Access Point Authentication via Wired-Wireless Identifier Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless networks are vulnerable to rogue access points, which can impersonate genuine networks, leading to man-in-the-middle attacks, as existing security measures like WEP and WPA are inadequate in preventing such impersonation attacks, and previous solutions either rely on unauthenticated communication or require complex intrusion detection systems.
Innovation Solution
A method and system utilizing a comparator accessible via a second wireless interface, co-located with an information server, that processes indicative data to verify the authenticity of access points by comparing MAC addresses and preventing spoofing through encryption and digital signatures, ensuring secure communication by detecting rogue access points and authenticating genuine ones before allowing network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If WEP and WPA security mechanisms are implemented, then authentication and data encryption are provided for wireless clients, but they remain vulnerable to rogue access point impersonation attacks
Solution Approach 1:
The system performs preliminary verification of the access point's authenticity before allowing wireless clients to connect. The information server validates the access point's identity by comparing its public key certificate with information received from the wired network, preventing rogue access points from impersonating genuine ones before any data transmission occurs.
Solution Approach 2:
An information server acts as an intermediary between the wireless network and the wired network. It receives information from both sides, verifies their consistency, and only allows communication when the access point is confirmed to be authentic. This intermediary prevents direct vulnerable connections between wireless clients and potentially rogue access points.
2Reliability
If firewalls and MAC address filtering are implemented, then internal network infrastructure and wireless clients are protected, but they overlook the threat posed by rogue access points
Solution Approach 1:
The system performs preliminary verification of the access point's authenticity before allowing wireless clients to connect. The information server validates the access point's identity by comparing its public key certificate with information received from the wired network, preventing rogue access points from impersonating genuine ones before any data transmission occurs.
Solution Approach 2:
The system establishes a feedback loop where the information server continuously monitors and verifies the authenticity of access points. By comparing information from the wired network with the access point's self-identified information, the system provides ongoing verification feedback to prevent impersonation attacks.
3Reliability
If digital certificates are transmitted to wireless devices, then access point authenticity is verified, but certificates can be sniffed and copied by rogue access points
Solution Approach 1:
The system performs preliminary verification of the access point's authenticity before allowing wireless clients to connect. The information server validates the access point's identity by comparing its public key certificate with information received from the wired network, preventing rogue access points from impersonating genuine ones before any data transmission occurs.
Solution Approach 2:
An information server acts as an intermediary between the wireless network and the wired network. It receives information from both sides, verifies their consistency, and only allows communication when the access point is confirmed to be authentic. This intermediary prevents direct vulnerable connections between wireless clients and potentially rogue access points.
4Reliability
If traceroute information is used to prevent certificate sniffing, then some protection is provided, but it is not suitable in IP networks since packets can be routed over many different routes and rogue access points can spoof traceroute packets
Solution Approach 1:
An information server acts as an intermediary between the wireless network and the wired network. It receives information from both sides, verifies their consistency, and only allows communication when the access point is confirmed to be authentic. This intermediary prevents direct vulnerable connections between wireless clients and potentially rogue access points.
Solution Approach 2:
The system establishes a feedback loop where the information server continuously monitors and verifies the authenticity of access points. By comparing information from the wired network with the access point's self-identified information, the system provides ongoing verification feedback to prevent impersonation attacks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Rogue or malicious access points pose a threat to wireless networks (32) and the users of these networks. In order to prevent or reduce this threat a method and system is proposed that verifies that an access point (31) is genuine and not rogue before setting up a connection between the access point and a wireless device (34). The authentication is based on comparing an identifier of the wireless device (34) obtained from an authentication server (33,35) in the wired network to an identifier of a wireless device obtained directly from the wireless device. A comparator (39) in an information server (36) receives the two sets of data and compares the two identifiers and if they match the access point is verified as genuine.