Network Controller Detecting Access Point Impersonators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face security vulnerabilities due to access point impersonators, which can steal sensitive information by impersonating valid access points, especially in environments with directional antennas where the narrow RF view makes detection challenging.

Innovation Solution

A network controller, such as a Dynamic Network Access Center (DNAC), receives beacon reports from access points, identifies potential impersonators by determining target areas with overlapping coverage, sends on-demand beacon requests, and validates responses to determine and disable actual impersonators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If directional antennas are used in access points to provide focused coverage in large venues, then coverage efficiency is improved, but security vulnerability increases due to narrow RF view making impersonator detection difficult

Engineering Contradiction:
Improvecoverage areaVSAvoidsecurity vulnerability
Core Design Contradiction:
Area of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent combines multiple access points with directional antennas into a coordinated network system managed by a central controller. The controller aggregates RF condition information from all APs to create a holistic view of the environment, compensating for individual narrow beams and enabling comprehensive impersonator detection while maintaining focused coverage efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The central controller acts as an intermediary that collects beacon reports from multiple access points and performs centralized analysis to detect impersonators. This mediator aggregates the limited RF views from individual directional APs into a comprehensive security monitoring capability, resolving the contradiction between focused coverage and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Use of energy by moving object

If access points operate with narrow beam patterns to provide targeted coverage, then energy efficiency is improved, but detection capability deteriorates due to limited RF environment visibility

Engineering Contradiction:
Improveenergy efficiencyVSAvoiddetection capability
Core Design Contradiction:
Use of energy by moving objectVSDifficulty of detecting and measuring

Solution Approach 1:

The system merges detection capabilities across multiple access points with narrow beams. By coordinating their surveillance efforts through a central controller that aggregates beacon reports, the system achieves comprehensive detection coverage equivalent to omnidirectional monitoring while maintaining the energy efficiency of directional transmission at each individual AP.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent transitions from single-point detection to multi-point spatial distribution. Multiple APs positioned at different locations provide RF views from different spatial dimensions, collectively covering the entire venue. This dimensional approach allows narrow-beam APs to achieve omnidirectional detection coverage through their coordinated spatial arrangement.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11057773B2Systems and methods for detecting access point impersonators
Publication Date: 2021.07.06 CISCO TECHNOLOGY INC
  • US11057773B2 patent drawing
  • US11057773B2 patent drawing
  • US11057773B2 patent drawing

AI summary

The present disclosure is related to systems and methods for detecting and disabling operations of access point impersonators in a network. In one aspect, a method includes receiving, at a network controller of a network, beacon reports from a plurality of access points; determining, by the network controller, one or more target areas with at least one potential access point impersonator operating therein; sending, by the network controller, on-demand beacon requests to one or more of the plurality of access points with corresponding coverage areas overlapping with the one or more target areas; receiving, at the network controller, responses to the on-demand beacon requests from the one or more of the plurality of access points; and determining, by the network controller, at least one access point impersonator based on the responses.