Access Point Untrusted Configurator Detection via Enrollee Simulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Device Provisioning Protocol (DPP) environments, unprovisioned devices can be vulnerable to connecting with untrusted configurators that may lead to data leakage, as they lack mutual authentication and can accept configuration from fake DPP service networks.
Innovation Solution
Implementing a detection scheme where an access point simulates an enrollee to broadcast configuration requests with simulated authentication information, allowing identification of untrusted configurators by responding to configuration responses and transmitting their device information to a network device for remedial action.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If unprovisioned devices accept configuration requests from any configurator to enable easy network provisioning, then device provisioning simplicity is improved, but security against untrusted configurators deteriorates
Solution Approach 1:
The system performs preliminary actions by having the access point simulate an enrollee and broadcast configuration requests with simulated authentication information before actual device provisioning. This allows the system to pre-identify potential untrusted configurators in the environment, establishing a security check mechanism before real devices connect, thus maintaining both provisioning simplicity and security
Solution Approach 2:
The access point acts as an intermediary between unprovisioned devices and configurators. By simulating an enrollee and mediating the configuration request process, the access point can detect untrusted configurators and prevent them from directly provisioning devices, thus protecting against security threats while maintaining the DPP-based simple provisioning flow for trusted configurators
2Reliability
If the access point broadcasts configuration requests with simulated authentication information to detect untrusted configurators, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The access point performs multiple functions: it serves as a network gateway, an enrollee simulator for security detection, and a mediator for configuration requests. By making the access point multi-functional, the patent avoids adding separate dedicated detection devices, thus improving untrusted configurator detection capability without significantly increasing overall system complexity
Solution Approach 2:
The access point performs self-service by autonomously simulating enrollee authentication information and broadcasting configuration requests to detect untrusted configurators. This self-detected mechanism eliminates the need for external detection systems or manual security verification, improving detection capability while keeping the system simple through automated self-operation
Data Source
AI summary
Implementations of the present disclosure relate to detection of an untrusted configurator. In the implementations, an access point (AP) receives enrollee authentication information simulated by the network device from a network device. Then, the AP simulates an enrollee and broadcasts a configuration request including the enrollee authentication information. When a configurator responds to the configuration request, the AP identifies the configurator as an untrusted configurator, and then the AP transmits device information of the untrusted configurator to the network device. In this way, the untrusted configurator in the serving range can be detected, thereby avoiding the devices being provisioned to connect to untrusted networks.


