Rogue Access Point Detection via Multi-Path Probe Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of network access technologies and the presence of rogue access points, particularly those performing man-in-the-middle attacks, pose significant challenges in validating and verifying network routing integrity, leading to data privacy threats and security risks.

Innovation Solution

A method utilizing dual network access technologies to transmit probes to a remote server via different radio access technologies, comparing the received probe replies to detect rogue access points by analyzing connection results and parameters, and applying a classifier model to determine malicious behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple network access technologies are used to detect rogue access points, then detection reliability is improved, but device complexity increases

Engineering Contradiction:
Improverogue access point detection reliabilityVSAvoidnetwork verification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the network verification process into distinct components: probe transmission module, probe reply reception module, and comparison analysis module. Each component handles a specific aspect of the verification process, allowing the system to achieve high detection reliability through multiple network interfaces while managing complexity through functional decomposition

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces probe messages as intermediary elements that facilitate verification between the communications device and remote servers. These probes act as mediators that carry verification information through different network paths, enabling reliable rogue access point detection without requiring direct complex interactions between multiple network interfaces

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If probe replies are analyzed in detail to detect rogue access points, then measurement precision is improved, but processing time increases

Engineering Contradiction:
Improveconnection parameter analysis precisionVSAvoidprobe reply processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts only the critical connection parameters from probe replies for comparison, such as path characteristics and routing information. By taking out only the essential verification elements rather than analyzing entire probe replies, the system achieves high measurement precision in detecting rogue access points while minimizing processing time

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs partial analysis of probe replies by focusing on specific key parameters rather than complete verification of all message contents. This partial action approach provides sufficient precision for rogue access point detection while significantly reducing the time required to process probe replies

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3574621B1Rogue access point detection using multi-path verification
Publication Date: 2020.12.30 QUALCOMM INC
  • EP3574621B1 patent drawingFigure 1
  • EP3574621B1 patent drawingFigure 2
  • EP3574621B1 patent drawingFigure 3~4

AI summary

Various embodiments provide methods, devices, and non-transitory processor- readable storage media enabling rogue access point detection with a communications device by sending multiple probes via different network connections to a remote server and receiving probe replies. Various embodiments may include a communication device transmitting a first probe addressed to a server via a first network connection and a second probe addressed to the server via a second network connection. Upon receiving a first probe reply from the server via the first network connection and a second probe reply from the server via the second network connection server, the communications device may analyze the received probe replies to determine whether an access point of either the first network or the second network is a rogue access point.