Wireless Access Point SSID Broadcast Control via Cellular VPN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless access points (WAPs) are vulnerable to man-in-the-middle attacks, particularly when connected to the internet via Ethernet cables, as they expose communications to potential snooping devices, compromising security for users who automatically connect without considering security risks.
Innovation Solution
Establishing a virtual private network (VPN) between the WAP and the cellular network provider's computing device to encrypt communications and only broadcast a specific SSID for user devices when a VPN is established, ensuring secure connections and halting SSID broadcast when the VPN is disconnected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a WAP broadcasts SSID for automatic connection, then ease of operation is improved, but security is worsened due to exposure to man-in-the-middle attacks
Solution Approach 1:
The patent introduces a cellular network as an intermediary authentication layer between the WAP and user devices. Before allowing Wi-Fi connection, the system verifies the device's cellular subscription status through the cellular network provider. This intermediary security check prevents unauthorized devices from connecting, even if they detect the SSID, thereby resolving the contradiction between ease of automatic connection and security against man-in-the-middle attacks.
2Ease of manufacture
If a WAP uses Ethernet cable for internet connection, then ease of manufacture is improved, but security is worsened due to exposure to snooping devices
Solution Approach 1:
The patent introduces a cellular network connection as an intermediary between the WAP and the internet. Instead of directly connecting the WAP to the internet via Ethernet, the system uses the cellular network provider's infrastructure as a secure intermediary channel. This eliminates the physical Ethernet connection that is vulnerable to snooping, while maintaining internet access through the encrypted cellular network pathway.
3Adaptability or versatility
If a WAP broadcasts multiple SSIDs for different users, then adaptability is improved, but security is worsened due to credential management vulnerabilities
Solution Approach 1:
The patent extracts the authentication credentials from the WAP itself and places them in the user's mobile device through the cellular network. Instead of the WAP storing and managing multiple sets of credentials for different users, the system leverages the existing cellular network authentication mechanism already present in each user's device. This eliminates the WAP's credential management vulnerability while maintaining the ability to serve multiple users through their device-specific cellular credentials.
Data Source
AI summary
Techniques are disclosed to increase security of a wireless access point (WAP). In embodiments, a cellular network provider has an arrangement with an owner of a WAP for cellular network customers to connect to the Internet through that WAP. The WAP may broadcast a SSID for cellular network customers only when a virtual private network (VPN) is established between the WAP and a server of the cellular network provider. If the VPN disconnects, then the WAP stops broadcasting this SSID until the VPN is re-established.


