Blocking Rogue Devices in WLANs via ACK Interference

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized devices, known as rogue devices, can compromise wireless communication systems by accessing them without authorization and interfering with security, and existing methods struggle to effectively block such devices from continued access.

Innovation Solution

A control element directs access points to send additional ACK messages when detecting messages from rogue devices, interfering with the responsive ACK messages and preventing rogue devices from maintaining communication by causing them to assume their messages are not received, leading to repeated retries and eventual loss of connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If de-authorization messages are sent to rogue mobile stations to prevent unauthorized access, then system security is improved, but the method becomes vulnerable to spoofing by rogue access points and is bypassed by IEEE 802.11w management frame protection

Engineering Contradiction:
Improvesystem securityVSAvoidauthorization mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of directly de-authorizing rogue devices (which can be spoofed), the system inverts the approach by having legitimate access points send excessive ACK messages to overwhelm and block rogue devices. This indirect method bypasses the spoofing vulnerability by not requiring rogue devices to process de-authorization commands.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent converts the harmful behavior of rogue devices (sending unauthorized messages) into a beneficial detection mechanism. When rogue devices send messages, legitimate access points detect these unauthorized transmissions and respond with blocking ACK messages, turning the rogue devices' own communication attempts against them.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If access points send additional ACK messages to block rogue devices, then rogue device communication is prevented, but normal ACK message timing and protocol behavior may be affected

Engineering Contradiction:
Improverogue device blocking effectivenessVSAvoidmessage transmission timing
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by sending ACK messages selectively - only to devices identified as rogue through detection of unauthorized communications. The excessive aspect comes from sending multiple ACK messages in rapid succession to ensure blocking effectiveness, rather than a single message.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10880749B2Blocking communication between rogue devices on wireless local access networks (WLANS)
Publication Date: 2020.12.29 FORTINET INC
  • US10880749B2 patent drawing
  • US10880749B2 patent drawing

AI summary

Techniques which prevent rogue devices from continued access to a wireless communication system. A control element directs access points as to which mobile stations to service. Each access point maintains a record of the mobile stations it is servicing. At the direction of the control element, one or more access points send ACK (acknowledgement) messages when hearing messages from a rogue device. When the rogue device sends a message, it expects an ACK message in response, but those additional ACK messages interfere with the responsive ACK message, causing the rogue device to never hear the responsive ACK message. The rogue device assumes its message was not received, so it retries sending of that message. When the rogue device retries sending of its message, the responsive ACK message is similarly interfered with, until the rogue device concludes that its connection has been lost.