Rogue AP Roaming Prevention via Association Control List

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks and devices face security challenges, including vulnerability to rogue access points and hacking, which compromise network security and authentication, unlike hard-wired connections that offer physical security.

Innovation Solution

A security component utilizing an association control list to differentiate between valid and rogue access points by listing valid and invalid IP and MAC addresses, ensuring only authorized access points are connected, thereby enhancing security for mobile devices on wireless networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless networks are used to eliminate physical restrictions and improve mobility, then ease of operation and range are improved, but security and vulnerability to rogue access points deteriorate

Engineering Contradiction:
ImprovemobilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by maintaining a whitelist of authorized access points and proactively checking whether detected access points are in the whitelist before allowing connections. This preventive approach ensures that only known, authorized access points can be connected to, blocking rogue access points before they can compromise security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a whitelist database as an intermediary between the mobile device and access points. This intermediary serves as a verification mechanism that mediates connection requests by checking against the whitelist, thereby ensuring that only authorized access points are accepted while maintaining wireless mobility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If wireless networks allow roaming between access points for mobility, then ease of operation is improved, but vulnerability to rogue access points increases

Engineering Contradiction:
Improveroaming capabilityVSAvoidrogue access point vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification by checking each detected access point against the whitelist before allowing roaming connections. This proactive validation ensures that mobile devices can roam freely among authorized access points while automatically blocking rogue access points that are not in the whitelist.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring for access points and comparing them against the whitelist. When a rogue access point is detected (one not in the whitelist), the system provides feedback by blocking the connection and can notify the user, creating a closed-loop security mechanism that adapts to threats in real-time.

Inventive Principle:
Principle #23Feedback

3Reliability

If access point verification is implemented to block rogue access points, then security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity component complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device performs self-service by autonomously checking detected access points against its local whitelist and making connection decisions without requiring external verification. This self-service approach enhances security while minimizing additional system complexity, as the device handles verification independently using pre-configured whitelist data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses copying by storing copies of authorized access point identifiers (MAC addresses, SSIDs) in a local whitelist database on the mobile device. This copying approach allows rapid local verification without requiring continuous communication with a central authority, thereby enhancing security response time while keeping the verification mechanism simple and self-contained.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP1908235B1Rogue AP roaming prevention
Publication Date: 2018.01.24 SYMBOL TECHNOLOGIES LLC
  • EP1908235B1 patent drawingFigure 1
  • EP1908235B1 patent drawingFigure 2
  • EP1908235B1 patent drawingFigure 3

AI summary

The claimed subject matter provides a system and/or a method that facilitates enhancing security in a wireless network for a mobile device that can connect to an access point. A mobile device can utilize a wireless connection with at least one access point. A security component can utilize an association control list to provide at least one of a valid access point to which the mobile can connect and a rogue access point to which the mobile device is not to connect.