Wireless Network Address Spoofing Detection via Verification Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless networks are vulnerable to address spoofing, which allows unauthorized access and denial of service attacks due to the acceptance of unsecured association and authentication messages, especially after a wireless client has lost its connection state.
Innovation Solution
Implementing a system where wireless access points and clients share a security association to send secured verification messages, encrypted with an encryption key and/or authenticated using a message integrity code, to determine the legitimacy of re-association or disassociation requests, thereby distinguishing between legitimate and spoofed requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If unsecured association and authentication messages are accepted to allow clients to reconnect after losing connection state, then client reconnection capability is improved, but vulnerability to address spoofing and denial of service attacks increases
Solution Approach 1:
The patent applies preliminary action by sending a verification message to the client before processing the association or authentication request. This verification message checks whether the client is in a state to properly respond (i.e., not in the process of reconnecting after loss). By performing this check in advance, the system can prevent spoofed requests from being processed while still allowing legitimate reconnect attempts to succeed.
2Reliability
If 802.1X and key exchange occur after association phase, then user data frame security is improved, but management frames remain vulnerable to spoofing
Solution Approach 1:
The patent introduces an intermediary verification mechanism that operates between the association phase and the 802.1X authentication phase. The verification message acts as a mediator that checks client state legitimacy before allowing the standard authentication process to proceed. This intermediary check protects management frames from spoofing while maintaining the existing 802.1X security framework for data frames.
3Ease of operation
If wireless infrastructure accepts unsecured association messages to accommodate client reconnection, then ease of operation is improved, but device complexity for security verification increases
Solution Approach 1:
The patent applies self-service by having the client itself respond to the verification message with a response containing the client's state information. The client must prove it is in the correct state (not in the process of reconnecting) by responding appropriately to the verification message. This shifts the burden of proof to the client, simplifying the server's verification logic while maintaining security.
Data Source
AI summary
Methods, apparatuses and systems directed to detecting address spoofing in wireless networks by, after receiving a wireless management frame, transmitting verification messages to determine whether a given wireless node (e.g., a wireless access point, or wireless client) has legitimately lost its connection state.


