Terminal device and method for identifying malicious ap by using same

US2021204135A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2021204135-A1
Application numberUS-201917057848-A
CountryUS
Kind codeA1
Filing dateMay 28, 2019
Priority dateMay 28, 2018
Publication dateJul 1, 2021
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method of identifying a malicious AP by a terminal apparatus includes obtaining first performance information related to hardware of a first AP based on a first beacon signal received from the first AP, comparing the first performance information with previously stored second performance information of a second AP, and determining whether the first AP is a malicious AP, based on a result of the comparing.

First claim

Opening claim text (preview).

1 . A method of identifying a malicious AP by a terminal apparatus, the method comprising: obtaining first performance information related to hardware of a first AP based on a first beacon signal received from the first AP; comparing the first performance information with previously stored second performance information of a second AP; and determining whether the first AP is a malicious AP, based on a result of the comparing. 2 . The method of claim 1 , further comprising: obtaining first time information related to the first beacon signal; comparing the first time information with second time information related to a second beacon signal of the second AP; and determining whether the first AP is a malicious AP, based on a result of the comparing. 3 . The method of claim 2 , wherein the first time information comprises first timestamp information included in the first beacon signal and first receiving time information of the first beacon signal, the second time information comprises second timestamp information included in the second beacon signal and second receiving time information of the second beacon signal, and the determining of whether the first AP is a malicious AP comprises determining the first AP to be a malicious AP when a difference value between the first timestamp information and the second timestamp information does not correspond to a difference value between the first receiving time information and the second receiving time information. 4 . The method of claim 1 , wherein the first AP is an AP to be accessed by the terminal apparatus after the terminal apparatus is disconnected from the second AP, and identification information of the first AP is the same as identification information of the second AP. 5 . The method of claim 1 , wherein the comparing of the first performance information with the previously stored second performance information of the second AP comprises, when an SSID of the first AP is included in a previously stored SSID list, comparing second performance information of the second AP received from a server device with the first performance information. 6 . The method of claim 1 , further comprising: transmitting, to the first AP, a request message including at least one of predetermined identification information and predetermined channel information; receiving a response message from the first AP in response to the request message; and determining the first AP to be a malicious AP, when the response message includes at least one of the predetermined identification information and the predetermined channel information. 7 . The method of claim 1 , further comprising: predicting pieces of first time information on or after an (n+1)th beacon signal, based on pieces of first time information related to first beacon signals received from the first AP on or before an n-th beacon signal, where n is a natural number; comparing the predicted pieces of first time information with the pieces of first time information of the first beacon signals received on or after an (n+1)th beacon signal; and determining whether the first AP is a malicious AP, based on a result of the comparing. 8 . The method of claim 7 , wherein the predicting of the pieces of first time information comprises predicting the pieces of first time information on or after the (n+1)th beacon signal through a linear regression analysis. 9 . The method of claim 7 , wherein the determining of whether the first AP is a malicious AP comprises determining the first AP to be a malicious AP when difference values between the predicted pieces of first time information and the pieces of first time information of the first beacon signals received on or after the (n+1)th beacon signal increase or decrease according to time. 10 . The method of claim 1 , further comprising: comparing a first arrangement order of information elements in the first beacon signal with a previously stored second arrangement order of information elements; and determining whether the first AP is a malicious AP, based on a result of the comparing. 11 . A program stored in a medium to execute a method of identifying a malicious AP according to claim 1 in combination with hardware. 12 . A terminal apparatus comprising: a memory storing one or more instructions; and a processor configured to execute the one or more instructions stored in the memory, wherein the processor is configured to: obtain first performance information related to hardware of the first AP based on a first beacon signal received from the first AP; compare the first performance information with previously stored second performance information of the second AP; and determine whether the first AP is a malicious AP, based on a result of the comparing. 13 . The terminal apparatus of claim 12 , wherein the processor is configured to: obtain first time information related to the first beacon signal; compare the first time information with second time information related to a second beacon signal of the second AP; and determine whether the first AP is a malicious AP, based on a result of the comparing. 14 . The terminal apparatus of claim 12 , wherein the processor is configured to: transmit, to the first AP, a request message including at least one of predetermined identification information and predetermined channel information; receive a response message from the first AP in response to the request message; and determine the first AP to be a malicious AP, when the response message includes at least one of the predetermined identification information and the predetermined channel information. 15 . The terminal apparatus of claim 12 , wherein the processor is configured to: predict pieces of first time information on or after an (n+1)th beacon signal, based on pieces of first time information related to first beacon signals received from the first AP on or before an n-th beacon signal, where n is a natural number; compare the predicted pieces of first time information with the pieces of first time information of the first beacon signals received on or after an (n+1)th beacon signal; and determine whether the first AP is a malicious AP, based on a result of the comprising.

Assignees

Inventors

Classifications

  • Time-dependent · CPC title

  • Access point logical identity · CPC title

  • H04W12/122Primary

    Counter-measures against attacks; Protection against rogue devices · CPC title

  • Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title

  • Hardware identity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2021204135A1 cover?
A method of identifying a malicious AP by a terminal apparatus includes obtaining first performance information related to hardware of a first AP based on a first beacon signal received from the first AP, comparing the first performance information with previously stored second performance information of a second AP, and determining whether the first AP is a malicious AP, based on a result of t…
Who is the assignee on this patent?
Samsung Electronics Co Ltd
What technology area does this patent fall under?
Primary CPC classification H04W12/122. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jul 01 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).