Secret-Derived AP Identity Frames for Secure Station Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless local area networks, the risk of secret leakage due to 'spoof AP' attacks, where an attacker sets up a masqueraded access point mimicking a user's home network, allowing tracking and identification of the user, is not adequately addressed by current association mechanisms.
Innovation Solution
An access point transmits a frame containing identity information determined by first secret information, which is used by a station to verify the authenticity of the AP before association, thereby preventing masqueraded access points from being connected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the STA automatically transmits an association request frame to the AP when receiving a beacon frame or probe response frame with a known SSID, then the association process is simplified and automated, but the system becomes vulnerable to spoof AP attacks where attackers can masquerade as legitimate APs and track users
Solution Approach 1:
The patent applies preliminary action by having the AP transmit identity information (such as a digital certificate or public key) in the beacon frame or probe response frame before the association process begins. This allows the STA to verify the AP's authenticity in advance, preventing spoof AP attacks while maintaining automatic association. The verification is performed before the STA transmits the association request frame, ensuring security is established proactively.
2Reliability
If identity verification mechanisms are added to prevent spoof AP attacks, then security is improved, but the signaling overhead and system complexity increase
Solution Approach 1:
The patent applies universality by using existing wireless communication frame structures (beacon frames and probe response frames) to carry identity information. These frames already serve the function of AP identification through SSID, and the patent extends their functionality to include security verification through additional identity elements. This multi-functionality approach avoids creating separate verification protocols, thereby limiting the increase in system complexity while improving security.
3Reliability
If identity information is included in beacon frames or probe response frames, then spoof AP attacks are prevented, but the frame size and signaling overhead increase
Solution Approach 1:
The patent applies the taking out principle by extracting the identity verification function from the main data transmission process. Instead of embedding large amounts of verification data that would significantly increase frame size, the patent extracts essential identity information (such as a certificate identifier or public key hash) that can be verified with minimal overhead. This allows security verification while keeping the additional signaling overhead to a minimum.
Data Source
AI summary
A method for wireless communication, an access point (AP), and a station (STA) are provided. An AP transmits a first frame, where the first frame contains identity information, and the identity information is determined based on first secret information. The identity information is used by an STA to associate with the AP.


