SeQR: A User-Friendly and Secure-by-Design Configurator for Enterprise Wi-Fi

Passwords & AuthenticationPrivacy Perception & Decision-MakingIoT Device PrivacyCybersecurity EngineersGovernment Officials & Civil Servants

Research Background and Problem

  • Identified Problems or Challenges:
    The authors highlight the issue of client misconfiguration in enterprise-mode Wi-Fi services, which makes users vulnerable to "Evil Twin" (ET) attacks. In ET attacks, malicious Wi-Fi access points can mimic legitimate Wi-Fi services, causing improperly verified clients to inadvertently expose sensitive credentials.

  • Why This Problem is Important:
    Enterprise-mode Wi-Fi supports access to organizational resources through fine-grained permission management. However, when credentials are stolen by attackers, it can lead to severe security issues such as network intrusions and data breaches.

  • Research Motivation and Related Work:
    Current enterprise Wi-Fi configuration interfaces have significant shortcomings. Users are required to perform complex configuration tasks and are prone to selecting insecure configuration options. Even when IT administrators provide configuration guidelines, users may still configure insecure settings. Additionally, related studies show that existing configuration methods lack mandatory security guarantees, and users/administrators tend to choose faster but less secure options.

Solution

  • Proposed Solution and Method:
    The authors propose a new configurator, SeQR, which prevents user errors by automatically configuring Wi-Fi connection parameters and reinforcing security-critical verifications. The system employs QR codes to carry connection information and uses existing trusted channels to distribute this information.

  • Innovations:

    1. Eliminates the possibility of users selecting insecure configurations by programmatically verifying certificates as part of the security design.
    2. Utilizes QR codes as carriers for connection configuration, enabling an automated process that simplifies user interaction to a "scan-and-connect" workflow.
    3. Discards the complex X.509 certificate chain verification mechanism, significantly simplifying implementation and eliminating related design and implementation vulnerabilities.
  • Implementation Steps and Key Techniques:

    • Encode connection parameters such as SSID and authentication methods into a QR code and publish it through authenticated channels (e.g., organizational web pages).
    • After scanning the QR code, SeQR automatically completes client Wi-Fi configuration, including selecting the correct verification method and pinning certificate fingerprints.
    • SeQR enforces programmatic verifications, including checks on certificate fingerprints, configuration validity, and associated server names.
    • The system ultimately stores the secure configuration to support subsequent automatic connections.

Research Outcomes

  • Specific Results:

    1. Developed a prototype of SeQR and tested its effectiveness on LineageOS (an Android-based operating system).
    2. Under experimental conditions, SeQR successfully defended against ET attacks and automatically rejected connections using forged certificates.
    3. User studies demonstrated that SeQR significantly improved user experience compared to existing configuration interfaces.
  • Advantages Compared to Existing Solutions:

    1. Eliminates the risk of users selecting insecure options in existing UIs.
    2. Reduces the complexity of user interactions and inputs, significantly lowering user errors and operational burden.
    3. Fully programmatizes the verification process, enhancing security and consistency.
  • Experimental or Evaluation Results:

    • User studies showed that SeQR significantly reduced the time required for a first successful connection and the number of failed attempts.
    • In System Usability Scale (SUS) and NASA Task Load Index (NASA-TLX) evaluations, SeQR demonstrated significant superiority.
    • Users generally found the "scan-and-connect" workflow of SeQR to be more efficient and user-friendly.
  • Limitations and Future Directions:

    1. SeQR relies on existing authenticated channels (e.g., websites), and attackers may attempt to compromise the process through forged QR codes or guidance.
    2. The current research focuses primarily on Android devices; future work could extend to other platforms (e.g., Windows or MacOS).
    3. While QR codes are convenient, future explorations could include other carriers (e.g., NFC tags) to further enhance applicability.
    4. Further analysis is needed on user awareness and behavioral patterns in preventing ET attacks.

In summary, SeQR not only excels in security design but also transforms the way users interact with enterprise Wi-Fi configuration. It has the potential for widespread application in configuring other security protocols and device environments in the future.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/189236/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3714223
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
5 authors
sell
Subtopics
Passwords & Authentication, Privacy Perception & Decision-Making, IoT Device Privacy
work
Professions
Cybersecurity Engineers, Government Officials & Civil Servants
article
Content Status
Full text indexed
hub
Related Papers
0 related papers