the case, the home gateway reduces the security mode to return to optimal connectivity for all the Wi-Fi stations, otherwise the access point can use this new security mode.
[0023] Thanks to this function, the operator can therefore dynamically increase the security of the Wi-Fi access points of a part of its domestic gateway fleet, only for homes with equipment compatible with the latest standards. This dynamic increase aims to benefit from the highest or most recent level of security while maintaining the access point compatible with all the Wi-Fi stations which are used to connecting to this access point.
[0024] For example, the protocols contemplated in the present invention may include the following protocols: WEP, WPA, WPA2, WPA2 / WPA3 or WPA3.
[0025]
[0026] According to an advantageous characteristic of the invention, if no alert signal is emitted after a predetermined duration, the following steps can be carried out: - activation of a third Wi-Fi security protocol, - checking whether at least one Wi-Fi station can no longer connect to the Wi-Fi access point, this checking being done by detecting an association anomaly, - sending an alert signal if an association anomaly is detected, - maintaining the third Wi-Fi security protocol if no alert signal is sent, - return to the second Wi-Fi security protocol if an alert signal is emitted.
[0027]
[0028] The method according to the invention thus makes it possible to dynamically activate several security protocols in succession; each attempt is followed by a verification phase to see if the Wi-Fi stations continue to connect. If there is no connection, the previous protocol is returned to.
[0029] Preferably, the verification is initiated as soon as the security level on the access point is changed. This verification includes waiting for association of each of the stations that were associated or connected before the security level change.
[0030] The verification duration is configurable, for example a few seconds or several minutes, in particular 2 min.
[0031] At the end of the verification period, if at least one station is not reconnected, the procedure is cancelled and the old security mode is returned to.
[0032] If all stations have reconnected before the end of the period, then the new security protocol is maintained.
[0033] The verification may consist of verifying only whether a few Wi-Fi stations, already known by the Wi-Fi access point, manage to connect again. These few Wi-Fi stations may be the Wi-Fi stations that have connected since a predetermined time in the past and / or those that have connected beyond a predetermined number of times.
[0034] The alert signal may for example only be emitted when, for a given duration, the ratio between the number of Wi-Fi stations which manage to connect and the number of Wi-Fi stations which do not manage to connect is lower than a predetermined threshold.
[0035]
[0036] During the verification phase, the present invention advantageously implements association anomaly detection. It is verified by various means whether a Wi-Fi station is no longer able to connect to the Wi-Fi access point.
[0037] Advantageously, the detection of an association anomaly between a Wi-Fi station and the Wi-Fi access point can comprise the following steps: - each time the Wi-Fi station sends a Wi-Fi standard management frame, called a “Probe Request”, including a MAC address and content, the following steps are carried out: - identification of content, - application of a unique identification algorithm to the content in order to generate a unique content identification code, - storage of the unique code within the access point, - check if the Wi-Fi station is associated with the access point, - if not associated, check if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point; - if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point, generation of an alert signal.
[0038]
[0039] With the method according to the invention, a Wi-Fi standard management frame, the “Probe Request”, is used. The latter is used by Wi-Fi stations to identify nearby networks. This is a relevant indicator because during an association attempt, this “Probe Request” is systematically sent by the Wi-Fi station.
[0040] If this Wi-Fi standard management frame is present but if the Wi-Fi station linked to this Wi-Fi standard management frame is not associated with the network access point, then it is considered that there is an interoperability problem between the access point and this Wi-Fi station. The present invention therefore makes it possible to detect the presence of this “Probe Request” by associating it with a Wi-Fi station known to the access point.
[0041] Unique identification could be done using the physical address of the Wi-Fi station, i.e. the MAC address. But since this address, supposed to be unique, is sometimes changing, the present invention provides for the creation of an invariable unique code.
[0042] By retaining only the content of the “Probe Request”, the random component is removed and the access point is thus able to link the “Probe Request” to a known device on the network.
[0043] Thus, during a next association attempt, the Wi-Fi station will send a “Probe Request”, if the unique code calculated from this “Probe Request” is known to the access point and the Wi-Fi station linked to this unique code is not connected, then the access point considers that this Wi-Fi station is unable to associate and raises an alert. If the station manages to connect, then the alert is raised.
[0044] Checking whether the Wi-Fi station linked to the unique code has already been associated with the access point consists of checking whether the Wi-Fi station has subsequently been associated and then disassociated from the access point, i.e. whether there has already been a successful association before.
[0045] The verification of whether the Wi-Fi station is associated with the access point is carried out immediately, at each “Probe Request” received by the access point.
[0046] With the method according to the invention, if an operator decides to modify a Wi-Fi parameter on an access point, this operator is informed of possible incompatibilities with Wi-Fi equipment of a client, even if the latter uses a random MAC address.
[0047]
[0048] According to an advantageous characteristic of the invention, the unique identification algorithm can be a hash function.
[0049] This function can more precisely be an MD5 cryptographic hash function. Such a function makes it possible to calculate a unique identifier from digital content. This makes it possible to distinguish Wi-Fi stations from each other.
[0050]
[0051] According to an advantageous embodiment of the invention, the communication network can comprise several access points including a gateway and at least one repeater, the steps of storing the unique code and verification being carried out within the gateway.
[0052] In this case, the step of verifying whether the Wi-Fi station linked to the unique code has already been associated concerns all of the access points. It is in fact verified whether the Wi-Fi station has not already been associated with one of the access points.
[0053] According to the invention, a processing unit of the gateway can be configured to carry out the steps of the method according to the invention. The intelligence is in the gateway.
[0054]
[0055] In other words, in a network including repeaters and a home gateway, each time a “Probe Request” is received on one of the devices in the network, a unique code is calculated and then saved in the home gateway for future comparison.
[0056]
[0057] According to one embodiment of the invention, the content may include a number of antennas of the Wi-Fi station or a maximum frequency band of the Wi-Fi station. These are elements relating to the Wi-Fi capabilities of the equipment. Obviously, the content of the Wi-Fi standard management frame may include other elements than those mentioned.
[0058]
[0059] According to a preferred embodiment of the invention, for communication according to the IEEE 802.11 standard, the content is the “IEEE 802.11 Wireless management” part. In particular, variable information such as the destination address or the source address is not retained.
[0060]
[0061] According to one embodiment of the invention, the communication network may be a home network, the access point comprising an internet connection router.
[0062] Such a router can be, for example, a gateway, a “homegateway” in English or any other device capable of connecting user equipment to the Internet.
[0063]
[0064] According to another aspect of the invention, a communication network is proposed for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations; this access point being configured to implement a method according to the invention.
[0065]
[0066] The present invention also relates to a computer program product comprising instructions which, when the program is executed by a processing unit in an access point or in a remote server, for example in the cloud, lead the latter to implement the method according to the invention.
[0067]
[0068] Description of the figures and embodiments.
[0069] Other advantages and particularities of the invention will appear on reading the detailed description of implementations and embodiments which are in no way limiting, and the following appended drawings:
[0070] [Fig.l] [Fig.l] is a schematic view of a house equipped with an access point in the form of an internet gateway and Wi-Fi stations of a user;
[0071] [Fig.2] [Fig.2] is a flowchart illustrating steps of the method according to the invention;
[0072] [Fig.3] [Fig.3] is a flowchart illustrating steps of a method according to the invention;
[0073] [Fig.4] [Fig.4] is a schematic view illustrating the fields in a frame of management of Wi-Fi standard of the “Probe Request” type according to the invention;
[0074] [Fig.5] [Fig.5] is a simplified schematic view of frames sent by a Wi-Fi station to an access point; and
[0075] [Fig.6] [Fig.6] is a simplified schematic view of frames sent by a Wi-Fi station with an access point according to the invention.
[0076]
[0077] The embodiments which will be described below are in no way limiting; it will be possible in particular to implement variants of the invention comprising only a selection of characteristics described below isolated from the other characteristics described, if this selection of characteristics is sufficient to confer a technical advantage or to differentiate the invention compared to the state of the prior art. This selection comprises at least one preferably functional characteristic without structural details, or with only a part of the structural details if this part alone is sufficient to confer a technical advantage or to differentiate the invention compared to the state of the prior art.
[0078]
[0079] [Fig.l] is a schematic view illustrating a house 1 equipped with an access point 2 which is a gateway allowing access to the Internet 3 via a wired connection 4 based on coaxial cable or optical fiber.
[0080] The access point 2 comprises a processing unit 7, such as a microcontroller for example, for implementing the method according to the invention and a Wi-Fi module 8 for wireless communication with equipment. The invention also provides an embodiment in which the processing unit implementing the invention, alternatively to the processing unit 7 or in a complementary manner, is a remote server 9. Such a remote server can control several processing units arranged in different residences.
[0081] In [Fig.l], home equipment can connect wired or wirelessly to the access point 2 to access the Internet 3.
[0082] In the example of [Fig.l], we can see a television 5 and a Wi-Fi station such as a mobile phone 6 of the “smartphone” type, both connected to the gateway 2 wirelessly by Wi-Fi. When the television 5 is in operation, a digital television service is notably activated between the television 5 and the access point 2.
[0083] The mobile telephone 6 is able to connect to the gateway 2 to access the Internet by implementing different types of services: web, downloading, telephony, etc.
[0084] The set of access point 2, television 5 and mobile telephone 6 forms a network do A system in which communications take place using a secure protocol. This secure protocol prevents unauthorized external connections to the wireless network and encrypts the data exchanged.
[0085] The access point 2 comprises conventional hardware and software means for serving as an access point and repeater between equipment and the Internet and further comprises one and / or the other a computer program product for implementing the method according to the invention.
[0086] Wi-Fi security protocols are undergoing evolutions and new protocols are emerging to improve security.
[0087] [Fig.2] is a schematic view of a flowchart illustrating a sequence security improvement dynamics according to the invention.
[0088] A first step 10 is distinguished which is the start of a procedure according to the invention consisting in particular of noting that the access point 2 is capable of communicating according to the WPA2 protocol.
[0089] In step 11, the processing unit 7 activates a change of security protocol to switch from the WPA2 protocol to the WPA2 / WPA3 protocol. At this time, the access point 2 can only communicate according to the WPA2 / WPA3 protocol.
[0090] In step 12, it is checked whether Wi-Fi stations already known to the access point are able to connect or not. If one or more Wi-Fi stations are no longer able to connect to the access point which is now in WPA2 / WPA3, the processing unit 7 then commands the activation of the previous protocol which is the WPA2 protocol. The security increase process ends there. A new attempt can be put in place later.
[0091] In other words, during the verification, we wait to see if each of the stations which were associated or connected before the change in security level will be able to associate again.
[0092] The verification duration is for example 2 minutes. This duration can be configurable depending on the number of Wi-Fi stations that were associated before the change of security protocol.
[0093] On the other hand, in step 12, if all the Wi-Fi stations manage to connect to the access point which is now in WPA2 / WPA3, the processing unit 7 then commands in step 13 an activation of another WPA3 security protocol considered superior to the WPA2 / WPA3 protocol. The access point can then communicate only according to the WP A3 protocol.
[0094] In step 14, it is checked whether Wi-Fi stations already known to the access point are able to connect or not. If one or more Wi-Fi stations are no longer able to connect to the access point which is now in WPA3, the processing unit 7 then commands the activation of the previous protocol which is the WPA2 / WPA3 protocol. The process The security increase ends here. A new attempt can be made later.
[0095] On the other hand, in step 14, if all the Wi-Fi stations manage to connect to the access point which is now in WPA3, the processing unit 7 maintains the WPA3 protocol and the improvement process thus ends in step 15.
[0096]
[0097] We will now describe the verification process if at least one Wi-Fi station is no longer able to connect to the Wi-Fi access point during a change of security protocol, this verification being carried out by detecting an association anomaly.
[0098] In [Fig. 1], when for example the mobile phone 6 is activated, it seeks to identify nearby Wi-Fi access points. When an access point is identified, an association attempt follows.
[0099]
[0100] [Fig.3] is a flowchart illustrating steps in implementing the steps of association anomaly detection according to the invention.
[0101] A step 16 is distinguished during which the Wi-Fi station transmits a Wi-Fi standard management frame, called “Probe Request”. This frame is received by the access point 2 which is a domestic gateway to the Internet. The frame includes a MAC address and content.
[0102] In [Fig.4] is illustrated a screen copy of the frame. We distinguish a first part which is the header of the frame and a second part which is the content according to the invention. The first part includes fields located between "type / Subtype:" up to "[FCS Status: Unverified]". The content according to the invention includes all the characteristics entered in the fields ranging from "Tagged parameters" up to "Tag: Vendor Specifies: Broadcom".
[0103] In step 17 in [Fig.3], the access point identifies the content according to the invention. A digital file is then created. An MD5 hash is then applied to this digital file in step 18 so as to obtain a unique code 19.
[0104] In step 20, the unique code is saved within the gateway.
[0105] In step 21, it is checked whether the Wi-Fi station, i.e. the telephone 6, is associated with the access point 2.
[0106] If yes, nothing happens at step 23.
[0107] If not, the “no”, we then check in step 22 whether the unique code is known in the access point and whether the Wi-Fi station linked to this unique code has already been associated with the access point. We are thus trying to find out whether, in the past, phone 6 has already been associated at least once with access point 2.
[0108] If not, nothing happens at step 23.
[0109] If the answer is "yes", an alert signal is generated in step 24, for example via the Internet to a remote server of the operator. This alert signal can advantageously remain local to the gateway but can also be propagated in the home network or in the cloud through a secure tunnel (MQTT) in both cases.
[0110] When the alert signal is local, it may be a software signal sent to a gateway application for the implementation of corrective actions, and / or a message sent on the local network to other network equipment, such as for example a Wi-Fi repeater.
[0111] In [Fig. 5] an embodiment according to the prior art is distinguished. Figure 5a illustrates a first association of the Wi-Fi station with the access point. Figure 5b illustrates a second association of the Wi-Fi station with the access point at a later time.
[0112] Figure 5a concerns a first phase during which a Wi-Fi station transmits a “Probe Request” frame at a time t0. This frame obviously includes the MAC address of the Wi-Fi station. In a second phase, during an association attempt, at a time t1, the Wi-Fi station also transmits the same MAC address. In such a situation where the Wi-Fi station uses the same MAC address between the “Probe Request” and its association, it is easy for the access point to detect the presence of this equipment.
[0113] Figure 5b concerns a second phase during which a Wi-Fi station transmits a “Probe Request” frame at a time t0. This frame obviously includes the MAC address of the Wi-Fi station. In a second phase, during an association attempt, at a time t1, the Wi-Fi station transmits a MAC address different from that sent in the “Probe Request”. In such a situation, the fact that the Wi-Fi station uses a different MAC address between the “Probe Request” and its association prevents the link from being made between the “Probe Request” and the association.
[0114] The MAC address is notably different by manufacturer implementation to mask its presence and avoid identification of the station.
[0115] It is therefore necessary to remove the random component of the “Probe Request” due to the fact that the MAC address is sometimes different.
[0116] The MAC address can be random, but the data contained in the "Probe Request" is not necessarily random. By separating the two sets and creating, for example, an MD5 hash of the content, we obtain a unique code for the Wi-Fi station, as we will see in [Fig.6].
[0117]
[0118] In [Fig. 6], an embodiment according to the invention can be seen. Figure 6a illustrates a first association of the Wi-Fi station with the access point. Figure 6b illustrates a second association of the Wi-Fi station to the access point at a later time.
[0119] Figure 6a concerns the same steps as in Figure 5a with the addition here of the calculation of the unique code at time t0 upon reception of the “Probe Request” frame. During the association attempt, at time t1, the Wi-Fi station also transmits the same MAC address. In such a situation where the Wi-Fi station uses the same MAC address between the “Probe Request” and its association, it is easy for the access point to detect the presence of this equipment.
[0120]
[0121] Figure 6b concerns the same steps as in Figure 5b with in addition here the calculation of the unique code at time t0 during the transmission of the “Probe Request” frame. In the same way, we consider the case where, during the association attempt, at time t1, the Wi-Fi station transmits a MAC address different from that sent in the “Probe Request”. With the present invention, if the association is not carried out, the unique code is used to identify the Wi-Fi station and to note that this Wi-Fi station had already associated in the past during the phase described in Figure 6a.
[0122]
[0123] Thus, with the method according to the invention, any anomaly in the connection of a Wi-Fi station to an access point is detected. This detection makes it possible to validate or not the upgrades of the security protocols.
[0124]
[0125] Of course, the invention is not limited to the examples which have just been described. Numerous modifications can be made to these examples without departing from the scope of the present invention as described.
[0126]
Claims
Claims
1. Method for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations in a communication network, this method comprising the following steps: - identification of a first Wi-Fi security protocol used within the Wi-Fi access point, - activation of a second Wi-Fi security protocol, - verification whether at least one Wi-Fi station is no longer able to connect to the Wi-Fi access point, this verification being carried out by detecting an association anomaly, - transmission of an alert signal in the event of detection of an association anomaly, - maintenance of the second Wi-Fi security protocol if no alert signal is transmitted, - return to the first Wi-Fi security protocol if an alert signal is transmitted.
2. Method according to claim 1, characterized in that if no alert signal is emitted after a predetermined duration, carrying out the following steps: - activation of a third Wi-Fi security protocol, - verification whether at least one Wi-Fi station can no longer connect to the Wi-Fi access point, this verification being carried out by detecting an association anomaly, - emission of an alert signal in the event of detection of an association anomaly, - maintenance of the third Wi-Fi security protocol if no alert signal is emitted, - return to the second Wi-Fi security protocol if an alert signal is emitted.
3. Method according to claim 1 or 2, characterized in that the detection of an anomaly of association between a Wi-Fi station and the Wi-Fi access point comprises the following steps: - each time the Wi-Fi station sends a Wi-Fi standard management frame, called "Probe Request", comprising a MAC address and a content, carrying out the following steps: - identification of the content, - application of a unique identification algorithm to the content of so as to generate a unique code for identifying the content, - storing the unique code within the access point, - checking whether the Wi-Fi station is associated with the access point, - if not associated, checking whether the unique code is known in the access point and whether the Wi-Fi station linked to this unique code has already been associated with the access point; - if the unique code is known in the access point and whether the Wi-Fi station linked to this unique code has already been associated with the access point, generating an alert signal.
4. Method according to claim 3, characterized in that the unique identification algorithm is a hash function.
5. Method according to claim 3 or 4, characterized in that the unique identification algorithm is an MD5 cryptographic hash function.
6. Method according to any one of claims 3 to 5, characterized in that the communication network comprises several access points including a gateway and at least one repeater, the steps of storing the unique code and verification being carried out within the gateway.
7. Method according to any one of claims 3 to 6, characterized in that the content comprises a number of antennas of the Wi-Fi station.
8. Method according to any one of claims 3 to 7, characterized in that the content comprises a maximum frequency band of the Wi-Fi station.
9. Method according to any one of claims 3 to 8, characterized in that for a communication according to the IEEE 802.11 standard, the content is the “IEEE 802.11 Wireless management” part.
10. Method according to any one of the preceding claims, characterized in that the communication network is a home network, the access point comprising an internet connection router.
11. Communication network for increasing the security level of a Wi-Fi access point capable of communicating with several Wi-Fi stations, the communication network comprising a Wi-Fi access point, characterized in that the access point is configured to implement a method according to any one of the preceding claims.
12. Computer program product comprising instructions which, when the program is executed by a processing unit in an access point or in a remote server, cause the latter to put into implements the method according to any one of claims 1 to 10.