Secret-Derived AP Identity Frames for Secure Station Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless local area networks, the risk of secret leakage due to 'spoof AP' attacks, where an attacker sets up a masqueraded access point mimicking a user's home network, allowing tracking and identification of the user, is not adequately addressed by current association mechanisms.

Innovation Solution

An access point transmits a frame containing identity information determined by first secret information, which is used by a station to verify the authenticity of the AP before association, thereby preventing masqueraded access points from being connected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the STA automatically transmits an association request frame to the AP when receiving a beacon frame or probe response frame with a known SSID, then the association process is simplified and automated, but the system becomes vulnerable to spoof AP attacks where attackers can masquerade as legitimate APs and track users

Engineering Contradiction:
Improveautomatic associationVSAvoidsecurity against spoof attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by having the AP transmit identity information (such as a digital certificate or public key) in the beacon frame or probe response frame before the association process begins. This allows the STA to verify the AP's authenticity in advance, preventing spoof AP attacks while maintaining automatic association. The verification is performed before the STA transmits the association request frame, ensuring security is established proactively.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If identity verification mechanisms are added to prevent spoof AP attacks, then security is improved, but the signaling overhead and system complexity increase

Engineering Contradiction:
Improvesecurity against spoof attacksVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using existing wireless communication frame structures (beacon frames and probe response frames) to carry identity information. These frames already serve the function of AP identification through SSID, and the patent extends their functionality to include security verification through additional identity elements. This multi-functionality approach avoids creating separate verification protocols, thereby limiting the increase in system complexity while improving security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If identity information is included in beacon frames or probe response frames, then spoof AP attacks are prevented, but the frame size and signaling overhead increase

Engineering Contradiction:
Improvesecurity against spoof attacksVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies the taking out principle by extracting the identity verification function from the main data transmission process. Instead of embedding large amounts of verification data that would significantly increase frame size, the patent extracts essential identity information (such as a certificate identifier or public key hash) that can be verified with minimal overhead. This allows security verification while keeping the additional signaling overhead to a minimum.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250294352A1Method for wireless communication, access point, and station
Publication Date: 2025.09.18 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • US20250294352A1 patent drawing
  • US20250294352A1 patent drawing
  • US20250294352A1 patent drawing

AI summary

A method for wireless communication, an access point (AP), and a station (STA) are provided. An AP transmits a first frame, where the first frame contains identity information, and the identity information is determined based on first secret information. The identity information is used by an STA to associate with the AP.