Blocking Rogue Devices in WLANs via ACK Interference
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unauthorized devices, known as rogue devices, can compromise wireless communication systems by accessing them without authorization and interfering with security, and existing methods struggle to effectively block such devices from continued access.
Innovation Solution
A control element directs access points to send additional ACK messages when detecting messages from rogue devices, interfering with the responsive ACK messages and preventing rogue devices from maintaining communication by causing them to assume their messages are not received, leading to repeated retries and eventual loss of connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If de-authorization messages are sent to rogue mobile stations to prevent unauthorized access, then system security is improved, but the method becomes vulnerable to spoofing by rogue access points and is bypassed by IEEE 802.11w management frame protection
Solution Approach 1:
Instead of directly de-authorizing rogue devices (which can be spoofed), the system inverts the approach by having legitimate access points send excessive ACK messages to overwhelm and block rogue devices. This indirect method bypasses the spoofing vulnerability by not requiring rogue devices to process de-authorization commands.
Solution Approach 2:
The patent converts the harmful behavior of rogue devices (sending unauthorized messages) into a beneficial detection mechanism. When rogue devices send messages, legitimate access points detect these unauthorized transmissions and respond with blocking ACK messages, turning the rogue devices' own communication attempts against them.
2Reliability
If access points send additional ACK messages to block rogue devices, then rogue device communication is prevented, but normal ACK message timing and protocol behavior may be affected
Solution Approach 1:
The patent applies partial action by sending ACK messages selectively - only to devices identified as rogue through detection of unauthorized communications. The excessive aspect comes from sending multiple ACK messages in rapid succession to ensure blocking effectiveness, rather than a single message.
Data Source
AI summary
Techniques which prevent rogue devices from continued access to a wireless communication system. A control element directs access points as to which mobile stations to service. Each access point maintains a record of the mobile stations it is servicing. At the direction of the control element, one or more access points send ACK (acknowledgement) messages when hearing messages from a rogue device. When the rogue device sends a message, it expects an ACK message in response, but those additional ACK messages interfere with the responsive ACK message, causing the rogue device to never hear the responsive ACK message. The rogue device assumes its message was not received, so it retries sending of that message. When the rogue device retries sending of its message, the responsive ACK message is similarly interfered with, until the rogue device concludes that its connection has been lost.

