Rogue Access Point Detection via Switch Port Shutdown

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and disabling rogue access points in wireless local-area networks often flood the radio spectrum, reducing bandwidth and are not sustainable with evolving standards, posing a security threat and efficiency issue.

Innovation Solution

A system where an authorized access point transmits a broadcast packet with a unique tag, and if received by an unauthorized access point, the network switch determines the port's authorization status and shuts it down, preventing network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deauthentication packets are transmitted to disable rogue APs, then rogue APs can be disabled, but radio spectrum is flooded and bandwidth is reduced

Engineering Contradiction:
Improverogue AP disabling effectivenessVSAvoiddata throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a network switch as an intermediary device that monitors and controls communication between APs and the network. The switch intercepts broadcast packets from authorized APs and selectively forwards them to rogue APs, enabling disabling while avoiding direct flooding of deauthentication packets that would harm legitimate traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network control function by separating the disabling mechanism from the data transmission path. The switch creates a distinct control channel using broadcast packets, allowing rogue AP identification and disabling to occur independently from the main data throughput path, thus avoiding spectrum flooding.

Inventive Principle:
Principle #1Segmentation

2Reliability

If deauthentication packets are used to disable rogue APs, then unauthorized access can be prevented, but the method is not compatible with future standards

Engineering Contradiction:
Improvenetwork securityVSAvoidstandard compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent uses broadcast packets, which are a fundamental and universally supported network communication mechanism, instead of relying on specific deauthentication packet types that may become obsolete. This approach provides a multi-functional solution that works across current and future IEEE 802.11 standards while achieving the same security objective.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Difficulty of detecting and measuring

If broadcast packets are forwarded to all ports, then rogue APs can be detected, but authorized AP ports may be incorrectly disabled

Engineering Contradiction:
Improverogue AP detection capabilityVSAvoidauthorized AP operation
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The network switch uses port authorization status as feedback to control packet forwarding decisions. The switch maintains knowledge of which ports are authorized for AP connections and uses this information to selectively forward or block broadcast packets, ensuring that only unauthorized ports are disabled while authorized APs continue to operate normally.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9439131B2Detecting and disabling rogue access points in a network
Publication Date: 2016.09.06 ADTRAN INC
  • US9439131B2 patent drawing
  • US9439131B2 patent drawing
  • US9439131B2 patent drawing

AI summary

A rogue access point in a wireless local-area network can be disabled by an authorized access point wirelessly transmitting a layer-2 broadcast packet. If a rogue access point receives this broadcast packet, it will forward a copy to the switch to which it is connected. The switch then determines whether the port on which the copy of the broadcast packet is received is associated an authorized access point port. If the switch determines the port is not an authorized access point port, the switch shuts down the port.