Validating de-authentication requests

US10771498B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-10771498-B1
Application numberUS-201615178979-A
CountryUS
Kind codeB1
Filing dateJun 10, 2016
Priority dateJun 10, 2015
Publication dateSep 8, 2020
Grant dateSep 8, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems, methods, and other embodiments associated with validating de-authentication requests to prevent spoofing are described. According to one embodiment, an apparatus includes a wireless controller configured to receive a de-authentication request and determine whether the de-authentication request is invalid based on the wireless controller's receipt of two or more responses to a timing request sent by the wireless controller. Only one response is expected. The two or more responses include the address of a first station.

First claim

Opening claim text (preview).

What is claimed is: 1. An apparatus for validating a de-authentication request, the apparatus comprising: a wireless controller configured to receive the de-authentication request and determine whether the de-authentication request is invalid based on the wireless controller's receipt of two or more responses to a timing request sent by the wireless controller in response to the de-authentication request, wherein only one response is expected, and wherein the two or more responses include an address of a first station, and at least one response of the two or more responses to the timing request includes a confirmation of transmitting the de-authentication request, the confirmation received from one of the first station or a second station, and at least one response of the two or more responses to the timing request includes a denial of transmitting the de-authentication request, the denial received (i) from the first station if the confirmation is received from second station or (ii) from the second station if the confirmation is received from the first station. 2. The apparatus of claim 1 , further comprising a memory configured to store at least a prior distance between the apparatus and the first station, and wherein the wireless controller is further configured to determine that one of the two or more responses which is associated with the de-authentication request is invalid based on a comparison of the prior distance with a distance associated with that one of the two or more responses and the confirmation of transmitting the de-authentication request in the one of the two or more responses. 3. The apparatus of claim 2 , wherein the wireless controller determines that the distance does not match the prior distance, wherein, in response to identifying that the de-authentication request is invalid based on the distance not matching the prior distance, the wireless controller is configured to provide an indication to ignore the de-authentication request. 4. The apparatus of claim 1 , wherein the wireless controller is configured to: determine, prior to receiving the de-authentication request, a distance between the apparatus and the first station using timing measurements exchanged with the first station, and store the distance in a memory to maintain a log of previous distances between the apparatus and the first station. 5. The apparatus of claim 1 , wherein the wireless controller is configured to indicate the query in the timing request based on at least one of a reserved bit and an additional bit, wherein the timing request is a fine time measurement (FTM) initiation request that includes at least one bit that causes the first station to provide the response with the confirmation or denial of transmitting the de-authentication request. 6. The apparatus of claim 1 , wherein the apparatus is an access point (AP) station configured to provide a wireless local area network (WLAN), and wherein the wireless controller is configured to receive the two or more responses to the timing request by monitoring for the responses for a threshold amount of time. 7. The apparatus of claim 1 , wherein the first station is an access point (AP) station and the apparatus is a station configured to communicate in a wireless local area network (WLAN) provided by the access point station, wherein a distance between the first station and the apparatus is based on a time measurement, the time measurement being a fine time measurement (FTM) that is an exchange of communications for a wireless location service (WLS). 8. A method for validating a de-authentication request, the method comprising: receiving the de-authentication request by a first wireless device; and determining whether the de-authentication request is invalid based on receipt of two or more responses to a timing request sent by the first wireless device in response to the de-authentication request, wherein only one response is expected, and wherein the two or more responses include an address of a second wireless device, and at least one response of the two or more responses to the timing request includes a confirmation of transmitting the de-authentication request, the confirmation received from one of the second wireless device and a third wireless device, and at least one response of the two or more responses to the timing request includes a denial of transmitting the de-authentication request, the denial received (i) from the second wireless device if the confirmation is received from the third wireless device or (ii) from the third wireless device if the confirmation is received from the second wireless device. 9. The method of claim 8 , further comprising: storing at least a prior distance between the first wireless device and the second wireless device, and determining that one of the two or more responses which is associated with the de-authentication request is invalid based on a comparison of the prior distance with a distance associated with that one of the two or more responses and the confirmation of transmitting the de-authentication request in the one of the two or more responses. 10. The method of claim 9 , further comprising: determining that the distance does not match the prior distance, wherein, in response to identifying that the de-authentication request is invalid based on the distance not matching the prior distance, providing an indication to ignore the de-authentication request. 11. The method of claim 8 , further comprising: determining, prior to receiving the de-authentication request, a distance between the first wireless device and the second wireless device using timing measurements exchanged with the second wireless device; and storing the distance in a memory to maintain a log of previous distances between the first wireless device and the second wireless device. 12. The method of claim 8 , wherein the timing request indicates the query based on at least one of a reserved bit and an additional bit, wherein the timing request is a fine time measurement (FTM) initiation request that includes at least one bit that causes the second wireless device to provide the response with the confirmation or denial of the de-authentication request. 13. The method of claim 8 , wherein the first wireless device is an access point (AP) station and the second wireless device is a station communicating in a wireless local area network (WLAN) provided by the first wireless device, and wherein receiving the at least two responses to the timing request includes monitoring for the responses for a threshold period of time. 14. The method of claim 8 , wherein the second wireless device is an access point (AP) station and the first wireless device is a station communicating in a wireless local area network (WLAN) provided by the second wireless device, wherein a distance between the first wireless device and the second wireless device is based on a time measurement, the time measurement being a fine time measurement (FTM) that is an exchange of communications for a wireless location service (WLS). 15. An apparatus for validating a de-authentication request, the apparatus comprising: a wireless controller module stored on a non-transitory computer-readable medium and including instructions that when executed cause the apparatus to receive the de-authentication request and determine whether the de-authentication request is invalid based on the wireless controller module's receipt of two or more responses to a timing request sent by the wireless controller module in response to the de-authentication request, wherein only one response is expected, and wherein t

Assignees

Inventors

Classifications

  • Location-dependent; Proximity-dependent · CPC title

  • Counter-measures against attacks; Protection against rogue devices · CPC title

  • H04W12/06Primary

    Authentication · CPC title

  • Denial of service attacks against endpoints in a network · CPC title

  • Denial of Service · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10771498B1 cover?
Systems, methods, and other embodiments associated with validating de-authentication requests to prevent spoofing are described. According to one embodiment, an apparatus includes a wireless controller configured to receive a de-authentication request and determine whether the de-authentication request is invalid based on the wireless controller's receipt of two or more responses to a timing re…
Who is the assignee on this patent?
Marvell Int Ltd, Marvell Asia Pte Ltd
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 08 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).