Wi-Fi Access Point Security Assessment via Crowd-Sourced Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in evaluating the security and connection quality of Wi-Fi access points, particularly those with strong security protocols but hidden vulnerabilities, and in distinguishing legitimate from malicious access points, leading to potential attacks and suboptimal connection choices.

Innovation Solution

A system that collects and aggregates data from multiple user devices to assess the security risk and connection quality of Wi-Fi access points by analyzing beacon parameters, user reports, and connection metrics, using a remote server to store and analyze data, and providing users with informed decisions on secure and high-quality connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users connect to Wi-Fi access points with strong security protocols (WPA-PSK, WPA Enterprise), then security protection is improved, but hidden vulnerabilities and honeypots can still expose users to attacks without detectable indicators

Engineering Contradiction:
Improvesecurity protectionVSAvoidhidden vulnerabilities and honeypot attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security assessment of Wi-Fi access points before users connect. Mobile devices collect beacon parameters, SSIDs, BSSIDs, and other characteristics of detected APs, then query a remote server to obtain pre-calculated security risk scores based on aggregated data from multiple users. This allows users to avoid connecting to potentially malicious APs (honeypots, compromised routers) before exposure to attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where user connection experiences and security events are reported back to the remote server. When users encounter security incidents (ARP spoofing, gateway changes, malware distribution), these events are aggregated and used to update security assessments for specific APs. This feedback mechanism enables the system to identify and warn about honeypots and compromised APs that initially appeared secure.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If users rely on security protocol announcements from Wi-Fi hotspots to assess safety, then assessment simplicity is improved, but accuracy deteriorates because protocol strength does not guarantee actual security

Engineering Contradiction:
Improveassessment simplicityVSAvoidsecurity assessment accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The remote server performs multiple assessment functions in a single system: analyzing beacon parameters, aggregating user reports, detecting security patterns, calculating risk scores, and providing recommendations. This multi-functional approach maintains simplicity for users (who only need to see the final risk score) while achieving high accuracy through comprehensive multi-dimensional analysis including protocol verification, behavioral pattern detection, and crowd-sourced security data.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The remote server acts as an intermediary between mobile devices and Wi-Fi access points. Instead of requiring users to perform complex security analysis themselves, the mobile device collects basic AP characteristics and queries the remote server, which returns pre-calculated security assessments. This intermediary process maintains ease of operation for users while achieving high measurement precision through sophisticated server-side analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If VPN is used to protect unsecure Wi-Fi connections, then security protection is improved, but connection performance deteriorates due to longer path through VPN server

Engineering Contradiction:
Improvesecurity protectionVSAvoidconnection performance
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary security assessment of Wi-Fi access points before users establish connections. By evaluating security risk scores based on aggregated data from multiple users and analyzing AP characteristics (beacon parameters, SSID, BSSID, encryption protocols), the system enables users to select inherently secure APs that do not require VPN protection. This preliminary assessment allows users to achieve both security and performance by connecting directly to trusted APs without VPN overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10542029B2System and method for security and quality assessment of wireless access points
Publication Date: 2020.01.21 AURA SUB LLC
  • US10542029B2 patent drawing
  • US10542029B2 patent drawing
  • US10542029B2 patent drawing

AI summary

A computer-implemented method for security risk assessment of wireless access point devices, the computer-implemented method comprising: receiving signals from one or more wireless access points by two or more mobile wireless devices visiting said access points, obtaining Basic Service Set Identifiers (BSSID) of visited access points and reporting values derived from BSSID and from an identifier of corresponding mobile device to a first database, receiving a request for a security risk assessment of evaluated wireless access point, said request containing value derived from BSSID of the evaluated access point, searching the first database for one or more entries corresponding to the evaluated access point, and processing search results to assess security risk of the evaluated access point, said processing comprises computing a component of said risk dependent on the count of unique identifiers of mobile devices reported for the evaluated access point.