WLAN Probe Request Key Validation for Secure Location Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Radio frequency-based tag locationing systems are vulnerable to security attacks where hackers can spoof location update messages, leading to incorrect data being fed into analytics engines, as the tags lack encryption and authorization, allowing malicious devices to mimic legitimate tags and send false location data from remote locations.

Innovation Solution

A system that validates the physical presence of a device within confined premises by using a combination of WLAN and WWAN networks, where a client device generates a key pair through a secure handshake over the WWAN and modifies WLAN probe requests to include this key, allowing only validated devices to access the server, thereby ensuring that only physically present clients can send location updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If radio frequency tags are used for locationing without encryption or authorization, then the system achieves low cost and simple deployment, but the system becomes vulnerable to security attacks where hackers can spoof location data

Engineering Contradiction:
Improvedeployment simplicityVSAvoiddata integrity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing WLAN probe request exchanges and collecting location data before allowing server access. The server validates device presence through WLAN communication patterns before accepting location updates, preventing spoofed data from remote devices while maintaining the simple RF tag infrastructure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The WLAN network acts as an intermediary validation layer between the RF tags and the server. Instead of directly trusting location updates from any device, the system uses WLAN probe requests and access point associations as a mediator to verify that the sending device is physically present in the premises, thereby ensuring data integrity without adding complex encryption to the tags themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the server accepts location updates from any device, then the system achieves high accessibility and ease of operation, but malicious devices can send fraudulent location data from remote locations

Engineering Contradiction:
Improveserver accessibilityVSAvoidfraudulent data injection
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The WLAN network serves as an intermediary authentication mechanism. The server requires devices to demonstrate physical presence through WLAN probe requests and access point associations before accepting their location updates. This intermediary validation layer maintains high accessibility for legitimate devices while blocking fraudulent remote access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies preliminary anti-action by validating device presence through WLAN communication before allowing location updates to be sent. This pre-validation prevents malicious devices from injecting fraudulent data, as they cannot establish the required WLAN presence without being physically located in the premises

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If the system implements strict validation to prevent spoofing, then data integrity is improved, but the system complexity increases due to additional authentication mechanisms

Engineering Contradiction:
Improvelocation data integrityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The WLAN infrastructure serves multiple functions: it provides network connectivity for legitimate devices and simultaneously acts as an authentication mechanism for validating physical presence. This multi-functionality allows the system to achieve high data integrity without adding dedicated authentication hardware or complex protocols, as the existing WLAN system performs both networking and security validation roles

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3014842B1Validating presence of a communication device using a wireless local area network
Publication Date: 2017.08.09 EXTREME NETWORKS INC
  • EP3014842B1 patent drawingFigure 1
  • EP3014842B1 patent drawingFigure 2
  • EP3014842B1 patent drawingFigure 3A

AI summary

A method and system for validating presence of a communication device in a confined area using a wireless local area network (WLAN) includes sending a first handshake message including a generated first key over a second network connection different from the WLAN connection by a device. A next step includes generating a second key to be returned to the device in a second handshake message over the same connection. A next step includes sending a WLAN probe request that has been modified to include the second key via the WLAN. A next step includes validating whether the device is present within the confined area using a second communication network; whereafter allowing communication access over the second network using both the first and second keys if the device is validated as being present within the confined area, and taking appropriate action if the device is not validated as being present within the confined area.