Crowd-Sourced Access Point Verification for Secure Wireless Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face challenges in securely verifying Access Points (APs) during non-verified connections, particularly in environments with multiple APs, leading to potential security gaps that can be exploited by attackers, resulting in incorrect information dissemination and compromised privacy.

Innovation Solution

Implementing AP verification logic using crowd-sourcing techniques, where a Station (STA) establishes initial non-verified connections with a source AP and subsequent connections with target APs based on shared security material, ensuring that APs within the same wireless infrastructure communicate securely and reliably.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If a STA establishes non-verified connections with multiple APs using shared security material, then connection speed and accessibility are improved, but security reliability deteriorates due to potential malicious APs

Engineering Contradiction:
Improveconnection speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system implements feedback mechanisms where STAs provide feedback about AP legitimacy to the network, and the network provides feedback about trusted APs to STAs. This enables continuous security verification while maintaining fast connections to verified APs.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary verification system that mediates between STAs and APs. This intermediary layer (crowd-sourcing verification system) validates AP legitimacy without requiring direct authentication between STA and AP, enabling secure connections to multiple APs while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional authentication methods are used for each AP connection, then security reliability is improved, but device complexity and time consumption increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary verification of AP legitimacy through crowd-sourcing before actual data transmission begins. STAs can pre-verify APs and share verification results, avoiding the need for complex authentication procedures during each connection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification system serves multiple functions: it authenticates APs, verifies network legitimacy, and enables fast reconnection to trusted APs. This multi-functional approach reduces overall system complexity compared to separate authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If crowd-sourcing verification is implemented for multiple APs, then security reliability is improved, but loss of time increases due to verification processes

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification process operates continuously in the background rather than blocking connection establishment. STAs can verify APs asynchronously, and verification results are cached for rapid reuse, maintaining continuous security monitoring without time loss during active connections.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system enables self-service verification where STAs independently verify AP legitimacy using distributed crowd-sourcing. This eliminates the need for centralized authentication servers, reducing verification time while maintaining security through peer-to-peer validation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250220428A1Access point verification using crowd-sourcing
Publication Date: 2025.07.03 CISCO TECHNOLOGY INC
  • US20250220428A1 patent drawing
  • US20250220428A1 patent drawing
  • US20250220428A1 patent drawing

AI summary

Techniques are provided for verifying Access Points (APs) using crowd sourcing. In one example, a STA establishes a first non-verified connection, based on security material, with a source AP in a wireless infrastructure. A target AP in a wireless infrastructure obtains an indication that the STA is attempting to establish a second non-verified connection with the target AP. In response, the target AP establishes the second non-verified connection based on the security material.