Wireless Network Station Authentication and Management Frame Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networking technologies are vulnerable to security threats like spoofing and resource starvation attacks due to the lack of verification of network device capabilities and management frames, which restrict network flexibility, especially in wireless networks where devices frequently switch access points.

Innovation Solution

Implementing a method where network stations authenticate access points using certificates and verify discovery information through a network authentication server, and subsequently verify management frames with security objects to ensure secure associations and protect against unauthorized tampering, allowing for seamless hand-offs between access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network devices require authentication and verification before accessing the network, then network security is improved, but network flexibility and device mobility are restricted

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs authentication and verification actions in advance before network access is granted. Devices are pre-authenticated and verified during the association process, so that when they need to access the network or switch access points, the security checks have already been completed, eliminating the need for repeated verification and maintaining both security and flexibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication server as an intermediary that manages security verification. The authentication server handles the complex verification processes centrally, allowing access points to grant network access without performing exhaustive security checks themselves, thus maintaining network flexibility while ensuring security through the intermediary's verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and verification processes are performed during each access point switch, then network security is maintained, but processing overhead and time consumption increase

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication and verification are performed in advance during the initial association process, so that when devices switch between access points, the security credentials are already established and can be quickly validated without repeating the full authentication sequence, reducing processing time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous security validation by establishing authentication states that persist across access point transitions. Once authenticated, devices maintain their security credentials and can seamlessly transition between access points without interrupting the useful action of network access, avoiding repeated authentication overhead

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If management frames are verified for authenticity, then network security against hijacking is improved, but processing complexity increases

Engineering Contradiction:
Improvesecurity against hijackingVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses security objects and authentication servers as intermediaries to verify management frames. Instead of requiring each device to implement complex verification logic, the authentication server acts as an intermediary that validates management frames using pre-established security credentials, simplifying the verification process while maintaining strong security against hijacking

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7743408B2Secure association and management frame verification
Publication Date: 2010.06.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7743408B2 patent drawing
  • US7743408B2 patent drawing
  • US7743408B2 patent drawing

AI summary

Network devices access a communications network and engage in secure associations with one or more network access points upon authenticating the access points and upon verifying the discovery information that is broadcast by the access point. Once a secure association is created, management frames that are subsequently transmitted between the network devices and the access points and that are used to control the secure association are verified to further enhance the security of the communications network.