Access point verification

By authenticating Wi-Fi APs using PKCs before connection, the method addresses insecure and confusing SSIDs, improving network security and user confidence in public Wi-Fi connections.

WO2026084628A1PCT designated stage Publication Date: 2026-04-23TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2024-10-18
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

Current Wi-Fi network identification methods using SSIDs are insecure and confusing, leading to increased cyber security risks and user uncertainty when connecting to public networks.

Method used

A method for verifying Wi-Fi access points (APs) using public key certificates (PKCs) to authenticate the AP before connection, allowing devices to display verified SSIDs, reducing uncertainty and enhancing security.

Benefits of technology

Enhances security and clarity in connecting to Wi-Fi networks by ensuring only authenticated and trusted APs are displayed to users, thereby reducing cyber security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050890_23042026_PF_FP_ABST
    Figure SE2024050890_23042026_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure provides method and apparatus to verify an Access Point, AP (102), providing access to an IEEE 80211 network. The method comprises a wireless device (101) receiving (201, 602, 702), from the AP (102), a broadcast message comprising a Service Set Identifier, SSID, of the AP (102). The WD (101) transmitting (202, 603, 703), to the AP (102), a request to access the AP (102). The WD (101) transmitting (203, 605, 705), to the AP (102), a first message comprising a second indication to verify the AP, in response to receiving (604, 704), from the AP (102), a response for the transmitted request. The WD (101) receiving (204, 609, 710), from the AP (102), a second message comprising a third indication indicating a certificate associated with the AP (102) verification and verifying (205, 610, 711) the certificate associated with the AP (102) verification.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] ACCESS POINT VERIFICATION

[0002] TECHNICAL FIELD

[0003] The disclosure relates to methods performed by a wireless device, an access point and a server, computer programs and computer program products comprising the computer programs, to verify the access point providing access to an IEEE 802.11 network.

[0004] BACKGROUND

[0005] IEEE 802.11 Standard (Technical Specification), commonly known as Wi-Fi is a set of protocols developed by the Institute of Electrical and Electronics Engineers, IEEE, for wireless local area networks, WLANs. The standard was first released in 1997, and since then, several amendments have been added to improve various aspects such as speed, range, and reliability. The 802.11 family includes various versions like 802.11 a, 802.11 b, 802.11 g, 802.11 n, 802.11 ac, and 802.11 ax (Wi-Fi 6) among others. Each version of 802.11 specifies different characteristics including the frequency bands used, data rates, and modulation techniques.

[0006] A Service Set Identifier SSID is a unique ID that Wi-Fi networks utilize for identification in WLANs structured as per the IEEE 802.11 standard. SSID is primarily utilized to separate one network from other networks in the vicinity and can accommodate up to 32 characters. The SSID is broadcast by a wireless access point, AP. The IEEE 802.11 standard regulates how devices communicate in the WLAN, including routers, wireless devices, and APs.

[0007] Extensible Authentication Protocol, EAP, is an authentication protocol widely utilized in wireless networks and Point-to-Point Protocol, PPP, connections. It was developed by the Internet Engineering Task Force, IETF, for authentication based on a flexible mechanism, allowing the use of various authentication methods. The EAP operates directly over data link layers like IEEE 802 and works effectively for PPP connections.

[0008] Public Key Certificates, PKC, are a technology used to associate the identity of an entity such as a website with its public key. This is achieved using a digital signature from a trusted third party, generally known as a certificate authority, CA. PKCs facilitate a high level of trust in electronic transactions, authenticating a user or device identity on a network. The Authentication, Authorization, and Accounting, AAA, Server handles user / client authentication to authorize user / client requests for access to computer resources and for keeping track of the activities of users / clients. It can be interfaced with multiple protocols including Remote Access Dial-In User Service, RADIUS.

[0009] EP 3 285 513 A1 discloses sending, by a terminal to an associated authentication center when determining that a Wi-Fi network exists in an area in which the terminal is located, a request message that carries a first user identifier, and receiving access verification information sent by the associated authentication center and allocated to a user represented by the first user identifier; sending, to a Wi-Fi authentication center, a login request that carries the access verification information, and receiving authentication information that is fed back by the Wi-Fi authentication center and that carries a second user identifier; and when the second user identifier carried in the authentication information is the same as the first user identifier, determining, by the terminal, that the Wi-Fi network is a secure network.

[0010] Current technology around SSIDs of public Wi-Fi networks presents several problems. First, SSIDs can be confusing and hard to locate, leaving users unsure of which network they are connecting to, which increases the risk of connecting to unsafe networks. Second, SSIDs are strings of text that an entity that controls the Wi-Fi access point arbitrarily decides on. This, in turn, could compromise the security of the user while using public Wi-Fi networks.

[0011] These limitations heighten cyber security risks and contribute to user uncertainty and inconvenience.

[0012] SUMMARY

[0013] An object of the invention to enable a more secure Wi-Fi connection for a wireless device.

[0014] This and other objects of the invention are achieved by means of different aspects of the invention, as defined by the independent claims. Embodiments of the invention are characterized by the dependent claims.

[0015] In a first aspect of the invention, a wireless device performs a method to verify an Access Point, AP, providing access to an IEEE 802.11 network. The method comprises receiving, from the AP, a broadcast message comprising a Service Set Identifier, SSID, of the AP. The method comprises transmitting, to the AP, a request to access the AP in response to the received broadcast message. The method comprises transmitting, to the AP, a first message comprising a second indication to verify the AP, in response to receiving, from the AP, a response for the transmitted request. The method comprises receiving, from the AP, a second message comprising a third indication indicating a certificate associated with the AP verification. The method comprises verifying the certificate associated with the AP verification. Hereby, the invention enables a way to reduce uncertainty involved in connecting to public Wi-Fi networks.

[0016] In a second aspect of the invention, the AP performs a method to verify the AP providing access to an IEEE 802.11 network. The method comprises transmitting to the WD the broadcast message comprising the SSID of the AP. The method comprises transmitting, to the WD, a response to a request, received from the WD, to access the AP. The method comprises receiving, from the WD, the first message comprising the second indication to verify the AP. The method comprises forwarding, to the server associated with the AP, the first message comprising the second indication. The method comprises receiving, from the server, the second message comprising the third indication indicating the certificate associated with AP verification. The method comprises forwarding, to the WD, the second message comprising the third indication. Hereby, the invention enables a way to reduce uncertainty involved in connecting to public Wi-Fi networks.

[0017] In a third aspect of the invention, the server performs a method to verify the AP providing access to an IEEE 802.11 network. The method comprises receiving, from the AP, the first message comprising the second indication to verify the AP. The method comprises selecting the verification method in response to receiving the first message comprising the second indication. The method comprises transmitting, to the AP, the second message comprising the third indication indicating the certificate associated with AP verification. Hereby, the invention enables a way to reduce uncertainty involved in connecting to public Wi-Fi networks.

[0018] According to a fourth aspect of the invention, there is presented a computer program comprising instructions which when executed on a processor of the WD, causes the WD to perform a method according to any of the embodiments of the first aspect. According to a fifth aspect of the invention, there is presented a computer program product which comprises a computer readable storage medium on which a computer program according to the fourth aspect is stored.

[0019] According to a sixth aspect of the invention, there is presented a computer program comprising instructions which when executed on a processor of the AP, causes the AP to perform a method according to any of the embodiments of the second aspect.

[0020] According to a seventh aspect of the invention, there is presented a computer program product which comprises a computer readable storage medium on which a computer program according to the sixth aspect is stored.

[0021] According to an eighth aspect of the invention, there is presented a computer program comprising instructions which when executed on a processor of the server, causes the server to perform a method according to any of the embodiments of the third aspect.

[0022] According to a ninth aspect of the invention, there is presented a computer program product which comprises a computer readable storage medium on which a computer program according to the eighth aspect is stored.

[0023] Other objectives, features and advantages of the enclosed embodiments will be apparent from the following detailed disclosure, from the attached dependent claims as well as from the drawings.

[0024] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, module, action, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, module, action, etc., unless explicitly stated otherwise. The actions of any method disclosed herein.

[0025] BRIEF DESCRIPTION OF THE DRAWINGS

[0026] A more complete understanding of the present embodiments, and the attendant advantages and features thereof, will be more readily understood by reference to the following detailed description when considered in conjunction with the accompanying drawings wherein:

[0027] Figure 1 illustrates a Wi-Fi network setup and a wireless device according to some embodiments of the present invention.

[0028] Figure 2 illustrates a method performed by the wireless device to verify the access point according to a first embodiment.

[0029] Figure 3 illustrates a method performed by the access point to verify the access point according to the first embodiment of the invention.

[0030] Figure 4 illustrates a method performed by a server to verify the access point according to the first embodiment.

[0031] Figure 5 illustrates a user interface of the wireless device according to some embodiments of the present invention.

[0032] Figure 6 illustrates a method to verify the access point according to a second embodiment.

[0033] Figure 7 illustrates a method to verify the access point according to a third embodiment.

[0034] Figure 8 illustrates an example wireless device according to some embodiments of the present invention.

[0035] Figure 9 illustrates an example access point according to some embodiments of the present invention.

[0036] Figure 10 illustrates an example server according to some embodiments of the present invention.

[0037] DETAILED DESCRIPTION

[0038] The invention tries to provide a solution to the challenge of identifying and connecting to credible IEEE 802.11 networks, also known as Wi-Fi networks. The invention does this by verifying Wi-Fi networks in advance and displaying them as verified Wi-Fi networks indicated by verified SSIDs to users during Wi-Fi network selection. Verified SSID refers to SSID of the Wi-Fi network indicating that the Wi-Fi network has been verified. The proposed solution to improve network identification and security may necessitate modifications to the existing IEEE 802.11 standard for Wi-Fi networks.

[0039] A wireless device, WD, capable of connecting to a Wi-Fi network is referred to as a Wi-Fi capable device. Hereon, WD and Wi-Fi capable device are used interchangeably, and a WD refers to a Wi-Fi capable device. As used herein, a WD refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other wireless devices. Examples of WDs comprises a smartphone, laptop, tablet, or any other device capable of connecting to a Wi-Fi network. Other examples include any wireless device identified by the 3rd Generation Partnership Project (3GPP), including a User Equipment (UE), a narrow band internet of things (NB-loT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE. Communications of the wireless device may be implemented according to a standard such as IEEE 802.11 or according to any other versions of IEEE 802.11 WD in the form of an Internet of Things (loT) device may be a device for use in one or more application domains, these domains comprising, but not limited to, home, city, wearable technology, extended reality, industrial application, and healthcare.

[0040] By way of example, the loT device for a home, an office, a building or an infrastructure may be a baking scale, a coffee machine, a grill, a fridge, a refrigerator, a freezer, a microwave oven, an oven, a toaster, a water tap, a water heater, a water geyser, a sauna, a vacuum cleaner, a washer, a dryer, a dishwasher, a door, a window, a curtain, a blind, a furniture, a light bulb, a fan, an air-conditioner, a cooler, an air purifier, a humidifier, a speaker, a television, a laptop, a personal computer, a gaming console, a remote control, a vent, an iron, a steamer, a pressure cooker, a stove, an electric stove, a hair dryer, a hair styler, a mirror, a printer, a scanner, a photocopier, a projector, a hologram projector, a 3D printer, a drill, a hand-dryer, an alarm clock, a clock, a security camera, a smoke alarm, a fire alarm, a connected doorbell, an electronic door lock, a lawnmower, a thermostat, a plug, an irrigation control device, a flood sensor, a moisture sensor, a motion detector, a weather station, an electricity meter, a water meter, and a gas meter.

[0041] By further ways of example, the loT device for use in a city, urban, or rural areas may be connected street lighting, a connected traffic light, a traffic camera, a connected road sign, an air control / monitor, a noise level detector, a transport congestion monitoring device, a transport controlling device, an automated toll payment device, a parking payment device, a sensor for monitoring parking usage, a traffic management device, a digital kiosk, a bin, an air quality monitoring sensor, a bridge condition monitoring sensor, a fire hydrant, a manhole sensor, a tarmac sensor, a water fountain sensor, a connected closed circuit television, a scooter, a hoverboard, a ticketing machine, a ticket barrier, a metro rail, a metro station device, a passenger information panel, an onboard camera, and other connected device on a public transport vehicle.

[0042] As further way of example, the communication loT device may be a wearable device, or a device related to extended reality, wherein the device related to extended reality may be a device related to augmented reality, virtual reality, merged reality, or mixed reality. Examples of such loT devices may be a smart-band, a tracker, a haptic glove, a haptic suit, a smartwatch, clothes, eyeglasses, a head mounted display, an ear pod, an activity monitor, a fitness monitor, a heart rate monitor, a ring, a key tracker, a blood glucose meter, and a pressure meter.

[0043] As further ways of example, the loT device may be an industrial application device wherein an industrial application device may be an industrial unmanned aerial vehicle, an intelligent industrial robot, a vehicle assembly robot, and an automated guided vehicle.

[0044] As further ways of example, the loT device may be a transportation vehicle, wherein a transportation vehicle may be a bicycle, a motor bike, a scooter, a moped, an auto rickshaw, a rail transport, a train, a tram, a bus, a car, a truck, an airplane, a boat, a ship, a ski board, a snowboard, a snow mobile, a hoverboard, a skateboard, rollerskates, a vehicle for freight transportation, a drone, a robot, a stratospheric aircraft, an aircraft, a helicopter and a hovercraft.

[0045] A Wi-Fi capable device, with Wi-Fi option enabled in the device, will constantly scan for Wi-Fi networks, i.e. , listen to Access Points, APs, broadcasting SSIDs. The WD will list the SSIDs of the Wi-Fi networks that the device had received during the broadcasting by the APs. A user of the Wi-Fi capable device can manually choose, from the listed SSIDs, an SSID of the Wi-Fi network that they want to connect to. Alternatively, if the Wi-Fi networks / SSIDs are known from before, the user might have configured the wireless device to automatically connect to a known (specific) Wi-Fi network.

[0046] Two approaches are disclosed by the invention on how the Wi-Fi network provided by an AP can be verified by the WD. Both solutions rely on the WD verifying the AP provider’s public key certificate, PKC, before the user connects to the Wi-Fi network or performs the SSID selection process.

[0047] As a result of verifying the AP provider, the wireless device is able to connect to the AP / SSID provided by an authentic AP provider. The user of the wireless device can find information about the verified AP provider. The information about the verified AP provider can be provided in a Wi-Fi network selection interface. Based on the information about the verified AP provider, an informed choice of Wi-Fi network or SSID can be made.

[0048] Figure 1 illustrates one or more Wi-Fi networks and a WD 101 according to some embodiments of present invention. The Wi-Fi networks 100a, 100b and 100c are provided by one or more access points, APs, 102a, 102b, 102c, respectively.

[0049] The WD 101 communicates with the AP (AP 102a or 102b or 102c) to establish a WiFi network connection and exchange data.

[0050] The AP 102a is a network device that allows WDs, such as WD 101 , to connect to a wireless network, e.g., Wi-Fi network. The AP 102a provides access to a Wi-Fi network 100a. The WD 101 may connect to Wi-Fi network 100a through a wireless connection 101 a. The AP 102a is associated with a server 103a. The server 103a is hosted by a network provider.

[0051] The AP 102b is a networking device that allows WDs, such as WD 101 , to connect to a wireless network. The AP 102b provides access to a Wi-Fi network 100b. The WD 101 may connect to Wi-Fi network 100b through a wireless connection 101 b. The AP 102b is associated with a server 102b. The server 103b is hosted by a network provider.

[0052] The AP 102c is a networking device that allows WDs, such as WD 101 , to connect to a wireless network. The AP 102c provides access to a Wi-Fi network 100c. The WD 101 may connect to Wi-Fi network 100c through a wireless connection 101 c. The AP 102c is associated with a server 102c. The server 103c is hosted by a network provider.

[0053] As shown in Figure 1 , the WD 101 is in the proximity of APs 102a, 102b and 102c. The WD 101 is located within a coverage area of the AP 102a, 102b and 102c. The coverage area of the AP 102a, 102b and 102c may overlap with one another. The wireless device 101 is capable of connecting to any of the Wi-Fi networks 100a, 100b or 100c.

[0054] Herein, AP 102 refers to AP 102a orAP 102b orAP 102c. Wi-Fi network 100 refers to Wi-Fi network 100a or Wi-Fi network 100b or Wi-Fi network 100c. Server 103 refers to server 103a or server 103b or server 103c.

[0055] The AP 102 serves as a central hub for the wireless network, allowing multiple devices to connect and communicate with each other and with the server 103 associated with the AP 102. The AP 102 provides the WD 101 with access to the network infrastructure and the services offered by the server 103. The server 103, hosted by a network provider, is a computer system that stores and processes data, and provides services to the wireless devices connected to the network. The server 103 may host applications, databases, or other resources that the wireless devices can access over the network. The WD 101 communicates with the AP 102 using wireless signals, and the AP 102 in turn is connected to the server 103 via a wired or wireless connection. The network provider is responsible for hosting and maintaining the server 103, ensuring that the server 103 is accessible to the AP 102 and the devices connected to the Wi-Fi network 100.

[0056] Together, these components form a system that enables wireless communication and data exchange between the WD 101 and the server 103, with the AP 102 serving as the intermediary.

[0057] Figure 2 refers to a method 200 performed by the wireless device to verify the access point according to a first embodiment of the invention. The method 200 is performed by the WD 101 to verify the AP 102 providing access to the Wi-Fi network 100. The method 200 comprises receiving, 201 , from the AP 102, a broadcast message. The broadcast message comprises an SSID of the AP 102. The method 200 comprises transmitting, 202, to the AP 102, a request to access the AP 102, in response to the received broadcast message. The method 200 comprises transmitting, 203, to the AP 102, a first message. The first message comprises a second indication to verify the AP 102. Transmitting, 203, the first message in response to receiving, from the AP 102, a response for the transmitted request. The method 200 comprises receiving, 204, from the AP 102, a second message comprising a third indication indicating a certificate associated with the AP 102 verification. The method 200 comprises verifying, 205, the certificate associated with the AP 102 verification. The method 200 may comprise receiving, 206, a third message from the AP 102. The third message indicates that the verification of the AP 102 is completed. Upon receiving the third message, the WD 101 may display, 207, the SSID of the AP 102. The WD 101 may display, 207, the SSID of the AP 102 by denoting that the AP 102 has been verified.

[0058] Figure 5 illustrates a user interface of the wireless device according to some embodiments of the present invention. As shown in Figure 5, the SSID of the verified AP 102 is displayed under a category titled “Verified Networks”, thereby, denoting that the one or more APs have been verified. The WD 101 may, according to method 200, verify each AP 102a, 102b and 102c. The verification of each AP 102a, 102b and 102c can be done parallelly or sequentially. Upon verification, the WD 101 may obtain a list of SSIDs wherein each SSID in the list corresponds to a verified AP. The WD 101 may display the list of SSIDs. As shown in Figure 5, the list of SSIDs can be displayed under the category titled “Verified Networks”.

[0059] Figure 3 refers to a method 300 performed by the access point to verify the access point according to the first embodiment of the invention. The method 300 performed by the AP 102, to verify the AP 102 providing access to the Wi-Fi network 100. The method 300 comprises transmitting, 301 , to the WD 101 , the broadcast message. The broadcast message comprises the SSID of the AP 102. The method 300 comprises transmitting, 302, to the WD 101 , the response to the request received from the WD 101 to access the AP 102. The method 300 comprises receiving, 303, from the WD 101 , the first message comprising the second indication to verify the AP 102. The method comprises forwarding, 304, the first message comprising the second indication to the server 103 associated with the AP 102. The method 300 comprises receiving, 305, from the server 103, the second message comprising the third indication indicating the certificate associated with AP 102 verification. The method 300 comprises forwarding, 305, to the WD 101 , the second message comprising the third indication. The method 300 may comprise receiving, 307, the third message from the server 103. The third message indicates that the verification of the AP 102 is completed. The method 300 may comprise forwarding, 308, the third message to the WD 101.

[0060] Figure 4 refers to a method 400 performed by a server to verify the access point according to the first embodiment of the invention. The method 400 performed by the server 103 associated with the AP 102. The method 400 performed by the server 103 to verify the AP 102 providing access the Wi-Fi network 100. The method 400 comprises receiving, 401 , from the AP 102, the first message comprising the second indication to verify the AP 102. The method 400 comprises selecting, 402, a verification method in response to receiving the first message comprising the second indication. The method 400 comprises transmitting, 403, to the AP 102, the second message comprising the third indication indicating the certificate associated with AP 102, verification. The method 400 may comprise transmitting, 404, the third message to the AP 102.

[0061] Figure 6 refers to a method 600 to verify the access point according to a second embodiment of the invention. In the second embodiment, the AP 102 can be referred to as an extensible authentication protocol, EAP, authenticator. In the second embodiment, the server 103 can be referred to as an EAP authentication server.

[0062] The method 600 comprises the WD 101 scanning, 601 a, for SSIDs. The method comprises the AP 102 or the EAP authenticator broadcasting, 601 b, its SSID. The AP 102 broadcasts its SSID by transmitting the broadcast message comprising the SSID. The broadcast message comprises the SSID of the AP 102. The broadcast message may comprise a first indication indicating the possibility to verify the AP 102. The scanning 601 a and the broadcasting 601 b may occur simultaneously. The first indication comprised in the broadcast message may denote a possibility to verify the AP 102. The first indication may comprise a parameter in the broadcast message. The first indication may comprise a parameter embedded in the SSID. For example, the parameter embedded in the SSID can be a prefix “ver” indicating the support, such as, “ver-<SSID>”. The first indication can be a combination of the parameter in the broadcast message and the parameter embedded in the SSID.

[0063] The method 600 comprises the WD 101 receiving, 602, the broadcast message comprising the SSID and optionally, the first indication indicating the possibility to verify the AP 102. The WD 101 may identify the first indication comprised in the broadcast message and may determine to initiate a process of verification. The WD 101 may initiate the process of verification upon receiving the broadcast message comprising the SSID of the AP 102. The process of verification comprises EAP based authentication. In response to the first indication comprised in the broadcast message or in response to receiving the broadcast message comprising the SSID of the AP 102, the WD 101 transmits, 603, to the AP 102, the request to access the AP 102. The request to access the AP 102 comprises an access request. A Wi-Fi client or the WD 101 would typically transmit the access request to an AP (such as AP 102) in order to connect to a Wi-Fi network provided by AP (such as AP 102). However, in the invention disclosed access request is used for verifying the AP. The WD 101 initiates the AP verification based on EAP by transmitting the request to access the AP 102.

[0064] The method 600 comprises, the AP (EAP authenticator) 102, transmitting, 604, the response to the WD 101 for the received request. The response may comprise an EAP identity request.

[0065] In response to receiving the EAP identity request, the method 600 comprises, the WD 101 , transmitting, 605, the first message to the AP 102. The first message comprises the second indication to verify the AP 102. For example, the first message comprises an EAP identity response. The second indication is comprised in an identity field of the EAP identity response. The second indication indicates an intention of the WD 101 to verify theAP 102. For example, the second indication can be an identifier in an identity field of the EAP identity response, such as, Identity- ’ SSI D_Verification”. Since the verification of the AP 102 may not require authenticating the WD 101 , the identity of the WD 101 transmitting the EAP identity response need not to be communicated in the EAP identity response. Thus, the identity field of the EAP identity response message may comprise the identifier indicating the AP 102 verification. For example, the identity field may comprise the identifier ”SSID_Verification”, ldentity=”SSID_Verification”. Alternatively, the second indication can be an identifier in other fields of the EAP identity response message or even other messages of the EAP authentication process. However, by including it in the EAP identity response, the intention of the WD 101 to verify the AP 102 is conveyed to the EAP authentication server 103 before the server 103 selects EAP method. Therefore, making it possible for the server 103 to choose a suitable method for AP 102 verification. The method 600 comprises, the AP 102, forwarding, 605, the first message comprising the second indication to the server (EAP server) 103 associated with the AP 102. The EAP server 103 handles backend operations of the AP 102. The sever 103, verifies that the EAP identity response message comprising the second indication came from a trusted and known AP 102. The method 600 comprises, the EAP server 103, selecting, 607, the EAP method in response to receiving the first message comprising the second indication. When the EAP server 103 identifies the second indication comprised in the first message, the EAP server 103 selects an EAP method suitable for verifying the AP 102. The verification method may comprise an EAP method. The verification method may comprise a tunnelled method, such as Extensible Authentication Protocol-Tunnelled Transport Layer Security, EAP-TTLS. By using the EAP-TTLS method, the WD 101 need not be authenticated as part of the verification method. The verification method may comprise some other method not requiring WD 101 authentication. The verification method may comprise some other non-tunnelled method not requiring WD 101 authentication. The EAP method supports a certificatebased server authentication. As part of the EAP method, a certificate of the server is made available to the WD 101. The method 600 comprises transmitting, 608, to the AP 102, the second message comprising the third indication indicating the certificate associated with AP 102 verification. The second message comprises an EAP request message. The third indication may comprise an identifier to the certificate associated with AP verification. The third indication may comprise a reference or an identifier to the certificate associated with AP verification. The third indication may comprise the certificate associated with AP verification. The third indication may comprise a signature. The certificate associated with theAP 102 may comprise a certificate of the server 103. The certificate associated with theAP 102 may comprise a public key and the signature comprised in the third indication has been created using a private key corresponding to the public key. The signature is created by the server and is based on exchanged protocol data including random data selected by both the client and the server.

[0066] The method 600 comprises, the WD 101 , verifying, 610, the certificate associated with the AP verification. Verifying comprises verifying using a public key comprised in the certificate associated with AP verification. The WD 101 utilizes a public key comprised in the certificate of the server 103 to verify the certificate. Verifying, 610, comprises verifying the certificate associated with AP verification and verifying the signature comprised in the third indication using the public key comprised in the certificate associated with AP verification. The signature is verified by the WD using its version of exchanged protocol data.

[0067] Information that EAP messages exchange and EAP based authentication are being performed for the purpose of AP verification is indicated, to WD 101 by the server 103, by a new parameter added to one of the EAP messages or by an existing parameter configured in one of the EAP messages. As part of the above EAP messages exchange, the EAP server 103 may relay back to the WD 101 an indication that the EAP messages exchange and related authentication are being performed for the purpose of AP verification by adding / configuring a parameter in one of the EAP messages. Or, by using a known value in place of the server random value used in TLS exchanges. Or, by using a known value as a pre-shared key in Transport Layer Security, TLS, extension (if EAP-TLS v1.3 is used).

[0068] If EAP-TTLS is selected and used for verifying the AP 102, or if some other tunneled method is selected and used, a tunnel is established between the server 103 and the WD 101 upon successful verification of the certificate. Establishment of the tunnel may indicate to the server 103 that the server 103 has been successfully authenticated by the WD 101 , thereby, indicating that the AP 102 has been verified. In such a scenario, authentication of the WD 101 may not be performed as it is not relevant for AP 102 verification.

[0069] Upon verification of the certificate, the server 103 may conclude the EAP based authentication process by transmitting, 611 , the third message to theAP 102. The third message may comprise an EAP success message. The method 600 comprises, the AP 102, forwarding, 612, the third message to the WD 101. The third message indicates that the AP 102 verification is completed.

[0070] The communication of EAP messages between AP 102 and EAP server 103, as described above, are performed by using Remote Access Dial-In User Service, RADIUS, or Diameter protocol.

[0071] The EAP server 103 may also transmit, 613, a fourth message to the AP or EAP Authenticator 102 to indicate the AP 102 to terminate EAP method with the WD 101. The fourth message may comprise a RADIUS Disconnect request message. The fourth message indicates the AP 102 to terminate the EAP based authentication process so that the AP 102 does not provide network access to the WD 101 . The AP 102 is not made aware that the EAP based authentication is carried out for verifying the AP 102 and not for enabling the WD 101 to connect to the Wi-Fi network 100 provided by the AP 102. That is, typically EAP based authentication is done for enabling the WD 101 to connect to the Wi-Fi network 100 provided by the AP 102. Meanwhile, in the invention disclosed here, EAP based authentication is carried out for verifying the AP 102 providing the Wi-Fi network 100. The AP 102 may not need to be informed about the EAP based authentication being carried out for verifying the AP 102. An indication to terminate the EAP authentication could optionally be comprised in a RADIUS protocol message that carries the EAP success message.

[0072] Upon receiving the third message, the WD 101 may display, 614, the SSID of the AP 102. The WD 101 may display the SSID of the AP by denoting that the AP 102 has been verified. As shown in Figure 5, the SSID of the verified AP is be displayed under a category titled “Verified Networks”, thereby, denoting that the AP has been verified. The WD 101 may, according to method 600, verify each AP 102a, 102b and 102c. The verification of each AP 102a, 102b and 102c can be done parallelly or sequentially. Upon verification, the WD 101 may obtain a list of SSIDs wherein each SSID in the list corresponds to a verified AP. The WD 101 may display the list of SSIDs. As shown in Figure 5, the list of SSIDs can be displayed under the category titled “Verified Networks”.

[0073] For network providers with a PKC for their website, the same PKC can be used for the AP 102 verification. In this case, the server 103 can be configured to identify when a request relates to AP verification and when a request relates to a HTTPS session establishment so as to prevent a malicious party from acting as an AP towards the WD 101 and as a web client towards the server 103. By having the indication in the EAP exchange, such as the second indication (a specially formatted identity) in the EAP identity response, as discussed above, the exchange can be identified as a part of AP verification process. By having the second indication, the server 103 can make sure to only participate in such exchanges with entities / APs it knows and trusts (and owns).

[0074] Figure 7 refers to a method 700 to verify the access point according to a second embodiment of the invention. In the second embodiment, the AP 102 can be referred to as the EAP authenticator. In the second embodiment, the server 103 can be referred to as the EAP authentication server.

[0075] The method 700 comprises the WD 101 scanning, 701a, for SSIDs. The method comprises the AP 102 or the EAP authenticator broadcasting, 701 b, its SSID. The AP 102 broadcasts its SSID by transmitting the broadcast message comprising the SSID. The broadcast message comprises the SSID of the AP 102. The broadcast message may comprise the first indication indicating the possibility to verify the AP 102. The scanning 701a and the broadcasting 701 b may occur simultaneously. The possibility to verify the AP 102 is denoted by the first indication comprised in the broadcast message. The first indication may comprise a parameter in the broadcast message. The first indication may comprise a parameter embedded in the SSID. For example, the parameter embedded in the SSID can be a prefix “ver” indicating the support, such as, “ver-<SSID>”. The first indication can be a combination of the parameter in the broadcast message and the parameter embedded in the SSID.

[0076] The method 700 comprises the WD 101 receiving the broadcast message comprising the SSID and optionally, the first indication indicating the possibility to verify the AP 102. The WD 101 may identify the first indication in the broadcast message and may determine to initiate a process of verification. The WD 101 may initiate the process of verification upon receiving the broadcast message comprising the SSID of the AP 102. The process of verification comprises EAP based authentication. In response to the first indication comprised in the broadcast message or in response to receiving the broadcast message comprising the SSID of the AP 102, the WD 101 transmits, 703, to the AP 102, the request to access the AP 102. The request to access the AP 102 comprises the access request. A Wi-Fi client or the WD 101 would typically transmit the access request to an AP (such as AP 102) in order to connect to a Wi-Fi network provided byAP (such as AP 102). However, in the invention disclosed EAP is used for verifying theAP. The WD 101 initiates theAP verification based on EAP by transmitting the request to access the AP 102.

[0077] The method 700 comprises, the AP (EAP authenticator) 102, transmitting, 704, the response to the WD 101 for the received request. The request may comprise the EAP identity request. In response to receiving the EAP identity request, the method 700 comprises, the WD 101 , transmitting, 705, to the AP 102, the first message. The first message comprising the second indication to verify the AP 102. The first message comprises the EAP identity response. The second indication is comprised in an identity field of the EAP identity response. Since the verification of the AP 102 may not require authenticating the WD 101 , the identity of the WD 101 transmitting the EAP identity response need not to be communicated in the EAP identity response. The identifier may mask the identity of the WD 101. The identifier may denote WD 101 as anonymous. For example, the identifier may comprise a network access identifier, NAI, “@realm”, as supported in EAP-TLS v1.3 or EAP-TLS v1.2 with privacy extension. The identifier may comprise “anonymous@realm” as supported in EAP-TLS v1.3 or EAP-TLS v1.2 with privacy extension. The identifier may also explicitly indicate the purpose of AP verification by e.g. having “AP_verification” as identifier.

[0078] The method 700 comprises, the AP 102, forwarding, 705, the first message comprising the second indication to the server (EAP server) 103 associated with the AP 102. The EAP server 103 handles backend operations of the AP 102. The sever 103, as is normal, verifies that the EAP identity response message comprising the second indication came from a trusted and known AP 102. The method 700 comprises, the EAP server 103, selecting, 707, the EAP method in response to receiving the first message comprising the second indication. When the EAP server 103 identifies the second indication comprised in the first message the EAP server 103 selects an EAP method suitable for verifying the AP 102. The EAP server 103, on determining that the second indication denotes anonymous or the second indication is masking the identity of the sender of the EAP identity response or the second indication is explicitly signaling an AP verification request, selects (e.g.) Extensible Authentication Protocol- Transport Layer Security, EAP-TLS, as the authentication method. The EAP Server 103 and WD 101 begin the EAP-TLS exchange wherein the EAP server 103 transmits, 708, an EAP request comprising a TLS Start trigger to the WD 101 via the AP 102. The WD 101 responds, 709, with an EAP response comprising a TLS Client Hello.

[0079] The method 700 comprises, the server 103, transmitting, 710, via the AP 102 to the WD 101 , the second message comprising the third indication indicating the certificate associated with AP 102 verification. The second message comprises an EAP request message. The third indication may comprise a reference or an identifier to the certificate associated with AP verification. The third indication may comprise the certificate associated with AP verification. The third indication may comprise a signature. The certificate associated with theAP 102 may comprise a certificate of the server 103. The certificate associated with theAP 102 may comprise a public key and the signature comprised in the third indication has been created using a private key corresponding to the public key.

[0080] The second message may also comprise a TLS Server Hello, a TLS request for the WD 101 certificate (TLS CertificateRequest message), and a TLS CertificateVerify message comprising the EAP Server 103 signature over the exchanged TLS messages. The TLS CertificateRequest message can also be sent in EAP-TLS with TLS v1.2 with the privacy extension where no WD 101 certificate is returned.

[0081] The method 700 comprises, the WD 101 , verifying, 711 , the certificate associated with the AP verification. The WD 101 utilizes a public key comprised in the certificate of the server 103 to verify the certificate. Verifying, 711 , comprises verifying the certificate associated with AP verification and verifying the signature comprised in the third indication using the public key comprised in the certificate associated with AP verification. The WD 101 may verify the EAP server 103 certificate (possibly a chain of certificates). The WD may use the public key comprised in the EAP server 103 certificate to authenticate the server 103. The WD may use a signature comprised in the TLS CertificateVerify message to verify the EAP server 103 certificate. The WD 101 may also verify that the second message comprises a request for the WD 101 certificate (TLS CertificateRequest message). The TLS CertificateRequest message indicates to the WD 101 that the EAP-TLS protocol is running in client authentication mode.

[0082] Upon successful verification, the WD 101 may transmit, to the AP 102, an alert message indicating the server 103 to abort EAP based verification. The AP 102 may forward the alert message to the server 103. Upon receiving the alert message indicating to abort the EAP based verification to the server 103, the server 103 may abort the EAP based verification process.

[0083] Upon successful verification of the certificate, the WD 101 may abort the EAP authentication process, by transmitting, 712, to the EAP server 103 a TLS alert via AP 102. For example, the TLS alert may comprise existing TLS alert message close_notify or TLS alert message user_canceled. Or, a new alert may be defined. In receiving, 712, the TLS alert from WD 101 via the AP 102, the server 103 may transmit an EAP failure message 713. The server 103 transmits the EAP failure message because the WD 101 cancelled the EAP authentication by sending the TLS alert. EAP failure message in this case indicates the closure of EAP authentication process by the WD 101 while the WD 101 has already verified the certificate associated with AP verification. Upon successful verification of the certificate, the server 103 may conclude the EAP authentication process by transmitting, 713, the third message to the WD 101 via the AP 102. The third message may comprise an EAP failure message. The third message indicates that the AP 102 verification is completed.

[0084] As an alternative to sending an alert message upon successful verification of the certificate, the WD 101 may on purpose indicate, in a response message to the second message, that some error occurred during processing of the second message even though it did not, and transmit this response message to the server 103 via the AP 102 instead of the alert message. When receiving such a response message the server may conclude the EAP authentication process by transmitting, 713, the third message to the WD 101 via the AP 102, where the third message comprises the EAP failure message. In yet another alternative, upon successful verification of the certificate, the WD 101 may on purpose not transmit a response message to the second message. When a timer expires in the server 103, the server may conclude the EAP authentication process by transmitting, 713, the third message to the WD 101 via the AP 102, where the third message comprises the EAP failure message.

[0085] Upon receiving the third message, the WD 101 may display, 714, the SSID of the AP 102. The WD 101 may display the SSID of the AP by denoting that the AP 102 has been verified. As shown in Figure 5, the SSID of the verified AP can be displayed under a category titled “Verified Networks”, thereby, denoting that the AP has been verified. The WD 101 may, according to method 600, verify each AP 102a, 102b and 102c. The verification of each AP 102a, 102b and 102c can be done parallelly or sequentially. Upon verification, the WD 101 may obtain a list of SSIDs wherein each SSID in the list corresponds to a verified AP. The WD 101 may display the list of SSIDs. As shown in Figure 5, the list of SSIDs can be displayed under the category titled “Verified Networks”. The WD 101 may further display domain information corresponding to the SSID of the AP 102a, 102b or 102c. Domain information comprises information about a domain to which the certificate associated with AP (102a, 102b or 102c) verification belongs. The WD 101 may display the domain information corresponding to each SSID (for example, SSID of AP 102a, SSID of AP 102b or SSID of AP 102c) listed under the category “Verified Networks”.

[0086] Figure 8 illustrates examples of the WD 101 according to some embodiments of the present invention. The WD 101 illustrated in Figure 8 implements the methods 200, 600 and 700 as illustrated in Figures 2, 6 and 7, respectively, for example on receipt of suitable instructions from a computer program 801. The WD 101 comprises a processor or processing circuitry 802, and a computer program product 804 in the form of a memory 803. The processing circuitry 802 is operable to perform one or more steps of the methods 200, 600 and 700 as illustrated in Figures 2, 6 and 7, respectively. The memory 803 contains instructions executable by the processing circuitry 802 such that the WD 101 is operable to perform some or all of the steps of the methods 200, 600 and 700 as illustrated in Figures 2, 6 and 7, respectively. The instructions may also include instructions for executing one or more telecommunications and / or data communications protocols. The instructions may be stored in the form of the computer program 801. In some examples, the processor or processing circuitry 802 may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, etc. The processor or processing circuitry 802 may be implemented by any type of integrated circuit, such as an Application Specific Integrated Circuit (ASIC), Field Programmable Gate Array (FPGA), etc. The memory 803 may include one or several types of memory suitable for the processor, such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, solid state disk, hard disk drive, etc.

[0087] Figure 9 illustrates examples of the AP 102 according to some embodiments of the present invention. The AP 102 illustrated in Figure 9 implements the methods 300, 600 and 700 as illustrated in Figures 3, 6 and 7, respectively, for example on receipt of suitable instructions from a computer program 901 . The AP 102 comprises a processor or processing circuitry 902, and a computer program product 904 in the form of a memory 903. The processing circuitry 902 is operable to perform some or all of the steps of the methods 300, 600 and 700 as illustrated in Figures 3, 6 and 7, respectively. The memory 903 contains instructions executable by the processing circuitry 902 such that the AP 102 is operable to perform some or all of the steps of the methods 300, 600 and 700 as illustrated in Figures 3, 6 and 7, respectively. The instructions may also include instructions for executing one or more telecommunications and / or data communications protocols. The instructions may be stored in the form of the computer program 901. In some examples, the processor or processing circuitry 902 may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, etc. The processor or processing circuitry 902 may be implemented by any type of integrated circuit, such as an Application Specific Integrated Circuit (ASIC), Field Programmable Gate Array (FPGA), etc. The memory 903 may include one or several types of memory suitable for the processor, such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, solid state disk, hard disk drive, etc.

[0088] Figure 10 illustrates examples of the server 103 according to some embodiments of the present invention. The server 103 illustrated in Figure 10 implements the methods 400, 600 and 700 as illustrated in Figures 4, 6 and 7, respectively, for example on receipt of suitable instructions from a computer program 1001. The server 103 comprises a processor or processing circuitry 1002, and a computer program product 1004 in the form of a memory 1003. The processing circuitry 1002 is operable to perform some or all of the steps of the methods 400, 600 and 700 as illustrated in Figures 4, 6 and 7, respectively. The memory 1003 contains instructions executable by the processing circuitry 1002 such that the server 103 is operable to perform some or all of the steps of the methods 400, 600 and 700 as illustrated in Figures 4, 6 and 7, respectively. The instructions may also include instructions for executing one or more telecommunications and / or data communications protocols. The instructions may be stored in the form of the computer program 1001. In some examples, the processor or processing circuitry 1002 may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, etc. The processor or processing circuitry 1002 may be implemented by any type of integrated circuit, such as an Application Specific Integrated Circuit (ASIC), Field Programmable Gate Array (FPGA), etc. The memory 1003 may include one or several types of memory suitable for the processor, such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, solid state disk, hard disk drive, etc.

[0089] The disclosed embodiments of the invention enhance the security of public Wi-Fi networks by preventing rogue Wi-Fi hotspot providers / APs from impersonating legitimate hotspots / APs. The invention safeguards Wi-Fi users’ valuable data from phishing attacks and other types of cyber threats. This makes it safer and more reliable for users to connect to public Wi-Fi networks. The disclosed approach simplifies the process of connecting to a Wi-Fi network. Users do not have to seek out and decipher the correct Wi-Fi network from a potentially long list of available Wi-Fi networks. Since the verified Wi-Fi networks are presented with an indication that they are verified and are presented in a separate category, users can select Wi-Fi network provided by verified APs with confidence, knowing they are trusted networks. The presented disclosure eliminates uncertainty involved in connecting to public Wi-Fi networks. The disclosure provides a way to reuse existing digital certificates to strengthen the trust established between the user and the Wi-Fi network providers.

[0090] It is to be understood that the singular form "a," "an," and "the" include plural referents unless the context clearly dictates otherwise. It will be further understood that the terms, "comprises" "comprising", "includes" and / or "including" when used herein, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0091] While various embodiments of the present disclosure are described, it should be understood that they have been presented by the way of example only, and not limitations. Thus, the breadth and scope of the present disclosure should not be limited by any of the above-described exemplary embodiments. Moreover, any combination of the above-described elements in all possible variations thereof is comprised by the disclosure unless otherwise indicated herein or otherwise clearly contradicted by context. Additionally, while the processes described above and illustrated in the drawings are shown as a sequence of steps this was done for the sake of illustration. It is contemplated that some steps may be added, some steps omitted, the order of the steps may be re-arranged, and some steps may be performed in parallel.

Claims

CLAIMS1 . A method (200, 600, 700) to verify an Access Point, AP (102), providing access to an IEEE 802.11 network (100), the method (200, 600, 700) being performed by a wireless device, WD (101 ), the method comprising: receiving (201 , 602, 702), from the AP (102), a broadcast message comprising a Service Set Identifier, SSID, of the AP (102); transmitting (202, 603, 703), to the AP (102), a request to access the AP (102) in response to the received broadcast message; transmitting (203, 605, 705), to the AP (102), a first message comprising a second indication to verify the AP, in response to receiving (604, 704), from the AP (102), a response for the transmitted request; receiving (204, 609, 710), from the AP (102), a second message comprising a third indication indicating a certificate associated with the AP (102) verification; and verifying (205, 610, 711 ) the certificate associated with the AP (102) verification.

2. The method (200, 600, 700) according to claim 1 , wherein the broadcast message comprises a first indication indicating a possibility to verify the AP (102).

3. The method (200, 600, 700) according to claim 2, wherein the first indication comprises a parameter in the broadcast message.

4. The method (200, 600, 700) according to claim 2 or 3, wherein the first indication comprises a parameter embedded in the SSID.

5. The method (200, 600, 700) according to any of claims 1 -4, wherein the request comprises an access request.

6. The method (200, 600, 700) according to any of claims 1 -5, wherein the received response for the transmitted request comprises an extensible authentication protocol, EAP, identity request.

7. The method (200, 600, 700) according to any of claims 1-6, wherein the first message comprises an EAP identity response.

8. The method (200, 600, 700) according to claim 7, wherein the second indication is comprised in an identity field of the EAP Identity response.

9. The method (200, 600, 700) according to claim 8, wherein the second indication comprised in the identity field of the EAP identity response indicates that the AP (102) is to be verified by the WD (101 ).

10. The method (200, 600, 700) according to any of claims 1 -9, wherein the second message comprises an EAP request message.11 . The method (200, 600, 700) according to any of claims 1 -10, wherein the third indication comprises the certificate associated with AP (102) verification.

12. The method (200, 600, 700) according to any of claims 1 -10, wherein the third indication comprises a reference to the certificate associated with AP (102) verification.

13. The method (200, 600, 700) according to any of claims 1 -12, wherein the third indication comprises a signature.

14. The method (200, 600, 700) according to any of claims 1-13, wherein the certificate associated with AP (102) verification is provided by a server (103) associated with the AP (102).

15. The method (200, 600, 700) according to any of claims 1 -14, wherein the certificate associated with AP (102) verification is a certificate of the server (103) associated with the AP (102).

16. The method (200, 600, 700) according to any of claims 13-15, wherein the certificate associated with AP (102) verification comprises a public key and thesignature comprised in the third indication is created using a private key corresponding to the public key.

17. The method (200, 600, 700) according to claim 16, wherein verifying (205, 610, 711 ) the certificate associated with AP (102) verification further comprises verifying the signature using the public key comprised in the certificate associated with AP verification.

18. The method (200, 600, 700) according to any of claims 1 -17, comprising transmitting, to the AP (102), upon successful verification, an alert message indicating the server (103) to abort EAP based authentication.

19. The method (200, 600, 700) according to any of claims 1 -18, comprising receiving a third message (206, 612, 713) indicating completion of AP (102) verification.

20. The method (200, 600, 700) according to any of claims 1 -19, wherein the third message comprises an EAP success message or an EAP failure message.

21. The method (200, 600, 700) according to any of claims 1 -20, comprising obtaining a list of SSIDs wherein each SSID in the list corresponds to a verified AP.

22. The method (200, 600, 700) according to any of claims 1 -21 , comprising displaying (207, 614, 714) the SSID of the AP or the obtained list of SSIDs, with an indication that the SSID of the AP or the obtained list of SSIDs have been verified.

23. The method (200, 600, 700) according to any of claims 1 -22, wherein information that EAP messages exchange and EAP based authentication are being performed for the purpose of AP verification is indicated, to WD 101 by the server 103, by a new parameter added to one of the EAP messages or by an existing parameter configured in one of the EAP messages.

24. A method (300, 600, 700) to verify an Access Point, AP (102), providing access to an IEEE 802.11 network (100), the method being performed by the AP (102), the method comprising: transmitting (301 , 601 b, 701 b), to a wireless device, WD (101 ), a broadcast message comprising a Service Set Identifier, SSID, of the AP (102); transmitting (302, 604, 704), to the WD (101 ), a response to a request, received (603, 703) from the WD (101 ), to access the AP (102); receiving (303, 605, 705), from the WD (101 ), a first message comprising a second indication to verify the AP (102); forwarding (304, 606, 706), to a server (103) associated with the AP (102), the first message comprising the second indication; receiving (305, 608, 710), from the server (103), a second message comprising a third indication indicating a certificate associated with AP (102) verification; and forwarding (306, 609, 710), to the WD (101 ), the second message comprising the third indication.

25. The method (300, 600, 700) according to claim 24, wherein the broadcast message comprises a first indication indicating a possibility to verify the AP (102).

26. The method (300, 600, 700) according to claim 25, wherein the first indication comprises a parameter in the broadcast message.

27. The method (300, 600, 700) according to any of claim 24 or 26, wherein the first indication comprises a parameter embedded in the SSID.

28. The method (300, 600, 700) according to any of claims 24-27, wherein the request comprises an access request.

29. The method (300, 600, 700) according to any of claims 24-28, wherein the transmitted response for the received request comprises an extensible authentication protocol, EAP, identity request.

30. The method (300, 600, 700) according to any of claims 24-29, wherein the first message comprises an EAP identity response.

31. The method (300, 600, 700) according to claim 30, wherein the second indication is comprised in an identity field of the EAP identity response.

32. The method (00, 600, 700) according to claim 31 , wherein the second indication comprised in the identity field of the EAP identity response indicates that the AP (102) is to be verified by the WD (101 ).

33. The method (300, 600, 700) according to any of claims 24-32, wherein the second message comprises an EAP request message.

34. The method (300, 600, 700) according to any of claims 24-33, wherein the third indication comprises the certificate associated with AP (102) verification.

35. The method (300, 600, 700) according to any of claims 24-33, wherein the third indication comprises a reference to the certificate associated with AP (102) verification.

36. The method (300, 600, 700) according to any of claims 24-35, wherein the third indication comprises a signature.

37. The method (300, 600, 700) according to any of claims 24-36, wherein the certificate associated with AP (102) verification is provided by the server (103) associated with the AP (102).

38. The method (300, 600, 700) according to any of claims 24-37, wherein the certificate associated with AP (102) verification is a certificate of the server (103) associated with the AP (102).

39. The method (300, 600, 700) according to any of claims 36-38, wherein the certificate associated with AP (102) verification comprises a public key and the signature comprised in the third indication has been created using a private key corresponding to the public key.

40. The method (300, 600, 700) according to any of claims 24-39, comprising: receiving, from the WD (101 ), upon successful verification, an alert message indicating the server (103) to abort EAP based authentication; and forwarding, to the server (103), the alert message.

41. The method (300, 600, 700) according to any of claims 24-40, comprising: receiving (307, 611 , 713), from the server (103), a third message indicating completion of AP 102 verification; and forwarding (308, 612, 713), to the WD (101 ), the third message.

42. The method (300, 600, 700) according to claim 41 , wherein the third message comprises an EAP success message or an EAP failure message.

43. The method (300, 600, 700) according to any of claims 24-42, wherein information that EAP messages exchange and EAP based authentication are being performed for the purpose of AP verification is indicated, to WD 101 by the server 103, by a new parameter added to one of the EAP messages or by an existing parameter configured in one of the EAP messages.

44. A method (400, 600, 700) to verify an Access Point, AP (102), providing access to an IEEE 802.11 network (100), the method (400, 600, 700) being performed by a server (103) associated with the AP (102), the method (400, 600, 700) comprising: receiving (401 , 606, 706), from the AP (102), a first message comprising a second indication to verify the AP (102); selecting (402, 607, 707) a verification method in response to receiving the first message comprising the second indication; and transmitting (403, 608, 710), to the AP (102), a second message comprising a third indication indicating a certificate associated with AP (102) verification.

45. The method (400, 600, 700) according to claim 44, wherein the verification method comprises an extensible authentication protocol, EAP, method.

46. The method (400, 600, 700) according to any of claims 44-45, wherein the EAP verification method comprises an EAP-TTLS verification method or an EAP- TLS method.

47. The method (400, 600, 700) according to any of claims 44-46, wherein the first message comprises an extensible authentication protocol, EAP, identity response.

48. The method (400, 600, 700) according to any of claims 44-47, wherein the second indication is comprised in an identity field of the EAP identity response.

49. The method (400, 600, 700) according to claim 48, wherein the second indication comprised in the identity field of the EAP identity response indicates that the AP (102) is to be verified by the WD (101 ).

50. The method (400, 600, 700) according to any of claims 44-49, wherein the second message sage comprises an EAP request message.51 . The method (400, 600, 700) according to any of claims 44-50, wherein the third indication comprises the certificate associated with AP verification.

52. The method (400, 600, 700) according to any of claims 44-50, wherein the third indication comprises a reference to the certificate associated with AP verification.

53. The method (400, 600, 700) according to any of claims 44-52, wherein the third indication comprises a signature.

54. The method (400, 600, 700) according to any of claims 44-53, wherein the certificate associated with AP (102) verification is provided by the server (103) associated with the AP (102).

55. The method (400, 600, 700) according to any of claims 44-54, wherein the certificate associated with AP (102) verification is a certificate of the server (103) associated with the AP (102).

56. The method (400, 600, 700) according to any of claims 53-55, wherein the certificate associated with AP (102) verification comprises a public key and the signature comprised in the third indication has been created using a private key corresponding to the public key.

57. The method (400, 600, 700) according to any of claims 44-56, comprising: receiving, from the AP (102), upon successful verification an alert message indicating the server (103) to abort EAP based authentication; and aborting EAP based authentication.

58. The method (400, 600, 700) according to any of claims 44-57, comprising transmitting (404, 611 , 713), to the AP (102), a third message indicating completion of AP (102) verification.

59. The method (400, 600, 700) according to claim 58, wherein the third message comprises an EAP success message or an EAP failure message.

60. The method (400, 600, 700) according to any of claims 44-59, comprising transmitting (613), to the AP (102), a fourth message to indicate the AP (102) to terminate communication with the WD (101 ).

61. The method (400, 600, 700) according to any of claims 44-60, wherein information that EAP messages exchange and EAP based authentication are being performed for the purpose of AP verification is indicated, to WD 101 by the server 103, by a new parameter added to one of the EAP messages or by an existing parameter configured in one of the EAP messages.

62. The method (400, 600, 700) according to claims 44-61 , wherein the messages communicated between the AP (102) and server (103) are according to Remote Access Dial-In User Service, RADIUS, or Diameter protocol.

63. The method (400, 600, 700) according to claim 62, wherein the fourth message comprises a RADIUS Disconnect request message.

64. The method (400, 600, 700) according to any of the preceding claims, wherein the AP (102) comprises an EAP authenticator.

65. The method (400, 600, 700) according to any of the preceding claims, wherein the server (103) comprises an EAP authentication server.

66. A wireless device, WD (101 ), configured to verify an Access Point, AP (102), providing access to an IEEE 802.11 (100) network, the WD (101 ) comprising processing circuitry (802) and a memory (803), the memory (803) containing instructions executable by the processing circuitry (802) such that the WD (102) is operable to: receive (201 , 602, 702), from the AP (102), a broadcast message comprising a Service Set Identifier, SSID, of the AP (102); transmit (202, 603, 703), to the AP (102), a request to access the AP (102) in response to the received broadcast message; transmit (203, 605, 705), to the AP (102), a first message comprising a second indication to verify the AP, in response to receiving (604, 704), from the AP (102), a response for the transmitted request; receive (204, 609, 710), from the AP (102), a second message comprising a third indication indicating a certificate associated with the AP (102) verification; and verify (205, 610) the certificate associated with the AP (102) verification.

67. The WD (101 ) of claim 66, further operable to perform a method according to any of claims 2-23 and claims 64-65.

68. An access point, AP, (102), configured to verify the AP (102) providing access to an IEEE 802.11 (100) network, the AP (102) comprising processing circuitry (902) and a memory (903), the memory (903) containing instructions executable by the processing circuitry (902) such that the AP (102) is operable to:transmit (301 , 601 b, 701 b), to a wireless device, WD (101 ), a broadcast message comprising a Service Set Identifier, SSID, of the AP (102); transmit (302, 604, 704), to the WD (101 ), a response to a request, received (603, 703) from the WD (101 ), to access the AP (102); receive (303, 605, 705), from the WD (101 ), a first message comprising a second indication to verify the AP (102); forward (304, 606, 706), to a server (103) associated with the AP (102), the first message comprising the second indication; receive (305, 608, 710), from the server (103), a second message comprising a third indication indicating a certificate associated with AP (102) verification; and forward (306, 609, 710), to the WD (101 ), the second message comprising the third indication.

69. The AP (102) of claim 68, further operable to perform a method according to any of claims 25-43 and claims 64-65.

70. A server (103) configured to verify an Access Point, AP (102), providing access to an IEEE 802.11 (100) network, the server (103) comprising processing circuitry (1002) and a memory (1003), the memory (1003) containing instructions executable by the processing circuitry (1002) such that the server (103) is operable to: receive (401 , 606, 706), from the AP (102), a first message comprising a second indication to verify the AP (102); select (402, 607, 707) a verification method in response to receiving the first message comprising the second indication; and transmit (403, 608, 710), to the AP (102), a second message comprising a third indication indicating a certificate associated with AP (102) verification.

71. The server (103) of claim 70, further operable to perform a method according to any of claims 45-65.

72. A computer program (801 ), comprising instructions which when run on a processor (802) of a wireless device, WD, (101 ), causes the WD (101 ) to perform a method according to any of claims 2-23 and claims 64-65.

73. A computer program product (804) which comprises a computer readable storage medium (803) on which a computer program according to claim 72 is stored.

74. A computer program (901 ), comprising instructions which when run on a processor (902) of an Access Point, AP, (102), causes the AP (102) to perform a method according to any of claims 25-43 or claims 64-65.

75. A computer program product (904) which comprises a computer readable storage medium (903) on which a computer program according to claim 74 is stored.

76. A computer program (1001 ), comprising instructions which when run on a processor (1002) of a server (103), causes the server (103) to perform a method according to any of claims 45-65.

77. A computer program product (1004) which comprises a computer readable storage medium (1003) on which a computer program according to claim 76 is stored.

Citation Information

Patent Citations

  • WIFI network authentication method, device and system

    EP3285513A1

  • Authentication of access points in wireless local area networks

    US20100070771A1

  • Wireless connections to a wireless access point

    US20110167263A1

  • System, Method, and Apparatus for Performing Reliable Network, Capability, and Service Discovery

    US20120246468A1