Julius Schulz-Zander, Raphael Lisicki, S. Schmid, A. Feldmann
{"title":"SecuSpot: Toward Cloud-Assisted Secure Multi-Tenant WiFi HotSpot Infrastructures","authors":"Julius Schulz-Zander, Raphael Lisicki, S. Schmid, A. Feldmann","doi":"10.1145/3010079.3012015","DOIUrl":null,"url":null,"abstract":"Despite the increasing popularity of WiFi networks and the trend toward automated offloading of cellular traffic to WiFi (e.g., HotSpot 2.0), today's WiFi networks still provide a very poor actual coverage: a WiFi equipped device can typically connect to the Internet only through a very small fraction of the \"available\" access points. Accordingly, there is an enormous potential for multi-tenant WiFi hotspot architectures, which however also introduce more stringent requirements in terms of scalability and security. The latter is particularly critical, as HotSpots are often deployed in untrusted environments, e.g., physically accessible Access Points deployed in the user's premises (e.g., FON) or cafes. This paper proposes a Cloud-assisted multi-tenant and secure WiFi HotSpot infrastructure, called SecuSpot. SecuSpot is based on a modular access point and features interesting deployment flexibilities. These flexibilities can be exploited, e.g., to move security critical functions to the Cloud, and hence prevent eavesdropping even when deployed across untrusted Access Points. At the heart of SecuSpot lies a novel programmable wireless switch, the wSwitch. The wSwitch allows to (de-)multiplex the different tenants already on the HotSpot and to decouple essential security functions (association, authentication, and cryptography).","PeriodicalId":286425,"journal":{"name":"Proceedings of the 2016 ACM Workshop on Cloud-Assisted Networking","volume":"74 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-12-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2016 ACM Workshop on Cloud-Assisted Networking","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3010079.3012015","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Despite the increasing popularity of WiFi networks and the trend toward automated offloading of cellular traffic to WiFi (e.g., HotSpot 2.0), today's WiFi networks still provide a very poor actual coverage: a WiFi equipped device can typically connect to the Internet only through a very small fraction of the "available" access points. Accordingly, there is an enormous potential for multi-tenant WiFi hotspot architectures, which however also introduce more stringent requirements in terms of scalability and security. The latter is particularly critical, as HotSpots are often deployed in untrusted environments, e.g., physically accessible Access Points deployed in the user's premises (e.g., FON) or cafes. This paper proposes a Cloud-assisted multi-tenant and secure WiFi HotSpot infrastructure, called SecuSpot. SecuSpot is based on a modular access point and features interesting deployment flexibilities. These flexibilities can be exploited, e.g., to move security critical functions to the Cloud, and hence prevent eavesdropping even when deployed across untrusted Access Points. At the heart of SecuSpot lies a novel programmable wireless switch, the wSwitch. The wSwitch allows to (de-)multiplex the different tenants already on the HotSpot and to decouple essential security functions (association, authentication, and cryptography).