Wireless Terminal MAC Frame Time Conversion for Cloned AP Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless local area networks (WLANs), terminals connected to a wireless access point (AP) may unknowingly access cloned APs with the same service set identifier (SSID), leading to security compromises as they fail to recognize the cloned AP, potentially exposing user information.

Innovation Solution

The solution involves a terminal and AP with frame management units that modify and store MAC frame information based on access time, allowing verification of AP authenticity through converted frame information, preventing unauthorized connections by recognizing cloned APs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a terminal uses SSID for automatic connection to wireless AP, then connection convenience is improved, but security is worsened because the terminal may connect to cloned APs with the same SSID

Engineering Contradiction:
Improveconnection convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The terminal performs preliminary actions by recording access time information and generating converted destination/source addresses before actual data transmission. This preliminary modification of frame information enables the terminal to distinguish between authentic and cloned APs in advance, preventing unauthorized connections while maintaining automatic connection functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by having the terminal verify the authenticity of the AP through time-based conversion of frame information. The terminal compares converted frame information with expected values to feedback whether the connection is secure, allowing dynamic adjustment of connection behavior based on authentication results.

Inventive Principle:
Principle #23Feedback

2Reliability

If the terminal records and converts frame information based on access time, then security against cloned APs is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidframe management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by modifying frame information parameters (destination and source addresses) based on access time. The terminal converts frame parameters using time-based calculations, transforming static frame information into dynamic, time-dependent parameters that enable authentication against cloned APs.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the terminal uses unique destination and source addresses for communication, then communication reliability is improved, but vulnerability to cloned APs increases because cloned APs can use the same addresses

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidvulnerability to cloned APs
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system transitions from static address usage to dynamic address conversion based on access time. The terminal generates time-dependent converted addresses that change with each connection session, making it difficult for cloned APs to replicate the authentication pattern while maintaining communication reliability through consistent time-based conversion logic.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8891502B2Apparatus and method for providing security of a network connection
Publication Date: 2014.11.18 PANTECH CORP
  • US8891502B2 patent drawing
  • US8891502B2 patent drawing
  • US8891502B2 patent drawing

AI summary

A terminal includes: a frame management unit to manage medium access control (MAC) frame information; an access time management unit to record time according to the terminal communicating with a wireless access point (AP); a conversion performing unit to modify the frame information based on the time; and a management storage unit to store the modified frame information. A method for providing security includes: at a mobile terminal, delivering mobile frame information to and requesting AP frame information from a wireless AP; at the wireless AP, delivering the AP frame information to and requesting modified mobile frame information from the mobile terminal; at the mobile terminal, delivering the modified mobile frame information to and requesting the modified AP frame information from the wireless AP; and at the wireless AP, delivering the modified AP information. A wireless AP manages modified MAC frame information.