Key points are not available for this paper at this time.
Wireless local area networks remain vulnerable to attacks initiated during the connection establishment (CE) phase. Even the latest Wi-Fi security protocols fail to fully mitigate threats such as man in the middle, preamble spoofing, and relaying. To fortify the CE phase, this paper presents a backwardcompatible scheme, reinforced with timing constraints, that interweaves a medium access control (MAC) layer digital signature into the preamble signals at the physical (PHY) layer to counter these attacks. The approach slices the signature and embeds the slices within CE frame preambles without extending frame size, allowing one or multiple stations to concurrently verify their respective APs' transmissions in enterprise and public Wi-Fi networks. The scheme supports concurrent CEs by enabling each station to analyze the consistent patterns of PHY-layer headers to determine whether the received frames are the anticipated ones from the expected APs, achieving 100% accuracy without needing to inspect MAC layer headers. Additionally, we design and implement a fast relay attack to challenge our defense's effectiveness. We extend existing open-source tools to support IEEE 802.11ax to evaluate the effectiveness and practicality of our scheme on a testbed consisting of universal software radio peripherals (USRPs), commercial APs, and Wi-Fi devices. Our results show that the proposed relay attack detection achieves 96-100% true positive rates. Finally, end-to-end formal analyses confirm the security and correctness of the proposed solution.
Hoque et al. (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: