IoT Beacon Spoof Detection via Dummy Reference Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Location broadcasting beacons are vulnerable to spoof attacks due to their openness and lack of encryption, which can confuse users and compromise sensitive information during e-commerce transactions.
Innovation Solution
A method involving the generation and broadcasting of dummy beacons with unique source identifiers, allowing for comparison with detected beacon streams to identify spoofing by matching identifiers and mismatching times and locations, followed by remediation actions such as alerts and security procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If location broadcasting beacons are made open and unencrypted for ease of access and interoperability, then ease of operation and adaptability improve, but security and reliability deteriorate due to vulnerability to spoof attacks
Solution Approach 1:
The system performs preliminary actions by generating dummy beacons with expected source identifiers, times, and locations before actual beacon detection occurs. These dummy beacons are stored as reference data to enable subsequent comparison and spoofing detection, allowing the system to prepare security validation mechanisms in advance rather than reacting after spoofing occurs
Solution Approach 2:
The system implements feedback by continuously comparing detected beacon source identifiers, times, and locations against the pre-generated dummy beacons. When mismatches are detected, the system provides feedback through spoofing detection alerts, enabling real-time security monitoring and response to spoofing attempts while maintaining open beacon operation
2Reliability
If authentication credentials and encryption are added to enhance security, then reliability improves, but device complexity and ease of operation worsen
Solution Approach 1:
The system uses dummy beacons as an intermediary mechanism to enable security validation without requiring complex authentication credentials or encryption protocols. The dummy beacons serve as a reference layer that mediates between the simple open beacon system and security requirements, allowing spoofing detection through comparison rather than through complex cryptographic verification
Solution Approach 2:
The system creates copies of expected beacons (dummy beacons) with predetermined source identifiers, times, and locations. These copies are used for comparison against actual detected beacons, enabling security validation through replication and comparison rather than through complex authentication mechanisms, thus maintaining simplicity while improving reliability
Data Source
AI summary
Spoof attacks on location based beacons are detected. A stream of beacons (e.g., IBEACONS) comprising at least a unique source identifier is generated. The stream of beacons is broadcast over a wireless communication channel to mobile devices within range. A list of broadcasted beacons is stored in a table along with a time and location of broadcast. Subsequent to broadcasting, a stream of beacons is detected. The detected beacon stream comprises a unique source identifier along with a time and a location of broadcast. The unique source identifier, the time and the location of at least one beacon of the detected beacon stream can be compared to the unique source identifier, the time and the location of at least one beacon of the broadcast beacon stream. Responsive to a match between the unique source identifiers and a mismatch of at least one of the time and locations, it is determined that the broadcast beacon stream has been spoofed by the detected beacon stream. Once a spoof has been detected, various remediation actions can be taken, such as sending alerts to admin, cautioning end users, and other security mode procedures.


