Wi-Fi 6E Rogue Access Point Detection With Spoofed Channel Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for disrupting rogue Wi-Fi 6E access point connections with Wi-Fi 6E stations are ineffective due to the inability of deauthentication frames and probe response protocols, allowing malicious connections to persist at 5 GHz or 2.4 GHz bands.

Innovation Solution

A Wi-Fi controller identifies rogue access points through on-wire data traffic monitoring and sends modified CSA values via spoofed action frames with a source BSSID of the rogue access point, causing Wi-Fi 6E stations to switch channels and disrupt connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deauthentication frames are used to disrupt rogue access point connections, then connection disruption is achieved in conventional Wi-Fi, but the method becomes ineffective against Wi-Fi 6E rogue access points that can reconnect at 5 GHz or 2.4 GHz bands

Engineering Contradiction:
Improveconnection disruption effectivenessVSAvoidrogue access point reconnection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from operating within a single frequency dimension to coordinating across multiple frequency dimensions. Authorized access points monitor and coordinate channel switching actions across different bands (6 GHz, 5 GHz, 2.4 GHz) to prevent rogue access points from reconnecting after disruption on one channel, effectively adding a dimensional aspect to the disruption strategy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent implements preliminary monitoring and coordination before rogue access points can reestablish connections. By continuously monitoring SSID/BSSID data and maintaining scan tables of authorized access points, the system prepares disruption actions in advance, detecting rogue access points before they can successfully connect and disrupt network operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If probe response frames are used to prevent rogue access point connections, then authentication can be controlled, but the protocol is not used for actual connections in Wi-Fi 6E

Engineering Contradiction:
Improveconnection authentication controlVSAvoidconnection establishment effectiveness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses Channel Switching Announcement (CSA) frames as an intermediary mechanism to disrupt rogue access point connections. Instead of relying on the ineffective probe response protocol, the system introduces CSA frames that instruct Wi-Fi 6E stations to switch channels, thereby indirectly preventing connections to rogue access points without directly interfering with the connection establishment protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If coordinated CSA disruption is implemented across multiple access points, then rogue access point connections are more effectively disrupted, but system complexity increases

Engineering Contradiction:
Improverogue access point disruption effectivenessVSAvoidcoordination system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of multiple authorized access points into a coordinated system managed by a central controller. The controller consolidates SSID/BSSID scan tables and coordinates channel switching actions across all authorized access points, allowing them to operate as a unified entity rather than independent devices, thereby managing complexity through centralization.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where authorized access points continuously monitor SSID/BSSID data and report to the central controller. The controller uses this feedback to update scan tables and coordinate disruption actions, creating a closed-loop system that adapts to changing network conditions and rogue access point behaviors.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12382292B2Mitigation of rogue Wi-Fi 6E compatible access points
Publication Date: 2025.08.05 FORTINET INC
  • US12382292B2 patent drawing
  • US12382292B2 patent drawing
  • US12382292B2 patent drawing

AI summary

A rogue Wi-Fi 6E access points are identified by on-wire data traffic of authorized Wi-Fi 6E access points. Data traffic is monitored across all access points for the rogue Wi-Fi 6E access points according to an SSID/BSSID scan table. In response, modified CSA values are sent from spoofed action frames that have a source BSSID of the rogue access points rather than the authenticated access point that transmits.