Wireless Access Point Scanning for Rogue Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in effectively policing and removing rogue devices, which can consume resources, hijack clients, and passively snoop information, due to inefficiencies in scanning and removing unauthorized devices without substantial communication overhead.

Innovation Solution

Access points (APs) are capable of simultaneously servicing authorized devices and scanning for rogue devices on multiple channels, using L1 protocol message manipulation to detect, isolate, and expel rogue devices with minimal communication overhead, and prevent passive listening by jamming protocol messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If APs scan for rogue devices on multiple channels, then security detection capability is improved, but communication overhead and airtime consumption increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the scanning process by having different APs scan different channels at different times. Each AP is assigned to scan specific channels during specific time periods, dividing the overall scanning task across multiple devices to reduce individual overhead while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements periodic scanning where APs alternately perform scanning and servicing functions. During designated scanning periods, APs monitor for rogue devices; during servicing periods, they normaly handle authorized device communications. This periodic alternation reduces continuous scanning overhead.

Inventive Principle:
Principle #19Periodic action

2Reliability

If APs remove rogue devices from the system, then system security is improved, but airtime and communication capacity are consumed

Engineering Contradiction:
Improvesystem securityVSAvoidairtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having APs prepare removal commands and protocols in advance. When a rogue device is detected, the pre-prepared removal mechanism is immediately activated, reducing the time and airtime needed for the actual removal process compared to ad-hoc removal procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts rogue devices from the system by having APs identify and isolate detected rogue devices through targeted communication protocols. The extraction process is optimized to remove only the necessary communication elements related to the rogue device, minimizing overall airtime consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If APs service authorized devices and scan for rogue devices simultaneously, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improveservice efficiencyVSAvoidAP functionality complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the scanning and servicing functions into a single AP operation. By combining these functions in one device with proper resource management, the system achieves better productivity without proportionally increasing overall system complexity, as the complexity is consolidated in individual APs rather than requiring separate dedicated scanning devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements dynamic functionality where APs can switch between scanning and servicing modes based on current system needs and detected conditions. This dynamic behavior allows APs to adapt their operation in real-time, improving productivity while managing complexity through flexible, context-dependent functionality rather than static complex architectures.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8867744B1Security in wireless communication systems
Publication Date: 2014.10.21 FORTINET INC
  • US8867744B1 patent drawing
  • US8867744B1 patent drawing
  • US8867744B1 patent drawing

AI summary

Wireless security is enforced at L1, in addition to or in lieu of other layers. AP's can switch dynamically from serving to scanning. Scanners listen for authorized frame headers. Scanners either receive, or allow authorized frames to be received, at their destination. Scanners kill unauthorized frames while they are still transmitting; scanners continue listening for and killing unauthorized frame headers until frame ending time demands their return to serving, multiplying their effectiveness. AP's include dual-mode multi-frequency omni-directional antennae, used to prevent third parties from snooping messages received at those AP's.