Wireless Access Point Management Frame Integrity Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network security schemes fail to adequately protect management frames, making networks vulnerable to attacks from rogue access points that can spoof management frames, leading to session disruption and data integrity issues.

Innovation Solution

Implementing a wireless access point with link keys and infrastructure management frame protection (IMFP) keys to secure management frames by generating and appending message integrity checks (MICs) to these frames, allowing neighboring access points to validate their authenticity and detect spoofed frames.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security schemes are used to protect data content, then data transmission security is improved, but management frame integrity and session protection remain vulnerable

Engineering Contradiction:
Improvedata transmission securityVSAvoidmanagement frame spoofing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security protection into two distinct layers: traditional data content encryption (WPA/WPA2) and new management frame protection (MFP). This segmentation allows data security to be maintained while adding separate protection for management frames, resolving the contradiction between data security and management frame integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces MFP as an intermediary protection mechanism between the existing data encryption layer and the management frame transmission. This intermediary layer specifically protects management frames from spoofing while allowing data content to be protected by traditional WPA mechanisms, thus resolving the vulnerability without compromising existing data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control mechanisms are implemented, then network access security is improved, but client-side vulnerability to spoofed management frames increases

Engineering Contradiction:
Improvenetwork access securityVSAvoidclient-side spoofing vulnerability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing MFP validation before clients process management frames. Access points validate the MIC of management frames beforehand, preventing spoofed frames from reaching clients. This preemptive validation eliminates the client-side vulnerability while maintaining access control security.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements feedback mechanisms where access points continuously validate management frame integrity and provide feedback about frame authenticity to clients. This feedback loop ensures that clients receive only authenticated frames, resolving the vulnerability while preserving access control effectiveness.

Inventive Principle:
Principle #23Feedback

3Reliability

If management frame protection is added, then session integrity is improved, but device complexity increases

Engineering Contradiction:
Improvesession integrityVSAvoidaccess point functionality
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the MFP validation functionality with the existing access point architecture, combining the MIC generation and validation processes with the existing frame handling mechanisms. This integration approach improves session integrity while minimizing the increase in device complexity by reusing existing hardware and software resources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameters of existing access point operations by adding MIC validation steps without fundamentally altering the access point architecture. The validation process uses existing cryptographic primitives and frame formats, modifying only the validation parameters and processes rather than redesigning the entire device, thus improving integrity with minimal complexity increase.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7882349B2Insider attack defense for network client validation of network management frames
Publication Date: 2011.02.01 CISCO TECHNOLOGY INC
  • US7882349B2 patent drawing
  • US7882349B2 patent drawing
  • US7882349B2 patent drawing

AI summary

Method for detecting an attack on a broadcast key shared between an access point and its wireless clients. Upon detection of the attack, actions are implemented to react to the attack as defined in one or more security policies. Detection of the attack is achieved by examining both a link message integrity check and an infrastructure management frame protection (IMFP) message integrity check contained in a broadcast management frame.