Terminal Device Identifies Malicious AP via Beacon Signal Performance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in distinguishing between normal and malicious access points (APs) in public networks, as hackers can spoof identification information, leading to potential data breaches and unauthorized information collection.

Innovation Solution

A terminal apparatus and method that identify malicious APs by comparing performance information from beacon signals with stored data, including time and arrangement order analysis, to determine if an AP is normal or malicious, thereby preventing data leaks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access public APs for internet connectivity, then network availability and convenience are improved, but security and reliability deteriorate due to malicious APs

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The terminal apparatus performs preliminary verification of AP legitimacy before establishing connection. It obtains performance information from beacon signals in advance, compares this information with stored reference data, and determines whether the AP is malicious before allowing network access, thus preventing security breaches while maintaining convenience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces performance information from beacon signals as an intermediary verification mechanism. This intermediary data (containing hardware performance characteristics) serves as a mediator between the terminal and AP, enabling indirect verification of AP authenticity without disrupting the direct connection establishment process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If APs use spoofed SSID and BSSID for malicious purposes, then ability to deceive terminals is improved, but detectability and identification accuracy deteriorate

Engineering Contradiction:
Improvemalicious AP deception capabilityVSAvoidAP identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent extracts performance information from beacon signals that is independent of spoofable identification data. By taking out hardware-specific performance characteristics (such as signal processing capabilities, transmission parameters) that cannot be easily replicated, the system creates a verification mechanism that remains effective even when SSID and BSSID are spoofed

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent moves verification from the identification dimension (SSID/BSSID) to the performance dimension (hardware characteristics in beacon signals). This dimensional shift allows detection of malicious APs by examining a different attribute space where spoofing is more difficult, thereby improving identification accuracy despite spoofed identifiers

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12133080B2Terminal device and method for identifying malicious AP by using same
Publication Date: 2024.10.29 SAMSUNG ELECTRONICS CO LTD
  • US12133080B2 patent drawing
  • US12133080B2 patent drawing
  • US12133080B2 patent drawing

AI summary

A method of identifying a malicious access point (AP) by a terminal apparatus includes obtaining first performance information related to hardware of a first AP based on a first beacon signal received from the first AP, comparing the first performance information with previously stored second performance information of a second AP, and determining whether the first AP is a malicious AP, based on a result of the comparing.