Access Point RSN IE Verification for DoS Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unsolicited probe responses in Wi-Fi networks are vulnerable to Denial of Service (DoS) attacks, where rogue access points send incorrect Robust Security Network Information Elements (RSN IE) to client devices, causing authentication failures and service interruptions.

Innovation Solution

Access points detect such attacks by comparing RSN IE parameters with their own security profiles and disable unsolicited probe responses, switching to alternative authentication methods like Fast Initial Link Setup (FILS) discovery to mitigate the attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If unsolicited probe responses are used for AP discovery, then client battery life is extended and airtime efficiency is improved, but the network becomes vulnerable to DoS attacks with incorrect RSN IE

Engineering Contradiction:
ImproveAP discovery efficiencyVSAvoidauthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the access point verify RSN IE parameters in advance before processing unsolicited probe responses. The AP compares received RSN IE against its own security profile configuration, and only processes responses with matching parameters. This pre-verification mechanism prevents malicious responses from causing authentication failures while maintaining the efficiency benefits of unsolicited probe responses.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If RSN IE verification is implemented in unsolicited probe responses, then DoS attack resistance is improved, but device complexity increases

Engineering Contradiction:
Improveattack resistanceVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing verification only in the specific context of unsolicited probe response processing, rather than throughout the entire authentication system. The RSN IE parameter comparison is performed locally at the probe response handling stage, focusing computational resources only where needed. This targeted approach provides attack resistance without unnecessarily increasing overall device complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If incorrect RSN IE is processed, then client authentication fails causing service interruption, but implementing verification increases processing overhead

Engineering Contradiction:
Improveauthentication success rateVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies the extraction principle by isolating the verification logic specifically for RSN IE parameters in unsolicited probe responses. Rather than implementing comprehensive verification of all message components, the system extracts and verifies only the critical RSN IE security parameters against the AP's profile. This focused verification prevents authentication failures from incorrect security information while minimizing processing overhead by avoiding unnecessary verification of non-critical elements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12081986B2Handling unsolicited probe responses
Publication Date: 2024.09.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12081986B2 patent drawing
  • US12081986B2 patent drawing
  • US12081986B2 patent drawing

AI summary

Examples of techniques for handling unsolicited probe responses are disclosed. In an example, occurrence of an attack on an access point (AP) in an enterprise Wireless Local Area Network (WLAN) is detected based on an unsolicited probe response and Robust Security Network Information Element (RSN IE). Responsive to detecting the attack, unsolicited probe responses at the AP is disabled. Further, Fast initial Link Setup (FILS) discovery at the AP is enabled.