WiFi Access Point Authenticity Verification via Probe Requests
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users connecting to public WiFi hotspots face security threats such as 'Twin Attack' and 'Man in the Middle' attacks, which allow attackers to intercept sensitive information, as existing technologies lack methods to verify the authenticity of WiFi access points before transmitting credentials.
Innovation Solution
A system and method using a user device with a processor, memory, and radio transceiver to perform an initial probe request, verify the authenticity of the WiFi access point through a security check, and only allow connection if the access point is validated, ensuring secure communication protocols and certificate matching are used.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users connect to open complementary WiFi hotspots to reduce costs and improve accessibility, then internet accessibility and cost-effectiveness are improved, but security vulnerability increases due to inability to verify AP authenticity
Solution Approach 1:
The system performs preliminary verification of the access point's authenticity before allowing any data transmission. A client application probes the network and verifies the AP's identity through certificate validation and URL probing mechanisms before the user connects, preventing premature exposure to malicious networks.
Solution Approach 2:
The invention introduces an intermediary verification mechanism between the user and the WiFi access point. The client application acts as a mediator that probes the network, validates certificates, and verifies the AP's identity before establishing a secure connection, adding a protective layer without preventing legitimate connectivity.
2Ease of operation
If no verification mechanism is implemented, then connection establishment is fast and simple, but credential transmission becomes vulnerable to interception by malicious entities
Solution Approach 1:
Verification actions are performed preliminarily before credential transmission. The client application probes the access point, validates its identity through multiple methods (certificate verification, URL probing), and only after successful verification does it proceed with connection establishment, ensuring security checks happen before any sensitive data is exposed.
Solution Approach 2:
The system implements feedback mechanisms where the client application continuously monitors and verifies the access point's identity throughout the connection process. Probe requests are sent, responses are analyzed, and verification status is feedback to determine whether to proceed with connection, creating a dynamic security verification process.
3Reliability
If certificate validation and probe requests are performed before connection, then authentication security is improved, but connection establishment time and device complexity increase
Solution Approach 1:
The system performs a minimal set of verification actions necessary for security. Rather than exhaustive verification, it implements targeted probe requests and certificate validation that provide sufficient security assurance without excessive time consumption, balancing security needs with practical connection speed requirements.
Data Source
AI summary
A system and method for verifying the identity of internet hotspots, comprising a user device having a processor, memory, and radio transceiver, an internet hotspot, a wireless access point, coupled to the radio transceiver of the user device and the internet hotspot, and a program stored in the memory and adapted to run on the processor of the user device, wherein the program is configured to identify a mobile wireless access point for connection by a user, connect a user to the wireless access point through a login request, query an initial probe request for the identity of the authenticating source of the wireless access point, perform a security check on the wireless access point, verify the validity and authenticity of the wireless access point to prevent transmission of information associated with the user device, and either permit or drop the connection to the wireless access point upon verification.


