Electronic Device Wi-Fi Security Verification via Dual Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security verification techniques for Wi-Fi networks are inadequate in detecting man-in-the-middle (MITM) attacks, especially when using malicious access points, and are limited by their reliance on certificate verification from APs that support the function, and black list-based phishing site detection is ineffective for internal network attacks.
Innovation Solution
An electronic device that establishes dual communication channels, one through a Wi-Fi network and another through a mobile network, to verify the security of the Wi-Fi network by comparing information such as protocol and fingerprint data, allowing for secure communication to be maintained or terminated based on these comparisons.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security verification techniques are implemented to detect MITM attacks on Wi-Fi networks, then security reliability is improved, but device complexity increases due to dual communication channels and comparison mechanisms
Solution Approach 1:
The patent uses the mobile network as an intermediary verification channel to authenticate the Wi-Fi network's legitimacy. By comparing information obtained through both channels, the system can detect MITM attacks without directly modifying the Wi-Fi communication itself. The mobile network acts as a trusted mediator that provides reference information for security verification.
Solution Approach 2:
The security verification process is segmented into separate communication channels: the primary Wi-Fi channel for data transmission and the secondary mobile network channel for security verification. This segmentation allows the system to maintain normal Wi-Fi operations while independently verifying network security through a separate path, reducing interference and complexity in the main communication flow.
2Measurement precision
If dual communication channels are established for security verification, then detection precision of MITM attacks is improved, but data transmission speed decreases due to additional verification overhead
Solution Approach 1:
The system performs partial verification by comparing only critical information elements (such as domain names or specific protocol features) between the two channels rather than analyzing entire data streams. This selective comparison approach maintains high detection precision for MITM attacks while minimizing the verification overhead that would slow down data transmission.
Solution Approach 2:
Security verification is performed preliminarily and periodically rather than continuously for every data packet. The system establishes the security status of the Wi-Fi network through initial verification and maintains this status until conditions change, allowing high-speed data transmission without constant verification overhead while still detecting attacks effectively.
3Reliability
If continuous security verification through mobile network is performed, then security reliability is improved, but energy consumption increases
Solution Approach 1:
The security verification process operates periodically rather than continuously. The system performs verification at intervals or when specific events occur (such as connection establishment, network switching, or suspected attack conditions), allowing the device to conserve energy during normal operations while maintaining security monitoring capability when needed.
Solution Approach 2:
The verification frequency and intensity are dynamically adjusted based on security risk levels and operational context. When the Wi-Fi network appears legitimate and stable, verification is reduced to maintain low energy consumption. When anomalies are detected or high-security operations are performed, verification intensity increases automatically, optimizing the balance between security and energy usage.
Data Source
AI summary
Disclosed are an electronic device capable of verifying security of a Wi-Fi network and a controlling method thereof. To be specific, the electronic device, in response to the received user command, obtains, through a first channel, first information related to an address of the website, and obtains, from a server providing the website through a second channel, second information related to the address of the website, based on the first information and the second information being identical, maintains communication with the server through the first channel, and based on the first information and the second information being different, terminates the communication with the server through the first channel or communicate with the server through the first channel according to the second information.


