Trusted Wireless Environment Evil Twin Detection via Beacon Security Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of wireless access points has led to security threats from 'evil twin' access points, which mimic legitimate APs to intercept sensitive information, compromising user data and allowing cybercriminals to gain control over Wi-Fi sessions without being detected.

Innovation Solution

Implementing a Trusted Wireless Environment (TWE) that uses secure tokens within IEEE 802.11 beacon frames and probe responses, employing HMAC algorithms to authenticate APs and prevent unauthorized connections, and utilizing Trusted Endpoint Agents (TEPA) to monitor and secure communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WPA/WPA2 security mechanisms are implemented, then communication encryption is improved, but user convenience deteriorates due to password requirements

Engineering Contradiction:
Improvecommunication encryptionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automatic security verification of access points without requiring user intervention. The endpoint agent automatically detects, validates, and responds to evil twin APs, making the security process transparent to users while maintaining strong encryption protections

Inventive Principle:
Principle #25Self-service

2Ease of operation

If public Wi-Fi networks are made accessible without passwords, then ease of operation is improved, but security against evil twin attacks deteriorates

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The endpoint agent acts as an intermediary between the user device and wireless access points. It automatically verifies the authenticity of APs by checking beacon frames and probe responses, providing security mediation that allows open networks to remain accessible while protecting against evil twin attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If mobile devices automatically connect to known SSIDs with strongest signal, then ease of operation is improved, but vulnerability to evil twin attacks increases

Engineering Contradiction:
Improveautomatic reconnectionVSAvoidevil twin vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security verification by analyzing beacon frames and probe responses before the device establishes a connection. The endpoint agent validates AP authenticity in advance, preventing automatic connection to evil twin APs while maintaining seamless reconnection to legitimate networks

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If security verification mechanisms are implemented, then detection of evil twin APs is improved, but device complexity increases

Engineering Contradiction:
Improveevil twin detection accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security verification functionality is merged into the existing wireless network stack and endpoint agent infrastructure. By integrating security checks within standard protocol handling (beacon frames, probe responses) rather than adding separate complex systems, the solution achieves accurate evil twin detection while minimizing additional device complexity

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11863984B2Method and apparatus for detecting and handling evil twin access points
Publication Date: 2024.01.02 WATCHGUARD
  • US11863984B2 patent drawing
  • US11863984B2 patent drawing
  • US11863984B2 patent drawing

AI summary

Methods and apparatus for detecting and handling evil twin access points (APs). The method and apparatus employ trusted beacons including security tokens that are broadcast by trusted APs. An Evil twin AP masquerades as a trusted AP by broadcasting beacons having the same SSID as the trusted AP, as well as other header field and information elements IE in the beacon frame body containing identical information. A sniffer on the trusted AP or in another AP that is part of a Trusted Wireless Environment (TWE) receives the beacons broadcasts by other APs in the TWE including potential evil twin APs. The content in the header and one or more IEs in received beacons are examined to determine whether a beacon is being broadcast by an evil twin. Detection of the evil twin are made by one of more of differences in MAC addresses of trusted and untrusted beacons, time jitter measurements and replay detection using timestamps in the beacons, detection of missing security tokens in untrusted beacons and detection that a security token that is mimicked by an evil twin is invalid. In one aspect, the security token is stored in a vendor-specific IE in trusted beacons that is generated by employing a secret key using a cryptographic operation operating on data in the beacon prior to the vendor-specific IE.