Wireless Access Point Proxy Trap Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer operating systems lack effective mechanisms to securely connect to wireless network access points, particularly in identifying and avoiding proxy traps that require payment or credentials without free internet access, and ensuring secure access to network resources.

Innovation Solution

A method and system for a computing device to identify operable wireless network access points, determine if they act as proxy traps by sending HTTP requests to known sites, and present the access points to the user in a way that distinguishes between secure and proxy-trapping access points, using multiple communication chip cores to scan and connect simultaneously.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the operating system prevents installation of new applications and implements security mechanisms to block unauthorized changes, then system security is improved, but the ability to adapt to new network conditions and identify proxy traps deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoidability to identify proxy traps
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary scanning and identification of proxy traps before the user attempts to connect to wireless access points. By proactively testing access points with automated HTTP requests to known websites and analyzing responses, the system pre-identifies malicious access points and prevents connection attempts, thus maintaining security while enabling adaptation to new network threats

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security mechanism that acts as a mediator between the user and wireless access points. This intermediary layer automatically scans, evaluates, and classifies access points as safe or malicious before allowing connection, thereby enabling the secure operating system to adapt to new network conditions without requiring direct user interaction or application installation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system automatically scans and tests all wireless access points to identify proxy traps, then identification accuracy is improved, but the time required to connect to a network deteriorates

Engineering Contradiction:
Improveidentification accuracyVSAvoidconnection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by performing automated security tests only on a subset of access points - specifically those that appear suspicious or unverified - rather than testing every single access point uniformly. The system uses heuristics to prioritize scanning of access points with unknown credentials or those flagged as potential proxies, thereby maintaining high identification accuracy while reducing overall connection time

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary quick-scanning of access points to categorize them as obviously safe, suspicious, or malicious before initiating full connection procedures. By pre-filtering and prioritizing access points that require detailed testing, the system reduces the time spent on comprehensive scanning while maintaining accurate identification of proxy traps

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the operating system allows only a browser as the native application with sandboxed web apps, then security is improved, but the ease of operation for network connectivity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically performing all security scanning, access point evaluation, and connection safety verification without requiring user intervention. The sandboxed browser and security mechanisms autonomously scan wireless networks, identify proxy traps, and present only safe access points to the user, thereby maintaining high security while simplifying the user experience for network connectivity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9060320B1Identifying trapping access points
Publication Date: 2015.06.16 GOOGLE LLC
  • US9060320B1 patent drawing
  • US9060320B1 patent drawing
  • US9060320B1 patent drawing

AI summary

A computer-implemented network node selection method includes identifying a plurality of operable wireless network access points within communication range of a wireless device connected to a mobile computer; identifying which of the operable wireless network access points is arranged to trap a requesting device in a proxy; and affecting a manner in which prospective wireless network access points are presented to a user of the mobile computer based on the identifying of which of the operable wireless network access points is arranged to trap a requesting party in a proxy.