Wireless Network Station Authentication and Management Frame Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing networking technologies are vulnerable to security threats like spoofing and resource starvation attacks due to the lack of verification of network device capabilities and management frames, which restrict network flexibility, especially in wireless networks where devices frequently switch access points.
Innovation Solution
Implementing a method where network stations authenticate access points using certificates and verify discovery information through a network authentication server, and subsequently verify management frames with security objects to ensure secure associations and protect against unauthorized tampering, allowing for seamless hand-offs between access points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network devices require authentication and verification before accessing the network, then network security is improved, but network flexibility and device mobility are restricted
Solution Approach 1:
The patent performs authentication and verification actions in advance before network access is granted. Devices are pre-authenticated and verified during the association process, so that when they need to access the network or switch access points, the security checks have already been completed, eliminating the need for repeated verification and maintaining both security and flexibility
Solution Approach 2:
The patent introduces an authentication server as an intermediary that manages security verification. The authentication server handles the complex verification processes centrally, allowing access points to grant network access without performing exhaustive security checks themselves, thus maintaining network flexibility while ensuring security through the intermediary's verification
2Reliability
If authentication and verification processes are performed during each access point switch, then network security is maintained, but processing overhead and time consumption increase
Solution Approach 1:
Authentication and verification are performed in advance during the initial association process, so that when devices switch between access points, the security credentials are already established and can be quickly validated without repeating the full authentication sequence, reducing processing time while maintaining security
Solution Approach 2:
The patent maintains continuous security validation by establishing authentication states that persist across access point transitions. Once authenticated, devices maintain their security credentials and can seamlessly transition between access points without interrupting the useful action of network access, avoiding repeated authentication overhead
3Reliability
If management frames are verified for authenticity, then network security against hijacking is improved, but processing complexity increases
Solution Approach 1:
The patent uses security objects and authentication servers as intermediaries to verify management frames. Instead of requiring each device to implement complex verification logic, the authentication server acts as an intermediary that validates management frames using pre-established security credentials, simplifying the verification process while maintaining strong security against hijacking
Data Source
AI summary
Network devices access a communications network and engage in secure associations with one or more network access points upon authenticating the access points and upon verifying the discovery information that is broadcast by the access point. Once a secure association is created, management frames that are subsequently transmitted between the network devices and the access points and that are used to control the secure association are verified to further enhance the security of the communications network.


