Wireless Access Point Spoof Detection via Location Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems fail to reliably verify the legitimacy of wireless access points, making computing devices vulnerable to attacks from malicious devices that mimic known access points, allowing attackers to intercept network traffic.

Innovation Solution

A method and system that detect potentially illegitimate wireless access points by determining the geographic location of a computing device and comparing it to the stored location of a known access point, blocking or prompting the user to avoid connections beyond a certain distance, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If computing devices automatically connect to wireless access points using stored credentials, then connection speed and ease of operation are improved, but security reliability deteriorates as devices become vulnerable to spoofed access points

Engineering Contradiction:
Improveautomatic connectionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification of the access point's geographic location before allowing automatic connection. By checking whether the access point's location matches the stored location within a threshold distance, the system prevents connection to spoofed access points while maintaining automatic reconnection functionality for legitimate ones.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If traditional network security systems are used, then device complexity remains low, but the ability to detect illegitimate access points is insufficient

Engineering Contradiction:
Improvesecurity system structureVSAvoidillegitimate access point detection
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces geographic location verification as an intermediary verification step between the computing device and the wireless access point. This intermediary mechanism (location comparison) provides a simple yet effective way to detect spoofed access points without requiring complex security infrastructure or additional hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If geographic location verification is implemented, then detection of spoofed access points is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improveaccess point verificationVSAvoidlocation verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing device performs self-verification by using its own stored location data and GPS capabilities to independently determine whether an access point is legitimate. The device compares the access point's advertised location with its own recorded location and makes the security determination autonomously without requiring external authentication servers or complex verification infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9913201B1Systems and methods for detecting potentially illegitimate wireless access points
Publication Date: 2018.03.06 GEN DIGITAL INC
  • US9913201B1 patent drawing
  • US9913201B1 patent drawing
  • US9913201B1 patent drawing

AI summary

The disclosed computer-implemented method for detecting potentially illegitimate wireless access points may include (1) detecting an attempt by the computing device to automatically connect to a wireless access point that resembles a known wireless access point whose geographic location is stored by the computing device, (2) identifying a current geographic location of the computing device, (3) determining that the current geographic location of the computing device is beyond a certain distance from the geographic location of the known wireless access point, and then (4) determining, based at least in part on the determination that the current geographic location of the computing device is beyond the certain distance from the geographic location of the known wireless access point, that the wireless access point is potentially illegitimate. Various other methods, systems, and computer-readable media are also disclosed.