Wireless Network Address Spoofing Detection via Verification Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks are vulnerable to address spoofing, which allows unauthorized access and denial of service attacks due to the acceptance of unsecured association and authentication messages, especially after a wireless client has lost its connection state.

Innovation Solution

Implementing a system where wireless access points and clients share a security association to send secured verification messages, encrypted with an encryption key and/or authenticated using a message integrity code, to determine the legitimacy of re-association or disassociation requests, thereby distinguishing between legitimate and spoofed requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If unsecured association and authentication messages are accepted to allow clients to reconnect after losing connection state, then client reconnection capability is improved, but vulnerability to address spoofing and denial of service attacks increases

Engineering Contradiction:
Improveclient reconnection capabilityVSAvoidsecurity against address spoofing
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by sending a verification message to the client before processing the association or authentication request. This verification message checks whether the client is in a state to properly respond (i.e., not in the process of reconnecting after loss). By performing this check in advance, the system can prevent spoofed requests from being processed while still allowing legitimate reconnect attempts to succeed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If 802.1X and key exchange occur after association phase, then user data frame security is improved, but management frames remain vulnerable to spoofing

Engineering Contradiction:
Improveuser data frame securityVSAvoidmanagement frame spoofing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary verification mechanism that operates between the association phase and the 802.1X authentication phase. The verification message acts as a mediator that checks client state legitimacy before allowing the standard authentication process to proceed. This intermediary check protects management frames from spoofing while maintaining the existing 802.1X security framework for data frames.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If wireless infrastructure accepts unsecured association messages to accommodate client reconnection, then ease of operation is improved, but device complexity for security verification increases

Engineering Contradiction:
Improveclient reconnection easeVSAvoidsecurity verification mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies self-service by having the client itself respond to the verification message with a response containing the client's state information. The client must prove it is in the correct state (not in the process of reconnecting) by responding appropriately to the verification message. This shifts the burden of proof to the client, simplifying the server's verification logic while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7809354B2Detecting address spoofing in wireless network environments
Publication Date: 2010.10.05 CISCO TECHNOLOGY INC
  • US7809354B2 patent drawing
  • US7809354B2 patent drawing
  • US7809354B2 patent drawing

AI summary

Methods, apparatuses and systems directed to detecting address spoofing in wireless networks by, after receiving a wireless management frame, transmitting verification messages to determine whether a given wireless node (e.g., a wireless access point, or wireless client) has legitimately lost its connection state.