Rogue Access Point Detection via SSL and URL Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network security systems struggle to detect rogue access points (APs) in mobile or uncontrolled environments, such as households and public places, making it difficult for individual users to identify and prevent unauthorized access, which poses a significant threat to personal data security.

Innovation Solution

A system and method that utilize a user device and a detection server to identify rogue APs by referencing a rogue AP database, using URL access detection, SSL certificate validity, electronic signature information, and MAC address collection, allowing users to determine if an accessed AP is rogue without the need for external devices, and generating a rogue AP database based on access log information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a separate sensor or network equipment is installed in the internal network to detect rogue APs, then detection capability is improved, but device complexity and installation requirements increase

Engineering Contradiction:
Improverogue AP detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The user device performs rogue AP detection functions by itself using its own network stack and processing capabilities, without requiring separate detection sensors or dedicated network equipment. The device leverages its existing resources (CPU, memory, network interface) to execute detection algorithms, thereby improving detection capability while avoiding additional hardware complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The user device is designed to perform multiple functions including both normal network communication and rogue AP detection simultaneously. By making the detection system universal across different device types and network environments, the patent eliminates the need for specialized detection equipment, reducing overall system complexity while maintaining detection effectiveness

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If existing WIPS or NAC products are used to detect rogue APs, then detection accuracy is improved, but ease of operation deteriorates due to requiring pre-installed sensors and fixed network environments

Engineering Contradiction:
Improverogue AP detection accuracyVSAvoidease of use
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The detection system operates autonomously on the user device without requiring pre-installation of separate sensors or configuration of fixed network environments. The device automatically performs detection when needed, making the system easy to use while maintaining high detection accuracy through its self-contained capabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The detection system is designed to be dynamic and adaptable to different network environments rather than requiring a fixed, pre-configured setup. It can operate in various scenarios (home networks, public Wi-Fi, mobile locations) without requiring reinstallation or complex configuration, thereby improving ease of operation while preserving detection accuracy

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple detection methods (URL access detection, SSL certificate validation, electronic signature verification, MAC address collection) are used, then detection reliability is improved, but device complexity increases

Engineering Contradiction:
Improverogue AP detection reliabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection system is divided into multiple independent modules, each responsible for a specific detection method (URL access detection, SSL certificate validation, electronic signature verification, MAC address collection). This segmentation allows each module to be implemented and maintained independently, managing complexity while achieving high reliability through the combination of multiple detection approaches

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple detection methods are merged into a unified detection framework that operates within the user device. By combining URL access detection, SSL certificate validation, electronic signature verification, and MAC address collection into a single integrated system, the patent achieves high detection reliability while avoiding the complexity of managing separate systems

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10609564B2System and method for detecting rogue access point and user device and computer program for the same
Publication Date: 2020.03.31 SEEDGEN
  • US10609564B2 patent drawing
  • US10609564B2 patent drawing
  • US10609564B2 patent drawing

AI summary

A system for detecting a rogue access point (AP) may include: a user device configured to detect whether an accessed AP is a rogue AP with reference to a rogue AP database based on uniform resource locator (URL) access detection, and determine whether the accessed AP is a rogue AP by further using one or more information of secure sockets layer (SSL) certificate validity information of a predetermined server, electronic signature information of an accessed web page, and media access control (MAC) address collection information of an accessed gateway, if information of the accessed AP is not searched in the rogue AP database; and a detection server configured to share the rogue AP database with the user device. Using the system for detecting a rogue AP, it is possible to detect existence of a rogue AP having an unknown form through access detecting using a one-time URL, and detect address resolution protocol (ARP) spoofing attack.