A Wireless Protocol Attack Detection Method Based on Timestamp Values

By adding time stamp value to each link frame in the wireless communication system and encrypting the process, combining the verification mechanism of the timestamp value and serial number, the problem of untimely and low accuracy of wireless protocol attack detection in the prior art is solved, and efficient wireless protocol attack detection and security alarm are achieved.

CN118741525BActive Publication Date: 2025-06-27MILITARY SECRECY QUALIFICATION EXAMINATION & CERTIFICATION CENT +2
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410483250.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-22
Publication Date
2025-06-27
Estimated Expiration
2044-04-22

AI Technical Summary

Technical Problem

The existing wireless protocol attack detection method fails to effectively combine the characteristics of TDMA time-division scheduling access, resulting in untimely alarms and low detection accuracy.

Method used

A wireless protocol attack detection method based on time stamp value is proposed. By reserveing ​​a time stamp position for each link frame in the wireless communication system, and adding the time stamp value of the current time of the timer before sending, the link frame is encrypted, and the legitimacy of the link frame is verified by the time stamp value and the serial number, and a security alarm is generated.

Benefits of technology

It realizes rapid detection and timely security alarms of wireless protocol attack messages, improves detection accuracy, avoids the vulnerability of relying on traditional authentication mechanisms, and has good compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118741525B_ABST
    Figure CN118741525B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of wireless communication and mobile data services, and discloses a wireless protocol attack detection method based on timestamp values. The method includes: S1 Starting the wireless communication system and periodically broadcasting time synchronization frames through a network manager to enable the timers of each wireless communication device to achieve clock synchronization; S2 Each wireless communication device constructs a link frame at the data link layer and reserves a timestamp position on the link frame; S3 Before sending the link frame, adding the timestamp value to the timestamp position; the timestamp value is the current moment of the timer; S4 Using a key and an encryption algorithm to encrypt each link frame with a timestamp value; S5 Sending the encrypted link frame with a timestamp value to the corresponding wireless communication device through the wireless air interface; S6 After receiving, the wireless communication device decrypts the ciphertext using the key, and after decryption, verifies the legality of the link frame. The method can quickly discover wireless protocol attack packets and generate security alerts in a timely manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of wireless communication and mobile data services, in particular to the technical fields of local area networks and industrial wireless networks, and particularly to a method for detecting wireless protocol attacks based on timestamp values. Background Art

[0002] Current wireless communication technologies mainly include 4G / 5G, WIFI, Bluetooth, as well as industrial wireless network protocols, wireless sensor network protocols, etc. In these wireless communication technologies, security protection functions are mainly achieved through network access authentication and encryption technologies. For example, the WPA2 authentication mechanism of WIFI, the block encryption mechanism of the Advanced Encryption Standard (AES) algorithm, etc. These mechanisms are used to solve the problems of illegal access to the network by "rogue base stations" and the cracking of clear communication data by "eavesdroppers".

[0003] However, current wireless network attacks, in addition to the traditional cracking of authentication keys and encryption keys, also attack wireless signals and wireless protocols. Attacks on wireless signals include spectrum suppression attacks, that is, using high-power wireless signals in the same frequency band for suppression, so that normal data cannot communicate, resulting in the paralysis of the wireless network. Usually, this kind of attack can be detected in time through real-time spectrum monitoring, and can be investigated and removed in time. Wireless protocol attacks include data replay attacks, attacks on control frames, attacks on beacon frames, etc., which have the characteristics of strong concealment and great lethality. For example, in a Time Division Multiple Access (TDMA) network, it is necessary to broadcast time synchronization frames through an Access Point (AP) to synchronize the clocks of the entire network. Then, a "protocol attacker" can forge time synchronization frames and broadcast them in a hidden place, and modify the time value, so that wireless nodes often receive time values different from those of the AP, resulting in clock chaos in the entire network, and then leading to the failure of the wireless communication protocol, greatly reducing the communication performance, and even causing the network to collapse. Another example is that the Request To Send / Clear To Send (RTS / CTS) mechanism of the WIFI network is used to negotiate an idle channel. When a wireless node sends a CTS, other wireless devices in the network cannot send data according to the WIFI protocol, so as to reserve an idle channel for a specific wireless device to send data. When a "protocol attacker" listens to the CTS frame and continuously replays and sends the CTS frame, then all devices in the wireless network cannot send data anymore, directly resulting in the paralysis of the wireless network.

[0004] Existing wireless protocol attack detection methods do not combine the characteristics of TDMA time division scheduling access, resulting in the defects of untimely alarms and low detection accuracy. Therefore, there is an urgent need to propose a method for detecting wireless protocol attacks to quickly discover wireless protocol attack packets and generate security alarms in a timely manner. Summary of the Invention

[0005] The purpose of the present invention is to propose a wireless protocol attack detection method based on timestamp values, which can quickly discover wireless protocol attack packets and generate security alarms in a timely manner.

[0006] In a first aspect, the present invention provides a wireless protocol attack detection method based on timestamp values, which is applied to a wireless communication system. The wireless communication system includes multiple wireless communication devices, and each wireless communication device has a timer; the wireless protocol attack detection method includes the following steps:

[0007] S10. Start the wireless communication system and periodically broadcast time synchronization frames through a network manager to synchronize the clocks of the timers of each wireless communication device;

[0008] S11. Each wireless communication device constructs a link frame at the data link layer and reserves a timestamp position on the link frame;

[0009] S12. Before sending the link frame, add the timestamp value to the timestamp position; the timestamp value is the time of the current moment of the timer;

[0010] S13. Encrypt each link frame with a timestamp value using a key and an encryption algorithm. The encryption plaintext range includes at least the timestamp value, the sequence number, and the upper-layer service data;

[0011] S14. Send the encrypted link frame with a timestamp value to the corresponding wireless communication device through the wireless air interface;

[0012] S15. After receiving the encrypted link frame with a timestamp value, the wireless communication device decrypts the ciphertext using the key. After decryption, it verifies the legality of the link frame using the sequence number, the transmission time slot, the source / destination address, and the timestamp value.

[0013] As a possible implementation, verifying the legality of the link frame using the sequence number and / or the timestamp value specifically includes:

[0014] When it is judged that the timestamp value is after the current time, or when it is judged that the timestamp value is before the current time, or the timestamp value does not belong to the current time slot number, a security alarm is generated; or,

[0015] When it is judged that the timestamp value and the sequence number do not conform to the wireless protocol, a security alarm is generated.

[0016] As a possible implementation, when determining whether the timestamp value and the sequence number conform to the wireless protocol, the following method is used:

[0017] Determine whether the link frame is sent within the specified source address and transmission time slot. If so, the timestamp value and sequence number conform to the wireless protocol; otherwise, they do not conform to the wireless protocol.

[0018] As a possible implementation, the transmission time slot is a pre-allocated transmission time slot.

[0019] As a possible implementation, the timestamp value of the link frame sent by each wireless communication device increases continuously; the sequence number of the link frame sent by each wireless communication device either increases continuously or flips.

[0020] As a possible implementation, when it is determined that the sequence number corresponding to the current link frame is the same as the sequence number corresponding to the previous link frame, and / or when it is determined that the timestamp value corresponding to the current link frame is the same as the timestamp value corresponding to the previous link frame, a security alert is generated.

[0021] As a possible implementation, in S13, the key used to encrypt each link frame with a timestamp value is updated according to a preset period.

[0022] As a possible implementation, in S12, the following method is specifically used to add a timestamp value to the link frame:

[0023] Add the timestamp value through software configured with a timestamp value addition program, or through a wireless baseband chip.

[0024] As a possible implementation, the link frame includes at least a Beacon frame, an Acknowledge (ACK) frame, a management frame, or a control frame.

[0025] As a possible implementation, in S13, a block encryption method is used to encrypt each link frame with a timestamp value. The block encryption method includes at least the SM4 algorithm or the AES algorithm, and the block encryption algorithm is updated periodically.

[0026] In a second aspect, the present invention further provides a wireless protocol attack detection system based on a timestamp value. The wireless protocol attack detection system is applied to a wireless communication system, and the wireless communication system includes multiple wireless communication devices, and each wireless communication device has a timer. The wireless protocol attack detection system executes the wireless protocol attack detection method provided in the first aspect.

[0027] In a third aspect, the present invention further provides a chip, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method for detecting wireless protocol attacks based on timestamp values provided in the first aspect is implemented.

[0028] In a fourth aspect, the present invention further provides a terminal, including a processor and a communication interface coupled to the processor; the processor is configured to run a computer program or instruction to implement the method for detecting wireless protocol attacks based on timestamp values provided in the first aspect.

[0029] Compared with the prior art, the beneficial effects produced by the present invention are as follows:

[0030] 1. The method for detecting wireless protocol attacks based on timestamp values provided by the present invention enables each link frame to have a timestamp value, and encrypts each link frame with a timestamp value. Therefore, the wireless packets detected and sniffed in the air by the listener are all ciphertext, and it is impossible for it to simulate or guess the timestamp value of the next frame of data, which can ensure that the attack data sent by the attacker will be detected, and the detection accuracy is high.

[0031] 2. The method for detecting wireless protocol attacks based on timestamp values provided by the present invention, when the wireless communication system is operating normally, the wireless access point and wireless node devices will verify all received data frames, and generate a security alarm in a timely manner when an abnormal data frame is found, informing the security management personnel to conduct relevant threat investigations, and can realize real-time detection and real-time alarm of wireless attack data frames.

[0032] 3. The method for detecting wireless protocol attacks based on timestamp values provided by the present invention does not rely on traditional authentication mechanisms, and can effectively prevent the vulnerabilities of relevant authentication mechanisms and algorithms.

[0033] 4. The method for detecting wireless protocol attacks based on timestamp values provided by the present invention does not rely on third-party detection devices, and can be completed by using the wireless devices in the wireless communication system, and has good compatibility. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention, and do not constitute an improper limitation to the present invention. In the drawings:

[0035] Figure 1 It is a flowchart of the method for detecting wireless protocol attacks based on timestamp values in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] For the convenience of clearly describing the technical solutions of the embodiments of the present invention, in the embodiments of the present invention, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. For example, the first threshold and the second threshold are only used to distinguish different thresholds, and do not limit their sequence. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and the terms such as "first" and "second" do not necessarily mean different.

[0037] It should be noted that in the present invention, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.

[0038] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. The following "at least one (item)" or its similar expressions refer to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b or c may represent: a, b, c, the combination of a and b, the combination of a and c, the combination of b and c, or the combination of a, b and c, where a, b and c may be single or multiple.

[0039] Wireless protocol attacks have the characteristics of strong concealment and low occupation of wireless spectrum resources. They can cause wireless networks to be paralyzed and are not easy to be discovered. They have strong destructive power on wireless local area networks in various civil, commercial and military application scenarios. Aiming at the characteristics of wireless protocol attacks, the present invention proposes a wireless protocol attack detection method based on timestamp value, which is applicable to wireless local area networks based on TDMA time division scheduling access mechanism, including wireless communication standards (WirelessHART) in the field of industrial wireless networks, wireless network systems (Wireless Networks for Industrial Automation Process Automation, WIA-PA), (Wireless Intelligent Actuator Interface for Home Automation, WIA-FA), etc., and also applicable to other wireless technology protocols, such as WIFI, Bluetooth protocol, etc., based on media access control (Media Access Control, MAC) layer message transformation, to realize wireless protocol attack detection, can quickly discover wireless protocol attack messages and generate security alarms in time.

[0040] In a first aspect, the present invention provides a wireless protocol attack detection method based on timestamp value, see Figure 1 , applied to a wireless communication system, the wireless communication system includes a plurality of wireless communication devices, each of which has a timer; the wireless protocol attack detection method includes the following steps:

[0041] S10. Start the wireless communication system and periodically broadcast the time synchronization frame through the network manager to synchronize the clock of the timer of each wireless communication device.

[0042] As an example, the network manager may be a gateway / access (AC) controller, the wireless communication device may be one of a gateway / AC controller, a wireless AP, and a node, each wireless communication device may have a timer, the timer is 64 bits, and the gateway / AC controller or the wireless AP is used as the clock source for the entire network, and the clock source for the entire network is unique. The operation of starting the wireless communication system includes but is not limited to starting the timer; the periodic broadcast of the time synchronization frame is implemented through the gateway / AC controller.

[0043] S11. Each wireless communication device constructs a link frame at the data link layer and reserves a timestamp position on the link frame.

[0044] As a possible implementation manner, the link frame includes all types of frames in the wireless communication system; the reserved timestamp position may be a frame head or a frame tail, which is not limited here.

[0045] As an example, the link frame at least includes a Beacon frame, an ACK frame, a management frame, or a control frame.

[0046] S12. Before sending the link frame, add a timestamp value to the timestamp position; the timestamp value is the time of the current moment of the timer.

[0047] As a possible implementation, add a timestamp value to the link frame by the following method: through software configured with a timestamp value addition program, or, add a timestamp value through a radio baseband chip.

[0048] As an example, the frame format of the link frame is shown in Table 1:

[0049] Table 1 Frame format of the link frame

[0050]

[0051] S13. Encrypt each link frame with a timestamp value using a key and an encryption algorithm. The plaintext range for encryption at least includes the timestamp value, the sequence number, and the upper-layer service data.

[0052] As a possible implementation, the plaintext range for encryption at least includes the timestamp value, the sequence number, and the upper-layer service data. The service data is the data that needs to be transmitted in wireless communication; by increasing the encryption variable, such as the sequence number, the detection accuracy can be improved and the false detection rate can be reduced. The key used to encrypt each link frame with a timestamp value is updated according to a preset period, and the period is greater than or equal to half an hour and less than or equal to one day.

[0053] As a possible implementation, use a block encryption method to encrypt each link frame with a timestamp value. The block encryption method at least includes the SM4 algorithm or the AES algorithm, and the block encryption algorithm is updated periodically.

[0054] As an example, the frame format after encryption is shown in Table 2:

[0055] Table 2 Frame format after encryption

[0056]

[0057] S14. Send the encrypted link frame with a timestamp value to the corresponding wireless communication device through the wireless air interface.

[0058] As a possible implementation, the timestamp value of the link frame sent by each wireless communication device increases continuously; the sequence number of the link frame sent by each wireless communication device increases continuously or flips.

[0059] After the wireless communication device receives an encrypted link frame with a timestamp value, it decrypts the ciphertext using the key. After decryption, it verifies the legality of the link frame using the sequence number, transmission time slot, source / destination address, and timestamp value.

[0060] As a possible implementation, when it is determined that the sequence number corresponding to the current link frame is the same as the sequence number corresponding to the previous link frame, and / or when it is determined that the timestamp value corresponding to the current link frame is the same as the timestamp value corresponding to the previous link frame, a security alert is generated.

[0061] As a possible implementation, verifying the legality of the link frame using the sequence number and / or timestamp value specifically includes:

[0062] When it is determined that the timestamp value is after the current time, or when it is determined that the timestamp value is before the current time, or the timestamp value does not belong to the current time slot number, a security alert is generated; or,

[0063] When it is determined that the timestamp value and the sequence number do not conform to the wireless protocol, a security alert is generated.

[0064] As a possible implementation, the following method is used to determine whether the timestamp value and the sequence number conform to the wireless protocol:

[0065] Determine whether the link frame is sent within the specified source address and transmission time slot. If so, the timestamp value and the sequence number conform to the wireless protocol; otherwise, they do not conform to the wireless protocol.

[0066] As a possible implementation, the transmission time slot is a pre-allocated transmission time slot.

[0067] The timestamp value of the link frame sent by the wireless communication device is continuously increasing. The timestamp value and the sequence number are encrypted by an encryption algorithm. If an attacker eavesdrops and changes one or several bits of the data and then launches an attack, the sequence number and the timestamp value will surely not conform to the protocol logic. Especially in a TDMA time division system, if the receiving device determines that the data is not sent from its specified source address and the pre-allocated transmission time slot, it is determined as attack data and a security alert is generated.

[0068] The method of the present invention does not rely on traditional authentication mechanisms and can effectively prevent the vulnerabilities of related authentication mechanisms and algorithms. Since the wireless packets detected and sniffed by the attacker in the air are all ciphertext, it cannot simulate or guess the reasonable values of the timestamp value and the sequence number of the next frame of data. Therefore, the attack data sent by the attacker will be detected.

[0069] Second aspect, the present invention further provides a wireless protocol attack detection system based on timestamp values. The wireless protocol attack detection system is applied to a wireless communication system, which includes a plurality of wireless communication devices, and each wireless communication device has a timer. The wireless protocol attack detection system executes the wireless protocol attack detection method provided in the first aspect.

[0070] Third aspect, the present invention further provides a chip, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the wireless protocol attack detection method based on timestamp values provided in the first aspect.

[0071] Fourth aspect, the present invention further provides a terminal, including a processor and a communication interface coupled to the processor; the processor is used to run a computer program or instruction to implement the wireless protocol attack detection method based on timestamp values provided in the first aspect.

[0072] Compared with the prior art, the present invention has the following technical effects:

[0073] 1. The wireless protocol attack detection method based on timestamp values provided by the present invention enables each link frame to have a timestamp value and encrypts each link frame with a timestamp value. Therefore, the wireless packets detected and sniffed in the air by the listener are all ciphertext, and it is impossible for it to simulate or guess the timestamp value of the next frame of data, which can ensure that the attack data sent by the attacker will be detected, and the detection accuracy is high.

[0074] 2. The wireless protocol attack detection method based on timestamp values provided by the present invention, when the wireless communication system is operating normally, the wireless access point and wireless node devices will verify all received data frames, and generate a security alarm in time when an abnormal data frame is found, informing the security management personnel to conduct relevant threat investigations, and can realize the real-time detection and real-time alarm of wireless attack data frames.

[0075] 3. The wireless protocol attack detection method based on timestamp values provided by the present invention does not rely on traditional authentication mechanisms and can effectively prevent the vulnerabilities of relevant authentication mechanisms and algorithms.

[0076] 4. The wireless protocol attack detection method based on timestamp values provided by the present invention does not rely on third-party detection devices and can be completed by using the wireless devices in the wireless communication system, and has good compatibility.

[0077] Although the present invention has been described in connection with the various embodiments, however, in the process of implementing the claimed invention, those skilled in the art can understand and achieve other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality. A single processor or other unit may implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0078] Although the present invention has been described in connection with specific features and their embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of the present invention. Accordingly, the present specification and the drawings are merely exemplary illustrations of the present invention defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present invention. Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A wireless protocol attack detection method based on timestamp value, characterized in that: The wireless protocol attack detection method is applied to a wireless communication system, wherein the wireless communication system includes a plurality of wireless communication devices, each of which has a timer; the wireless protocol attack detection method includes the following steps: S10 starts the wireless communication system and periodically broadcasts a time synchronization frame through the network manager so that each wireless communication device has a timer to achieve clock synchronization; S11. Each wireless communication device completes the link frame construction at the data link layer and reserves a timestamp position on the link frame; S12 before sending the link frame, the timestamp value is added to the timestamp position; the timestamp value is the current time of the timer; S13. Encrypt each of the link frames having a timestamp value using a key and an encryption algorithm, wherein the encrypted plaintext range includes at least a timestamp value, a sequence number, and upper-layer service data; encrypt each of the link frames having a timestamp value using a packet encryption method, wherein the packet encryption method includes at least an SM4 algorithm or an AES algorithm and the packet encryption algorithm is periodically updated; S14. Send the encrypted link frame with the timestamp value to the corresponding wireless communication device through the wireless air interface, and the timestamp value of the link frame sent by each wireless communication device is continuously increasing; the sequence number of the link frame sent by each wireless communication device is continuously increasing or flipping; S15. After receiving the encrypted link frame with a timestamp value, the wireless communication device uses the key to decrypt the ciphertext. After decryption, the legitimacy of the link frame is verified using the sequence number, the sending time slot, the source / destination address, and the timestamp value; when it is determined that the sequence number corresponding to the current link frame is the same as the sequence number corresponding to the previous link frame, and / or when it is determined that the timestamp value corresponding to the current link frame is the same as the timestamp value corresponding to the previous link frame, a security alarm is generated; when it is determined that the timestamp value is after the current time, or when it is determined that the timestamp value is before the current time, or when the timestamp value does not belong to the current timeslot number, a security alarm is generated; or when it is determined that the timestamp value and the sequence number do not comply with the wireless protocol, a security alarm is generated; Determine whether the timestamp value and the sequence number conform to the wireless protocol by the following method: It is determined whether the link frame is sent out within the specified source address and sending time slot. If so, the timestamp value sequence number complies with the wireless protocol; otherwise, it does not comply with the wireless protocol.

2. The wireless protocol attack detection method based on timestamp value according to claim 1 is characterized in that: The transmission time slot is a pre-allocated transmission time slot.

3. The wireless protocol attack detection method based on timestamp value according to claim 1 is characterized in that: In S13, the key used to encrypt each link frame having a timestamp value is updated according to a preset period.

4. The wireless protocol attack detection method based on timestamp value according to claim 1 is characterized in that: In S12, a timestamp value is added to the link frame specifically by the following method: The timestamp value can be added by configuring software with a timestamp value adding program, or by the wireless baseband chip.

5. The wireless protocol attack detection method based on timestamp value according to claim 1 is characterized in that: The link frame includes at least a Beacon frame, an ACK frame, a management frame or a control frame.

Citation Information

Patent Citations

  • A method for measuring relative time delay of data service in optical transmitting network

    CN101336520A

  • Wireless network attack immune method based on frame sequence feature analysis and terminal device

    CN106535175A

  • Security reinforcement method for Modbus TCP protocol

    CN113824705A