Probe Response Frames for MFP-Resilient Wireless Intrusion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless networks face challenges in disrupting unauthorized wireless connections due to the encryption of Deauthentication management frames under Management Frame Protection (MFP) in IEEE 802.11w and WPA3, making it impossible to use spoofed Deauthentication frames for connection disruption.

Innovation Solution

Employing Probe Response management frames, which are not encrypted under MFP, to selectively disrupt undesired wireless connections by offering enticing wireless connection characteristics to client devices, such as improved signal strength and lower noise levels, thereby enticing them to reconnect to authorized access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Deauthentication management frames are used to disrupt unauthorized wireless connections, then connection disruption is achieved, but the method becomes ineffective under Management Frame Protection (MFP) encryption

Engineering Contradiction:
Improveconnection disruption effectivenessVSAvoidmethod applicability under MFP
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of using Deauthentication frames to disconnect clients, the patent inverts the approach by using Probe Response frames to attract clients away from unauthorized access points. The authorized access point sends Probe Response frames with enticing connection characteristics, causing the client to voluntarily disconnect from the rogue AP and reconnect to the authorized network.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the parameters of Probe Response frames to make them more attractive than unauthorized access points. By modifying signal strength, noise levels, and other connection characteristics in the Probe Response frames, the authorized access point creates more favorable connection conditions that entice clients to switch networks.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If Probe Response management frames are used to disrupt unauthorized connections, then selectivity is improved, but the mechanism requires enticing connection characteristics

Engineering Contradiction:
Improveselective disruption capabilityVSAvoidconnection characteristic manipulation
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies local quality by sending tailored Probe Response frames to specific clients connected to unauthorized access points. Each Probe Response frame is customized with connection characteristics targeted at that particular client's requirements, allowing selective disruption of only unauthorized connections while leaving authorized connections intact.

Inventive Principle:
Principle #3Local quality

3Reliability

If MFP encryption is implemented to secure management frames, then security is improved, but the ability to spoof Deauthentication frames is lost

Engineering Contradiction:
Improvemanagement frame securityVSAvoidinability to disrupt rogue connections
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent converts the limitation of MFP encryption into a benefit by using unencrypted Probe Response frames instead of encrypted Deauthentication frames. Since Probe Response frames are not encrypted under MFP, they can be sent freely to entice clients away from rogue access points, turning the security restriction into an opportunity for a new disruption method.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS12375921B2Wireless intrusion prevention
Publication Date: 2025.07.29 ARISTA NETWORKS INC
  • US12375921B2 patent drawing
  • US12375921B2 patent drawing
  • US12375921B2 patent drawing

AI summary

A networking system may disrupt an unauthorized wireless connection to the network. In particular, the networking system may detect a wireless connection between a client device and an unauthorized wireless access point. The networking system may receive a probe request management frame from the client device. The network system may, responsive to the detection of the wireless connection, send a probe response management frame to the client device.