Wireless Access Point Detection via Reputation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users connecting to wireless access points in public areas, such as homes, cafes, or airports, are vulnerable to phishing and man-in-the-middle attacks due to the lack of effective methods to detect suspect or rogue wireless access points, which conventional solutions do not address.

Innovation Solution

A method and apparatus for detecting suspect wireless access points by collecting and comparing identity information from multiple client devices, using a reputation system to determine the trustworthiness of available access points, and transmitting trust indications to client devices, allowing them to connect securely or disconnect from untrusted points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users connect to wireless access points in public areas, then network access is provided, but vulnerability to phishing and man-in-the-middle attacks increases

Engineering Contradiction:
Improvenetwork access availabilityVSAvoidattack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection of wireless access points by collecting identity information from multiple client devices before users connect. A reputation score is calculated in advance based on this collected data, allowing users to make informed decisions about which access points to connect to, thereby preventing attacks before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary reputation system that acts as a mediator between users and wireless access points. This system collects, processes, and evaluates access point identity information, then provides reputation scores to users. The intermediary layer enables users to safely access public networks by filtering out malicious access points through the reputation evaluation mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If conventional solutions are used for wireless access, then simplicity is maintained, but detection of suspect access points is ineffective

Engineering Contradiction:
Improvesystem simplicityVSAvoidaccess point trustworthiness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The reputation system is designed to be universal and work across multiple wireless networks and devices. It collects identity information from various sources (multiple client devices), processes different types of data, and provides a unified reputation score that can be applied to any wireless access point. This multi-functional approach maintains simplicity for the end user while providing comprehensive detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If identity information is collected from multiple client devices, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveaccess point identification accuracyVSAvoiddata collection infrastructure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges identity information from multiple client devices into a unified reputation evaluation. By combining data from multiple sources, the system achieves more accurate detection of suspect access points. The merging process consolidates redundant information and synthesizes a comprehensive reputation score, managing the complexity of multi-source data collection through integration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where reputation scores are continuously updated based on collected identity information from multiple client devices. This feedback loop allows the system to learn from accumulated data, improving detection accuracy over time while managing complexity through iterative refinement rather than requiring all complexity upfront.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8655312B2Wireless access point detection
Publication Date: 2014.02.18 WITHSECURE CORP (A K A WITHSECURE OYJ)
  • US8655312B2 patent drawing
  • US8655312B2 patent drawing
  • US8655312B2 patent drawing

AI summary

According to aspects of the present invention there are provided methods and apparatus for detecting a suspect wireless access point in a communication network including a plurality of wireless access points providing access services to client devices. Identity information associated with the wireless access points is collected from a multiplicity of client devices. A reputation request is received from a client device, the request including identity information of an available wireless access point. The received identity information is compared with the collected identity information for determining an indication of trust of the available wireless access point. The indication of trust of the available wireless access point is transmitted to the client device. The wireless access points may include a cellular wireless access point or base station, wireless access point, a Wi-Fi access point, or a femto-cell access point.