WiFi Access Point Authenticity Verification via Probe Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users connecting to public WiFi hotspots face security threats such as 'Twin Attack' and 'Man in the Middle' attacks, which allow attackers to intercept sensitive information, as existing technologies lack methods to verify the authenticity of WiFi access points before transmitting credentials.

Innovation Solution

A system and method using a user device with a processor, memory, and radio transceiver to perform an initial probe request, verify the authenticity of the WiFi access point through a security check, and only allow connection if the access point is validated, ensuring secure communication protocols and certificate matching are used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users connect to open complementary WiFi hotspots to reduce costs and improve accessibility, then internet accessibility and cost-effectiveness are improved, but security vulnerability increases due to inability to verify AP authenticity

Engineering Contradiction:
Improveinternet accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of the access point's authenticity before allowing any data transmission. A client application probes the network and verifies the AP's identity through certificate validation and URL probing mechanisms before the user connects, preventing premature exposure to malicious networks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary verification mechanism between the user and the WiFi access point. The client application acts as a mediator that probes the network, validates certificates, and verifies the AP's identity before establishing a secure connection, adding a protective layer without preventing legitimate connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If no verification mechanism is implemented, then connection establishment is fast and simple, but credential transmission becomes vulnerable to interception by malicious entities

Engineering Contradiction:
Improveconnection establishmentVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Verification actions are performed preliminarily before credential transmission. The client application probes the access point, validates its identity through multiple methods (certificate verification, URL probing), and only after successful verification does it proceed with connection establishment, ensuring security checks happen before any sensitive data is exposed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the client application continuously monitors and verifies the access point's identity throughout the connection process. Probe requests are sent, responses are analyzed, and verification status is feedback to determine whether to proceed with connection, creating a dynamic security verification process.

Inventive Principle:
Principle #23Feedback

3Reliability

If certificate validation and probe requests are performed before connection, then authentication security is improved, but connection establishment time and device complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs a minimal set of verification actions necessary for security. Rather than exhaustive verification, it implements targeted probe requests and certificate validation that provide sufficient security assurance without excessive time consumption, balancing security needs with practical connection speed requirements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10305884B2Secure identification of internet hotspots for the passage of sensitive information
Publication Date: 2019.05.28 SAUTHER MARK
  • US10305884B2 patent drawing
  • US10305884B2 patent drawing
  • US10305884B2 patent drawing

AI summary

A system and method for verifying the identity of internet hotspots, comprising a user device having a processor, memory, and radio transceiver, an internet hotspot, a wireless access point, coupled to the radio transceiver of the user device and the internet hotspot, and a program stored in the memory and adapted to run on the processor of the user device, wherein the program is configured to identify a mobile wireless access point for connection by a user, connect a user to the wireless access point through a login request, query an initial probe request for the identity of the authenticating source of the wireless access point, perform a security check on the wireless access point, verify the validity and authenticity of the wireless access point to prevent transmission of information associated with the user device, and either permit or drop the connection to the wireless access point upon verification.