Terminal Device Identifies Malicious AP via Beacon Signal Performance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in distinguishing between normal and malicious access points (APs) in public networks, as hackers can spoof identification information, leading to potential data breaches and unauthorized information collection.
Innovation Solution
A terminal apparatus and method that identify malicious APs by comparing performance information from beacon signals with stored data, including time and arrangement order analysis, to determine if an AP is normal or malicious, thereby preventing data leaks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users access public APs for internet connectivity, then network availability and convenience are improved, but security and reliability deteriorate due to malicious APs
Solution Approach 1:
The terminal apparatus performs preliminary verification of AP legitimacy before establishing connection. It obtains performance information from beacon signals in advance, compares this information with stored reference data, and determines whether the AP is malicious before allowing network access, thus preventing security breaches while maintaining convenience
Solution Approach 2:
The patent introduces performance information from beacon signals as an intermediary verification mechanism. This intermediary data (containing hardware performance characteristics) serves as a mediator between the terminal and AP, enabling indirect verification of AP authenticity without disrupting the direct connection establishment process
2Adaptability or versatility
If APs use spoofed SSID and BSSID for malicious purposes, then ability to deceive terminals is improved, but detectability and identification accuracy deteriorate
Solution Approach 1:
The patent extracts performance information from beacon signals that is independent of spoofable identification data. By taking out hardware-specific performance characteristics (such as signal processing capabilities, transmission parameters) that cannot be easily replicated, the system creates a verification mechanism that remains effective even when SSID and BSSID are spoofed
Solution Approach 2:
The patent moves verification from the identification dimension (SSID/BSSID) to the performance dimension (hardware characteristics in beacon signals). This dimensional shift allows detection of malicious APs by examining a different attribute space where spoofing is more difficult, thereby improving identification accuracy despite spoofed identifiers
Data Source
AI summary
A method of identifying a malicious access point (AP) by a terminal apparatus includes obtaining first performance information related to hardware of a first AP based on a first beacon signal received from the first AP, comparing the first performance information with previously stored second performance information of a second AP, and determining whether the first AP is a malicious AP, based on a result of the comparing.


