WI-FI deauthentication attack detection and prevention
By comparing the difference between the transmitter signature and the protected frame of the unprotected management frame in Wi-Fi client devices, identifying and preventing fake disassociation and deauthentication frames, the vulnerability in Wi-Fi deployment is solved and network security is improved.
Patent Information
- Application Number
- CN202380086191.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-21
- Filing Date
- 2023-12-04
- Publication Date
- 2025-07-22
AI Technical Summary
In existing Wi-Fi deployments, many systems do not support or implement protected management frames, resulting in vulnerability to forged disassociation and deauthentication frame attacks, causing devices to disconnect and potentially subject to denial of service attacks and password dictionary attacks.
By detecting the transmitter signature of the unprotected management frame in the client device, comparing with the signature of the previously received protected frame, the forged disassociation and deauthentication frame is identified, and the difference exceeds the threshold is determined using the MAC/PHY signature engine to identify the forged frame and discard or remediate.
Effectively detect and prevent fake Wi-Fi deauthentication attacks, prevent device disconnection and potential network attacks, and improve network security.
Smart Images

Figure CN120359724A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to wireless communication. For example, aspects of the present disclosure relate to Wi-Fi deauthentication attacks. Background Art
[0002] Wireless communication systems are deployed to provide various telecommunication services including telephony, video, data, messaging, broadcasting, etc. These systems may be multi-access systems capable of supporting communication with multiple users by sharing available system resources such as time, frequency, and power. Multi-access systems may be based on code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), and orthogonal frequency division multiple access (OFDMA), etc.
[0003] Wireless networks such as wireless local area networks (WLANs) such as Wi-Fi (e.g., Institute of Electrical and Electronics Engineers (IEEE) 802.11) networks may include one or more access points (APs) that can communicate with one or more stations (STAs) or mobile devices. One or more APs may provide a shared wireless communication medium for use by multiple STAs. The AP may be coupled to a network such as the Internet and may enable mobile devices to communicate via the network (or communicate with other devices coupled to the access point). Wireless devices may communicate bidirectionally with network devices. For example, in a WLAN, an STA may communicate with an associated AP via a downlink (DL) and an uplink (UL). The DL (or forward link) may refer to the communication link from the AP to the station, while the UL (or reverse link) may refer to the communication link from the station to the AP. Summary of the Invention
[0004] The following presents a simplified summary of one or more aspects related to the present disclosure. Accordingly, the following summary should not be considered an exhaustive overview of all contemplated aspects, nor should it be considered to identify key or critical elements of all contemplated aspects or to delineate the scope associated with any particular aspect. Thus, the sole purpose of the following summary is to present in a concise form certain concepts related to one or more aspects of the mechanisms disclosed herein before the detailed description that follows.
[0005] Systems, methods, apparatuses, and computer-readable media for performing wireless communication are disclosed. According to at least one illustrative example, an apparatus for wireless communication is provided. The apparatus includes at least one memory; and at least one processor coupled to the at least one memory and configured to: receive an unprotected management frame indicating a disconnection of the apparatus, where the unprotected management frame includes an address of an identified wireless access point (AP) associated with the disconnection; determine a transmitter signature associated with the unprotected management frame; determine a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP; and based on the difference being greater than a threshold, determine that the unprotected management frame was not sent by the identified wireless AP.
[0006] In another example, a method for wireless communication at a network device is provided. The method includes: receiving an unprotected management frame indicating a disconnection of the network device, where the unprotected management frame includes an address of an identified wireless access point (AP) associated with the disconnection; determining a transmitter signature associated with the unprotected management frame; determining a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP; and based on the difference being greater than a threshold, determine that the unprotected management frame was not sent by the identified wireless AP.
[0007] A non-transitory computer-readable storage medium for a network device is provided, on which instructions are stored that, when executed by one or more processors, cause the one or more processors to: receive an unprotected management frame indicating a disconnection of the network device, where the unprotected management frame includes an address of an identified wireless access point (AP) associated with the disconnection; determine a transmitter signature associated with the unprotected management frame; determine a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP; and based on the difference being greater than a threshold, determine that the unprotected management frame was not sent by the identified wireless AP.
[0008] An apparatus for wireless communication is provided. The apparatus includes: means for receiving an unprotected management frame indicating a disconnection of the apparatus, where the unprotected management frame includes an address of an identified wireless access point (AP) associated with the disconnection; means for determining a transmitter signature associated with the unprotected management frame; means for determining a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP; and means for based on the difference being greater than a threshold, determining that the unprotected management frame was not sent by the identified wireless AP.
[0009] Each aspect generally includes a method, apparatus, system, computer program product, non-transitory computer-readable medium, user equipment, base station, wireless communication device, and / or processing system, as fully described herein with reference to the accompanying drawings and the specification and as illustrated in the accompanying drawings and the specification. In some aspects, one or more of the above-described apparatuses are or are part of the following: a camera, a mobile device (e.g., a mobile phone or a so-called "smartphone" or other mobile device), a vehicle or a computing system or device of a vehicle, a wearable device, an extended reality device (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a personal computer, a laptop computer, a server computer, or other devices.
[0010] The features and technical advantages of examples in accordance with the present disclosure have been outlined rather broadly above so that the detailed description that follows may be better understood. Additional features and advantages will be described hereinafter. The disclosed concepts and specific examples may be readily utilized as a basis for modifying or designing other structures for achieving the same purposes of the present disclosure. Such equivalent constructions do not depart from the scope of the appended claims. When considered in conjunction with the accompanying drawings, the features of the concepts disclosed herein, the manner of their organization and operation, and the associated advantages, will be better understood from the following description. Each of the drawings provided herein is for the purpose of illustration and description and not as a definition of the limits of the claims.
[0011] Although aspects are described herein by way of illustration of some examples, those skilled in the art will understand that such aspects may be implemented in many different arrangements and scenarios. The techniques described herein may be implemented using different platform types, devices, systems, shapes, sizes, and / or packaging arrangements. For example, some aspects may be embodied via an integrated chip or other non-module component-based devices (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / shopping devices, medical devices, and / or artificial intelligence devices). Aspects may be implemented in chip-level components, modular components, non-modular components, non-chip-level components, device-level components, and / or system-level components. Devices incorporating the described aspects and features may include additional components and features for implementing and practicing the claimed and described aspects. For example, the transmission and reception of wireless signals may include one or more components for analog and digital purposes (e.g., hardware components including antennas, radio frequency (RF) chains, power amplifiers, modulators, buffers, processors, interleavers, adders, and / or summers). The aspects described herein are intended to be practiced in a wide variety of devices, components, systems, distributed arrangements, and / or end-user devices of various sizes, shapes, and configurations.
[0012] Based on the accompanying drawings and the specific embodiments, other objectives and advantages associated with the various aspects disclosed herein will be apparent to those skilled in the art. This summary is not intended to identify the key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood with reference to the appropriate portions of the entire specification of this patent, any or all of the drawings, and each claim.
[0013] The foregoing, as well as other features and aspects, will become more apparent when referring to the following specification, claims, and appended drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Exemplary aspects of the present application are described in detail below with reference to the following drawings:
[0015] Figure 1 is a block diagram illustrating an exemplary wireless communication network according to some examples;
[0016] Figure 2 is a diagram illustrating an exemplary communication flow associated with a Wi-Fi deauthentication attack according to some examples;
[0017] Figure 3 is a diagram illustrating an exemplary system that can be used to detect a Wi-Fi deauthentication attack and / or detect forged unprotected Wi-Fi management frames according to some examples;
[0018] Figure 4 is a flowchart illustrating an exemplary process for performing wireless communication; and
[0019] Figure 5 is a block diagram illustrating an example of a computing system for implementing certain aspects described herein. DETAILED DESCRIPTION
[0020] Certain aspects of the present disclosure are provided below. Some of these aspects can be applied independently, and some of them can be applied in combination, which will be apparent to those skilled in the art. In the following description, specific details are set forth for the purpose of explanation to provide a thorough understanding of the aspects of the present application. However, it will be apparent that the various aspects can be implemented without these specific details. The drawings and the description are not intended to be restrictive.
[0021] The following description provides only example aspects and is not intended to limit the scope, applicability, or configuration of the present disclosure. Instead, the following description of the example aspects will provide those skilled in the art with a description that can be used to implement the example aspects. It should be understood that various changes can be made to the functions and arrangements of the elements without departing from the spirit and scope of the present application as set forth in the appended claims.
[0022] Many Wi-Fi deployments (such as deployments of Wi-Fi networks, access points (APs), client devices, or stations (STAs), etc.) currently do not support or otherwise implement the use of protected management frames (such as disassociation and / or deauthentication frames). For example, many Wi-Fi deployments currently utilize Wi-Fi Protected Access II (WPA2) (where protected management frames are optional) or otherwise do not support Wi-Fi Protected Access III (WPA3) (where protected management frames are made mandatory). There is a need for systems and techniques that can be used to detect and prevent forged management frames in Wi-Fi networks that utilize unprotected (e.g., unencrypted) management frames. There is also a need for systems and techniques that can be used to detect and prevent forged disassociation frames and / or forged deauthentication frames associated with disassociation attacks in Wi-Fi networks that utilize unprotected frames (e.g., unencrypted management frames).
[0023] This document describes systems, apparatuses, processes (also referred to as methods), and computer-readable media (collectively referred to as "systems and techniques") for detecting Wi-Fi deauthentication attacks. For example, the systems and techniques can determine one or more signatures for unprotected Wi-Fi management frames. The signatures associated with currently received unprotected (e.g., unencrypted) frames can be analyzed against one or more corresponding signatures associated with previously received protected (e.g., encrypted) frames. In some cases, one or more signatures can be determined by a client device or station (STA) that receives frames from the respective one or more access points (APs). For example, the systems and techniques can be used to detect forged deauthentication frames and / or forged disassociation frames associated with Wi-Fi deauthentication attacks.
[0024] In some cases, the systems and techniques can be used to detect Wi-Fi deauthentication attacks based on determining that the MAC / PHY signatures associated with unprotected deauthentication or disassociation frames are different from the MAC / PHY signatures associated with protected frames. For example, an STA can determine one or more MAC / PHY signatures for each protected frame received from one or more APs (e.g., where the transmitting AP associated with the protected frame is determined based on the MAC address and successful decryption of the protected data frame or other AP identifiers included in the protected frame and / or protected frame header).
[0025] Based on receiving an unprotected management frame (e.g., an unprotected deauthentication or disassociation frame) claiming to be from an AP that has previously determined a MAC / PHY signature, the MAC / PHY signature of the unprotected management frame can be compared to the MAC / PHY signature of a protected data frame sent by the indicated AP. Based on this comparison, the system and techniques can determine whether the unprotected deauthentication or disassociation frame is genuine (e.g., not forged, sent by the AP identified in the unprotected frame) or not genuine (e.g., forged, sent by a forged AP different from the AP identified in the unprotected frame). In some examples, based on determining that the unprotected deauthentication or disassociation frame is sent by a forged AP, the system and techniques can be used to discard the corresponding frame or packet and / or indicate the attempted attack for further remediation.
[0026] Some or all of the examples described herein can be implemented in any device, system, or network capable of sending and receiving radio frequency (RF) signals according to one or more of the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards, IEEE 802.15 standards, standards defined such as by the Bluetooth Special Interest Group (SIG), or standards released by the Third Generation Partnership Project (3GPP) such as Long Term Evolution (LTE), 3G, 4G, 5G (New Radio (NR)), or other standards. The specific implementations described can be implemented in any device, system, or network capable of sending and receiving RF signals according to one or more of the following technologies or techniques: Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal FDMA (OFDMA), Single Carrier FDMA (SC-FDMA), Single User (SU) Multiple Input Multiple Output (MIMO), and Multi-User (MU) MIMO. The specific implementations described can also be implemented using other wireless communication protocols or RF signals suitable for use in one or more of a Wireless Personal Area Network (WPAN), Wireless Local Area Network (WLAN), Wireless Wide Area Network (WWAN), or Internet of Things (IoT) network.
[0027] Additional aspects of the system and techniques will be described with reference to the drawings.
[0028] As used herein, the phrase "based on" should not be construed to refer to a closed set of information, one or more conditions, one or more factors, etc. In other words, the phrase "based on A" (where "A" can be information, a condition, a factor, etc.) should be construed as "at least based on A", unless stated differently specifically.
[0029] Figure 1is a block diagram illustrating an example wireless communication network 100. In some aspects, wireless communication network 100 may be an example of a wireless local area network (WLAN). As used herein, a WLAN may also be referred to as a Wi-Fi network. In some examples, WLAN 100 may be a network that implements at least one of the IEEE 802.11 family of wireless communication protocol standards (e.g., standards defined by the IEEE 802.11-2016 specification or its revisions, including but not limited to 802.11ay, 802.11ax, 802.11az, 802.11ba, and 802.11be). WLAN 100 may include at least one access point (AP) 102 and a plurality of associated stations (STA) 104. Although only one AP 102 is shown, WLAN network 100 may also include multiple APs 102.
[0030] Each STA in STA 104 may also be referred to as a mobile station (MS), mobile device, mobile phone, wireless phone, access terminal (AT), user equipment (UE), subscriber station (SS), and / or subscriber unit, etc. STA 104 may represent various devices, such as mobile phones, personal digital assistants (PDAs), other handheld devices, netbooks, notebook computers, tablet computers, laptop computers, display devices (e.g., TVs, computer monitors, navigation systems, etc.), music or other audio or stereo devices, remote control devices (“remote controls”), printers, kitchen or other household appliances, remote key fobs (e.g., for passive keyless entry and start (PKES) systems), etc.
[0031] A single AP 102 and the associated set of STAs 104 may be referred to as a basic service set (BSS), which is managed by the corresponding AP 102. Figure 1 An example coverage area 106 of AP 102 is additionally shown, which may represent the basic service area (BSA) of WLAN 100. A BSS may be identified to users by a service set identifier (SSID) and to other devices by a basic service set identifier (BSSID), which may be the media access control (MAC) address of AP 102.
[0032] The AP 102 periodically broadcasts beacon frames ("beacons") including the BSSID so that any STA 104 within the wireless range of the AP 102 can "associate" or re-associate with the AP 102 to establish a corresponding communication link 108 (e.g., also referred to hereinafter as a "Wi-Fi link"). The STA 104 can additionally use the beacon frames broadcast by the AP 102 to maintain the communication link 108 with the AP 102. For example, the beacon can include the identification of the primary channel used by the corresponding AP 102 and a timing synchronization function for establishing or maintaining timing synchronization with the AP 102. The AP 102 can provide access to an external network to various STAs 104 in the WLAN via the corresponding communication link 108.
[0033] To establish a communication link 108 with the AP 102, each of the STAs 104 can perform a passive or active scanning operation ("scanning") on frequency channels in one or more frequency bands (e.g., 2.4 GHz, 5 GHz, 6 GHz, or 60 GHz bands). For example, to perform passive scanning, the STA 104 listens for beacons sent by the corresponding AP 102 at periodic time intervals (referred to as the Target Beacon Transmission Time (TBTT)). The TBTT can be measured in time units (TUs). In some examples, one TU can be equal to 1024 microseconds (μs). To perform active scanning, the STA 104 generates probe requests and sequentially sends these probe requests on each channel to be scanned, and listens for probe responses from the AP 102. Each STA 104 can be configured to identify or select the AP 102 with which to associate (e.g., based on scanning information obtained through passive or active scanning), and perform authentication and association operations to establish a communication link 108 with the selected AP 102. The AP 102 assigns an association identifier (AID) to the STA 104 at the end of the association operation, and the AP 102 uses this association identifier (AID) to track the STA 104.
[0034] In some cases, STA 104 may have the opportunity to select one of many BSSs within the range of that STA or among multiple APs 102 that together form an extended service set (ESS) (including multiple connected BSSs). Extended network stations associated with WLAN 100 can connect to a wired or wireless distribution system that permits multiple APs 102 to be connected within such an ESS. In some examples, STA 104 may be covered by more than one AP 102 and may be associated with different APs 102 at different times for different transmissions. After associating with an AP 102, STA 104 may also be configured to periodically scan its surroundings to look for a more suitable AP 102 to associate with. For example, a STA 104 that is moving relative to its associated AP 102 may perform a "roaming" scan to look for another AP 102 with more desirable network characteristics (e.g., such as a greater received signal strength indicator (RSSI), reduced traffic load, etc.).
[0035] In some cases, STA 104 may form a network without an AP 102 or without other equipment other than STA 104 itself. An example of such a network is an ad hoc network (e.g., or a wireless ad hoc network). An ad hoc network may alternatively be referred to as a mesh network or a peer-to-peer (P2P) network. In some cases, an ad hoc network may be implemented within a larger wireless network (e.g., such as WLAN 100). In such embodiments, although STA 104 may be able to communicate with each other through an AP 102 using communication link 108, STA 104 may also communicate directly with each other (e.g., with other STA 104) using a direct wireless link 110. In some examples, two STA 104 may communicate via a direct communication link 110 regardless of whether the two STA 104 are associated with the same AP 102 and served by the same AP. In such an ad hoc system, one or more STA 104 may assume the role that an AP 102 serves in a BSS. Such STA 104 may be referred to as a group owner (GO) and may coordinate transmissions within the ad hoc network. Examples of direct wireless link 110 may include one or more (or all) Wi-Fi direct connections, connections established through the use of Wi-Fi tunnel direct link setup (TDLS) links, and other P2P group connections, etc.
[0036] AP 102 and STA 104 can operate and communicate (e.g., using the respective communication link 108) according to the IEEE 802.11 series of wireless communication protocol standards (e.g., standards defined such as by the IEEE 802.11-2016 specification or its revisions, including but not limited to 802.11ay, 802.11ax, 802.11az, 802.11ba, and 802.11be). These standards define the WLAN radio and baseband protocols for the physical (PHY) and media access control (MAC) layers. For example, AP 102 and STA 104 send and receive wireless communications (e.g., also referred to hereinafter as "Wi-Fi communications") to and from each other in the form of PHY protocol data units (PPDUs) (or physical layer convergence protocol (PLCP) PPDUs). The AP 102 and STA 104 in the WLAN 100 can send PPDUs on an unlicensed spectrum, which can be part of a spectrum that includes bands traditionally used by Wi-Fi technology (such as the 2.4 GHz band, 5 GHz band, 60 GHz band, 3.6 GHz band, and 900 MHz band). Some specific implementations of the AP 102 and STA 104 described herein can also communicate in other bands (such as the 6 GHz band) that can support both licensed and unlicensed communications. The AP 102 and STA 104 can also be configured to communicate on other bands (such as shared licensed bands) where multiple operators can have licenses to operate in one or more of the same or overlapping bands.
[0037] Each of the bands can include multiple sub-bands or frequency channels. For example, PPDUs compliant with the IEEE 802.11n, 802.11ac, 802.11ax, and 802.11be standard revisions can be sent on the 2.4 GHz, 5 GHz, or 6 GHz bands, where each of these bands is divided into multiple 20 MHz channels. Thus, these PPDUs are sent on physical channels with a 20 MHz minimum bandwidth. In some cases, larger bandwidth channels can be formed by channel bonding. For example, PPDUs can be sent on physical channels that have a 40 MHz, 80 MHz, 160 MHz, or CCC20 MHz bandwidth by bonding multiple 20 MHz channels together.
[0038] Each PPDU is a composite structure that includes a PHY preamble and a payload in the form of a PHY Service Data Unit (PSDU). The information provided in the preamble can be used by a receiving device to decode subsequent data in the PSDU. In instances where the PPDU is transmitted on a bound channel, the preamble field can be replicated and transmitted in each of a plurality of component channels. The PHY preamble can include both a legacy portion (or "legacy preamble") and a non-legacy portion (or "non-legacy preamble"). The legacy preamble can be used for other purposes such as packet detection, automatic gain control, and channel estimation. The legacy preamble is also typically used to maintain compatibility with legacy devices. The format, decoding, and information provided in the non-legacy portion of the preamble are based on the particular IEEE 802.11 protocol to be used for transmitting the payload.
[0039] As previously mentioned, a Wi-Fi network (e.g., such as WLAN 100) can utilize different frames (e.g., different frame types and / or different frame structures) for wireless communication. Wi-Fi frames can also be referred to as datagrams or L2 datagrams. In one illustrative example, a Wi-Fi network can utilize management frames, control frames, and data frames. Management frames can be used to manage the BSS, control frames can be used to control access to the physical transmission medium, and data frames can be used to transmit payload data. In some aspects, data frames can carry a payload that indicates layer 3 to layer 7 information (e.g., based on the OSI model of communication).
[0040] Each Wi-Fi frame can include a Media Access Control (MAC) header, a payload, and a Frame Check Sequence (FCS). In some cases, a Wi-Fi frame can be generated (e.g., transmitted, received, etc.) without including a payload. In some examples, the first two bytes of the MAC header can indicate a Frame Control field that specifies the form and function of the frame. For example, the Frame Control field can include one or more bits that indicate the type of the associated Wi-Fi frame (e.g., management frame, control frame, data frame). In one illustrative example, the Frame Control field can include two bits that indicate the frame type of the Wi-Fi frame that includes the MAC header (e.g., which itself includes Frame Control field bits).
[0041] The MAC header of a Wi-Fi frame may additionally include a sequence control field. The sequence control field is a two-byte section that can be used to indicate or identify the message order and / or eliminate duplicate frames. The sequence control field may include a 4-bit fragment number followed by a 12-bit sequence number. Wi-Fi frames sent between a given AP-STA pair may each be associated with a unique sequence control value (e.g., also referred to as a sequence control number or sequence number). For each different AP-STA pair that uses one or more Wi-Fi frames to perform wireless communication with each other, the sequence control value may be maintained and incremented as a separate sequence (e.g., a counter).
[0042] Management frames can be used for the maintenance or interruption of communication between an AP and a STA. For example, management frame subtypes include authentication frames, association frames, deauthentication frames, and disassociation frames, etc.
[0043] An authentication frame may include an authentication request frame sent from a STA to an AP, thereby requesting authentication of the STA to access the AP and / or the WLAN (e.g., Wi-Fi network) associated with the AP. The authentication request frame may include or otherwise indicate the identity of the STA. The AP may perform authentication of the indicated STA identity and may generate and send an authentication response frame. The authentication response frame may indicate the authentication result (e.g., accepted or rejected) of the STA. The authentication result may also be referred to as the authentication status of the STA.
[0044] An association request frame may be sent from a STA to an AP. The association request frame can be used by the AP to allocate resources and synchronize with the STA. For example, the association request frame may indicate information about the STA, such as the SSID of the network that the STA wishes to associate with (e.g., connect to). The AP may accept or not accept the association request indicated by the association request frame. If the association request is accepted, the AP may reserve memory and establish an association ID for the STA.
[0045] An association response frame is sent from the AP to the STA (e.g., the STA that sent the association request frame received by the AP). The association response frame may indicate whether the AP accepts or rejects the STA's association request. If the association response is an acceptance, the association response frame sent by the AP may indicate association ID information, supported data rate information, etc.
[0046] The disassociation frame can be sent by either the STA or the AP. The disassociation frame can be used to terminate the association of the STA (e.g., the association between the STA and the AP). The disassociation frame can be implemented as a notification type frame that does not expect a response. For example, the STA can send a disassociation frame to the AP before powering off. In another example, the AP can send a disassociation frame to the STA to disassociate the STA from the AP. The AP can disassociate from the STA based on factors such as failure to authenticate correctly, load balancing, timeout, entering a maintenance state, etc. The disassociation frame can include a reason code in the body of the disassociation frame.
[0047] When the STA is disassociated, the STA maintains its authentication with the AP that sent the disassociation frame received by the STA. For example, maintaining the authentication of the STA can permit easier association with the same AP at a future time. In an illustrative example, the STA that is disassociated from the AP (e.g., based on the STA sending a disassociation frame to the AP, or the STA receiving a disassociation frame from the AP) can reconnect to the AP (e.g., re-associate with it) by sending an association request frame at a future time.
[0048] The deauthentication frame can be sent from the AP to the STA. The deauthentication frame can be used to reset the state machine of the associated client (e.g., the STA that receives the deauthentication frame). The deauthentication frame can include a reason code in the body of the deauthentication frame. When the STA receives the deauthentication frame, the STA deauthenticates from the AP and also disassociates from the AP (e.g., based on the authentication performed prior to association during the connection process between the STA and the AP). The STA that is deauthenticated from the AP must send an authentication request frame and an association request frame to the AP in order to reconnect at a future time.
[0049] The Wi-Fi Protected Access (WPA) protocol can be used to secure Wi-Fi networks and / or other WLANS. The WPA protocol includes WPA, WPA2, and WPA3. A Wi-Fi network protected using WPA can be password protected with an exchanged encryption key that is used to encrypt the frames sent between a given AP and STA. For example, the four-way handshake can be used by the AP and STA to exchange the sending key.
[0050] A Wi-Fi frame can be a protected frame or can be an unprotected frame. Protected frames are sent after key establishment (e.g., between the AP and the STA) and can be protected using the existing protection key hierarchy in the 802.11 standard and its revisions. For example, the WPA keys exchanged between the AP and STA using the four-way handshake can be used to protect (e.g., encrypt) the protected frames. Wi-Fi data frames are sent as protected frames.
[0051] Send unprotected frames without using a protected key hierarchy. For example, unprotected frames can be sent before the AP and STA have completed key establishment (e.g., before completing the four-way handshake for exchanging the sending key). Unprotected frames can also be sent after the AP and STA have completed key establishment (e.g., the sending key has been exchanged but is not used for sending unprotected frames).
[0052] Some Wi-Fi management frames are always sent as unprotected frames. Other Wi-Fi management frames can be sent as protected or unprotected frames. For example, Wi-Fi management frames sent before WPA key establishment are sent as unprotected frames. The required Wi-Fi management frames sent before the four-way handshake for WPA key exchange include beacon frames, authentication frames, and association frames, etc.
[0053] Wi-Fi management frames sent after WPA key establishment can be sent as protected or unprotected frames. Wi-Fi management frames sent after key establishment can also be referred to as "protected-capable management frames". Protected-capable management frames include disassociation frames and deauthentication frames, etc. WPA3 requires protected-capable management frames to be sent as protected (e.g., encrypted) frames. For example, an AP implementing WPA3 will always send protected (e.g., encrypted) disassociation frames and deauthentication frames.
[0054] In a Wi-Fi network implementing WPA2, the use of protected management frames is optional. For example, a WPA2 Wi-Fi network can be configured to use protected disassociation and deauthentication frames encrypted with the WPA2 key exchanged between the AP and the STA (e.g., protected disassociation and deauthentication frames can be encrypted in the same way as Wi-Fi data frames). However, a WPA2 Wi-Fi network can also be configured to use unprotected disassociation and deauthentication frames that are sent publicly and without integrity checking. Unprotected disassociation and / or deauthentication frames are not encrypted and may be vulnerable to attacks.
[0055] For example, when a Wi-Fi network does not use protected management frames (and specifically, does not use protected disassociation and / or deauthentication frames), an attacker can inject forged disassociation or deauthentication frames to disconnect one or more STAs from the network. In some examples, forged deauthentication frames can be injected to force a STA to reconnect to the network, and the attacker can then capture the authentication frames exchanged during the forced reconnection to perform a dictionary attack on the passwords associated with the Wi-Fi network.
[0056] Figure 2FIG. 200 is a diagram illustrating an example communication flow associated with a Wi-Fi deauthentication attack (e.g., also referred to herein as a Wi-Fi disconnection attack). In a Wi-Fi disconnection attack, a STA 202 may initiate communication with a legitimate AP 206 before subsequently receiving a forged, unprotected deauthentication or disassociation frame from a forged AP 204 (e.g., also referred to as an attacker AP). Based on receiving the forged deauthentication or disassociation frame, the STA 202 may disconnect from the legitimate AP 206 and be forced to connect to the forged AP 204, as will be described in more depth below.
[0057] To register with the legitimate AP 206, the STA 202 may send an authentication request frame 222, as previously described above. Based on receiving the authentication request frame 222, the legitimate AP 206 authenticates the STA 202 (e.g., accepts or rejects the STA) and sends an authentication response frame 224 indicating the authentication result (e.g., also as described above). If the authentication response frame 224 indicates an 'accepted' authentication result, the STA 202 sends an association request frame 232 to the legitimate AP 206 and subsequently receives a corresponding association response frame 234 (e.g., also as described above).
[0058] The authentication request and response frames 222, the authentication request and response frames 224 (respectively), and the association request and response frames 232, the association request and response frames 234 (respectively) may each be unprotected (e.g., unencrypted) management frames. For example, because the authentication and association frames are sent before key establishment (e.g., WPA2, WPA3, etc.) between the STA 202 and the legitimate AP 206, the authentication and association frames are unprotected frames in Wi-Fi networks based on both WPA2 and WPA3.
[0059] After receiving the association response frame 234, the STA 202 may connect to the legitimate AP 206 and the corresponding Wi-Fi network associated with the legitimate AP 206. Once connected, the STA 202 and the legitimate AP 206 may perform one-way communication and / or two-way communication.
[0060] The forged AP 204 can generate and send forged, unprotected deauthentication frames 250, which disconnect the STA 202 from the legitimate AP 206. The forged deauthentication frame 250 can be a unicast frame (e.g., sent from the forged AP 204 to the STA 202), or can be a broadcast frame (e.g., broadcast from the forged AP 204 to multiple STAs including the STA 202). The forged AP 204 may also be referred to as an attacker AP and / or a malicious AP. The forged AP 204 is different from the legitimate AP 206 and may not be connected to the same Wi-Fi network as the legitimate AP 206 or otherwise associated with that Wi-Fi network.
[0061] For example, based on retrieving the MAC address of the legitimate AP 206 and the BSSID of the Wi-Fi network associated with the legitimate AP 206, the forged AP 204 can "forge" the legitimate AP 206. By sending Wi-Fi frames that are altered (e.g., forged) to include the MAC address of the legitimate AP 206 and the corresponding Wi-Fi network BSSID, the altered Wi-Fi frames sent by the forged AP 204 will (e.g., to the STA 202) appear to have been sent by the legitimate AP 206.
[0062] In some aspects, when the legitimate AP 206 does not support or implement management frame protection, the STA 202 treats the forged deauthentication frame 250 (e.g., sent by the forged AP 204) as a legitimate deauthentication frame indicating a disconnection command from the legitimate AP 206. As previously mentioned, the forged deauthentication frame 250 can be a unicast frame or a multicast (e.g., broadcast) frame. When the legitimate AP 206 does not support or implement management frame protection, the forged AP 204 can generate and send a forged unicast deauthentication frame 250 based on determining the MAC address of the legitimate AP 206, the corresponding BSSID of the Wi-Fi network associated with the legitimate AP 206, and the MAC address of the STA 202. To generate and send a forged broadcast deauthentication frame 250, the forged AP 250 does not need to determine the MAC address of the connected client (e.g., STA) and can utilize only the MAC address of the legitimate AP 206 and the corresponding BSSID.
[0063] In some cases, the MAC address (e.g., the MAC address of the real AP 206, STA 202, and / or any other connected client associated with the real AP 206) and the BSSID can be obtained by the spoofed AP 204 using packet sniffing on one or more Wi-Fi channels. After the spoofed AP 204 generates a spoofed deauthentication frame 250 and sends the spoofed deauthentication frame to the STA 202, the connection between the STA 202 and the real AP 206 is terminated (e.g., the STA 202 disassociates and deauthenticates from the real AP 206).
[0064] A disassociation attack can be performed based on using the spoofed deauthentication frame 250 to force one or more clients (e.g., STA 202) to disconnect from the real AP 206. Repeatedly performing the disassociation attack can be used to implement a denial-of-service (DoS) attack. In some cases, the disassociation attack may result in an unstable connection between the STA 202 and the real AP 206 and / or may cause the STA 202 to blacklist the real AP 206 (and / or the entire Wi-Fi network associated with the real AP 206) for an extended period of time. The disassociation attack can also be used to implement a dictionary attack against the password used to secure the Wi-Fi network using WPA2 (e.g., WPA2-Personal) encryption. For example, in such a scenario, the spoofed AP 204 can perform the disassociation attack within a relatively short period of time to interrupt the connection between the STA 202s and force the STA 202 to reconnect to the Wi-Fi network associated with the real AP 206. The attacker (e.g., the spoofed AP 204 and / or other devices associated with the spoofed AP 204) can capture the authentication frames exchanged between the STA 202 and the real AP 206 during the forced reconnection in order to perform a dictionary attack on the password used to secure the corresponding Wi-Fi network.
[0065] In a further example, the disassociation or deauthentication attack can be extended to perform a honeypot or man-in-the-middle attack, which can be used to manipulate one or more client devices (e.g., STA 202) to move away from the AP they are currently connected to (e.g., the real AP 206) and instead join the attacker's AP (e.g., the spoofed AP 204). For example, as Figure 2As illustrated, after sending a forged deauthentication frame 250 that disconnects the STA 202 from the genuine AP 206, the STA 202 can be driven to connect to the forged AP 206 (e.g., instead of reconnecting to the genuine AP 204). The connection between the STA 202 and the forged AP 204 can be performed based on an authentication request frame 262, an authentication response frame 264, an association request frame 272, and an association response frame 274, which can be the same as or similar to those described above regarding the connection established between the STA 202 and the genuine AP 206. After driving the STA 202 to connect to the forged AP 204, the forged AP 204 can monitor data traveling to and from the STA 202.
[0066] Many Wi-Fi deployments (e.g., deployments of Wi-Fi networks, APs, STAs, etc.) currently do not support or otherwise implement the use of protected management frames such as disassociation and / or deauthentication frames. For example, many Wi-Fi deployments currently utilize WPA2 (e.g., where protected management frames are optional) or otherwise do not support WPA3 (e.g., where protected management frames are made mandatory).
[0067] There is a need for systems and techniques that can be used to detect and prevent forged management frames in Wi-Fi networks that utilize unprotected (e.g., unencrypted) management frames. There is also a need for systems and techniques that can be used to detect and prevent forged disassociation frames and / or forged deauthentication frames associated with disconnection attacks in Wi-Fi networks that utilize unprotected (e.g., unencrypted management frames).
[0068] Systems, apparatuses, processes (also referred to as methods), and computer-readable media (collectively referred to as "systems and techniques") for detecting Wi-Fi deauthentication attacks are described herein. For example, the systems and techniques can determine one or more transmitter signatures for unprotected Wi-Fi management frames. The transmitter signature associated with a currently received unprotected (e.g., unencrypted) frame can be analyzed against one or more corresponding transmitter signatures associated with a previously received protected (e.g., encrypted) frame. In some cases, one or more transmitter signatures can be determined by a client device or station (STA) that receives frames from the corresponding one or more access points (APs). In an illustrative example, the systems and techniques can be used to detect forged deauthentication frames and / or forged disassociation frames associated with Wi-Fi deauthentication attacks.
[0069] For example, the systems and techniques can be used to detect Wi-Fi deauthentication attacks based on determining that a MAC / PHY transmitter signature associated with an unprotected deauthentication or disassociation frame is different from a MAC / PHY transmitter signature associated with a protected frame. In some aspects, a protected frame received by a given STA can include information indicating an AP that sent the protected frame to the STA. In some cases, the STA can determine one or more MAC / PHY transmitter signatures for each protected frame received from one or more APs. In some examples, the STA can determine one or more MAC / PHY transmitter signatures for at least one protected frame sent by a corresponding one or more APs. Based on receiving an unprotected management frame (e.g., an unprotected deauthentication or disassociation frame) claiming to be from an AP for which a MAC / PHY transmitter signature has previously been determined, the MAC / PHY transmitter signature of the unprotected management frame can be compared to the MAC / PHY transmitter signature of a protected management frame sent by the indicated AP. Based on this comparison, the systems and techniques can determine whether the unprotected deauthentication or disassociation frame is authentic (e.g., not forged, sent by the AP identified in the unprotected frame) or inauthentic (e.g., forged, sent by a forged AP different from the AP identified in the unprotected frame). In some examples, based on determining that an unprotected deauthentication or disassociation frame is sent by a forged AP, the systems and techniques can be used to discard the corresponding frame or packet and / or indicate the attempted attack for further remediation.
[0070] Figure 3 FIG. 300 is a diagram illustrating an example system 300 that can be used to detect Wi-Fi deauthentication attacks and / or detect forged unprotected Wi-Fi management frames. For example, the deauthentication detection system 300 can be included in or implemented by an STA or other wireless client device to detect and prevent Wi-Fi deauthentication attacks using forged deauthentication frames (e.g., such as Figure 2 the forged deauthentication frame 250 shown).
[0071] In one illustrative example, the systems and techniques described herein can be used to detect whether a given unprotected deauthentication frame 307 is sent by a legitimate AP (e.g., an AP to which the STA was previously or recently connected) or a forged AP. For example, the MAC / PHY signature engine 310 can be used to generate or otherwise determine one or more transmitter signatures associated with the received Wi-Fi frame 305. The received Wi-Fi frame 305 can include a management frame and / or a data frame. In some aspects, the received Wi-Fi frame 305 can be a management and / or data frame received at an STA that includes or implements the deauthentication detection system 300.
[0072] In some aspects, the MAC / PHY signature engine 310 may determine a MAC / PHY transmitter signature for some (or all) of the Wi-Fi frames received at a given STA that includes or implements the deauthentication detection system 300. In some examples, the MAC / PHY transmitter signature engine 310 may determine a MAC / PHY transmitter signature for a portion of the Wi-Fi frames received at a given STA, may determine a MAC / PHY transmitter signature for protected (e.g., encrypted) data frames received at a given STA, and so on. The MAC / PHY transmitter signatures determined for previously received frames at a given STA may be stored and associated with the corresponding AP used, where the corresponding AP used transmitted each of the respective previously received frames in the previously received frames.
[0073] Based on determining and storing MAC / PHY transmitter signatures for previously received frames (e.g., previously received protected frames and / or protected data frames) transmitted by one or more APs, the system and techniques may be used to detect forged deauthentication frames. For example, a MAC / PHY transmitter signature may be determined for the unprotected deauthentication frame 307 and compared to one or more MAC / PHY transmitter signatures determined for previously received protected frames that were transmitted by the same AP (e.g., the same AP MAC address) as indicated in the unprotected deauthentication frame.
[0074] In some aspects, one or more (or all) of the received signal strength indicator (RSSI) engine 322, sequence engine 324, angle of arrival (AoA) engine 326, and PHY engine 328 may be used to perform MAC / PHY transmitter signature analysis for the unprotected deauthentication frame 307. For example, the MAC / PHY signature determined for a given Wi-Fi frame may include one or more different transmitter signatures. In some aspects, the MAC / PHY signature may include a sequence number transmitter signature, an RSSI transmitter signature, a PHY transmitter signature, and / or an AoA transmitter signature. Each type of transmitter signature may be associated with a corresponding engine (e.g., engine 322 to engine 328) for comparing the transmitter signature determined for the deauthentication frame 307 to the transmitter signatures determined for one or more previously received frames 305.
[0075] For example, the RSSI engine 322 can determine the difference between the RSSI of the deauthentication frame 307 received at a given STA and the RSSI of one or more previously received encrypted (e.g., protected) data frames received at the given STA. The previously received protected data frames can be included in the previously received frames 305 and can include one or more of the data frames in the data frames received at the STA immediately prior to receiving the deauthentication frame 307. In some cases, separate comparisons can be performed between the RSSI of the deauthentication frame 307 and the RSSI of each respective previously received protected data frame among the previously received protected data frames. In some examples, the RSSI of the deauthentication frame 307 can be compared with an average RSSI, a maximum RSSI, a minimum RSSI, etc. determined for a plurality of previously received protected data frames. As previously mentioned, the RSSI engine 322 can compare the RSSI of the deauthentication frame 307 with the RSSI of a previously received protected data frame that was sent by the same AP as identified in the header of the deauthentication frame 307.
[0076] The sequence engine 324 can be used to determine a sequence jump (e.g., sequence difference) between the deauthentication frame 307 and a previous management frame received from the same AP as identified in the header of the deauthentication frame 307. For example, Wi-Fi management frames sent between a given AP-STA pair can each be associated with a unique sequence value that can increment for each frame sent between the AP-STA pair. In some aspects, the sequence value can increment between 0 and 4096. If the deauthentication frame 307 is a legitimate deauthentication frame sent by a real AP (e.g., the AP to which the STA was most recently connected), the sequence difference between the deauthentication frame and a previous management frame from the same real AP should be relatively small. If the deauthentication frame 307 is a forged frame sent by a forged AP (e.g., an AP to which the STA is not and / or was not previously connected), the sequence value of the forged deauthentication frame from the forged AP is unlikely to be similar to the sequence value of the most recently received management frame from the real AP.
[0077] The AoA engine 326 can be used to determine a jump or difference in the AoA (e.g., angle of arrival) measured for an unprotected deauthentication frame 307 claimed to be sent by a genuine AP, compared to the AoA measured for one or more previously received protected (e.g., encrypted) data frames sent by the genuine AP. For example, the AoA engine 326 can determine the AoA difference between the deauthentication frame 307 and one or more previously received protected data frames by determining the individual AoA differences between the deauthentication frame 307 and each respective previously received protected data frame among the previously received protected data frames. In some aspects, the AoA engine 326 can determine the AoA difference between the deauthentication frame 307 and an average AoA value, a maximum AoA value, a minimum AoA value, etc., determined for a plurality of previously received protected data frames. For example, a large change or sudden jump in the AoA between a deauthentication frame 307 claimed to be from a genuine AP and a previously received protected (e.g., encrypted) data frame sent by the genuine AP can indicate that the deauthentication frame 307 was sent by a forged AP (e.g., the deauthentication frame 307 is a forged deauthentication frame).
[0078] The PHY engine 328 can be used to determine one or more differences between the AP that sent the unprotected deauthentication frame 307 and the AP that sent one or more previously received protected frames (e.g., data frames). For example, the PHY engine 328 can determine a PHY transmitter signature that indicates physical transmission layer characteristics associated with a given frame received from a given AP. In an illustrative example, the PHY engine 328 can determine the PHY transmitter signature based on one or more of the amplitude and / or phase shift of each subcarrier of the received frame (e.g., deauthentication frame 307, previously received frame 305, etc.). In some aspects, the PHY transmitter signature can also include or otherwise indicate IQ imbalance associated with the received frame. For example, determining that the PHY transmitter signature associated with a deauthentication frame 307 claimed to be from a genuine AP differs from the PHY transmitter signature associated with one or more previously received protected frames from the genuine AP by more than a threshold amount can indicate that the deauthentication frame 307 is a forged deauthentication frame sent by a forged AP.
[0079] In an illustrative example, the deauthentication attack detection engine 350 may generate a detection output 355 that indicates whether the unprotected deauthentication frame 307 is a forged deauthentication frame (e.g., sent by a forged AP) or a genuine deauthentication frame (e.g., sent by a genuine AP). For example, the deauthentication attack detection engine 350 may receive MAC / PHY transmitter signature information as input from one or more (or all) of the RSSI engine 322, the sequence engine 324, the AoA engine 326, and the PHY engine 328. Based on the combined transmitter signature information, the deauthentication attack detection engine 350 may generate a detection output 355 that indicates a forged or genuine deauthentication frame 307.
[0080] In some aspects, the output of the RSSI engine 322 may include one or more ΔRSSI values. For example, the deauthentication attack detection engine 350 may receive the ΔRSSI value associated with the deauthentication frame 307 and may compare the ΔRSSI with a first threshold T1. The comparison result ΔRSSI > T1 may be a Boolean variable v1. For example, a first value of v1 (e.g., 1 or 0, true or false, etc.) may indicate that the ΔRSSI associated with the deauthentication frame 307 exceeds the first threshold T1, and a second value of v1 may indicate that the ΔRSSI associated with the deauthentication frame 307 is below the first threshold T1. In some examples, the RSSI engine 322 may be used to perform the evaluation of the ΔRSSI against the first threshold T1, and the input to the deauthentication attack detection engine 350 may be the Boolean variable v1.
[0081] In some examples, the output of the sequence engine 324 may include one or more ΔSN values (e.g., sequence increment values). For example, the deauthentication attack detection engine 350 may receive the ΔSN value associated with the deauthentication frame 307 and may compare the ΔSN with a second threshold T2. The comparison result ΔSN > T2 may be a Boolean variable v2. For example, a first value of v2 (e.g., 1 or 0, true or false, etc.) may indicate that the ΔSN associated with the deauthentication frame 307 exceeds the second threshold T2, and a second value of v2 may indicate that the ΔSN associated with the deauthentication frame 307 is below the second threshold T2. In some examples, the sequence engine 324 may be used to perform the evaluation of the ΔSN against the second threshold T2, and the input to the deauthentication attack detection engine 350 may be the Boolean variable v2.
[0082] In some examples, the output of the AoA engine 326 may include one or more ΔAoA values. For example, the deauthentication attack detection engine 350 may receive the ΔAoA value associated with the deauthentication frame 307, and may compare the ΔAoA with a third threshold T3. The comparison result ΔAoA>T3 may be a Boolean variable v3. For example, the first value of v3 (e.g., 1 or 0, true or false, etc.) may indicate that the ΔAoA associated with the deauthentication frame 307 exceeds the third threshold T3, and the second value of v3 may indicate that the ΔAoA associated with the deauthentication frame 307 is below the third threshold T3. In some examples, the AoA engine 326 may be used to perform the evaluation of ΔAoA against the third threshold T3, and the input to the deauthentication attack detection engine 350 may be the Boolean variable v3.
[0083] In some examples, the output of the PHY engine 328 may include one or more ΔPHY values. For example, the deauthentication attack detection engine 350 may receive the ΔPHY value associated with the deauthentication frame 307, and may compare the ΔPHY with a fourth threshold T4. The comparison result ΔPHY>T4 may be a Boolean variable v4. For example, the first value of v4 (e.g., 1 or 0, true or false, etc.) may indicate that the ΔPHY associated with the deauthentication frame 307 exceeds the fourth threshold T4, and the second value of v4 may indicate that the ΔPHY associated with the deauthentication frame 307 is below the fourth threshold T4. In some examples, the PHY engine 328 may be used to perform the evaluation of ΔPHY against the fourth threshold T4, and the input to the deauthentication attack detection engine 350 may be the Boolean variable v4.
[0084] In an illustrative example, one or more (or all) of the thresholds T1, T2, T3, T4 may be configurable values associated with the exemplary deauthentication detection system 300. For example, when the deauthentication detection system 300 is included in or implemented by an STA or other client device, the STA may adjust one or more of the four thresholds. In some cases, the STA may adjust one or more of the four thresholds based on configuration or adjustment information received from an AP or other STA associated with or included in the same Wi-Fi network.
[0085] In another illustrative example, the deauthentication attack detection engine 350 may apply one or more weights to respective boolean variables v1, v2, v3, v4 associated with MAC / PHY transmitter signature analysis at engines 322, 324, 326, 328, respectively. For example, a first weight value w1 may be associated with ΔRSSI and / or the corresponding determination of v1, a second weight value w2 may be associated with ΔSN and / or the corresponding determination of v2, a third weight value w3 may be associated with ΔAoA and / or the corresponding determination of v3, and a fourth weight value w4 may be associated with ΔPHY and / or the corresponding determination of v4. In some aspects, the four weight values may be the same (e.g., w1 = w2 = w3 = w4 = 0.25). In some cases, one or more (or all) of the four weight values may be different.
[0086] In one illustrative example, the forged deauthentication frame detection output 355 may be determined based on forged value = w1 * v1 + w2 * v2 + w3 * v3 + w4 * v4. In some aspects, the forged deauthentication frame detection output 355 may be determined based on comparing the calculated forged value with a forgery detection threshold. For example, the forgery detection threshold may be 0.7, where the deauthentication frame 307 is identified as a forged deauthentication frame in cases where the forged value > 0.7, and is identified as a genuine deauthentication frame in cases where the forged value < 0.7. For example, if all four MAC / PHY transmitter signature detection values v1 through v4 are equally weighted (e.g., w1 = w2 = w3 = w4 = 0.25), then in cases where three or more of the MAC / PHY transmitter signature detection values are true (e.g., in cases where three or more of the four MAC / PHY transmitter signature detection values exceed their respective thresholds), the forged deauthentication frame detection output 355 will indicate that the deauthentication frame 307 is forged.
[0087] Figure 4 is a flowchart illustrating an example of a process 400 for wireless communication. The process 400 may be performed by a network device (such as a station (e.g., Figure 1 station (STA) 104)) or a component of a network device (e.g., a chipset, a processor, etc.). The operations of the process 400 may be implemented as software components executed and run on one or more processors (e.g., Figure 5 processor 510 and / or other processors). Additionally, the transmission and reception of signals by the wireless communication device in the process 400 may be implemented, for example, by one or more antennas and / or one or more transceivers (such as a wireless transceiver) (e.g., Figure 5 communication interface 540 and / or other antennas and / or transceivers).
[0088] At block 402, a network device (or its component) may receive an unprotected management frame indicating a disconnection of the network device. The unprotected management frame includes an address of the identified wireless access point (AP) associated with the disconnection. In one illustrative example, the address is a media access control (MAC) address associated with the identified wireless AP. In some cases, the unprotected management frame is a deauthentication frame indicating that the identified wireless AP deauthenticates the network device. In some examples, the unprotected management frame is a disassociation frame indicating that the identified wireless AP disassociates from the network device.
[0089] At block 404, the network device (or its component) may determine a transmitter signature associated with the unprotected management frame. At block 406, the network device (or its component) may determine a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP. In some aspects, the protected data frame is received before the unprotected management frame and includes an address indicating the identified wireless AP. In some cases, the corresponding transmitter signature is a stored transmitter signature associated with the address indicating the identified wireless AP.
[0090] In some examples, the transmitter signature includes a first sequence value associated with receiving the unprotected management frame, and the corresponding transmitter signature includes a second sequence value associated with a previously received management frame from the identified wireless AP. Additionally or alternatively, in some examples, the transmitter signature includes a first received signal strength indicator (RSSI) value associated with receiving the unprotected management frame, and the corresponding transmitter signature includes a second RSSI value associated with a previously received protected data frame from the identified wireless AP. Additionally or alternatively, in some examples, the transmitter signature includes a first angle of arrival (AoA) value associated with receiving the unprotected management frame, and the corresponding transmitter signature includes a second AoA value associated with a previously received protected data frame from the identified wireless AP. Additionally or alternatively, in some cases, the transmitter signature includes one or more of a first amplitude and a first phase shift associated with a subcarrier of the unprotected management frame, and the corresponding transmitter signature includes one or more of a second amplitude and a second phase shift associated with a subcarrier of a previously received protected data frame from the identified wireless AP.
[0091] In some aspects, a network device (or its components) may determine a second transmitter signature associated with an unprotected management frame. The network device (or its components) may determine a corresponding second transmitter signature associated with a protected data frame. The network device (or its components) may also determine a second difference between the second transmitter signature and the corresponding second transmitter signature. To determine that the unprotected management frame was not sent by the identified wireless AP, the network device (or its components) may weight the difference between the transmitter signature and the corresponding transmitter signature using a first weight value and weight the second difference using a second weight value. The network device (or its components) may determine that the unprotected management frame was not sent by the identified wireless AP based on the weighted differences.
[0092] At block 408, the network device (or its components) may determine that the unprotected management frame was not sent by the identified wireless AP based on the difference being greater than a threshold. In some aspects, the network device (or its components) may discard the unprotected management frame based on determining that the unprotected management frame was not sent by the identified wireless AP. In some aspects, the network device (or its components) may determine that the unprotected management frame is a forged deauthentication frame sent by a forged AP different from the identified wireless AP based on the difference being greater than a threshold.
[0093] In some examples, the processes described herein (e.g., process 400 and / or any other process described herein) may be performed by a computing device, apparatus, or system. In one example, process 400 may be performed by a computing device or system having Figure 5 a computing device architecture 500. The computing device, apparatus, or system may include any suitable device, such as a mobile device (e.g., a mobile phone), a desktop computing device, a tablet computing device, a wearable device (e.g., a VR headset, an AR headset, AR glasses, a connected watch or smartwatch, or other wearable device), a server computer, a computing device of an autonomous vehicle or autonomous vehicle, a robotic device, a laptop computer, a smart TV, a camera, and / or any other computing device having the resource capabilities to perform the processes described herein (including process 500 and / or any other process described herein). In some cases, the computing device or apparatus may include various components, such as one or more input devices, one or more output devices, one or more processors, one or more microprocessors, one or more microcomputers, one or more cameras, one or more sensors, and / or other components configured to perform the steps of the processes described herein. In some examples, the computing device may include a display, a network interface configured to communicate and / or receive data, any combination thereof, and / or other components. The network interface may be configured to communicate and / or receive data based on Internet Protocol (IP) or other types of data.
[0094] The components of a computing device may be implemented in circuitry. For example, a component may include, and / or may be implemented using, electronic circuitry or other electronic hardware, which may include one or more programmable electronic circuits (e.g., a microprocessor, a graphics processing unit (GPU), a digital signal processor (DSP), a central processing unit (CPU), and / or other suitable electronic circuitry), and / or may include, and / or may be implemented using, computer software, firmware, or any combination thereof for performing the various operations described herein.
[0095] Process 400 is illustrated as a logic flow diagram, the operations of which represent a sequence of operations that may be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. In general, computer-executable instructions include routines, programs, objects, components, data structures, etc. that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations may be combined in any order and / or in parallel to implement the process.
[0096] Additionally, process 400 and / or any other process described herein may be executed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) executed jointly on one or more processors, by hardware, or a combination thereof. As noted above, the code may be stored on a computer-readable or machine-readable storage medium, e.g., in the form of a computer program comprising a plurality of instructions executable by one or more processors. The computer-readable or machine-readable storage medium may be non-transitory.
[0097] Figure 5Example computing device architecture 500 of an example computing device that can implement the various techniques described herein. In some examples, the computing device may include a mobile device, a wearable device, an extended reality device (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a personal computer, a laptop computer, a video server, a vehicle (or a computing device of a vehicle), or other devices. The components of the computing device architecture 500 are shown to communicate with each other electrically using a connection 505 (such as a bus). The example computing device architecture 500 includes a processing unit (CPU or processor) 510 and a computing device connection 505 that couples various computing device components including a computing device memory 515 (such as a read-only memory (ROM) 520 and a random access memory (RAM) 525) to the processor 510.
[0098] The computing device architecture 500 may include a cache of high-speed memory that is directly connected to, very close to, or integrated as part of the processor 510. The computing device architecture 500 may copy data from the memory 515 and / or the storage device 530 to the cache 512 for quick access by the processor 510. In this way, the cache can provide a performance boost that avoids latency in the processor 510 while waiting for data. These engines and other engines may control or be configured to control the processor 510 to perform various actions. Other computing device memories 515 may also be used. The memory 515 may include multiple different types of memory with different performance characteristics. The processor 510 may include any general-purpose processor and hardware or software services (such as service 1 532, service 2 534, and service 3 536 stored in the storage device 530) configured to control the processor 510, as well as a dedicated processor in which software instructions are incorporated into the processor design. The processor 510 may be a self-contained system that includes multiple cores or processors, buses, memory controllers, caches, etc. The multi-core processor may be symmetric or asymmetric.
[0099] To enable user interaction with the computing device architecture 500, the input device 545 may represent any number of input mechanisms, such as a microphone for voice, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice, etc. The output device 535 may also be one or more of the many output mechanisms known to those skilled in the art, such as a display, a projector, a television, a speaker device, etc. In some instances, a multimodal computing device may enable a user to provide multiple types of input to communicate with the computing device architecture 500. The communication interface 540 generally may govern and manage user input and computing device output. There is no limitation on operating on any particular hardware arrangement, and thus the underlying features here can be easily replaced to obtain improved hardware or firmware arrangements as they are developed.
[0100] The storage device 530 is a non-volatile memory and can be a hard disk or other types of computer-readable media that can store computer-accessible data, such as magnetic tape cartridges, flash memory cards, solid-state memory devices, digital versatile discs, cassette tapes, random access memory (RAM) 525, read-only memory (ROM) 520, and their hybrid forms. The storage device 530 may include services 532, 534, 536 for controlling the processor 510. Other hardware or software modules or engines are contemplated. The storage device 530 may be connected to the computing device connection 505. In one aspect, a hardware module that performs a specific function may include software components stored in a computer-readable medium connected to necessary hardware components (such as the processor 510, the connection 505, the output device 535, etc.) to perform the function.
[0101] The term "device" is not limited to one or a specific number of physical objects (such as a smart phone, a controller, a processing system, etc.). As used herein, a device can be any electronic device having one or more parts that can implement at least some parts of the present disclosure. Although the following description and examples use the term "device" to describe various aspects of the present disclosure, the term "device" is not limited to a specific configuration, type, or number of objects. Additionally, the term "system" is not limited to multiple components or a specific aspect. For example, a system can be implemented on one or more printed circuit boards or other substrates and can have movable or static components. Although the following description and examples use the term "system" to describe various aspects of the present disclosure, the term "system" is not limited to a specific configuration, type, or number of objects.
[0102] Specific details are provided in the above description to provide a thorough understanding of the aspects and examples provided herein. However, those of ordinary skill in the art will understand that these aspects can be practiced without these specific details. For clarity, in some cases, the technology may be presented as including separate functional blocks, including functional blocks that contain devices, device components, steps or routines in a method embodied in software or a combination of hardware and software. Additional components other than those shown in the figures and / or described herein may be used. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form to avoid obscuring these aspects in unnecessary details. In other cases, well-known circuits, processes, algorithms, structures, and technologies may be shown without unnecessary details to avoid obscuring the aspects.
[0103] Each aspect can be described above as a process or method, which is depicted as a flowchart, process diagram, data flow diagram, structure diagram, or block diagram. Although a flowchart may describe operations as a sequential process, many of the operations in the process can be performed in parallel or concurrently. In addition, the order of the operations can be rearranged. When the operations of a process are completed, the process is terminated, but the process may have additional steps not included in the figures. A process can correspond to a method, function, procedure, subroutine, subprogram, etc. When a process corresponds to a function, the termination of the process can correspond to the function returning to the calling function or the main function.
[0104] The processes and methods according to the above examples can be implemented using computer-executable instructions stored or otherwise obtained from a computer-readable medium. Such instructions can include, for example, instructions and data that cause or otherwise configure a general-purpose computer, a special-purpose computer, or a processing device to perform a certain function or group of functions. Portions of the computer resources used can be accessed via a network. The computer-executable instructions can be, for example, binary files, intermediate format instructions (such as assembly language), firmware, source code, etc.
[0105] The term "computer-readable medium" includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or data. A computer-readable medium can include non-transitory media in which data can be stored and that do not include carrier waves and / or transient electronic signals propagated wirelessly or over a wired connection. Examples of non-transitory media can include, but are not limited to, magnetic disks or tapes, optical storage media (such as flash memory), memories or memory devices, magnetic or optical disks, flash memory, USB devices provided with non-volatile memory, network storage devices, compact discs (CDs) or digital versatile discs (DVDs), any suitable combination thereof, etc. A computer-readable medium can have code and / or machine-executable instructions stored thereon, which can represent a process, function, subroutine, program, routine, subroutine, module, engine, software package, class, or any combination of instructions, data structures, or program statements. A code segment can be coupled to another code segment or a hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. The information, arguments, parameters, data, etc. can be passed, forwarded, or sent via any suitable means, including memory sharing, message passing, token passing, network transmission, etc.
[0106] In some aspects, computer-readable storage devices, media, and memories can include wires or wireless signals, such as bitstreams, etc. However, when mentioned, non-transitory computer-readable storage media specifically exclude media such as power consumption, carrier signals, electromagnetic waves, and signals themselves.
[0107] Devices implementing the processes and methods according to these disclosures may include hardware, software, firmware, middleware, microcode, hardware description language, or any combination thereof, and may take any form factor among a variety of form factors. When implemented in software, firmware, middleware, or microcode, the program code or code segments (e.g., computer program product) for performing the necessary tasks may be stored in a computer-readable or machine-readable medium. The processor may execute the necessary tasks. Typical examples of form factors include laptop computers, smart phones, mobile phones, tablet devices, or other small form factor personal computers, personal digital assistants, rack-mounted devices, stand-alone devices, etc. The functionality described herein may also be embodied in peripheral devices or plug-in cards. By additional example, such functionality may also be implemented on a circuit board among different chips or different processes executed on a single device.
[0108] Instructions, the medium for conveying such instructions, the computing resources for executing them, and other structures for supporting such computing resources are example components for providing the functionality described in this disclosure.
[0109] In the above description, aspects of the present application are described with reference to their specific aspects, but those skilled in the art will recognize that the present application is not limited thereto. Thus, although the illustrative aspects of the present application have been described in detail herein, it is to be understood that the various inventive concepts may be implemented and adopted in other various ways, and the appended claims are not to be construed as including such variations, unless limited by the prior art. The various features and aspects of the above applications may be used individually or in combination. In addition, without departing from the broader spirit and scope of this specification, the aspects may be utilized in any number of environments and applications beyond those described herein. Therefore, the specification and drawings should be regarded as illustrative rather than restrictive. For purposes of illustration, the methods are described in a particular order. It should be understood that in alternative aspects, the methods may be performed in a different order than that described.
[0110] Those of ordinary skill in the art will appreciate that the less than (“<”) and greater than (“>”) symbols or terms used herein may be replaced with less than or equal to (“≤”) and greater than or equal to (“≥”) symbols, respectively, without departing from the scope of this specification.
[0111] In cases where a component is described as “configured to” perform certain operations, such configuration may be achieved, for example, by designing an electronic circuit or other hardware to perform the operations, by programming a programmable electronic circuit (e.g., a microprocessor or other suitable electronic circuit) to perform the operations, or any combination thereof.
[0112] The phrase "coupled to" means that any component is directly or indirectly physically connected to another component, and / or any component directly or indirectly communicates with another component (e.g., connected to another component via a wired or wireless connection and / or other suitable communication interface).
[0113] Claim language or other language reciting "at least one of" a set and / or "one or more" of a set indicates that one member or multiple members (in any combination) of the set satisfy the claim. For example, claim language reciting "at least one of A and B" or "at least one of A or B" means A, B, or A and B. In another example, claim language reciting "at least one of A, B, and C" or "at least one of A, B, or C" means A, B, C, or A and B, or A and C, or B and C, or A and B and C. The language "at least one of" a set and / or "one or more" of a set does not limit the set to the items listed in the set. For example, claim language reciting "at least one of A and B" or "at least one of A or B" may mean A, B, or A and B, and may additionally include items not listed in the set of A and B.
[0114] The various illustrative logical blocks, modules, engines, circuits, and algorithm steps described in connection with the aspects disclosed herein may be implemented as electronic hardware, computer software, firmware, or combinations thereof. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present application.
[0115] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices, such as a general purpose computer, a wireless communication device such as a cellular phone, or an integrated circuit device having multiple uses, including applications in wireless communication devices such as cellular phones and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be implemented at least in part by a computer-readable data storage medium comprising program code, the program code including instructions that, when executed, perform one or more of the methods described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging material. The computer-readable medium may include a memory or data storage medium, such as random access memory (RAM) (such as synchronous dynamic random access memory (SDRAM)), read only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read only memory (EEPROM), flash memory, magnetic or optical data storage media, and the like. Additionally or alternatively, the techniques may be implemented at least in part by a computer-readable communication medium that carries or conveys program code in the form of instructions or data structures that can be accessed, read, and / or executed by a computer, such as a propagated signal or wave.
[0116] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general purpose microprocessors, application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Such processors may be configured to perform any of the techniques described in this disclosure. A general purpose processor may be a microprocessor; but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Thus, as used herein, the term "processor" may refer to any of the foregoing structures, any combination of the foregoing structures, or any other structure or device suitable for implementing the techniques described herein.
[0117] Exemplary aspects of the present disclosure include:
[0118] Aspect 1. A device for wireless communication, the device comprising: at least one memory; and at least one processor, the at least one processor coupled to the at least one memory and configured to: receive an unprotected management frame indicating a disconnection of the device, wherein the unprotected management frame includes an address indicating an identified wireless access point (AP) associated with the disconnection; determine a transmitter signature associated with the unprotected management frame; determine a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP; and based on the difference being greater than a threshold, determine that the unprotected management frame was not sent by the identified wireless AP.
[0119] Aspect 2. The device according to aspect 1, wherein the at least one processor is further configured to: based on determining that the unprotected management frame was not sent by the identified wireless AP, discard the unprotected management frame.
[0120] Aspect 3. The device according to any one of aspects 1 or 2, wherein the unprotected management frame includes a deauthentication frame indicating that the identified wireless AP deauthenticates the device.
[0121] Aspect 4. The device according to aspect 3, wherein the at least one processor is further configured to: based on the difference being greater than the threshold, determine that the unprotected management frame is a forged deauthentication frame sent by a forged AP different from the identified wireless AP.
[0122] Aspect 5. The device according to any one of aspects 1 to 4, wherein the unprotected management frame includes a disassociation frame indicating that the identified wireless AP disassociates from the device.
[0123] Aspect 6. The device according to any one of aspects 1 to 5, wherein the at least one processor is configured to receive the protected data frame before the unprotected management frame, and wherein the protected data frame includes the address indicating the identified wireless AP.
[0124] Aspect 7. The device according to aspect 6, wherein the corresponding transmitter signature is a stored transmitter signature associated with the address indicating the identified wireless AP.
[0125] Aspect 8. The device according to any one of aspects 1 to 7, wherein: the transmitter signature includes a first sequence value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second sequence value associated with a previously received management frame from the identified wireless AP.
[0126] Aspect 9. The apparatus according to any one of Aspects 1 to 8, wherein: the transmitter signature includes a first received signal strength indicator (RSSI) value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second RSSI value associated with a previously received protected data frame from the identified wireless AP.
[0127] Aspect 10. The apparatus according to any one of Aspects 1 to 9, wherein: the transmitter signature includes a first angle of arrival (AoA) value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second AoA value associated with a previously received protected data frame from the identified wireless AP.
[0128] Aspect 11. The apparatus according to any one of Aspects 1 to 10, wherein: the transmitter signature includes one or more of a first amplitude and a first phase shift associated with a subcarrier of the unprotected management frame; and the corresponding transmitter signature includes one or more of a second amplitude and a second phase shift associated with a subcarrier of a previously received protected data frame from the identified wireless AP.
[0129] Aspect 12. The apparatus according to any one of Aspects 1 to 11, wherein the at least one processor is further configured to: determine a second transmitter signature associated with the unprotected management frame; determine a corresponding second transmitter signature associated with the protected data frame; and determine a second difference between the second transmitter signature and the corresponding second transmitter signature.
[0130] Aspect 13. The apparatus according to Aspect 12, wherein, in order to determine that the unprotected management frame is not sent by the identified wireless AP, the at least one processor is configured to: weight the difference between the transmitter signature and the corresponding transmitter signature using a first weight value; and weight the second difference using a second weight value.
[0131] Aspect 14. The apparatus according to any one of Aspects 1 to 13, wherein the address is a media access control (MAC) address associated with the identified wireless AP.
[0132] Aspect 15. A method for wireless communication at a network device, the method comprising: receiving an unprotected management frame indicating disconnection of the network device, wherein the unprotected management frame includes an address indicating an identified wireless access point (AP) associated with the disconnection; determining a transmitter signature associated with the unprotected management frame; determining a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP; and based on the difference being greater than a threshold, determining that the unprotected management frame is not sent by the identified wireless AP.
[0133] Aspect 16. The method according to aspect 15, the method further comprising: based on determining that the unprotected management frame is not sent by the identified wireless AP, discarding the unprotected management frame.
[0134] Aspect 17. The method according to any one of aspects 15 or 16, wherein the unprotected management frame includes a deauthentication frame indicating deauthentication of the network device by the identified wireless AP.
[0135] Aspect 18. The method according to aspect 17, the method further comprising: based on the difference being greater than the threshold, determining that the unprotected management frame is a forged deauthentication frame sent by a forged AP different from the identified wireless AP.
[0136] Aspect 19. The method according to any one of aspects 15 to 18, wherein the unprotected management frame includes a disassociation frame indicating disassociation of the identified wireless AP from the network device.
[0137] Aspect 20. The method according to any one of aspects 15 to 19, wherein the protected data frame is received before the unprotected management frame and includes the address indicating the identified wireless AP.
[0138] Aspect 21. The method according to aspect 20, wherein the corresponding transmitter signature is a stored transmitter signature associated with the address indicating the identified wireless AP.
[0139] Aspect 22. The method according to any one of aspects 15 to 21, wherein: the transmitter signature includes a first sequence value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second sequence value associated with a previously received management frame from the identified wireless AP.
[0140] Aspect 23. The method according to any one of aspects 15 to 22, wherein: the transmitter signature includes a first received signal strength indicator (RSSI) value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second RSSI value associated with a previously received protected data frame from the identified wireless AP.
[0141] Aspect 24. The method according to any one of aspects 15 to 23, wherein: the transmitter signature includes a first angle of arrival (AoA) value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second AoA value associated with a previously received protected data frame from the identified wireless AP.
[0142] Aspect 25. The method according to any one of aspects 15 to 24, wherein: the transmitter signature includes one or more of a first amplitude and a first phase shift associated with subcarriers of the unprotected management frame; and the corresponding transmitter signature includes one or more of a second amplitude and a second phase shift associated with subcarriers of a previously received protected data frame from the identified wireless AP.
[0143] Aspect 26. The method according to any one of aspects 15 to 25, the method further comprising: determining a second transmitter signature associated with the unprotected management frame; determining a corresponding second transmitter signature associated with the protected data frame; and determining a second difference between the second transmitter signature and the corresponding second transmitter signature.
[0144] Aspect 27. The method according to aspect 26, wherein determining that the unprotected management frame is not sent by the identified wireless AP includes: weighting the difference between the transmitter signature and the corresponding transmitter signature using a first weight value; and weighting the second difference using a second weight value.
[0145] Aspect 28. The method according to any one of aspects 15 to 27, wherein the address is a media access control (MAC) address associated with the identified wireless AP.
[0146] Aspect 29. A non-transitory computer-readable storage medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform any of the operations according to any one of aspects 15 to 28.
[0147] Aspect 30. An apparatus comprising one or more components for performing the operations according to any one of aspects 15 to 28.
Claims
1. An apparatus for wireless communication, the apparatus comprising: at least one memory; and at least one processor, the at least one processor coupled to the at least one memory and configured to: receive an unprotected management frame indicating disconnection of the apparatus, wherein the unprotected management frame includes an address indicating the identified wireless access point (AP) associated with the disconnection; determine a transmitter signature associated with the unprotected management frame; determine a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP; and based on the difference being greater than a threshold, determine that the unprotected management frame is not sent by the identified wireless AP.
2. The apparatus according to claim 1, wherein the at least one processor is further configured to: discard the unprotected management frame based on determining that the unprotected management frame is not sent by the identified wireless AP.
3. The apparatus according to claim 1, wherein the unprotected management frame includes a deauthentication frame indicating deauthentication of the apparatus by the identified wireless AP.
4. The apparatus according to claim 3, wherein the at least one processor is further configured to: based on the difference being greater than the threshold, determine that the unprotected management frame is a forged deauthentication frame sent by a forged AP different from the identified wireless AP.
5. The apparatus according to claim 1, wherein the unprotected management frame includes a disassociation frame indicating disassociation of the identified wireless AP from the apparatus.
6. The apparatus according to claim 1, wherein the at least one processor is configured to receive the protected data frame before the unprotected management frame, and wherein the protected data frame includes the address indicating the identified wireless AP.
7. The apparatus according to claim 6, wherein the corresponding transmitter signature is a stored transmitter signature associated with the address indicating the identified wireless AP.
8. The apparatus according to claim 1, wherein: the transmitter signature includes a first sequence value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second sequence value associated with a previously received management frame from the identified wireless AP.
9. The apparatus according to claim 1, wherein: the transmitter signature includes a first received signal strength indicator (RSSI) value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second RSSI value associated with a previously received protected data frame from the identified wireless AP.
10. The apparatus according to claim 1, wherein: the transmitter signature includes a first angle of arrival (AoA) value associated with receiving the unprotected management frame; and the corresponding transmitter signature includes a second AoA value associated with a previously received protected data frame from the identified wireless AP.
11. The apparatus according to claim 1, wherein: The transmitter signature includes one or more of a first amplitude and a first phase shift associated with the subcarriers of the unprotected management frame; and The corresponding transmitter signature includes one or more of a second amplitude and a second phase shift associated with the subcarriers of a previously received protected data frame from the identified wireless AP.
12. The apparatus according to claim 1, wherein the at least one processor is further configured to: Determine a second transmitter signature associated with the unprotected management frame; Determine a corresponding second transmitter signature associated with the protected data frame; and Determine a second difference between the second transmitter signature and the corresponding second transmitter signature.
13. The apparatus according to claim 12, wherein, in order to determine that the unprotected management frame is not sent by the identified wireless AP, the at least one processor is configured to: Weight the difference between the transmitter signature and the corresponding transmitter signature using a first weight value; and Weight the second difference using a second weight value.
14. The apparatus according to claim 1, wherein the address is a media access control (MAC) address associated with the identified wireless AP.
15. A method for wireless communication at a network device, the method comprising: Receiving an unprotected management frame indicating disconnection of the network device, wherein the unprotected management frame includes an address indicating the identified wireless access point (AP) associated with the disconnection; Determining a transmitter signature associated with the unprotected management frame; Determining a difference between the transmitter signature and a corresponding transmitter signature associated with a protected data frame received from the identified wireless AP; And Based on the difference being greater than a threshold, determining that the unprotected management frame is not sent by the identified wireless AP.
16. The method according to claim 15, the method further comprising: Based on determining that the unprotected management frame is not sent by the identified wireless AP, discarding the unprotected management frame.
17. The method according to claim 15, wherein the unprotected management frame includes a deauthentication frame indicating deauthentication of the network device by the identified wireless AP.
18. The method according to claim 17, the method further comprising: Based on the difference being greater than the threshold, determining that the unprotected management frame is a forged deauthentication frame sent by a forged AP different from the identified wireless AP.
19. The method according to claim 15, wherein the unprotected management frame includes a disassociation frame indicating disassociation of the identified wireless AP from the network device.
20. The method according to claim 15, wherein the protected data frame is received before the unprotected management frame and includes the address indicating the identified wireless AP.
21. The method according to claim 20, wherein the corresponding transmitter signature is a stored transmitter signature associated with the address indicating the identified wireless AP.
22. The method according to claim 15, wherein: The transmitter signature includes a first sequence value associated with receiving the unprotected management frame; and The corresponding transmitter signature includes a second sequence value associated with a previously received management frame from the identified wireless AP.
23. The method according to claim 15, wherein: The transmitter signature includes a first received signal strength indicator (RSSI) value associated with receiving the unprotected management frame; and The corresponding transmitter signature includes a second RSSI value associated with a previously received protected data frame from the identified wireless AP.
24. The method according to claim 15, wherein: The transmitter signature includes a first angle of arrival (AoA) value associated with receiving the unprotected management frame; and The corresponding transmitter signature includes a second AoA value associated with a previously received protected data frame from the identified wireless AP.
25. The method according to claim 15, wherein: The transmitter signature includes one or more of a first amplitude and a first phase shift associated with a subcarrier of the unprotected management frame; and The corresponding transmitter signature includes one or more of a second amplitude and a second phase shift associated with a subcarrier of a previously received protected data frame from the identified wireless AP.
26. The method according to claim 15, the method further comprising: Determining a second transmitter signature associated with the unprotected management frame; Determining a corresponding second transmitter signature associated with the protected data frame; And Determining a second difference between the second transmitter signature and the corresponding second transmitter signature.
27. The method according to claim 26, wherein determining that the unprotected management frame is not sent by the identified wireless AP includes: Weighting the difference between the transmitter signature and the corresponding transmitter signature using a first weight value; And Weighting the second difference using a second weight value.
28. The method according to claim 15, wherein the address is a media access control (MAC) address associated with the identified wireless AP.