Access Point Flooding Attack Prevention with Timeouts and Power-Save Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems are vulnerable to authentication, association, and reassociation flooding attacks due to the lack of clear definitions in the Protected Management Frames (PMF) standard, particularly when non-AP stations operate in power saving mode or are attacked by malicious entities.

Innovation Solution

Implementing an attack prevention method at the access point (AP) that includes generating an authentication response frame with a timeout interval and ignoring specific request frames during power saving mode to prevent resource occupation and maintain secure connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the access point frequently sends Security Association Query requests to check if non-AP STA is alive, then connection monitoring is improved, but vulnerability to authentication flooding attack increases

Engineering Contradiction:
Improveconnection monitoringVSAvoidauthentication flooding attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a timeout interval mechanism in advance that automatically prevents the AP from sending SA Query requests during the timeout period. This pre-configured protective measure ensures that even if authentication flooding attacks occur, the AP will not respond to authentication requests during the timeout window, thereby preventing resource exhaustion while maintaining connection monitoring capability when needed.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the access point processes authentication requests from non-AP STA in power saving mode, then connection management is improved, but resource occupation by flooding attacks increases

Engineering Contradiction:
Improveconnection managementVSAvoidresource occupation
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent detects when a non-AP STA enters power saving mode and preliminarily establishes a state where the AP ignores subsequent authentication requests during this mode. This preliminary detection and state establishment prevents the AP from processing unnecessary authentication requests that would consume resources, while still allowing legitimate reassociation requests to be handled when the STA returns from power saving mode.

Inventive Principle:
Principle #10Preliminary action

3Speed

If the access point sends authentication response frames without timeout control, then authentication speed is improved, but susceptibility to flooding attacks worsens

Engineering Contradiction:
Improveauthentication speedVSAvoidflooding attack susceptibility
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic action by introducing timeout intervals between authentication response transmissions. Instead of continuously or frequently sending authentication responses, the AP sends responses according to a periodic timeout-based schedule. This reduces the frequency of authentication frame exchanges to acceptable levels while maintaining adequate authentication functionality, thereby reducing susceptibility to flooding attacks.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12389228B2Attack prevention method for dealing with authentication flooding attack, association flooding attack, and/or reassociation flooding attack and access point using the same
Publication Date: 2025.08.12 MEDIATEK INC
  • US12389228B2 patent drawing
  • US12389228B2 patent drawing
  • US12389228B2 patent drawing

AI summary

An attack prevention method includes: receiving an authentication request frame; and in response to receiving the authentication request frame, replying with an authentication response frame that is sent to a non-access-point (non-AP) station (STA), wherein the authentication request frame includes a timeout interval element that carries Authentication Comeback time. Another attack prevention method includes: ignoring each specific request frame that is received within a period in which a connected non-AP STA operates under a power saving mode, wherein each specific request frame includes one of an authentication request frame, an association request frame, and a reassociation request frame.