Method for detecting anomalies on wi-fi stations
Patent Information
- Application Number
- EP2023798253
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-11-10
- Filing Date
- 2023-10-31
- Publication Date
- 2025-09-17
AI Technical Summary
Wi-Fi stations often face difficulties connecting to home networks due to incompatibility with Wi-Fi standards or security modes, making it challenging to detect anomalies, especially when using random MAC addresses, which can prevent the gateway from distinguishing known devices.
A method that involves generating a unique identification code from the content of Wi-Fi standard management frames, such as 'Probe Request', and storing it in the access point to detect association anomalies, using algorithms like MD5 hashing to create an invariable code, allowing the access point to identify and alert on interoperability issues.
Enables effective detection of connection anomalies and optimization of Wi-Fi station management within the network, even when using random MAC addresses, by ensuring the access point can recognize and alert on incompatibilities, thus facilitating better network management and operator notification.
Smart Images

Figure 1.1
Abstract
Description
Description Title of the invention: Method for detecting anomalies on Wi-Fi stations.
[0001] Technical field
[0002] The present invention relates to a method for detecting an association anomaly of a Wi-Fi station to an access point of a communication network.
[0003] Such a network is notably a home network equipped with a gateway as an access point allowing local equipment to be connected to the internet.
[0004]
[0005] Prior art
[0006] In general, Wi-Fi is the most widely used medium for transmitting data at home. It is used by a large and growing number of different devices (smartphones, tablets, PCs, TV decoders, IoT equipment, etc.) and for a wide variety of uses: email, telephony, live video, OTT video, IoT monitoring, etc.
[0007] Wi-Fi technologies are becoming more complex and are providing complementary tools that allow for the optimization of certain characteristics of the data streams, while taking into account certain constraints: 802.11e, 802.1lu, 802.11ax, OFDMA, ...
[0008] Similarly, because Wi-Fi technologies evolve so rapidly, some existing Wi-Fi equipment on the market is sometimes incompatible with these advancements. For a telecommunications operator deploying a new Wi-Fi technology in a home, it is important not to introduce new problems for its customers' Wi-Fi equipment.
[0009]
[0010] Some stations may occasionally have difficulty using a gateway's Wi-Fi network. These difficulties manifest as an inability to establish a Wi-Fi connection, and the reasons can be numerous: incompatibility of the Wi-Fi station with a particular Wi-Fi standard, incompatibility with a security mode currently used by the home gateway, or an outdated Wi-Fi driver present on the client's equipment.
[0011]
[0012] It's difficult to detect when a Wi-Fi access point can no longer connect to the network because it can use a random MAC address. Therefore, the home gateway cannot distinguish whether it's a Wi-Fi access point already known to its network.
[0013]
[0014] The present invention aims to detect anomalies in the Wi-Fi connection between Wi-Fi stations and a gateway within a home network.
[0015] Another objective of the invention is to optimize the management of Wi-Fi stations within a communication network access point.
[0016] Description of the invention
[0017] At least one of the aforementioned objectives is achieved with a method for detecting an association anomaly between a Wi-Fi station and an access point of a communication network. According to the invention, each time the Wi-Fi station sends a Wi-Fi standard management frame, known as a "Probe Request," containing a MAC address and content, the following steps are performed: - identification of the content, - application of a unique identification algorithm to the content in order to generate a unique content identification code, - storage of the unique code within the access point, - checking if the Wi-Fi station is associated with the access point, - if not associated, check if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point; - if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point, an alert signal is generated.
[0018]
[0019] The method according to the invention uses a management frame from the Wi-Fi standard, the "Probe Request." This frame is used by Wi-Fi stations to identify nearby networks. It is a relevant indicator because, during an association attempt, this "Probe Request" is systematically sent by the Wi-Fi station.
[0020] If this Wi-Fi standard management frame is present, but the Wi-Fi station associated with this management frame is not linked to the network access point, then there is considered an interoperability problem between the access point and this Wi-Fi station. The present invention therefore makes it possible to detect the presence of this "Probe Request" by associating it with a Wi-Fi station known to the access point.
[0021] Unique identification could be achieved using the physical address of the Wi-Fi station, i.e., the MAC address. However, since this address, which is supposed to be unique, sometimes changes, the present invention provides for the creation of a unique, unchanging code.
[0022] By retaining only the content of the "Probe Request", the random component is removed and the access point is thus able to link the "Probe Request" to a known device on the network.
[0023] Therefore, during the next association attempt, the Wi-Fi station will send a "Probe Request." If the unique code calculated from this "Probe Request" is known to the access point, and the Wi-Fi station associated with this unique code is not connected, then the access point considers that this Wi-Fi station is unable to associate and raises an alert. If the station successfully connects, then the alert is lifted.
[0024] Checking whether the Wi-Fi station linked to the unique code has already been associated with the access point involves checking whether the Wi-Fi station has subsequently been associated and then unassociated from the access point, i.e., whether there has already been a successful association before.
[0025] The check to see if the Wi-Fi station is associated with the access point is performed immediately, with each "Probe Request" received by the access point.
[0026] With the method according to the invention, if an operator decides to modify a Wi-Fi parameter on an access point, this operator is informed of possible incompatibilities with a client's Wi-Fi equipment, even if the latter uses a random MAC address.
[0027]
[0028] According to an advantageous feature of the invention, the unique identification algorithm can be a hash function.
[0029] This function can be more precisely described as an MD5 cryptographic hash function. Such a function allows for the calculation of a unique identifier from a numerical value. This makes it possible to distinguish between Wi-Fi stations.
[0030]
[0031] According to an advantageous embodiment of the invention, the communication network may include several access points including a gateway and at least one repeater, the steps of storing the unique code and verification being carried out within the gateway.
[0032] In this case, the step to check if the Wi-Fi station linked to the unique code has already been associated applies to all access points. Specifically, it checks if the Wi-Fi station has already been associated with any of the access points.
[0033] According to the invention, a gateway processing unit can be configured to perform the steps of the process according to the invention. The intelligence is in the gateway.
[0034]
[0035] In other words, in a network including repeaters and a home gateway, each time a "Probe Request" is received on one of the network devices, a unique code is calculated and then saved in the home gateway for future comparison.
[0036]
[0037] According to one embodiment of the invention, the content may include the number of antennas of the Wi-Fi station or the maximum frequency band of the Wi-Fi station. These are elements relating to the Wi-Fi capabilities of the equipment. Of course, the content of the Wi-Fi standard management frame may include elements other than those mentioned.
[0038]
[0039] According to a preferred embodiment of the invention, for communication to occur- According to the IEEE 802.11 standard, the content is the "IEEE 802.11 Wireless management" section. Variable information such as the destination or source address is not included.
[0040]
[0041] According to one embodiment of the invention, the communication network can be a home network, the access point comprising an internet connection router.
[0042] Such a router can be, for example, a gateway, a "homegateway" in English, or any other device capable of connecting user equipment to the internet.
[0043]
[0044] According to another aspect of the invention, a communication network is proposed to detect an association anomaly of a Wi-Fi station to an access point; this access point being configured to implement a method according to the invention.
[0045]
[0046] The present invention also relates to a computer program product comprising instructions which, when the program is executed by a processing unit in an access point, cause the latter to implement the process according to the invention.
[0047] Description of the figures and methods of implementation.
[0048] Other advantages and features of the invention will become apparent upon reading the detailed description of implementations and embodiments, which are by no means limiting, and the following attached drawings:
[0049] [Fig. 1] Figure 1 is a schematic view of a house equipped with an access point in the form of an internet gateway and a user's Wi-Fi stations;
[0050] [Fig. 2] Figure 2 is a flowchart illustrating steps of a process according to the invention;
[0051] [Fig. 3] Figure 3 is a schematic view illustrating the fields in a standard Wi-Fi management frame of the "Probe Request" type according to the invention;
[0052] [Fig. 4] Figure 4 is a simplified schematic view of frames sent by a Wi-Fi station to an access point; and
[0053] [Fig. 5] Figure 5 is a simplified schematic view of frames sent by a Wi-Fi station to an access point according to the invention.
[0054] The embodiments described below are by no means limiting; in particular, variants of the invention may be implemented comprising only a selection of features described below, isolated from the others. The described features, if this selection of features is sufficient to confer a technical advantage or to differentiate the invention from the prior art. This selection includes at least one preferably functional feature without structural details, or with only some of the structural details if this part alone is sufficient to confer a technical advantage or to differentiate the invention from the prior art.
[0055] Figure 1 Figure 1 is a schematic view illustrating a house 1 equipped with an access point 2 which is a gateway allowing access to the internet 3 via a wired connection 4 based on coaxial cable or fiber optic.
[0056] The access point 2 includes a processing unit 7, such as a microcontroller for example, to implement the process according to the invention and a Wi-Fi module 8 for wireless communication with equipment.
[0057] Home devices can connect via wired or wireless connection to access point 2 to access the internet 3.
[0058] In the example shown in Figure 1, a television 5 and a Wi-Fi device, such as a smartphone 6, are both wirelessly connected to the gateway 2 via Wi-Fi. When the television 5 is on, a digital television service is activated between the television 5 and the access point 2.
[0059] Mobile phone 6 is capable of connecting to gateway 2 to access the internet by implementing different types of services: web, download, telephony, . . .
[0060] The access point 2, television 5 and mobile phone 6 together form a home network.
[0061] Access point 2 comprises conventional hardware and software means for serving as an access point and repeater between equipment and the internet and further comprise one and / or both a computer program product for implementing the method according to the invention.
[0062] When the mobile phone 6 is activated, it searches for nearby Wi-Fi access points. When an access point is identified, an attempt is made to connect.
[0063] Figure 2 is a flowchart illustrating the steps in implementing the process according to the invention.
[0064] A step 9 is distinguished during which the Wi-Fi station transmits a Wi-Fi standard management frame, called a "Probe Request". This frame is received by access point 2, which is a home gateway to the internet. The frame includes a MAC address and content.
[0065] Figure 3 illustrates a screenshot of the frame. We can distinguish a first part, which is the frame header, and a second part, which is the content according to The invention. The first part comprises fields located from "type / Sub-type:" to "[FCS Status: Unverified]". The content according to the invention comprises all the characteristics entered in the fields from "Tagged parameters" to "Tag: Vendor Specific: Broadcom".
[0066] In step 10 of Figure 2, the access point identifies the content according to the invention. A digital file is then created. In step 11, MD5 hashing is then applied to this digital file to obtain a unique code 12.
[0067] In step 13, the unique code is saved within the gateway.
[0068] In step 14, we check if the Wi-Fi station, i.e. phone 6, is associated with access point 2.
[0069] If the answer is "yes", nothing happens in step 16.
[0070] If the answer is no, step 15 checks whether the unique code is known to the access point and whether the Wi-Fi station associated with that unique code has already been connected to the access point. This determines if phone 6 has been connected to access point 2 at least once in the past.
[0071] If the answer is "no", nothing happens at step 16.
[0072] If the answer is "yes," an alert signal is generated, for example, via the internet to a remote server of the operator. This alert signal can advantageously remain local to the gateway, but can also be propagated throughout the home network or to the cloud via a secure tunnel (MQTT) in both cases.
[0073] When the alert signal is local, it may be a software signal sent to a gateway application for corrective actions, and / or a message sent over the local network to other network equipment, such as a Wi-Fi repeater.
[0074] Figure 4 illustrates an embodiment according to the prior art. Figure 4a shows an initial association of the Wi-Fi station with the access point. Figure 4b shows a second association of the Wi-Fi station with the access point at a later time.
[0075] Figure 4a depicts a first phase in which a Wi-Fi station transmits a "Probe Request" frame at time t0. This frame obviously includes the Wi-Fi station's MAC address. Subsequently, during an association attempt at time t1, the Wi-Fi station also transmits the same MAC address. In such a situation, where the Wi-Fi station uses the same MAC address for both the "Probe Request" and its association, it is easy for the access point to detect the presence of this device.
[0076] Figure 4b depicts a second phase in which a Wi-Fi station transmits a "Probe Request" frame at time t0. This frame obviously includes the MAC address of the Wi-Fi station. Subsequently, during an association attempt at time t1, the Wi-Fi station transmits a MAC address different from the one sent in the "Probe Request". In such a situation, the The fact that the Wi-Fi station uses a different MAC address between the "Probe Request" and its association prevents linking the "Probe Request" and the association.
[0077] The MAC address is notably different by manufacturer's implementation to mask its presence and avoid identification of the station.
[0078] It is therefore necessary to remove the random component of the "Probe Request" due to the fact that the MAC address is sometimes different.
[0079] The MAC address can be random, but not necessarily the data contained in the "Probe Request". By separating the two sets and creating, for example, an MD5 hash of the content, we obtain a unique code for the Wi-Fi station, as shown in Figure 5.
[0080]
[0081] Figure 5 shows an embodiment of the invention. Figure 5a illustrates a first association of the Wi-Fi station with the access point. Figure 5b illustrates a second association of the Wi-Fi station with the access point at a later time.
[0082] Figure 5a shows the same steps as Figure 4a, with the addition of calculating the unique code at time t0 upon receiving the "Probe Request" frame. During the association attempt, at time t1, the Wi-Fi station also transmits the same MAC address. In such a situation, where the Wi-Fi station uses the same MAC address for both the "Probe Request" and its association, it is easy for the access point to detect the presence of this device.
[0083]
[0084] Figure 5b shows the same steps as Figure 4b, but also calculates the unique code at time t0 during the transmission of the "Probe Request" frame. Similarly, we consider the case where, during the association attempt, at time t1, the Wi-Fi station transmits a MAC address different from the one sent in the "Probe Request". With the present invention, if the association fails, the unique code is used to identify the Wi-Fi station and determine that this Wi-Fi station had already associated in the past during the phase described in Figure 5a.
[0085]
[0086] Thus, with the method according to the invention, any connection anomaly of a Wi-Fi station to an access point is detected.
[0087]
[0088] Of course, the invention is not limited to the examples just described. Many modifications can be made to these examples without departing from the scope of the present invention as described.
Claims
Claims
1. Method for detecting an anomaly in the association of a Wi-Fi station with an access point of a communication network, comprising: - each time the Wi-Fi station sends a Wi-Fi standard management frame, called a “Probe Request”, comprising a MAC address and content, the following steps are carried out: - identification of content, - application of a unique identification algorithm to the content in order to generate a unique content identification code, - storage of the unique code within the access point, - check if the Wi-Fi station is associated with the access point, - if not associated, check if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point; - if the unique code is known in the access point and if the Wi-Fi station linked to this unique code has already been associated with the access point, generation of an alert signal.
2. Method according to claim 1, characterized in that the unique identification algorithm is a hash function.
3. Method according to claim 1 or 2, characterized in that the unique identification algorithm is an MD5 cryptographic hash function.
4. Method according to any one of the preceding claims, characterized in that the communication network comprises several access points including a gateway and at least one repeater, the steps of storing the unique code and verification being carried out within the gateway.
5. Method according to any one of the preceding claims, characterized in that the content comprises a number of antennas of the Wi-Fi station.
6. Method according to any one of the preceding claims, characterized in that the content comprises a maximum frequency band of the Wi-Fi station.
7. Method according to any one of the preceding claims, characterized in that for a communication according to the IEEE 802.11 standard, the content is the “IEEE 802.11 Wireless management” part.
8. Method according to any one of the preceding claims, characterized in that the communication network is a network home, the access point including an internet connection router.
9. Communication network for detecting an anomaly in the association of a Wi-Fi station with an access point, characterized in that the access point is configured to implement a method according to any one of the preceding claims.
10. A computer program product comprising instructions which, when the program is executed by a processing unit in an access point, cause the latter to implement the method according to any one of claims 1 to 8.