Wireless Discovery Cluster Verification Against Rogue Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems, such as Wi-Fi Aware, are vulnerable to malicious devices manipulating discovery protocols, leading to potential man-in-the-middle attacks and unauthorized connections.
Innovation Solution
A device equipped with a processor that detects and compares cluster identities and discovery window timings with other devices, executing a security process to ensure intended connections by aborting or warning against mismatched clusters and requiring additional security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a discovery protocol is used to enable automatic device discovery and connection setup, then ease of operation is improved, but security is worsened due to vulnerability to malicious device manipulation
Solution Approach 1:
The system performs preliminary verification of device identity and cluster membership before establishing a connection. The verifying device checks whether the discovered device belongs to the same cluster and has valid timing parameters before proceeding with connection setup, preventing malicious devices from establishing unauthorized connections
Solution Approach 2:
The patent introduces cluster identity and timing parameters as intermediary verification mechanisms. These parameters act as mediators that enable automatic discovery while ensuring security by verifying that both devices belong to the same legitimate cluster before allowing connection
2Reliability
If cluster identity verification is implemented to prevent malicious connections, then security is improved, but device complexity increases due to additional verification steps
Solution Approach 1:
The cluster identity and timing parameters serve multiple functions simultaneously: they enable automatic device discovery, establish cluster membership verification, and provide timing synchronization. This multi-functionality reduces the need for separate verification mechanisms, thereby limiting the increase in device complexity
3Measurement precision
If timing parameters are monitored to detect malicious devices, then measurement precision is improved, but use of energy increases due to continuous monitoring requirements
Solution Approach 1:
Instead of continuous monitoring, the system uses periodic timing parameters associated with discovery windows. The verifying device checks timing parameters at specific periodic intervals defined by the discovery window structure, achieving accurate detection of malicious devices while reducing energy consumption compared to continuous monitoring
Data Source
AI summary
A device arranged for wireless communication according to a communication protocol has a processor to execute a connection sequence according to a discovery protocol. The connection sequence includes determining a current cluster identity and a current discovery window timing used by the device. Next, at least one other device within wireless range is detected, while further determining a detected cluster identity and a detected discovery window timing of the detected other device. Then it is detected whether the detected device is operating in a different cluster than the device by comparing the current cluster identity with the detected cluster identity or comparing the current discovery window timing with the detected discovery window timing. Finally, upon detecting said different cluster, a security process is executed, which may warn the user or abort the connection sequence. Thereby, a malicious device trying to manipulate the connection sequence is detected.


