Power Line Communication (PLC) Denial of Service Attacks

By introducing custom preamble and priority resolution symbols in the PLC network, the denial of service attack problem in the PLC network is solved, communication continuity and security are ensured, and hardware changes are avoided.

CN119366117BActive Publication Date: 2025-09-05QUALCOMM INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380046593.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-06-21
Filing Date
2023-05-04
Publication Date
2025-09-05
Estimated Expiration
2043-05-04

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively mitigate denial-of-service attacks in power line communication (PLC) networks, resulting in communication disruptions and potentially dangerous power conditions.

Method used

By introducing custom preambles and priority resolution symbols in the PLC network, countermeasures are activated to identify and filter denial of service attacks, adjusting the CSMA mechanism and priority contention mechanism to ignore transmissions that do not conform to the custom preamble or symbol.

Benefits of technology

Effectively mitigate denial-of-service attacks, ensuring continuity of PLC network communications, avoiding charging interruptions and hazardous power conditions without requiring significant hardware changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119366117B_ABST
    Figure CN119366117B_ABST
Patent Text Reader

Abstract

The present disclosure provides systems, methods, and apparatus for mitigating denial of service attacks on a power line communication (PLC) network, including a computer program encoded on a computer storage medium. When one or more transmissions associated with a denial of service attack are injected onto a communication medium, a first node of the PLC network can activate a countermeasure that enables the PLC network (including a first node and a second node) to continue communicating. The present disclosure includes several techniques for detecting denial of service attacks and several countermeasures that can be implemented. For example, one countermeasure may include using a custom preamble or a custom priority resolution symbol specific to the PLC network. The first node and the second node may ignore transmissions that do not conform to the custom preamble or the custom priority resolution symbol.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references

[0002] This patent application claims the benefit of U.S. patent application No. 17 / 808,105, filed by SUBRAMANIAN et al. on June 21, 2022, entitled “POWERLINE COMMUNICATION (PLC) DENIAL OF SERVICE ATTACK,” which has been assigned to the assignee of this application and is hereby expressly incorporated herein by reference. Technical Field

[0003] Generally speaking, the present disclosure relates to power line communication (PLC) and mitigation of denial of service attacks on PLC networks. Background Art

[0004] A communication system typically includes two or more nodes configured to communicate via a communication medium. A power line communication (PLC) network is an example of a communication system in which the communication medium includes a wired communication medium. PLC systems are well suited for certain applications, such as when a wired communication medium is required to support power delivery and communication. For example, a charging station (sometimes referred to as electric vehicle supply equipment or EVSE) can utilize a PLC network for power delivery and communication with an electric vehicle (EV). The PLC standard specification can describe the messages, protocols, and timing for communication in a PLC network. Recently, denial of service attacks have emerged that are associated with documented features that utilize the PLC standard specification. In some cases, a denial of service attack may be designed to disrupt PLC network communications between an EVSE and an EV. Without technology to mitigate denial of service attacks, a denial of service attack may prevent an EV from charging or cause a dangerous power condition. Summary of the Invention

[0005] The systems, methods and devices of the disclosure each have several innovative aspects, no single one of which is solely responsible for the desirable attributes of the disclosure.

[0006] One innovative aspect of the subject matter described in the present disclosure can be implemented using a method of a first node in a power line communication (PLC) network. The method can include establishing the PLC network via a communication medium. The PLC network can include at least a first node and a second node. The method can include negotiating a custom preamble for the PLC network. The method can include activating a countermeasure in the PLC network associated with a denial of service attack, the denial of service attack being associated with one or more transmissions injected onto the communication medium to disrupt PLC network communications. Activating the countermeasure can include utilizing the custom preamble for PLC network communications between the first node and the second node.

[0007] In some implementations, the method may include processing at least a first transmission of the one or more transmissions in association with a PLC frame format of a PLC standard specification. The method may include activating the countermeasure when the first transmission includes a first portion that complies with the PLC standard specification and a second portion that conflicts with the PLC standard specification.

[0008] In some implementations, the PLC network may be associated with a PLC standard specification that specifies the operation of the PLC network. The PLC standard specification may include a standard carrier sense multiple access (CSMA) mechanism, wherein a first node or a second node refrains from communicating via the communication medium during a backoff period after observing a communication having a standard preamble. The method may include utilizing a custom CSMA mechanism associated with a modification of the standard CSMA mechanism, wherein the custom CSMA mechanism includes monitoring for the custom preamble instead of the standard preamble.

[0009] In some implementations, activating the countermeasure includes transmitting a preamble change indication to a central node of the PLC network to cause the central node to instruct one or more other nodes in one or more corresponding PLC networks to use the custom preamble.

[0010] Another innovative aspect of the subject matter described in the present disclosure can be implemented using a first node for use in a PLC network. The first node may include a communication unit configured to establish a PLC network via a communication medium, the PLC network including at least a first node and a second node. The first node may include a processor communicatively coupled to the communication unit. The processor may be configured to: negotiate a custom preamble for the PLC network; and activate a countermeasure in the PLC network associated with a denial of service attack, the denial of service attack being associated with one or more transmissions injected onto the communication medium to disrupt PLC network communications. The communication unit may be configured to: utilize the custom preamble for PLC network communications between the first node and the second node when the countermeasure is activated.

[0011] Another innovative aspect of the subject matter described in the present disclosure can be implemented using a method of a first node in a PLC network. The method can include establishing a PLC network via a communications medium, the PLC network comprising at least a first node and a second node. The method can include negotiating a custom priority resolution symbol for use with the PLC network. The method can include activating a countermeasure in the PLC network associated with a denial of service attack associated with one or more transmissions injected onto the communications medium to disrupt PLC network communications. Activating the countermeasure can include utilizing the custom priority resolution symbol for priority contention in the PLC network communications.

[0012] In the accompanying drawings and the following description, details of one or more implementations of the subject matter described in this disclosure are set forth. Other features, aspects, and advantages will become apparent from the description, drawings, and claims. It should be noted that the relative dimensions in the following drawings are not depicted to scale. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 An exemplary power line communication (PLC) system and an exemplary denial of service attack are described.

[0014] Figure 2A An exemplary medium access control (MAC) protocol data unit (MPDU) frame format is shown.

[0015] Figure 2B An exemplary physical layer (PHY) protocol data unit (PPDU) frame format is shown.

[0016] Figure 3 An exemplary carrier sense multiple access (CSMA) mechanism is shown.

[0017] Figure 4 An exemplary denial of service attack utilizing the CSMA mechanism is shown.

[0018] Figure 5 An example marker for a denial of service attack based on processing PPDU frames is shown.

[0019] Figure 6 An example marker for a denial of service attack based on processing MPDU frames is shown.

[0020] Figure 7 Shows example markers for a denial of service attack based on the history of activity on the communication medium.

[0021] Figure 8 An example process for implementing countermeasures associated with multiple indicia of a denial of service attack is shown.

[0022] Figure 9 A timing diagram showing the activation of an example countermeasure in association with a denial of service attack is shown.

[0023] Figure 10 An exemplary charging station is described that includes a plurality of electric vehicle supply equipment (EVSE) for charging a corresponding plurality of electric vehicles (EVs).

[0024] Figure 11 A timing diagram showing the activation of an example countermeasure associated with central node participation and a denial of service attack.

[0025] Figure 12 An exemplary preamble change indication is shown.

[0026] Figure 13 An exemplary priority contention mechanism is shown.

[0027] Figure 14 An exemplary denial of service attack that exploits a priority contention mechanism is shown.

[0028] Figure 15 A flow chart is described for activating example countermeasures in association with a denial of service attack and an overwrite condition.

[0029] Figure 16 Exemplary coverage conditions are shown.

[0030] Figure 17 A block diagram conceptually illustrating an example node capable of implementing countermeasures is shown.

[0031] Figure 18 A flowchart illustrating an example process for mitigating a denial of service attack is shown.

[0032] Figure 19 A flowchart illustrating another example process for mitigating a denial of service attack is shown.

[0033] Figure 20 According to some implementations, a block diagram of an example apparatus that supports countermeasures associated with denial of service attacks is shown.

[0034] Figure 21 Shows an example custom preamble compared to a standard preamble.

[0035] Figure 22 The partial frequency / phase configuration of an exemplary custom preamble is shown compared to the partial frequency / phase configuration of a standard preamble.

[0036] Like reference numbers and designations throughout the various drawings represent like elements. DETAILED DESCRIPTION

[0037] To illustrate the innovative aspects of the present disclosure, the following description is directed to certain implementations. However, one of ordinary skill in the art will readily recognize that the teachings herein can be applied in a variety of different ways. Some examples in the present disclosure are based on power line communication (PLC) standards. Examples of such PLC standards may include Examples include the Green Physical Layer (PHY) specification, the International Standards Organization (ISO) 15118, the Society of Automotive Engineering (SAE) J1772, the International Electrotechnical Commission (IEC) 61851-1, and the German Institute for Standardization (DIN) 70121. However, the described embodiments may be implemented in any device, system, or network capable of transmitting and receiving radio frequency signals in accordance with any wired or wireless communication standard, including any of the following: Institute of Electrical and Electronics Engineers (IEEE) wired or wireless standards (e.g., 802.3 or IEEE 802.11), IEEE 1901, Third Generation Partnership Project (3GPP) wireless standards, and Standards, etc.

[0038] A power line communication (PLC) network may include multiple nodes that communicate via a communication medium, wherein the communication medium includes a power line. For example, the first node may be an electric vehicle (EV) and the second node may be an electric vehicle supply equipment (EVSE). To support vehicle charging, the EV and the EVSE may be coupled via a cable and a connector. At one end of the cable, a first connector may be connected to the vehicle socket of the EV. At the other end of the cable, a second connector (sometimes called a plug) may be connected to the socket of the EVSE. The cable may be used to deliver power from the EVSE to the EV. The EVSE and the EV may form a PLC network via the communication medium in the cable. The PLC network may operate according to a set of protocols and messages to create a PLC network and manage communications. These communications may be used to exchange information about power transmission, billing, or charging status, among other things.

[0039] PLC is well-suited to supporting communications between EVs and EVSEs. However, the wired communications medium has the potential to act as an antenna, potentially injecting interference and external signals onto the communications medium. PLC networks implement noise cancellation, security protocols, and robust coding to overcome the presence of noise and benign signals on the communications medium. However, traditional techniques may not be sufficient to prevent or mitigate denial-of-service attacks, in which transmissions are injected onto the communications medium to disrupt PLC network communications. For example, transmissions can be formatted to mimic PLC network communications. These transmissions can utilize carrier sense multiple access (CSMA) mechanisms or the priority contention mechanisms of the PLC network. Traditional techniques for protecting the communications medium from such attacks may be insufficient or prohibitively expensive.

[0040] The present disclosure provides systems, methods, and apparatus for mitigating denial of service attacks in power line communication (PLC) networks. When one or more transmissions associated with a denial of service attack are injected onto a communication medium, a first node of the PLC network can activate countermeasures that enable the PLC network (including the first node and the second node) to continue communicating. The present disclosure includes several techniques for detecting or identifying a denial of service attack and several countermeasures that can be implemented. For example, the countermeasures can include using a custom preamble or custom priority resolution symbol specific to the PLC network. The custom preamble or custom priority resolution symbol may be known to the first node and the second node of the PLC network, but unknown to the attacking node. The first node and the second node can ignore transmissions that do not conform to the custom preamble or the custom priority resolution symbol. In several examples of the present disclosure, the first node can be an EV or EVSE, and the second node can be another of the EV or EVSEs. Additionally, the first node or the second node can be a central node that manages multiple PLC networks associated with corresponding EVSE-EV associations.

[0041] In some aspects, a denial of service attack may include one or more transmissions that are at least partially formatted to comply with PLC standard specifications. For example, a transmission may include a first part (e.g., a part of a standard preamble) that complies with the PLC standard specifications and a second part that conflicts with the PLC standard specifications. A node may process one or more transmissions according to the PLC frame format to identify a failure indicating that a transmission is associated with a denial of service attack. The failure may include an invalid or omitted part relative to the PLC frame format in the transmission. For example, the transmission may include a preamble but omit a frame control (FC) part or a payload part. In another example, the transmission may include an invalid value in the FC part, such as an invalid beacon timestamp, an invalid media access control (MAC) frame flow state, or an invalid payload part, etc. In some implementations, a node may identify or detect a denial of service attack when the communication medium has a history of a CSMA busy condition, priority contention failure, or abnormal congestion, etc.

[0042] Some denial-of-service attacks are based on the repeated injection of preamble signals. For example, an attacking node could repeatedly inject a standard preamble onto the communication medium to make it appear busy. Because PLC networks use CSMA to check for a clear communication medium before communicating, the injected preamble could cause the node to back off and avoid communicating via the communication medium. In some aspects, a node could activate a custom preamble that is different from the standard preamble. The node could then ignore the standard preamble for CSMA clear channel assessment purposes and instead use the custom preamble when performing CSMA clear channel assessment.

[0043] In some aspects, the countermeasures may include ignoring or filtering one or more transmissions associated with the denial of service attack. For example, a node may generate correlation data associated with one or more transmissions of the denial of service attack. The correlation data describes the amplitude, phase, signal strength, or any combination thereof of at least a portion of the one or more transmissions. The node may adjust the physical (PHY) layer of its communication unit to ignore subsequent transmissions that match the correlation data. In some implementations, the node may adjust the PHY layer to filter out one or more transmissions of the denial of service attack (e.g., it will filter out noise).

[0044] In some aspects, a node may activate a countermeasure by transmitting a preamble change indication. The preamble change indication may indicate that one or more other nodes use a custom preamble for PLC network communications. In some implementations, the node may transmit a preamble change indication in a management message entry (MME) frame or an application layer protocol message. Alternatively or additionally, the node may transmit a pulse width modulation (PWM) signal having a specific duty cycle or sequence associated with the preamble change indication. In some implementations, the node may transmit the preamble change indication to a central node so that the central node indicates that one or more other nodes of one or more corresponding PLC networks use a custom preamble.

[0045] In some aspects, nodes of a PLC network may activate countermeasures to mitigate denial of service attacks based on priority contention. Typically, nodes of a PLC network will use a priority contention mechanism in which a node signals its priority during a priority resolution slot (PRS). Traditionally, the priority contention mechanism uses a standard priority resolution symbol, where the standard priority resolution symbol is based on a predetermined waveform sent during the PRS. An attacking node may attempt to exploit the priority contention mechanism by injecting a transmission that indicates that it has the highest priority using the standard priority resolution symbol. If a legitimate node of the PLC network does not also have the highest priority, the legitimate node of the PLC network may defer contention for access to the communication medium. When there is a denial of service attack, the legitimate node may modify the priority contention mechanism of the PLC network to use a custom priority resolution symbol (instead of the standard priority resolution symbol).

[0046] Specific implementations of the subject matter described in this disclosure may be implemented to achieve one or more of the following potential advantages. Nodes of a PLC network may mitigate denial of service attacks that might otherwise disrupt PLC network operation. In the case of EV charging, the PLC network between the EV and EVSE may remain active so that EV charging may continue without interrupting charging or creating potentially dangerous power conditions in the charging cable. Advantageously, the techniques of this disclosure may be implemented with little or no changes to cables, connectors, or other expensive components associated with modifying the EV or EVSE hardware to mitigate denial of service attacks. Some aspects of this disclosure may facilitate rapid utilization of charging stations by leveraging denial of service countermeasures of existing infrastructure.

[0047] Figure 1 An exemplary power line communication (PLC) system 100 and an exemplary denial of service attack are described. The exemplary PLC system 100 includes a first node 110 and a second node 120. For example, the first node 110 may be associated with an EVSE 102. The second node 120 may be associated with an EV 104. The EVSE 102 may include an outlet 106. The EV 104 may include a vehicle outlet 108. A cable 125 may include a plug (not shown) on one end that is configured to connect to the outlet 106. The cable 125 may also include a connector (not shown) on the other end that is configured to connect to the vehicle outlet 108. The type of connector used for the cable 125 may vary depending on the geographic / regional standards of the charging station, the manufacturer of the EV 104, the charging station operator, and the like. The cable 125 may include a communication medium 115 and other conductors for transmitting power from the EVSE 102 to the EV 104. When the EVSE 102 is connected to the EV 104 via the cable 125, the first node 110 of the EVSE 102 may communicate with the second node 120 of the EV 104 using the communication medium 115. The first node 110, the communication medium 115, and the second node 120 may be referred to as a PLC network 190.

[0048] The first node 110 may include a processor 118 and a communication unit 114. The communication unit 114 may include a transceiver (or separate transmitter and receiver components) for sending and receiving communications via a communication medium 115. The processor 118 may control the communication unit 114 and manage settings such as PLC frame processing, CSMA mechanisms, priority contention mechanisms, or other configurations used by the communication unit 114 to communicate with a corresponding communication unit 124 of the second node 120. Similar to the first node 110, the second node 120 may include a communication unit 124 and a processor 128.

[0049] The PLC network 190 may operate in accordance with a PLC standard specification. An exemplary PLC standard specification may be Green PHY Specification. The PLC standard specification may specify standard operation of the PLC network 190, including the format, content, and protocol of messages between nodes of the PLC network. The PLC standard specification may also specify contention procedures such as CSMA with collision avoidance (CSMA / CA), CSMA with collision detection (CSMA / CD), or priority contention mechanisms. In some implementations, the PLC standard specification specifies standard preamble symbols, standard priority resolution symbols, or other specified sequences.

[0050] Nodes of the PLC network 190 (e.g., the first node 110 and the second node 120) communicate by sending or receiving signals via the communication medium 115. While the PLC standard specification may define protocols to secure communications between nodes of the PLC network 190, a denial of service attack may be designed to interfere with or otherwise disrupt the ability of a node to utilize the communication medium 115. For example, a denial of service attack may be designed to make the communication medium 115 appear congested with PLC network communications in an attempt to prevent the first node 110 or the second node 120 from accessing the communication medium 115 during the period of time during which the denial of service attack is active. Figure 1 An exemplary denial of service attack is shown in which an attacking node 130 sends one or more transmissions 155 injected onto the communication medium 115. Because the communication medium 115 is a conductive material, it can act as an antenna capable of receiving radio frequency transmissions (e.g., one or more transmissions 155 from the attacking node 130). It should be noted that the techniques of this disclosure are not limited to attacks utilizing radio frequency transmissions, but rather mitigate denial of service attacks from an attacking node (not shown) that has a wired connection to the power line (not shown) of the EVSE 102.

[0051] exist Figure 1In the example shown, the attacking node 130 may include an antenna 136, a transmitter 134, and a processor 138. The processor 138 may implement at least a portion of the PLC standard specification so that one or more transmissions 155 may simulate PLC network communications. For example, the one or more transmissions 155 may include at least a first portion of a PLC frame format (e.g., at least a portion of a standard preamble or frame control (FC) field). In some implementations, the PLC frame format may be a physical layer protocol data unit (PPDU) frame format. Alternatively or additionally, the one or more transmissions 155 may include an invalid media access control (MAC) protocol data unit (MDPU) transmitted within an otherwise valid PPDU. According to the standard CSMA mechanism of the PLC network 190, the first node 110 or the second node 120 (or both) may avoid communicating via the communication medium 115 during a backoff period after observing a communication having at least the first portion of the PLC frame format. Thus, the attacking node 130 can exploit the standard CSMA mechanism by causing the first node 110 or the second node 120 (or both) to interpret one or more transmissions 155 as PLC network communications. Without the techniques of the present disclosure, the attacking node 130 can continuously inject one or more transmissions 155 to prevent the first node 110 or the second node (or both) from gaining access to the communication medium 115.

[0052] Figure 2A An exemplary MPDU frame format 201 is shown. The exemplary MPDU frame format 201 may be one of various types of MPDU frame formats specified by the standard PLC specification. The exemplary MPDU frame format 201 may include a frame control block 210 and an MPDU payload 220. The MPDU payload 220 may convey transport layer or application layer data from the EVSE to the EV, or vice versa. The MPDU may also be referred to as a packet. The frame control block 210 includes frame control information 230. In some implementations, the frame control information 230 may be partially incorporated into a variant field (not shown) of the frame control (FC) field of the PPDU (e.g., as Figure 2B The MPDU payload 220 may include a MAC header (not shown) and a MAC service data unit (MSDU, not shown). The MPDU payload 220 may also be referred to as a packet.

[0053] Figure 2BAn exemplary PPDU frame format 202 is shown. The exemplary PPDU frame format 202 may be one of various types of PPDU frame formats specified by the standard PLC specification. The PPDU (sometimes also referred to as a frame) may be transmitted via the communication medium using orthogonal frequency division multiplexing (OFDM) symbols. In the present disclosure, the OFDM symbol may be referred to as a symbol or a waveform. The exemplary PPDU frame format 202 may include one or more preamble symbols (e.g., preamble 271), one or more frame control symbols (e.g., audio-visual (AV) frame control (FC) 272), and one or more payload symbols (e.g., payload symbols 273 and 274). Due to the historical development and backward compatibility of the PLC standard specification, the AF FC 272 may include "audio-visual", but the PLC standard specification is not limited to audio or visual information. For EV charging applications, the type of information conveyed by the PPDU (and the MPDU it carries) may be application data that is not related to audio or visual applications. For simplicity, the AV FC 272 may also be referred to as the frame control (FC) portion of the PPDU. The FC portion may include a symbol (e.g., Figure 2B ), or may span multiple symbols of other PLC frame formats defined by the PLC standard specification. Similarly, the preamble 271 may include a symbol (such as Figure 2B ), and may also span multiple symbols of other PLC frame formats defined by the PLC standard specification.

[0054] A PPDU ("frame") can carry an MPDU ("packet"). In some implementations, a portion of the MPDU frame control information can be conveyed via a variant field (not shown) of the AV FC 272. Without the techniques of the present disclosure, the preamble 271 may include standard preamble symbols defined by the PLC standard specification. In this case, the preamble 271 may be referred to as a standard preamble. The preamble 271 and the AV FC 272 may be collectively referred to as a delimiter 250. The AV FC 272 may include one or more fields (not shown), such as a contention control (CC) field, a delimiter type (DT) field, a variant field (VF) based on the delimiter type, and a frame control check sequence (FCCS). For example, the DT field may indicate whether the PPDU is a beacon, a start of frame (SOF), a selective acknowledgement (SAC), a request to send (RTS) / clear to send (CTS), a sounding frame, a reverse start of frame (RSOF), and the like. The format of the variant field (not shown) may differ based on the delimiter type.

[0055] Figure 3 An exemplary CSMA mechanism 300 is shown. A PLC network (e.g., Figure 1A PLC network 190) can utilize the CSMA mechanism to determine whether the communication medium is idle or busy. Under CSMA, a sending node uses a carrier sensing mechanism to determine whether another transmission is in progress before initiating a transmission. That is, a node attempts to detect the presence of a carrier signal from another node before attempting to transmit. If a carrier is sensed, the node waits for the ongoing transmission to end before starting its own transmission. Using CSMA, multiple nodes can transmit and receive on the same medium in sequence. A node's transmission is typically received by all other nodes connected to the communication medium. When the communication medium is busy, a node can avoid communicating and wait for a backoff period before checking the communication medium again.

[0056] Figure 3 An example CSMA mechanism 300 is shown for use by a first node 110 and a second node 120 of a PLC network. For clarity of illustration, the use of the communication medium is shown as separate timelines for the first node 110 and the second node 120; however, it should be understood that they are using the same communication medium. Figure 3 , the first node 110 may have data to transmit to the second node 120. At block 310, the first node 110 may sense the communication medium using a CSMA mechanism. For example, the first node 110 may observe the communication medium for any signal that matches a standard preamble. In some implementations, the process of observing the communication medium may be referred to as channel assessment (sometimes also referred to as clear channel assessment (CCA), energy detection, or carrier sensing, among other examples). The result of the channel assessment may be an idle state or a busy state. For example, an idle state may be the result when the first node 110 does not detect a PLC network communication on the communication medium. A busy state may be the result when the first node detects a PLC network communication. In a busy condition ( Figure 3 (not shown), the first node 110 may avoid communicating via the communication medium and wait for a backoff period before performing a subsequent channel assessment.

[0057] exist Figure 3 In the example shown, the first node 110 may determine at block 310 that the communication medium is idle (meaning that the first node 110 does not detect PLC network communications on the communication medium). The first node 110 may continue to transmit the PPDU (including the delimiter 320 and the payload 330) on the communication medium. At some point, the second node 120 may have data to communicate via the communication medium. At block 340, the second node 120 may perform a channel assessment and determine that the communication medium is idle, and may continue to transmit its PPDU (including the delimiter 350 and the payload 360).

[0058] Figure 4An exemplary denial of service attack 400 utilizing the CSMA mechanism is shown. Figure 3 Likewise, the communication medium has been illustrated using timelines of different nodes sharing the same communication medium. Figure 4 In FIG, first node 110 and second node 120 may be part of a PLC network utilizing a communication medium. A third node (referred to as attacking node 130) may inject one or more transmissions 455, 465, 475, and 485 onto the communication medium to cause a denial of service attack. Each of transmissions 455, 465, 475, and 485 may be formatted to include at least a portion of a PLC frame format. For example, transmissions 455, 465, 475, and 485 may include a portion of a delimiter. In some cases, transmissions 455, 465, 475, and 485 may include only a standard preamble (e.g., as described in reference to FIG). Figure 2B In some cases, transmissions 455, 465, 475, and 485 may omit or include other portions of the delimiter (e.g., as described in reference to Figure 2B FC symbols as described above). Transmissions 455, 465, 475, and 485 may omit or include payload symbols. In this exemplary denial of service attack, transmissions 455, 465, 475, and 485 include the standard preamble portion of the delimiter.

[0059] When the first node 110 performs the CSMA evaluation 410, without the techniques of the present disclosure, the first node 110 may determine that the communication medium is busy with PLC network communications (based on the presence of transmission 455). The first node 110 may avoid accessing the communication medium during the backoff period 412. After the backoff period 412, the first node 110 may again observe the communication medium for a CSMA evaluation 420 and again determine that the communication medium is busy (this time based on the presence of transmission 465). The attacking node 130 may continuously inject transmissions 455, 465, 475, and 487 onto the communication medium such that each time the first node 110 performs a CSMA evaluation 410, 420, 430, and 440, the first node may determine that the communication medium is busy and avoid accessing the communication medium during the corresponding backoff periods 412, 422, 432, and so on. Although Figure 4 The first node 110 is shown attempting to access the communication medium, but the second node 120 may also have data to transmit and may similarly be blocked from accessing the communication medium based on a CSMA evaluation (not shown) that it performs.

[0060] In the case where the first node 110 and the second node 120 are an EVSE and an EV, respectively, the inability to communicate over the communication medium may interrupt the power transfer session. For example, a node (e.g., an EVSE or an EV) may be configured to terminate the power transfer session after a timeout period if it does not receive communications (e.g., charging status, power control messages, or keep-alive communications) from the other node (e.g., an EV or an EVSE). A denial of service attack may exploit the CSMA mechanism of the PLC network to prevent the EVSE and the EV from communicating for a duration exceeding the timeout period.

[0061] According to aspects of the present disclosure, the first node 110, the second node 120, the central node (not shown), or any combination thereof may activate countermeasures in the PLC network to mitigate denial of service attacks, e.g. Figure 4 Examples shown. In some implementations, countermeasures associated with a denial of service attack can be activated. For example, as part of establishing a PLC network, the countermeasures can be activated to render the denial of service attack inoperable. Alternatively or additionally, the countermeasures can be activated based on the detection of a denial of service attack. The present disclosure includes several example markers for a denial of service attack. A node of the PLC network can process at least a portion of one or more transmissions (e.g., transmissions 455, 465, 475, and 485) to obtain an indication that the one or more transmissions are associated with a denial of service attack.

[0062] Figure 5An example indicia 500 of a denial of service attack based on processing a PPDU frame is shown. When a node (e.g., the first node 110 or the second node 120 described herein) receives a transmission, the node may attempt to process the transmission according to the PPDU frame format. For example, the PPDU frame format may be defined by the PLC standard specification. The PPDU frame format may specify one or more preamble symbols (e.g., preamble 271), one or more frame control (FC) symbols (e.g., AV FC 272), and one or more payload symbols 273 and 274. However, an attacking node may omit some or all of the standard portions of the specified PPDU frame format. When a transmission only partially conforms to the PPDU frame format, the node may detect a signature that indicates the transmission is associated with a denial of service attack. For example, the node may be unable to process the transmission according to the expected PLC frame format. Failure to process the transmission may occur due to one or more error conditions. In some implementations, a single error condition may be sufficient to determine that a transmission is associated with a denial of service attack. Alternatively or additionally, a denial of service attack may be associated with a number of error conditions exceeding a processing error threshold. In some implementations, the processing error threshold may be a fixed value. Alternatively or additionally, the processing error threshold may be a dynamic value based on the number of nodes in the PLC network. In another alternative, the processing error threshold may be a dynamic value based on a quality metric associated with the communication medium, such as a noise measurement, a signal-to-noise ratio (SNR), or an amount of interference, or the like. Figure 5 Shows some examples of error conditions that a node might encounter when attempting to process one or more transmissions associated with a denial of service attack.

[0063] In the first example 510, an error condition may occur when the preamble 271 is incomplete. For example, if a transmission includes only one preamble symbol, where the PPDU frame format defines two or more preamble symbols, the preamble 271 may be incomplete. Alternatively, the preamble 271 may be a symbol that includes a portion of a sequence associated with a standard preamble. After attempting to process a transmission, the node may count an error condition when the portion of the preamble 271 of the transmission is truncated or incomplete.

[0064] In the second example 520, an error condition may occur when the preamble 271 is confirmed to be a standard preamble, but the AV FC 272 is invalid. For example, the AF FC 272 may be omitted or truncated. Alternatively or additionally, the AV FC 272 may be invalid if it does not include one or more designated fields (e.g., CC, DT, variant field, or FCCS). In another example, the AV FC 272 may include an incorrect format for the variant field associated with the delimiter type indicated in the DT field of the AV FC 272.

[0065] In a third example 530, an error condition may occur when the AV FC 272 fails a cyclic redundancy check (CRC). For example, if the AV FC 272 is omitted or includes dummy data, the node may experience a CRC error when comparing the calculated CRC of the AV FC 272 to the FCCS of the AV FC 272. When the node processes the AV FC 272, the node will access the portion of the transmission where the FCCS of the AV FC 272 is expected to be sent. When the transmission omits the AV FC 272 or includes dummy data in the AF FC 272, the CRC will indicate an error. When a node experiences multiple CRC errors associated with corresponding multiple transmissions, the node may use a standard preamble followed by an invalid AV FC 272 portion to determine that the transmissions are associated with a denial of service attack.

[0066] In a fourth example 540, an error condition may occur when a transmission does not include a payload symbol following the preamble 271 and the AV FC 272. For example, an attacking node may repeatedly transmit the preamble 271 and the AV FC 272 without the payload symbol 273. When processing the transmission as a PPDU and determining that the payload symbols are omitted or invalid, the node may detect the error condition.

[0067] Figure 6 An example mark 600 of a denial of service attack based on processing MPDU frames is shown. Figure 2A and Figure 2B As described, the frame control block 210 of the MPDU can be incorporated into the AV FC portion of the PPDU. The PLC standard specification may specify the fields and valid values ​​of the AV FC portion. For example, the AV FC portion of the PPDU may indicate the delimiter type associated with the MPDU. Depending on the delimiter type, the AV FC portion of the PPDU may include a Variant field containing frame control information from the frame control block 210 of the MPDU. When a node processes the AV FC portion based on a specific delimiter type, the node may determine that some values ​​in the Variant field are invalid. Figure 6 Includes two examples where variant fields may contain invalid information.

[0068] In the first example 610, the delimiter type indicated in the AV FC portion may be a "start of frame" (SOF) type. When the delimiter type is SOF, the variant field of the AV FC portion is defined to include one or more MAC frame flow fields. For example, the variant field may include a management MAC frame flow command field, a data MAC frame flow command field, a management MAC frame flow response field, and a data MAC frame flow response field (collectively referred to as a MAC frame flow field).

[0069] The MAC frame flow field is used as part of the MAC framing process, in which a MAC frame can be generated from an MSDU and multiple MAC frames belonging to the same flow are concatenated into a MAC frame flow. Each MAC frame flow can be segmented into PHY blocks (PBs) for transmission via a PPDU. The PLC standard specification may specify how the MAC frame flow field operates. The MAC management MAC frame flow command and data MAC frame flow command fields include commands for the MAC frame flow from the sending node to enable the receiving node to reassemble the flow. The management MAC frame flow response and data MAC frame flow response fields include responses from the sending node regarding the data sent in the previous reverse SOF frame.

[0070] According to one aspect of the present disclosure, a node of a PLC network may track MAC frame flow states associated with MAC frame flow fields of one or more transmissions suspected of being associated with a denial of service attack. For example, when a management MAC frame flow response in a transmission does not correspond to an expected MAC frame flow state derived from a previous transmission, the node may increment a count of an error condition.

[0071] In the second example 620, the delimiter type indicated in the AV FC portion may be a "beacon" type. When the delimiter type is a beacon type, the MPDU payload may be expected to include a beacon timestamp (BTS). The BTS is a value based on the network time base (NTB). A node may observe the BTS by comparing it to one or more previous transmissions to verify that the BTS is increasing as expected based on the timing between transmissions. In some cases, a denial of service attack may include the same BTS value in consecutive transmissions, or may include dummy data in the BTS field of the MPDU payload. When the BTS value in one transmission is inconsistent with the expected BTS value associated with one or more previous BTS values ​​(in one or more previous beacon-type transmissions), the BTS value may be considered invalid. An invalid value for BTS may indicate an error condition and a sign of a denial of service attack.

[0072] Figure 6An example mark 630 of an invalid format based on MPDU frame processing is also shown. When a node detects a valid preamble and AV FC portion of a PPDU, the node can start a virtual carrier sense (VCS) timer. According to the PLC standard specification, the VCS timer is maintained by all nodes to improve the reliability of channel access during CSMA. The VCS timer is used to identify the expected CSMA state of the communication medium after a period of time. When a node detects a standard preamble, it can be configured to start a VCS timer to expire with the expected completion of the transmission including the standard preamble. In a denial of service attack, the attacking node can omit the payload portion of the transmission and repeatedly send the standard preamble and AV FC portion of the PPDU. According to the present disclosure, the node can monitor the communication medium during the VCS timer to confirm that the transmission continues for the expected duration associated with the PPDU frame type.

[0073] Figure 7 An example marker 700 of a denial of service attack based on a history of communication medium activity is shown. For reference, Figure 7 Include reference Figure 4 , 465, 475, and 487 are described as examples of denial of service attacks. The attacking node 130 may continuously inject transmissions 455, 465, 475, and 487 onto the communication medium, such that each time the first node 110 performs CSMA evaluations 410, 420, 430, and 440, the first node 110 may determine that the communication medium is busy (referred to as a busy condition) and avoid accessing the communication medium during the corresponding backoff periods 412, 422, 432, and so on. In the first example 710, the first node 110 may determine that the amount of busy conditions is above a busy threshold. For example, the first node 110 may maintain a counter that increments for each consecutive busy condition. After a threshold number of times, the first node 110 may determine that the multiple consecutive busy conditions are associated with a denial of service attack. Alternatively, in the second example 720, the first node 110 may maintain a timer that indicates how long the first node 110 has experienced a consecutive busy condition on the communication medium, resulting in a CSMA transmission failure. When the timer reaches the maximum time of consecutive CSMA transmission failures, the first node 110 may determine that the pattern of consecutive busy conditions is associated with a denial of service attack.

[0074] In a third example 730, first node 110 may compare one or more transmissions 455, 465, 475, and 485 to determine whether they are identical. In some cases, an attacking node may repeatedly transmit the same transmission (e.g., a standard preamble) such that one or more transmissions 455, 465, 475, and 485 include the same transmission format. First node 110 may determine that one or more transmissions 455, 465, 475, and 485 are associated with a denial of service attack based on the pattern that transmissions 455, 465, 475, and 485 are identical transmissions.

[0075] Figure 8 An example process 800 for implementing countermeasures associated with multiple indicia of a denial of service attack is shown. The operations of process 800 may be implemented by a node of a PLC network or any component thereof as described herein. In some implementations, the operations may be implemented by a communication unit of the node (e.g., a reference signaling module). Figure 1 14 or 124) described herein. Figure 1 、 3 , 4, 10, 11, 13, 14 or Figure 17 The process 800 may be performed by the first node 110, the second node 120, or the central node 150 described in any one of the preceding claims. In some implementations, the process 800 may be performed by an apparatus or a component thereof (e.g., a reference to Figure 20 For the sake of brevity, the example process 800 is described as being executable by an apparatus or component thereof that is any one of the nodes, communication units, or apparatuses described above.

[0076] At block 810, the apparatus may detect a transmission having a standard preamble during a CSMA evaluation of the communication medium. For example, the transmission (e.g., reference Figure 4 Any of the described transmissions 455, 465, 475, and 485) are formatted to include at least a standard preamble portion of the PPDU frame format.

[0077] At block 815, the device may determine whether the transmission has a valid FC portion. For example, the device may attempt to process the AV FC symbols of the transmission to determine whether the AV FC symbols are correctly formatted. Additionally or alternatively, the device may determine whether the FC portion of the transmission generates a CRC error indicating that the FC portion is invalid. If the transmission does not have a valid FC portion, the process may proceed to block 860 (indicated by reference numeral "A") associated with an error condition. Otherwise, the process may proceed to block 820.

[0078] At block 820, the device may determine whether the delimiter type field in the FC portion of the transmission indicates that the transmission is a beacon. If so, the process may proceed to block 825 to determine whether the BTS included in the transmission matches the expected BTS. The expected BTS may be derived based on previous BTS values ​​in previous beacon transmissions received by the device. If the BTS value in the transmission does not match the expected BTS value, the process may proceed to block 860 (indicated by reference numeral "A") associated with an error condition. Otherwise, if the BTS value matches the expected BTS value, the process may proceed to block 850 (indicated by reference numeral "B").

[0079] Returning to block 820, if the Delimiter Type field in the FC portion of the transmission does not indicate that the transmission is a beacon, the process may proceed to block 830. At block 830, the device may determine whether the Delimiter Type field in the FC portion of the transmission indicates whether the transmission is a Start of Frame (SOF) or a Reverse Direction Start of Frame (RSOF). If so, the process may proceed to block 835. At block 835, the device may determine whether the MAC Frame Flow field of the transmission matches an expected MAC Frame Flow State. The expected MAC Frame Flow State may be based on one or more previous transmissions. If the MAC Frame Flow field in the transmission does not match the expected MAC Frame Flow State, the process may proceed to block 860 (indicated by reference numeral "A") associated with an error condition. Otherwise, if the MAC Frame Flow field matches the expected MAC Frame Flow State, the process may proceed to block 840.

[0080] Returning to block 830 , if the delimiter type field in the FC portion of the transmission does not indicate that the transmission is a SOF or RSOF, the device may attempt to process the transmission using another type of delimiter. If the delimiter type in the FC portion of the transmission appears to be a valid type, the process may proceed to block 840 .

[0081] At block 840, the device may monitor the communication medium during the VCS timer to verify whether the transmission includes a payload. If the transmission does not include a payload, the process may proceed to block 860 associated with an error condition. If the transmission does include a payload, the process may proceed to block 850.

[0082] At block 850 (also indicated by reference numeral "B"), the device may increment a count of busy conditions. For example, a transmission may contain an expected portion of a valid transmission even though it is part of a denial of service attack. By counting the number of consecutive busy conditions, the device may obtain a signature of a denial of service attack.

[0083] At block 870, the device may compare the count of busy conditions to a busy threshold. The busy threshold may be a fixed value or a dynamic value. For example, the busy threshold may be a fixed value of five (5) consecutive CSMA busy conditions. At block 870, if the count of busy conditions is above the busy threshold, the process may proceed to block 890 to activate countermeasures associated with a denial of service attack. Alternatively, at block 870, if the count of busy conditions is below the busy threshold, the process may proceed to block 885. At block 885, the device may back off from the communication medium for a period of time and retry the CSMA evaluation after the back off timer.

[0084] Returning to block 860 (also indicated by reference numeral "A"), the device may process the error condition associated with any error condition detected in blocks 815, 825, or 835. At block 860, the device may increment a count of error conditions. At block 880, the device may compare the count of error conditions to a process error threshold. If the count of error conditions is above the process error threshold, the process may proceed to block 890 to activate countermeasures associated with a denial of service attack. Alternatively, at block 880, if the count of error conditions is below the process error threshold, the process may proceed to block 885. At block 885, the device may back off from the communication medium for a period of time and retry CSMA evaluation after the backoff timer.

[0085] Figure 5-7 Several techniques and markers are presented that enable a node to detect denial of service attacks associated with exploitation of the CSMA mechanism of a PLC network. Other techniques and markers can enable a node to detect denial of service attacks associated with other exploitation of a PLC network. For example, a denial of service attack might exploit the priority contention mechanism of a PLC, such as the one described in this paper. Figure 14 The exemplary denial of service attacks described herein are provided for illustrative purposes only, and the techniques of this disclosure can mitigate other types of denial of service attacks.

[0086] Countermeasures can be implemented to mitigate denial of service attacks. In some aspects, countermeasures can be implemented before a denial of service attack occurs, such that the countermeasures prevent or limit the effectiveness of the denial of service attack before it occurs in the communication medium. Alternatively or additionally, countermeasures can be activated in response to detecting a denial of service attack. This disclosure includes several example countermeasures that can be used to mitigate denial of service attacks.

[0087] Figure 9A timing diagram 900 is shown activating an example countermeasure in association with a denial of service attack. The timing diagram 900 illustrates a first node 110 and a second node 120 associated with a PLC network. The timing diagram 900 also illustrates an attacking node 130 attempting to attack the PLC network using a denial of service attack.

[0088] The first node 110 and the second node 120 may exchange messages 910 to establish a PLC network. For example, the first node 110 and the second node 120 may exchange probe messages, signal level measurements, association messages, or configuration messages, as well as other examples associated with establishing a PLC network including the first node 110 and the second node 120. In some implementations, the first node 110 and the second node 120 may establish a network encryption key (NEK), a network membership key (NMK), or both associated with the PLC network. In some implementations, the messages 910 establishing the PLC network may include messages associated with the Signal Level Attenuation Characteristic (SLAC) protocol of the PLC standard specification.

[0089] The first node 110 and the second node 120 may exchange messages 930 to negotiate a custom preamble. The custom preamble may be different from the standard preamble specified by the PLC standard specification. When the countermeasure is activated, the first node 110 and the second node 120 may ignore communications with the standard preamble and attempt to communicate via the communication medium using the custom preamble instead of the standard preamble. The custom preamble may be a sequence that is known to the first node 110 and the second node 120 but is unknown to the attacking node 130. The custom preamble may include one or more OFDM symbols configured to replace the standard preamble symbols. In some implementations, NEK or other secure messaging techniques may be used to encrypt the message 930 for negotiating the custom preamble. Additionally, the message 930 may be based on a modification of the SLAC protocol to include the negotiation of the custom preamble. The message 930 for negotiating the custom preamble may be exchanged at any time after the PLC network is established. For example, in a scenario such as Figure 9 In some implementations shown, messages 930 can be exchanged before a denial of service attack occurs. Alternatively or additionally, messages 930 can be exchanged after a denial of service attack is detected.

[0090] At some point, the attacking node 130 may send one or more transmissions 920 injected onto the communication medium. At block 940, the first node 110 may observe the transmissions 920 and detect indicia of a denial of service attack associated with the transmissions 920. Indicia of a denial of service attack may include reference to Figure 5-8 Any one or more of the examples described. Figure 9The first node 110 is shown detecting a denial of service attack, but it is apparent that the first node 110 or the second node 120 (or another node, not shown) can obtain indicia of a denial of service attack by monitoring transmissions 920 on the communication medium.

[0091] Return to Figure 9 For example, when the first node 110 detects a marker of a denial of service attack, the first node 110 may transmit a preamble change indication 952 to the second node 120. For example, by referring to Figure 12 The preamble change indication 952 may be transmitted by any of the examples described above. The preamble change indication 952 notifies the second node 120 that the first node 110 will use a custom preamble for subsequent PLC network communications 974. In some aspects, the preamble change indication 952 may be a message indicating that the first node 110 has detected a denial of service attack and is activating countermeasures associated with the denial of service attack. Figure 9 In the example of , the countermeasure includes using a custom preamble. In some implementations, the second node 120 can respond to the preamble change indication 952 by transmitting an acknowledgment 954 to the first node.

[0092] At block 962, the first node 110 may configure its communication unit to ignore communications associated with the standard preamble when performing CSMA evaluation. Furthermore, the first node 110 may configure its communication unit to use the custom preamble for subsequent CSMA evaluations, for sending subsequent PLC network communications to the second node, and for receiving subsequent PLC network communications from the second node 120. At block 964, the second node 120 may similarly configure its communication unit to utilize the custom preamble for CSMA evaluations and for sending or detecting subsequent PLC network communications.

[0093] After implementing the custom preamble at blocks 962 and 964, the first node 110 and the second node 120 may include the custom preamble in place of the standard preamble for subsequent PLC network communications. For example, the first node 110 may include the custom preamble as the first symbol of each subsequent PLC network communication 974 to the second node 120. The second node 120 may monitor the communication medium for the custom preamble and receive the subsequent PLC network communication 974 that includes the custom preamble.

[0094] Figure 9An example of using a preamble change indication 952 to activate a custom preamble after the first node 110 detects an indicator of a denial of service attack at block 940 is shown. In some implementations, the custom preamble can be activated before a denial of service attack occurs. For example, the preamble change indication 952 can be included as part of the message 930 used to negotiate the custom preamble. Thus, the PLC network can implement the custom preamble (as described with reference to blocks 962 and 964) before a denial of service attack occurs.

[0095] Figure 10 An exemplary charging station 1000 is described, comprising multiple EVSEs for charging a corresponding plurality of EVs. The exemplary charging station 1000 includes several EVSEs (e.g., EVSEs 1010, 1011, 1012, 1013, 1014, 1015, 1016, and 1017) capable of respectively charging various EVs (e.g., EVs 1020, 1021, 1022, 1023, 1024, 1025, 1026, and 1027). The exemplary charging station 1000 may also include a central node 150 (sometimes also referred to as a central coordinator). Central node 150 may coordinate the addition of nodes to a PLC network or the establishment of a new PLC network. In some implementations, each pair of EVSEs and EVs may be referred to as a PLC network, such that the charging station operates multiple PLC networks (one network per pair of EVSEs and EVs) managed by the central node. Alternatively or additionally, the EVSE may belong to a PLC network including the central node 150, such that the central node 150 manages the network operations of the EVSE and EVs at the charging station 1000. Figure 11 As further described, the central node 150 may participate in the activation of countermeasures associated with a denial of service attack. For example, any of the nodes within the EVSE 1010, 1011, 1012, 1013, 1014, 1015, 1016, or 1017 or within the EV 1020, 1021, 1022, 1023, 1024, 1025, 1026, or 1027 may transmit a preamble change indication (or a denial of service attack detection message) to the central node 150. The central node 150 may activate the countermeasure so that all nodes within the EVSEs 1010, 1011, 1012, 1013, 1014, 1015, 1016, and 1017 and within the EVs 1020, 1021, 1022, 1023, 1024, 1025, 1026, and 1027 benefit from the countermeasure, thereby quickly mitigating the denial of service attack.

[0096] Figure 11A timing diagram 1100 is shown of an example countermeasure activated in association with a denial of service attack involving a central node. The timing diagram 1100 shows a first node 110 and a second node 120 associated with a PLC network. The timing diagram 1100 also shows a central node 150 configured to manage the operation of the PLC network, and an attacking node 130 attempting to attack the PLC network using a denial of service attack. The first node 110 and the second node 120 may exchange messages 910 to establish the PLC network. For example, the messages 910 may be similar to those in reference to Figure 9 The corresponding message 910 described. In addition, as shown in reference Figure 9 As depicted, the first node 110 and the second node 120 may exchange messages 930 to negotiate a custom preamble.

[0097] At some point, the attacking node 130 may send one or more transmissions 920 injected onto the communication medium. At block 940, the first node 110 may observe the transmissions 920 and detect indicia of a denial of service attack associated with the transmissions 920. Indicia of a denial of service attack may include reference to Figure 5-8 When the first node 110 detects a marker of a denial of service attack, the first node 110 may transmit a preamble change indication 1152 to the central node 150. For example, the preamble change indication 1152 may be transmitted by referring to Figure 12 The preamble change indication 1152 may be transmitted using any of the examples described above. The preamble change indication 1152 notifies the central node 150 that the first node 110 has detected a denial of service attack. Alternatively or additionally, the preamble change indication 1152 may represent a request to activate a countermeasure associated with the denial of service attack. The preamble change indication 1152 may be configured to cause the central node 150 to activate the countermeasure and notify other nodes of the PLC network (including the second node 120) to use a custom preamble for subsequent PLC network communications 974. For example, the central node 150 may send the preamble change instruction 1154 to the second node 120. In some implementations, the preamble change instruction 1154 may be a broadcast communication that also notifies the first node 110 of the activation of the countermeasure. Furthermore, in some implementations, the central node 150 may transmit the preamble change instruction 1156 to other nodes associated with the central node 150 or other PLC networks (e.g., EVSEs at charging stations and nodes within EVs).

[0098] At blocks 962 and 964, the first node 110 and the second node 120 may implement the Figure 9 For example, the first node 110 and the second node 120 may implement a custom CSMA mechanism for monitoring a custom preamble instead of a standard preamble. Thereafter, subsequent PLC network communications 974 may include the custom preamble.

[0099] Figure 12 Example preamble change indications are shown. In a first example 1201, a preamble change indication 1210 can be included in an application layer message 1205. Examples of application layer messages 1205 can include packets to or from a central controller, an EVSE, or an application in an EV, among other examples. In some implementations, application layer messages 1205 can be Transmission Control Protocol / Internet Protocol (TCP / IP) packets to or from a central controller of an automotive device. In a second example 1202, a preamble change indication 1210 can be included in a MAC frame, such as a Management Message Entry (MME) frame 1220. In a third example 1203, preamble change indication 1210 can be represented as a PWM sequence 1260. For example, PWM sequence 1260 can include a specific duty cycle or PWM pulse sequence. Nodes of a PLC network can monitor a communication medium for PWM sequence 1260. A first node can transmit PWM sequence 1260 via the communication medium to signal the preamble change indication. The second node may receive the PWM sequence 1260 and interpret it as a preamble change indication.

[0100] although Figure 12 While exemplary preamble change indications are described that may be used to activate countermeasures associated with custom preambles to mitigate CSMA exploitation attacks, the same type of communication may also be used to activate countermeasures associated with custom priority resolution symbols to mitigate priority contention exploitation attacks.

[0101] Figure 13 An exemplary priority contention mechanism 1300 is shown. The PLC standard specification may specify a priority contention mechanism that enables nodes of a PLC network to indicate their respective priorities. When a node has a lower priority than another node, the node with the lower priority may be configured to postpone contention for the communication medium for a backoff period. This allows the node with the higher priority to compete for access to the communication medium before other nodes with the lower priority. Figure 13 An example is provided in which the first node 110 has a higher priority than the second node 120 .

[0102] After the previous PPDU 1310 (performed by any node in the PLC network), there is a Priority Resolution Slot (PRS) 1315. Figure 13 In the example, there are two PRSs (sometimes referred to as PRS0 and PRS1). The nodes can signal their priorities by sending standard priority resolution symbols during the PRSs according to one of the following four options:

[0103] The priority resolution symbol in PRS0 or PRS1 must not indicate a priority of "0"

[0104] ●The priority resolution symbol in PRS0 can indicate a priority of "1"

[0105] The priority resolution symbol in PRS1 can indicate a priority of "2"

[0106] The priority resolution symbol in PRS0 and PRS1 can indicate a priority of "3"

[0107] exist Figure 13 In the example shown in FIG1 , the first node 110 may indicate a priority of "2" by transmitting a priority resolution symbol during PRS1. The second node 120 may indicate a priority of "1" by transmitting a priority resolution symbol during PRS0. When the second node 120 determines that it has a lower priority than the first node 110, the second node may avoid contending for access and wait for a backoff period 1332 before contending for access. Simultaneously, the first node 110 may contend for access to the communication medium (as shown in block 1330). For example, the first node 110 may contend for access by performing a CSMA evaluation and determining that the communication medium is idle. After determining that the first node 110 has the highest priority and the communication medium is idle, the first node 110 may transmit the PLC network communication (e.g., delimiter 1340 and payload 1350) on the communication medium.

[0108] While priority contention is a useful feature of PLC networks, it can be exploited to perform denial-of-service attacks.

[0109] Figure 14 An example of a denial of service attack 1400 utilizing a priority contention mechanism is shown. The standard priority contention mechanism (as specified in the PLC standard specification) uses a standard priority resolution symbol. The standard priority resolution symbol is documented and predefined according to the PLC standard specification. Figure 14As shown in , an attacking node can exploit this vulnerability by continuously sending standard priority resolution symbols 1410 to indicate the highest priority. In some cases, attacking node 130 may not know when the previous PPDU 1310 has ended, but because it can continuously inject standard priority resolution symbols 1410 onto the communication medium, there is a possibility that standard priority resolution symbols 1410 may overlap with a set of priority resolution slots 1315. For example, standard priority resolution symbols 1415 and 1417 overlap with priority resolution slots 1315. Furthermore, because standard priority resolution symbols 1415 and 1417 are included in both PRS0 and PRS1, they may indicate the highest priority of "3." First node 110 and second node 120 may assume that their priorities are lower than that of attacking node 130 and both exit the contention (shown at backoff periods 1422 and 1332, respectively). After the corresponding backoff periods 1422 and 1332, the first node 110 and the second node 120 may again participate in the priority contention mechanism during PRS 1435 and PRS 1445. Without the techniques of the present disclosure, the attacking node 130 may perform a denial of service attack by continuously sending a higher priority than the first node 110 and the second node 120.

[0110] The detection techniques and countermeasures for a denial of service attack utilizing a priority contention mechanism may be similar to the detection techniques and countermeasures for a denial of service attack utilizing a CSMA mechanism. For example, the first node 110 or the second node 120 may detect a signature of a denial of service attack based on a history of failing to win a priority within a period of time or over a series of consecutive priority resolution time slots. When the amount of time associated with consecutive priority contention backoff periods exceeds a maximum time limit, the first node 110 or the second node 120 may obtain a signature of a denial of service attack, similar to the reference to Figure 7 An example of the description. Countermeasures for this type of denial of service attack may include using a custom priority resolution symbol instead of a standard priority resolution symbol. For example, a custom priority resolution symbol may be negotiated between the first node 110 and the second node 120. Thereafter, the first node 110 and the second node 120 may use a custom priority contention mechanism that ignores the standard priority resolution symbol and instead monitors the priority resolution slot for the custom priority resolution symbol. Additionally, a priority resolution symbol change activation may be transmitted to activate the countermeasure, similar to the one described herein with reference to Figure 9 、 11 and Figure 12 The described preamble changes are activated.

[0111] Figure 15A flow chart for activating example countermeasures associated with a denial of service attack and an overwrite condition is described. The operations of process 1500 may be implemented by a node of a PLC network or any component thereof as described herein. In some implementations, the operations may be implemented by a communication unit of a node (e.g., a reference to a communication unit). Figure 1 14 or 124) described herein. In some implementations, the process 1500 (or a portion thereof) may be performed by a node or a component thereof (e.g., a node or a component thereof, respectively). Figure 1 、 3 , 4, 10, 11, 13, 14 or Figure 17 The process 1500 may be performed by the first node 110, the second node 120, or the central node 150 described in any one of the preceding claims. In some implementations, the process 1500 may be performed by an apparatus or a component thereof (e.g., a reference to Figure 20 The process 1500 is performed by the apparatus 2000 described above. For the sake of brevity, the example process 1500 is described as being executable by an apparatus or component thereof that is any one of the nodes, communication units, or apparatuses described above.

[0112] At block 1510, the device may initially use a standard preamble and a standard CSMA mechanism. For example, the standard preamble and the standard CSMA mechanism may be specified in the PLC standard specification. Similarly, the device may utilize a standard priority resolution symbol and a standard priority contention mechanism.

[0113] At block 1520, the device may determine whether it has received indicia of a denial of service attack. For example, the device may observe one or more transmissions for reference Figure 5-8 If the device detects a denial of service attack, the process may proceed to block 1530. Otherwise, the process may return to block 1510.

[0114] At block 1520, the device may determine whether coverage conditions are met. Figure 16 An exemplary coverage condition is further described. When the coverage condition is met, the process may proceed to block 1540. Otherwise, the process may return to block 1510. The coverage condition may be implemented to prevent a node from overriding a standard CSMA mechanism or a standard priority resolution mechanism unless a countermeasure can be activated without impacting the operation of the PLC network. For example, in some aspects, the countermeasure may include ignoring transmissions that include a standard preamble or a standard priority resolution symbol. However, if the signal strength of the transmission is stronger than a threshold condition, the first node 110 and the second node 120 may not be able to ignore these transmissions to communicate via the communication medium. In some implementations, the countermeasure may not be activated unless the coverage condition is met.

[0115] At block 1540, the device may activate a countermeasure. For example, the device may utilize a custom preamble and custom CSMA instead of a standard preamble and standard CSMA. Alternatively or additionally, the device may utilize a custom priority resolution symbol and a custom priority contention mechanism instead of a standard priority resolution symbol or a standard priority contention mechanism.

[0116] Figure 16 An exemplary coverage condition 1600 is shown. The exemplary coverage condition 1600 may be satisfied when a signal strength metric 1610 of a denial of service attack is below a signal strength threshold 1620. For example, the signal strength metric may be an SNR value, an amplitude plot, a metric indicating a front-end gain at a node's receiver, or a metric associated with an analog-to-digital converter (ADC) of the receiver, among others. In some implementations, the signal strength metric may be measured for a standard preamble portion of a denial of service attack transmission. The signal strength metric 1610 may be compared to a signal strength threshold 1620. The signal strength threshold 1620 may be associated with any combination of a fixed threshold, a reference signal strength associated with a previous communication between the first node and the second node, a fixed offset value associated with the reference signal strength, a dynamic threshold associated with the number of authenticated nodes in the PLC network, or a dynamic offset value associated with the number of CSMA collisions on the communication medium.

[0117] For example, for illustrative purposes, the signal strength threshold 1620 ("T") may be calculated as:

[0118] T=X ± Y (1)

[0119] Wherein, "X" is a reference value and "Y" is an offset. In some implementations, the reference value (X) may be based on previous communications between the first node and the second node, or may be a fixed reference value. In some implementations, the offset "Y" may be a fixed offset value. Alternatively or additionally, the offset "Y" may be derived based on a combination of offsets. For example, the offset Y may be calculated by adding a first offset Y1 and a second offset Y2, wherein the first offset Y1 is a static value derived from experimental data, and the second offset Y2 is a dynamic value. In some implementations, the second offset Y2 may be proportional to the number of robust (ROBO) communication failures detected on the communication medium, wherein a ROBO communication failure occurs when a node encounters a communication conflict with another node. Typically, ROBO communication failures may increase as the number of nodes in the PLC network increases. Therefore, in some implementations, the offset value Y2 may be proportional to the number of nodes in the PLC network.

[0120] The exemplary coverage condition 1600 may be satisfied when the signal strength metric 1610 associated with the standard preamble is less than a signal strength threshold 1620. For example, the signal strength metric 1610 may indicate that the standard preamble has been detected, and a signal strength metric 1610 below the signal strength threshold 1620 may indicate that the standard preamble is part of a denial of service attack. In some implementations, the signal strength threshold 1620 may be adjusted (e.g., increased) when the signal strength metric 1610 is above the signal strength threshold 1620, but it is known that the standard preamble is part of a denial of service attack based on other indicia described herein.

[0121] Figure 17 A block diagram conceptually illustrating an example node 1700 capable of implementing countermeasures is shown. The node 1700 may include a transmitter device 1702 for transmitting a signal (eg, a sequence of OFDM symbols) to a receiver device 1706 over a communication medium 1704.

[0122] The transmitter device 1702 and the receiver device 1706 may be incorporated into a communication unit (eg, reference 1700 ) of each node (eg, the first node 110 and the second node 120 ). Figure 1 The communication medium 1704 may represent a communication channel from one device to another device via a wired or wireless network. For example, the communication medium 1704 may be a reference to Figure 1 Examples of communication media 115 are described.

[0123] At transmitter device 1702, a module implementing the PHY layer can receive an MPDU from the MAC layer (not shown). The MPDU is sent to encoder module 1720 for processing, which may include scrambling, error correction coding, and interleaving. The encoded MPDU may be referred to as a PPDU. Encoder module 1720 may also generate FC symbols for the PPDU. The PPDU is fed to mapping module 1722, which extracts groups of data bits (e.g., 1, 2, 3, 4, 6, 8, or 10 bits) based on the constellation used for the current symbol (e.g., BPSK, QPSK, 8-QAM, 15-QAM constellation) and maps the data values ​​represented by these bits to the corresponding amplitudes of the in-phase (I) and quadrature-phase (Q) components of the modulated symbol's carrier waveform. Alternatively, any suitable mapping scheme that associates data values ​​with the modulated carrier waveform may be used. Mapping module 1722 may also determine the modulation type to be used on each carrier (or "tone") based on the tone mapping. The tone map may be a default tone map or a customized tone map provided by the receiver device 1706 in response to the channel estimation process.

[0124] The modulation module 1724 modulates the result set of N complex numbers (wherein some complex numbers may be zero for unused carriers) determined by the mapping module 1722 to have peak frequencies f1, . . . , f N The data from the mapping module 1722 is modulated onto N orthogonal carrier waveforms. The modulation module 1724 performs an inverse discrete Fourier transform (IDFT) to form a discrete-time symbol waveform. In one example, an 8192-point inverse fast Fourier transform (IFFT) is used to modulate the data from the mapping module 1722 onto the subcarrier waveforms, generating 8192 time samples that form part of an OFDM symbol. The resulting time samples are in the time domain, while the input to the IDFT is in the frequency domain.

[0125] The post-processing module 1726 can combine consecutive (potentially overlapping) symbol sequences into a "symbol set," which can be transmitted as a continuous block over the communication medium 1704. The post-processing module 1726 can pre-set a preamble to the symbol set, which can be used for automatic gain control (AGC) and symbol timing synchronization. According to aspects of the present disclosure, when countermeasures are activated in association with a denial of service attack, the post-processing module 1726 can pre-set a custom preamble (instead of a standard preamble). The analog front end (AFE) module 1728 couples an analog signal containing a continuous-time (e.g., low-pass filtered) version of the symbol set to the communication medium 1704. The encoder module 1720, mapping module 1722, modulation module 1724, post-processing module 1726, and AFE module 1728 together can be referred to as the TX chain of the transmitter. A PHY controller (not shown) can configure and manage various components of the transmitter, including those shown in the transmitter device 1702.

[0126] At the receiver device 1706, a module implementing the PHY layer can receive a signal from the communication medium 1704 and generate a receive MPDU for the MAC layer (not shown). The AFE module 1730 can receive a receive signal having a set of symbols and send the received signal to the demodulation module 1736. The demodulation module 1736 can generate sampled signal data. The demodulation module 1736 can also include a discrete Fourier transform (DFT) feature to convert the sampled receive waveform into frequency domain data in complex form. For example, in an OFDM system, demodulation can involve a fast Fourier transform (FFT). In a single carrier system, demodulation can involve constellation demapping to convert symbols into hard bits or soft bits.

[0127] The decoder module 1738 can map the complex numbers onto corresponding bit sequences and perform appropriate decoding of the bits (including deinterleaving and descrambling). The AFE module 1730, the demodulation module 1736, and the decoder module 1738 together can be referred to as the RX chain of the receiver. The RX chain may include other components (not shown) such as equalizers, filters, automatic gain control, etc. A PHY controller (not shown) can manage and control the components of the receiver.

[0128] According to aspects of the present disclosure, the receiver device 1706 can include a filter 1732 associated with the AFE module 1730. In some aspects, when the countermeasure is activated, the filter 1732 can filter transmissions that begin with a standard preamble. For example, when a node detects a denial of service attack, the node can generate correlation data associated with the denial of service attack. The correlation data can be associated with the amplitude, phase, signal strength, or any combination thereof of at least one standard preamble included in one or more transmissions. The node can configure the filter 1732 to ignore subsequent transmissions that include a standard preamble that matches the correlation data.

[0129] Figure 18 A flow chart illustrating an example process 1800 for mitigating a denial of service attack is shown. The operations of process 1800 may be implemented by a node of a PLC network or any component thereof as described herein. In some implementations, the operations of process 1800 may be implemented by a communication unit of a node (e.g., a reference Figure 1 14 or 124) described herein. Figure 1 、 3 , 4, 10, 11, 13, 14 or Figure 17 The process 1800 may be performed by the first node 110, the second node 120, or the central node 150 described in any one of the preceding claims. In some implementations, the process 1800 may be performed by an apparatus or a component thereof (e.g., a reference to Figure 20 For the sake of brevity, the example process 1800 is described as being executable by an apparatus or component thereof that is any one of the nodes, communication units, or apparatuses described above.

[0130] At block 1810, a first node may establish a PLC network via a communication medium, the PLC network comprising at least the first node and a second node. At block 1820, the first node may negotiate a custom preamble for use in the PLC network. At block 1830, the first node may activate a countermeasure in the PLC network associated with a denial of service attack associated with one or more transmissions injected onto the communication medium to disrupt PLC network communications, wherein activating the countermeasure includes utilizing a custom preamble for PLC network communications between the first node and the second node.

[0131] Figure 19 A flowchart illustrating another example process for mitigating a denial of service attack is shown. The operations of process 1900 may be implemented by a node of a PLC network or any component thereof as described herein. In some implementations, the operations may be implemented by a communication unit of a node (e.g., a reference Figure 1 114 or 124) described herein. In some implementations, the process 1900 (or a portion thereof) may be performed by a node or a component thereof (e.g., a node or a component thereof, respectively). Figure 1 、 3 , 4, 10, 11, 13, 14 or Figure 17 The process 1900 may be performed by the first node 110, the second node 120, or the central node 150 described in any one of the preceding claims. In some implementations, the process 1900 may be performed by an apparatus or a component thereof (e.g., a reference to Figure 20 For the sake of brevity, the example process 1900 is described as being executable by a first node or a component thereof that is any one of the above-described nodes, communication units, or devices.

[0132] At block 1910, a first node may establish a PLC network via a communication medium, the PLC network comprising at least a first node and a second node. At block 1920, the first node may negotiate a custom priority resolution symbol for the PLC network. At block 1930, the apparatus may activate a countermeasure in the PLC network associated with a denial of service attack associated with one or more transmissions injected onto the communication medium to disrupt communications in the PLC network, wherein activating the countermeasure includes utilizing the custom priority resolution symbol to enforce priority contention in the PLC network.

[0133] Figure 20According to some implementations, a block diagram of an example apparatus 2000 for supporting countermeasures associated with a denial of service attack is shown. The apparatus 2000 may be or may include a chip, a system on chip (SoC), a chipset, a package, or a device. The term "system on chip" (SoC) is used herein to refer to a group of interconnected electronic circuits, which typically include (but are not limited to) one or more processors, memories, and communication interfaces. The SoC may include various types of processors and processor cores, such as general-purpose processors, central processing units (CPUs), digital signal processors (DSPs), graphics processing units (GPUs), accelerated processing units (APUs), subsystem processors, auxiliary processors, single-core processors, and multi-core processors. The SoC may also include other hardware and hardware combinations, such as field programmable gate arrays (FPGAs), configuration and status registers (CSRs), application specific integrated circuits (ASICs), other programmable logic devices, discrete gate logic, transistor logic, registers, performance monitoring hardware, watchdog hardware, counters, and time bases. The SoC may be an integrated circuit (IC) that is configured so that the components of the IC are located on the same substrate such as a monolithic semiconductor material (e.g., silicon).

[0134] The term "system in package" (SIP) is used herein to refer to a single module or package that can contain multiple resources, computing units, cores, or processors on two or more IC chips, substrates, or SoCs. For example, a SIP can include a single substrate on which multiple IC chips or semiconductor dies are stacked in a vertical configuration. Similarly, a SIP can include one or more multi-chip modules (MCMs) on which multiple ICs or semiconductor dies are packaged into a unified substrate. A SIP can also include multiple independent SoCs that are coupled together via high-speed communication circuits and packaged in close proximity, such as on a single motherboard or in a single mobile communication device. The proximity of the SoCs facilitates high-speed communication and sharing of memory and resources.

[0135] The term "multi-core processor" is used herein to refer to a single IC chip or chip package that contains two or more independent processing cores (e.g., CPU cores, IP cores, GPU cores, etc.) that are configured to read and execute program instructions. A SoC may include multiple multi-core processors, and each processor in the SoC may be referred to as a core. The term "multiprocessor" may be used herein to refer to a system or device that includes two or more processing units that are configured to read and execute program instructions.

[0136] The apparatus 2000 may include one or more modems 2002. In some implementations, the one or more modems 2002 (collectively referred to as "modems 2002") may include. For example, the modems 2002 may implement reference Figure 17 1706 . In some implementations, the apparatus 2000 further includes one or more radios (collectively, “radios 2004”). In some implementations, the apparatus 2000 further includes one or more processors, processing modules, or processing elements (collectively, “processing system 2006”) and one or more memory blocks or elements (collectively, “memory 2008”). In some implementations, the processing system 2006 may include the memory 2008.

[0137] Modem 2002 may include intelligent hardware modules or devices, such as application specific integrated circuits (ASICs) and the like. Modem 2002 is typically configured to implement a PHY layer. For example, modem 2002 is configured to modulate packets and output the modulated packets to radio 2004 for transmission on a communication medium. Modem 2002 is similarly configured to obtain modulated packets received by radio 2004 and demodulate these packets to provide demodulated packets. In addition to a modulator and demodulator, modem 2002 may also include a digital signal processing (DSP) circuit, an automatic gain control (AGC), an encoder, a decoder, a multiplexer, and a demultiplexer. For example, when in transmission mode, data obtained from processing system 2006 is provided to an encoder, which encodes the data to provide coded bits. The coded bits are mapped to points in a modulation constellation (using a selected MCS) to provide modulated symbols. The modulated symbols can be mapped to multiple NSS spatial streams or multiple NSTS space-time streams. The modulated symbols in each spatial stream or space-time stream can be multiplexed, converted via an inverse fast Fourier transform (IFFT) block, and then provided to the DSP circuit for Tx windowing and filtering. The digital signal can be provided to a digital-to-analog converter (DAC). The resulting analog signal can be provided to a frequency upconverter and ultimately to the radio 2004. In embodiments involving beamforming, the modulated symbols in each spatial stream are precoded via a steering matrix before being provided to the IFFT block.

[0138] When in receive mode, a digital signal received from radio 2004 is provided to a DSP circuit configured to acquire the received signal, for example, by detecting the presence of a signal and estimating initial timing and frequency offset. The DSP circuit is also configured to digitally condition the digital signal, for example, using channel (narrowband) filtering, analog impairment adjustment (e.g., correcting I / Q imbalance), and applying digital gain to ultimately obtain a narrowband signal. The output of the DSP circuit can be fed to an AGC, which is configured to use information extracted from the digital signal (e.g., in one or more received training fields) to determine an appropriate gain. The output of the DSP circuit is also coupled to a demodulator, which is configured to extract modulation symbols from the signal and, for example, calculate a log-likelihood ratio (LLR) for each bit position of each subcarrier in each spatial stream. The demodulator is coupled to a decoder, which can be configured to process the LLRs to provide decoded bits. The decoded bits from all spatial streams are fed to a demultiplexer for demultiplexing. The demultiplexed bits may be descrambled and provided to the MAC layer (processing system 2006) for processing, evaluation, or interpretation.

[0139] Radio 2004 typically includes at least one radio frequency (RF) transmitter (or "transmitter chain") and at least one RF receiver (or "receiver chain"), which can be combined into one or more transceivers. For example, the RF transmitter and receiver can include various DSP circuits, each including at least one power amplifier (PA) and at least one low-noise amplifier (LNA). In turn, the RF transmitter and receiver can be coupled to a wired or wireless communication medium. Symbols output from modem 2002 are provided to radio 2004, which in turn transmits the symbols via the coupled communication medium. Similarly, symbols received via the communication medium are obtained by radio 2004, which in turn provides these symbols to modem 2002.

[0140] The processing system 2006 may include intelligent hardware modules or devices, such as a processing core, a processing block, a central processing unit (CPU), a microprocessor, a microcontroller, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a programmable logic device (PLD) (e.g., a field-programmable gate array (FPGA)), discrete gate or transistor logic, discrete hardware components, or any combination thereof, designed to perform the functions described herein. The processing system 2006 processes information received via the radio 2004 and the modem 2002 and processes information to be output by the modem 2002 and the radio 2004 for transmission over a communication medium. In some implementations, the processing system 2006 may generally control the modem 2002 to cause the modem to perform the various operations described above.

[0141] The memory 2008 may include tangible storage media such as random access memory (RAM) or read-only memory (ROM), or a combination thereof. The memory 2008 may also store non-transitory processor or computer executable software (SW) code containing instructions that, when executed by the processing system 2006, cause the processor to perform various operations described herein for PLC network communications, including the generation, transmission, reception, and interpretation of MPDUs, frames, or packets. For example, various functions of the components disclosed herein, or various blocks or steps of the methods, operations, processes, or algorithms disclosed herein, may be implemented as one or more modules of one or more computer programs.

[0142] Figure 21 An exemplary custom preamble 2120 is shown compared to the standard preamble 2100. The standard preamble 2100 may include a combination of synchronization symbols. The first type of synchronization symbol is denoted as a "SYNCP AV" symbol and the second type of synchronization symbol is denoted as a "SYNCM AV" symbol. The SYNCP AV and SYNCM AV symbols may be specified in the standard specification (e.g., the frequency and phase angle of each carrier in the synchronization symbol). In some implementations, the synchronization symbols utilize a carrier spanning 1.8-30 MHz. The symbols labeled "second half" and "first half" span 192 samples or 2.56 us, while the other symbols span 384 samples or 5.12 us. The standard specification may define the order and structure of the standard preamble 2100 to include the following (in this order):

[0143] Partial SYNCP AV symbol (second half) 2101,

[0144] Seven (7) SYNCP AV symbols 2102, 2013, 2014, 2015, 2016, 2017 and 2018,

[0145] Two (2) SYNCM AV symbols 2111 and 2113, and

[0146] Partial SYNCM AV symbol (first half) 2113.

[0147] Figure 21 Also shown in FIG. 2 is an exemplary custom preamble 2120. In some implementations, the exemplary custom preamble 2120 may include the same types of SYNCP AV and SYNCM AV symbols as defined for the standard preamble 2100, albeit in a different order. For example, the exemplary custom preamble 2120 may include the following (in this order):

[0148] Partial SYNCP AV symbol (second half) 2121,

[0149] SYNCP AV symbol 2122,

[0150] SYNCM AV symbol 2123,

[0151] Two (2) SYNCP AV symbols 2124 and 2125,

[0152] SYNCM AV symbol 2126,

[0153] Four (4) SYNCP AV symbols 2127, 2128, 2129, and 2131, and

[0154] Partial SYNCM AV symbol (first half) 2113.

[0155] For ease of comparison, the differences in the exemplary custom preamble 2120 compared to the standard preamble 2100 are shown in bold.

[0156] An exemplary custom preamble 2120 is provided for illustration purposes. In practice, the custom preamble may employ any arrangement of SYNCP AV, SYNCP AV, or other synchronization symbols.

[0157] Figure 22 A comparison of a partial frequency / phase configuration 2210 of an exemplary custom preamble symbol and a partial frequency / phase configuration 2200 of a standard preamble symbol is shown. The standard specification may define the frequency and phase angle of each carrier in the preamble symbol. The partial frequency / phase configuration 2200 shows the frequency and phase angle used in the standard preamble compared to the standard SYNCP AV symbol (e.g., reference 1). Figure 21 A partial listing of the carrier, frequency, and phase angle associated with each waveform (as described in the symbols). The actual phase (in radians) is the phase angle multiplied by π / 8. The SYNCM AV time domain waveform can be defined as the SYNCP AV waveform multiplied by –1, with the SYNCM AV phase being the SYNCP AV phase offset by π radians.

[0158] The partial frequency / phase configuration 2210 of the exemplary custom preamble symbol can use different frequency or phase angle values ​​compared to the partial frequency / phase configuration 2200 of the standard preamble symbol. For example, carriers 10 and 14 of the custom preamble symbol can each use a different frequency than carriers 10 and 14 of the standard preamble symbol. As another example, carriers 12 and 13 of the custom preamble symbol can each use a different phase angle than carriers 12 and 13 of the standard preamble symbol. For ease of comparison, the differences between the exemplary custom preamble symbol 2210 and the standard preamble symbol 2200 are shown in bold.

[0159] An exemplary custom preamble symbol 2210 is provided for illustration purposes. In practice, a custom preamble symbol may have a different frequency, phase angle, or both associated with one or more tones than a standard preamble symbol.

[0160] Described with respect to standard preambles and exemplary custom preambles Figure 21 and Figure 22 Examples are provided for priority resolution symbols, but these examples may also apply to priority resolution symbols. Standard specifications may define the symbol structure of standard priority resolution symbols based on the frequencies and phase angles of various carriers. An exemplary custom priority resolution symbol may include differences (e.g., frequencies, phase angles, or both) for one or more carriers compared to the standard priority resolution symbol.

[0161] The present disclosure includes example messages (e.g., application layer messages, MME messages, MAC frames, or messages associated with the SLAC protocol, etc.) that can be used to negotiate a custom preamble or a custom priority resolution time slot. In some implementations, a message can include a field indicating the order of SYNCM or SYNCP symbols associated with the custom preamble. In some implementations, a message can include a field indicating the frequency / phase configuration of the SYNCM or SYNCP symbols. In some implementations, a message can include a field formatted to indicate a change to a standard preamble, such that the custom preamble can be derived from the standard preamble and the indicated change. In some implementations, a message can carry a value indicating one of a plurality of custom preambles. For example, the value can correspond to an entry in a lookup table that includes a predefined value associated with a corresponding predefined custom preamble. In some implementations, information about the custom preamble can be transmitted in a compressed format so that the first node and the second node can derive the custom preamble from the information.

[0162] Figure 1-22 The operations described herein are examples intended to aid in understanding example implementations and should not be used to limit potential implementations or to limit the scope of the claims. Some implementations may perform additional operations, fewer operations, operations in parallel or in a different order, and perform some operations differently.

[0163] The above disclosure provides illustration and description, rather than being exhaustive, nor is it intended to limit these aspects to the precise form disclosed. Modifications and variations may be made according to the above disclosure, or modifications and variations may be obtained from the practice of these aspects. Although various aspects of the present disclosure have been described according to various examples, any combination of various aspects from any example is also within the scope of protection of the present disclosure. The examples in the present disclosure are provided for teaching purposes. Alternatively, or in addition to other examples described herein, examples include any combination of the following implementation options (listed as clauses for clarity of explanation).

[0164] Clause 1. A method for a first node in a power line communication (PLC) network, comprising: establishing a PLC network via a communication medium, the PLC network including at least the first node and a second node; negotiating a custom preamble for the PLC network; and activating countermeasures in the PLC network associated with a denial of service attack, the denial of service attack being associated with one or more transmissions injected onto the communication medium to disrupt PLC network communications, wherein activating the countermeasures comprises utilizing the custom preamble for PLC network communications between the first node and the second node.

[0165] Clause 2. The method according to Clause 1 further includes: processing at least a first transmission of the one or more transmissions in association with a PLC frame format of a PLC standard specification; activating the countermeasure when the first transmission includes a first part that complies with the PLC standard specification and a second part that conflicts with the PLC standard specification.

[0166] Clause 3. The method according to any one of clauses 1-2 further includes: attempting to process the one or more transmissions in association with a PLC frame format of a PLC standard specification, wherein the PLC frame format includes at least a preamble portion, a frame control (FC) portion, and a payload portion; counting the number of error conditions associated with failure to process the preamble portion, the FC portion, the payload portion, or any combination thereof; and activating the countermeasure when the number of error conditions is higher than a processing error threshold.

[0167] Clause 4. A method according to clause 3, wherein processing the failure of the preamble portion, the FC portion, the payload portion, or any combination thereof includes: processing the failure of the first transmission in association with at least one error condition selected from the group consisting of: the preamble portion of the first transmission is invalid or incomplete; the FC portion of the first transmission is invalid or omitted; a cyclic redundancy check (CRC) error is associated with the FC portion of the first transmission; the FC portion of the first transmission includes an invalid beacon timestamp (BTS) delimiter; the FC portion of the first transmission includes an invalid value for a management media access control (MAC) frame flow command field or a management MAC frame flow response field; the payload portion of the first transmission is invalid or omitted; the first transmission ends before a virtual carrier sense (VCS) timer expires, otherwise the first transmission is typically associated with the end of a valid PLC frame; the first transmission is the same as a previous transmission in the one or more transmissions.

[0168] Clause 5. A method according to any one of clauses 1-4, wherein the one or more transmissions include multiple transmissions, and the method further comprises: attempting to process the multiple transmissions in association with a PLC frame format specified by a PLC standard; counting the number of cyclic redundancy check (CRC) errors associated with the multiple transmissions; and activating the countermeasure when the number of CRC errors is higher than a CRC error threshold.

[0169] Clause 6. The method according to any one of clauses 1-5 further includes: attempting to process a first transmission of the one or more transmissions in association with a PLC frame format of a PLC standard specification; and activating the countermeasure when the first transmission includes an invalid value in a frame control (FC) portion of the first transmission.

[0170] Clause 7. A method according to clause 6, wherein the invalid value includes a first beacon timestamp (BTS) value in the first transmission that is inconsistent with an expected BTS value, the expected BTS value being associated with one or more previous BTS values ​​of one or more corresponding previous transmissions and an amount of time between the one or more corresponding previous transmissions.

[0171] Clause 8. The method according to any one of clauses 1-7 further includes: receiving a current media access control (MAC) frame flow state indicated in a frame control (FC) portion of a current transmission of the one or more transmissions; and activating the countermeasure when the current MAC frame flow state is inconsistent with an expected MAC frame flow state, wherein the expected MAC frame flow state is derived from a previous MAC frame flow state of a previous transmission of the one or more transmissions.

[0172] Clause 9. The method of clause 8, wherein the previous MAC frame flow state is a management MAC frame flow command or a management MAC frame flow response, and the expected MAC frame flow state is the other of the management MAC frame flow command or the management MAC frame flow response.

[0173] Clause 10. The method according to any one of clauses 1-9 further includes: periodically evaluating the busy condition of the communication medium in association with a carrier sense multiple access (CSMA) mechanism; counting the number of busy conditions within a period of time; and activating the countermeasure when the number of busy conditions is higher than a busy threshold.

[0174] Clause 11. A method according to any one of clauses 1-10, wherein the PLC network is associated with a PLC standard specification that specifies the operation of the PLC network, wherein the PLC standard specification includes a standard carrier sense multiple access (CSMA) mechanism, wherein the first node or the second node avoids communicating via the communication medium during a backoff period after observing communication with a standard preamble, and the method further includes: utilizing a custom CSMA mechanism associated with a modification of the standard CSMA mechanism, wherein the custom CSMA mechanism includes monitoring the custom preamble instead of the standard preamble.

[0175] Clause 12. The method of any one of clauses 1-11, wherein activating the countermeasure comprises overriding a carrier sense multiple access (CSMA) mechanism of the PLC network when an overriding condition associated with the denial of service attack is met.

[0176] Clause 13. A method according to clause 12, wherein the coverage condition is satisfied when a signal strength metric of the one or more transmissions is below a signal strength threshold, and wherein the signal strength threshold is associated with any combination of: a threshold associated with the signal strength metric; a dynamic threshold associated with the number of authenticated nodes in the PLC network; a reference signal strength associated with previous communications between the first node and the second node; a fixed offset value associated with the reference signal strength; or a dynamic offset value associated with the number of CSMA collisions on the communication medium.

[0177] Clause 14. A method according to any one of clauses 12-13, wherein the CSMA mechanism includes: the first node generally avoids communicating via the communication medium during a backoff period after observing communication having a PLC frame format specified by the PLC standard, and wherein the coverage condition is met when the first node avoids communication during multiple consecutive backoff periods that exceed a maximum time, or when the multiple consecutive backoff periods reach a maximum number.

[0178] Clause 15. A method according to any one of clauses 1-14, wherein the custom preamble is different from the standard preamble of the PLC standard specification, so that the custom preamble is known to the first node and the second node, but is unknown to the attacking node associated with the denial of service attack, and wherein activating the countermeasure includes: adjusting the carrier sense multiple access (CSMA) mechanism of the first node to monitor the custom preamble instead of the standard preamble.

[0179] Clause 16. The method of any one of clauses 1-15, wherein activating the countermeasure further comprises transmitting a preamble change indication to the second node to notify the second node that the first node will use the custom preamble for the PLC network communication.

[0180] Clause 17. The method of clause 16, wherein transmitting the preamble change indication comprises transmitting the preamble change indication in a management message entry (MME) frame or an application layer protocol message.

[0181] Clause 18. The method of clause 16, wherein transmitting the preamble change indication comprises sending a pulse width modulated (PWM) signal having a predetermined duty cycle or sequence associated with the preamble change indication.

[0182] Clause 19. The method of any one of clauses 1-18, wherein activating the countermeasure comprises transmitting a preamble change indication to a central node of the PLC network to cause the central node to instruct one or more other nodes in one or more corresponding PLC networks to use the custom preamble.

[0183] Clause 20. A method according to any one of clauses 1-19, wherein activating the countermeasure includes: receiving a preamble change indication associated with the denial of service attack from the second node or the central node, wherein the preamble change indication indicates that the second node or the central node will use the custom preamble for the PLC network communication from the second node.

[0184] Clause 21. A method according to any one of clauses 1-20, wherein activating the countermeasure includes: generating correlation data associated with the denial of service attack, the correlation data being associated with the amplitude, phase, signal strength, or any combination thereof of at least one standard preamble code included in the one or more transmissions; and adjusting the physical (PHY) layer of the first node to ignore subsequent transmissions of the one or more transmissions that include the standard preamble code that matches the correlation data.

[0185] Clause 22. The method of any one of clauses 1-21, wherein negotiating the custom preamble comprises transmitting the custom preamble in a cryptographic message, a Management Message Entry (MME) frame, or an application layer protocol message.

[0186] Clause 23. A first node for use in a power line communication (PLC) network, comprising: a communication unit configured to establish a PLC network via a communication medium, the PLC network including at least the first node and a second node; a processor communicatively coupled to the communication unit, the processor configured to: negotiate a custom preamble for the PLC network; and activate a countermeasure in the PLC network associated with a denial of service attack, the denial of service attack being associated with one or more transmissions injected onto the communication medium to interrupt PLC network communications, wherein the communication unit is configured to: utilize the custom preamble for PLC network communications between the first node and the second node when the countermeasure is activated.

[0187] Clause 24. A first node according to clause 23, wherein the processor is further configured to: process at least a first transmission of the one or more transmissions in association with a PLC frame format of a PLC standard specification; and activate the countermeasure when the first transmission includes a first part that complies with the PLC standard specification and a second part that conflicts with the PLC standard specification.

[0188] Clause 25. A first node according to any one of clauses 23-24, wherein the processor is further configured to: attempt to process the one or more transmissions in association with a PLC frame format of a PLC standard specification, wherein the PLC frame format includes at least a preamble portion, a frame control (FC) portion, and a payload portion; count the number of error conditions associated with failure to process the preamble portion, the FC portion, the payload portion, or any combination thereof; and activate the countermeasure when the number of error conditions is higher than a processing error threshold.

[0189] Clause 26. A first node according to clause 25, wherein processing the failure of the preamble portion, the FC portion, the payload portion, or any combination thereof comprises: processing the failure of the first transmission in association with at least one error condition selected from the group consisting of: the preamble portion of the first transmission is invalid or incomplete; the FC portion of the first transmission is invalid or omitted; a cyclic redundancy check (CRC) error is associated with the FC portion of the first transmission; the FC portion of the first transmission includes an invalid beacon timestamp (BTS) delimiter; the FC portion of the first transmission includes an invalid value for a management media access control (MAC) frame flow command field or a management MAC frame flow response field; the payload portion of the first transmission is invalid or omitted; the first transmission ends before a virtual carrier sense (VCS) timer expires, otherwise the first transmission is typically associated with the end of a valid PLC frame; the first transmission is the same as a previous transmission in the one or more transmissions.

[0190] Clause 27. The first node of any one of clauses 23-26, wherein the processor is further configured to override a carrier sense multiple access (CSMA) mechanism of the PLC network when an override condition associated with the denial of service attack is met.

[0191] Clause 28. A first node according to clause 27, wherein the coverage condition is met when a signal strength metric of the one or more transmissions is below a signal strength threshold, and wherein the signal strength threshold is associated with any combination of: a threshold associated with the signal strength metric, a dynamic threshold associated with the number of authenticated nodes in the PLC network, a reference signal strength associated with previous communications between the first node and the second node, a fixed offset value associated with the reference signal strength, or a dynamic offset value associated with a number of CSMA collisions on the communication medium.

[0192] Clause 29. A first node according to any one of clauses 27-28, wherein the CSMA mechanism includes: the communication unit generally avoids communicating via the communication medium during a backoff period after observing communication having a PLC frame format specified by the PLC standard, and wherein the coverage condition is met when the communication unit avoids communication during multiple consecutive backoff periods that exceed a maximum time, or when the multiple consecutive backoff periods reach a maximum number.

[0193] Clause 30. A first node according to any one of clauses 23-29, wherein the processor is further configured to: cause the communication unit to transmit a preamble change indication to the second node so as to notify the second node that the first node will use the custom preamble for the PLC network communication.

[0194] Clause 31. A first node according to clause 30, wherein the communication unit is configured to: transmit the preamble change indication via at least one member selected from the group consisting of: a management message entry (MME) frame including the preamble change indication; an application layer protocol message including the preamble change indication; a pulse width modulation (PWM) signal having a predetermined duty cycle or sequence associated with the preamble change indication; a message including the preamble change indication, wherein the communication unit is configured to transmit the message to a central node of the PLC network to cause the central node to instruct one or more other nodes in one or more corresponding PLC networks to use the custom preamble.

[0195] Clause 32. A first node according to any one of clauses 23-31, wherein the communication unit is configured to: obtain a preamble change indication associated with the denial of service attack from the second node or the central node, wherein the preamble change indication indicates that the second node or the central node will use the custom preamble for PLC network communication from the second node.

[0196] Clause 33. A first node according to any one of clauses 23-32, wherein the processor is configured to generate correlation data associated with the denial of service attack, the correlation data being associated with the amplitude, phase, signal strength, or any combination thereof, of at least one standard preamble code included in the one or more transmissions; and wherein the communication unit is configured to ignore subsequent transmissions of the one or more transmissions that include the standard preamble code that matches the correlation data.

[0197] Clause 34. A method for a first node in a power line communication (PLC) network, comprising: establishing a PLC network via a communication medium, the PLC network including at least the first node and a second node; negotiating a custom priority resolution symbol for the PLC network; and activating countermeasures in the PLC network associated with a denial of service attack, the denial of service attack being associated with one or more transmissions injected onto the communication medium to interrupt PLC network communications, wherein activating the countermeasures comprises: utilizing the custom priority resolution symbol for priority contention in the PLC network communications.

[0198] Clause 35. The method of clause 34, wherein activating the countermeasure comprises ignoring one or more standard priority resolution symbols associated with a PLC standard specification.

[0199] Clause 36. A method according to clause 34, wherein the PLC network is associated with a PLC standard specification that specifies the operation of the PLC network, wherein the PLC standard specification includes a standard priority contention mechanism, wherein the first node or the second node uses a standard priority resolution symbol to signal their respective priorities during a priority resolution time slot (PRS), and the method further includes: utilizing a custom priority contention mechanism associated with a modification of the standard priority contention mechanism, wherein the custom priority contention mechanism includes: monitoring the custom priority resolution symbol instead of the standard priority resolution symbol.

[0200] Clause 37. A method according to clause 34, wherein the custom priority resolution symbol is different from the standard priority resolution symbol of the PLC standard specification, so that the custom priority resolution symbol is known to the first node and the second node, but is unknown to the attacking node associated with the denial of service attack, and wherein activating the countermeasure includes: adjusting the priority competition mechanism of the first node to monitor the custom priority resolution symbol instead of the standard priority resolution symbol.

[0201] As used herein, the term "component" is intended to be broadly interpreted to mean hardware, firmware, or a combination of hardware and software. As used herein, a processor is implemented using hardware, firmware, or a combination of hardware and software. As used herein, the phrase "based on" is intended to be broadly interpreted to mean "based at least in part on."

[0202] Some aspects are described herein in conjunction with thresholds. As used herein, satisfying a threshold may refer to a value being greater than a threshold, greater than or equal to a threshold, less than a threshold, less than or equal to a threshold, equal to a threshold, not equal to a threshold, and the like.

[0203] As used herein, a phrase referring to "at least one of" or "one or more of" a list of items refers to any combination of those items (including single members). For example, "at least one of a, b, or c" is intended to cover the following possibilities: only a, only b, only c, a combination of a and b, a combination of a and c, a combination of b and c, and a combination of a, b, and c.

[0204] The various exemplary components, logic, logic blocks, modules, circuits, operations, and algorithmic processes described in conjunction with the implementations disclosed herein may be implemented as electronic hardware, firmware, software, or a combination of hardware, firmware, or software (including the structures disclosed in this specification and their structural equivalents). Generally, to illustrate this interchangeability between hardware, firmware, and software, the various exemplary components, blocks, modules, circuits, and processes are generally described above in terms of their functionality. Whether such functionality is implemented as hardware, firmware, or software depends on the specific application and the design constraints imposed on the overall system.

[0205] A general purpose single-chip or multi-chip processor, digital signal processor (DSP), application specific integrated circuit (ASIC), field programmable gate array (FPGA) or other programmable logic device (PLD), discrete gate or transistor logic device, discrete hardware components, or any combination thereof for performing the functions described herein may be used to implement or execute the hardware and data processing apparatus for implementing the various exemplary components, logic, logic blocks, modules, and circuits described in conjunction with the aspects disclosed herein. A general purpose processor may be a microprocessor, or the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, a combination of one or more microprocessors and a DSP core, or any other such configuration. In some implementations, specific processes, operations, and methods may be performed by circuitry specific to a given function.

[0206] As described above, in some aspects, the implementation of the subject matter described in this specification can be implemented as software. For example, the various functions of the components disclosed herein, or the various boxes or steps of the methods, operations, processes or algorithms disclosed herein can be implemented as one or more modules of one or more computer programs. Such a computer program may include non-temporary processor-executable instructions or computer-executable instructions embodied in one or more tangible processors or computer-readable storage media to be executed or controlled by a data processing device (which includes components of the equipment described herein). For example, but not limitation, such a storage medium may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, disk storage or other magnetic storage device, or any other medium that can be used to store program code in the form of instructions or data structures. The above combination should also be included in the scope of protection of the storage medium.

[0207] Various modifications to the implementations described in this disclosure will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other implementations without departing from the spirit or scope of this disclosure. Therefore, the present invention is not limited to the implementations shown herein, but is intended to be accorded the widest scope consistent with the disclosure, principles, and novel features disclosed herein.

[0208] In addition, various features described in this specification in the context of different implementations may also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation may also be implemented in multiple implementations individually or in any suitable subcombination. Thus, although some features are described above as operating in a specific combination (even if initially claimed as such), in some cases, one or more features of a claimed combination may be cut out of that combination, and a claimed combination may be specific to a particular subcombination or variant of a subcombination.

[0209] Similarly, although operations are described in a particular order in the accompanying drawings, it should not be understood that in order to obtain the desired result, these operations must be performed in the particular order shown or in a serial order, or that all of the illustrated operations must be performed. In addition, the accompanying drawings schematically depict one or more exemplary processes in the form of flow charts or block diagrams. However, other operations not described may be incorporated into the exemplary processes illustrated. For example, one or more additional operations may be performed before, after, simultaneously with, or between the illustrated operations. In certain circumstances, multitasking and parallel processing are advantageous. Furthermore, the division of the various system components in the implementations described above should not be understood as requiring such division in all implementations. Instead, it should be understood that the described program components and systems can generally be integrated into a single software product or packaged into multiple software products. In addition, other implementations also fall within the scope of protection of the appended claims. In some cases, the actions set forth in the claims can be performed in a different order and still obtain the desired result.

Claims

1. A method for a first node in a power line communication (PLC) network, comprising: Establishing a PLC network via a communication medium, the PLC network including at least the first node and the second node; Negotiating a custom preamble for the PLC network; as well as activating a countermeasure in the PLC network associated with a denial of service attack associated with one or more transmissions injected onto the communication medium to disrupt PLC network communications, wherein activating the countermeasure comprises utilizing the custom preamble for PLC network communications between the first node and the second node.

2. The method according to claim 1, further comprising: processing at least a first transmission of the one or more transmissions in association with a PLC frame format of a PLC standard specification; as well as The countermeasure is activated when the first transmission includes a first portion that complies with the PLC standard specification and a second portion that conflicts with the PLC standard specification.

3. The method according to claim 1, further comprising: attempting to process the one or more transmissions in association with a PLC frame format specified by a PLC standard, wherein the PLC frame format includes at least a preamble portion, a frame control (FC) portion, and a payload portion; counting a number of error conditions associated with failures to process the preamble portion, the FC portion, the payload portion, or any combination thereof; and When the number of error conditions is above a process error threshold, the countermeasure is activated.

4. The method according to claim 3, wherein: The failure to process the preamble portion, the FC portion, the payload portion, or any combination thereof comprises a failure to process the first transmission associated with at least one error condition selected from the group consisting of: the preamble portion of the first transmission is invalid or incomplete; the FC portion of the first transmission is invalid or omitted; a cyclic redundancy check (CRC) error associated with the FC portion of the first transmission; the FC portion of the first transmission includes an invalid beacon timestamp (BTS) delimiter; the FC portion of the first transmission includes an invalid value for a Management Medium Access Control (MAC) frame Flow Command field or a Management MAC frame Flow Response field; the payload portion of the first transmission is invalid or omitted; The first transmission ends before expiration of a Virtual Carrier Sense (VCS) timer, which is otherwise typically associated with the end of a valid PLC frame; and The first transmission is identical to a previous transmission of the one or more transmissions.

5. The method according to claim 1, wherein The one or more transmissions include a plurality of transmissions, the method further comprising: attempting to process the plurality of transmissions in association with a PLC frame format specified by a PLC standard; counting a number of cyclic redundancy check (CRC) errors associated with the plurality of transmissions; and When the number of CRC errors is above a CRC error threshold, the countermeasure is activated.

6. The method according to claim 1, further comprising: attempting to process a first transmission of the one or more transmissions in association with a PLC frame format of a PLC standard specification; as well as The countermeasure is activated when the first transmission includes an invalid value in a frame control (FC) portion of the first transmission.

7. The method according to claim 6, wherein: The invalid value comprises a first beacon timestamp (BTS) value in the first transmission that is inconsistent with an expected BTS value, the expected BTS value being associated with one or more previous BTS values ​​of one or more corresponding previous transmissions and an amount of time between the one or more corresponding previous transmissions.

8. The method according to claim 1, further comprising: receiving a current medium access control (MAC) frame flow state indicated in a frame control (FC) portion of a current transmission of the one or more transmissions; as well as The countermeasure is activated when the current MAC frame flow state is inconsistent with an expected MAC frame flow state, wherein the expected MAC frame flow state is derived from a previous MAC frame flow state of a previous transmission of the one or more transmissions.

9. The method according to claim 8, wherein The previous MAC frame flow state is a management MAC frame flow command or a management MAC frame flow response, and the expected MAC frame flow state is the other of the management MAC frame flow command or the management MAC frame flow response.

10. The method according to claim 1, further comprising: In association with a carrier sense multiple access (CSMA) mechanism, periodically evaluating a busy condition of the communication medium; Counting the number of busy conditions over a period of time; and When the number of busy conditions is above a busy threshold, the countermeasure is activated.

11. The method according to claim 1, in, the PLC network is associated with a PLC standard specification that specifies operation of the PLC network, Wherein, the PLC standard specification includes a standard carrier sense multiple access (CSMA) mechanism, in which the first node or the second node avoids communicating via the communication medium during a backoff period after observing a communication with a standard preamble, and the method further includes: A custom CSMA mechanism is utilized in association with a modification of the standard CSMA mechanism, wherein the custom CSMA mechanism includes monitoring the custom preamble instead of the standard preamble.

12. The method according to claim 1, wherein Activating the countermeasure includes overriding a Carrier Sense Multiple Access (CSMA) mechanism of the PLC network when an overriding condition associated with the denial of service attack is met.

13. The method according to claim 12, wherein: The coverage condition is satisfied when a signal strength metric of the one or more transmissions is below a signal strength threshold, and wherein the signal strength threshold is associated with any combination of: a threshold value associated with said signal strength metric, a dynamic threshold associated with the number of authenticated nodes in the PLC network, a reference signal strength associated with previous communications between the first node and the second node, a fixed offset value associated with the reference signal strength, or A dynamic offset value is associated with a number of CSMA collisions on the communication medium.

14. The method according to claim 12, wherein: The CSMA mechanism includes: the first node generally avoiding communication via the communication medium during a backoff period after observing communication having a PLC frame format specified by the PLC standard, and wherein the coverage condition is met when the first node avoids communication during multiple consecutive backoff periods that exceed a maximum time, or when the multiple consecutive backoff periods reach a maximum number.

15. The method according to claim 1, wherein The custom preamble differs from a standard preamble of a PLC standard specification such that the custom preamble is known to the first node and the second node but is unknown to an attacking node associated with the denial of service attack, and wherein activating the countermeasure comprises: A carrier sense multiple access (CSMA) mechanism of the first node is adjusted to monitor the custom preamble instead of the standard preamble.

16. The method according to claim 1, wherein Activating the countermeasures also includes: A preamble change indication is transmitted to the second node to inform the second node that the first node will use the custom preamble for the PLC network communication.

17. The method according to claim 16, wherein Transmitting the preamble change indication includes transmitting the preamble change indication in a management message entry (MME) frame or an application layer protocol message.

18. The method according to claim 16, wherein Transmitting the preamble change indication includes sending a pulse width modulated (PWM) signal having a predetermined duty cycle or sequence associated with the preamble change indication.

19. The method according to claim 1, wherein Activating the countermeasures involves: Transmitting to a central node of the PLC network causes the central node to instruct one or more other nodes in one or more corresponding PLC networks to utilize the custom preamble.

20. The method according to claim 1, wherein Activating the countermeasures involves: A preamble change indication associated with the denial of service attack is received from the second node or the central node, wherein the preamble change indication indicates that the second node or the central node is to use the custom preamble for the PLC network communications from the second node.

21. The method according to claim 1, wherein Activating the countermeasures involves: generating correlation data associated with the denial of service attack, the correlation data associated with the amplitude, phase, signal strength, or any combination thereof, of at least one standard preamble included in the one or more transmissions; and A physical (PHY) layer of the first node is adjusted to ignore subsequent ones of the one or more transmissions that include the standard preamble that matches the correlation data.

22. The method according to claim 1, wherein Negotiating the custom preamble includes transmitting the custom preamble in an encrypted message, a Management Message Item (MME) frame, or an application layer protocol message.

23. A first node for use in a power line communication (PLC) network, comprising: a communication unit configured to establish a PLC network through a communication medium, the PLC network including at least the first node and the second node; as well as a processor communicatively coupled to the communication unit, the processor configured to: negotiating a custom preamble for the PLC network; and activating a countermeasure in the PLC network associated with a denial of service attack associated with one or more transmissions injected onto the communication medium to disrupt PLC network communications, The communication unit is configured to: when the countermeasure is activated, utilize the custom preamble for PLC network communication between the first node and the second node.

24. The first node according to claim 23, wherein: The processor is further configured to: processing at least a first transmission of the one or more transmissions in association with a PLC frame format of a PLC standard specification; and The countermeasure is activated when the first transmission includes a first portion that complies with the PLC standard specification and a second portion that conflicts with the PLC standard specification.

25. The first node according to claim 23, wherein: The processor is further configured to: attempting to process the one or more transmissions in association with a PLC frame format specified by a PLC standard, wherein the PLC frame format includes at least a preamble portion, a frame control (FC) portion, and a payload portion; counting a number of error conditions associated with failures to process the preamble portion, the FC portion, the payload portion, or any combination thereof; and When the number of error conditions is above a process error threshold, the countermeasure is activated.

26. The first node according to claim 25, wherein: The failure to process the preamble portion, the FC portion, the payload portion, or any combination thereof comprises a failure to process the first transmission associated with at least one error condition selected from the group consisting of: the preamble portion of the first transmission is invalid or incomplete; the FC portion of the first transmission is invalid or omitted; a cyclic redundancy check (CRC) error associated with the FC portion of the first transmission; the FC portion of the first transmission includes an invalid beacon timestamp (BTS) delimiter; the FC portion of the first transmission includes an invalid value for a Management Medium Access Control (MAC) frame Flow Command field or a Management MAC frame Flow Response field; the payload portion of the first transmission is invalid or omitted; The first transmission ends before expiration of a Virtual Carrier Sense (VCS) timer, which is otherwise typically associated with the end of a valid PLC frame; and The first transmission is identical to a previous transmission of the one or more transmissions.

27. The first node according to claim 23, wherein: The processor is further configured to override a carrier sense multiple access (CSMA) mechanism of the PLC network when an override condition associated with the denial of service attack is met.

28. The first node according to claim 27, wherein: The coverage condition is satisfied when a signal strength metric of the one or more transmissions is below a signal strength threshold, and wherein the signal strength threshold is associated with any combination of: a threshold value associated with said signal strength metric, a dynamic threshold associated with the number of authenticated nodes in the PLC network, a reference signal strength associated with previous communications between the first node and the second node, a fixed offset value associated with the reference signal strength, or A dynamic offset value is associated with a number of CSMA collisions on the communication medium.

29. The first node according to claim 27, wherein: The CSMA mechanism includes: the communication unit generally avoiding communication via the communication medium during a backoff period after observing communication having a PLC frame format specified by the PLC standard, and wherein the coverage condition is met when the communication unit avoids communication during multiple consecutive backoff periods that exceed a maximum time, or when the multiple consecutive backoff periods reach a maximum number.

30. The first node according to claim 23, wherein: The processor is further configured to: The communication unit is caused to transmit a preamble change indication to the second node to inform the second node that the first node will use the custom preamble for the PLC network communication.

31. The first node according to claim 30, wherein: The communication unit is configured to transmit the preamble change indication via at least one member selected from the group consisting of: a management message entry (MME) frame including the preamble change indication; an application layer protocol message including the preamble change indication; a pulse width modulated (PWM) signal having a predetermined duty cycle or sequence associated with the preamble change indication; as well as A message including the preamble change indication, wherein the communication unit is configured to transmit the message to a central node of the PLC network to cause the central node to instruct one or more other nodes in one or more corresponding PLC networks to use the custom preamble.

32. The first node according to claim 23, wherein: The communication unit is configured to: A preamble change indication associated with the denial of service attack is obtained from the second node or the central node, wherein the preamble change indication indicates that the second node or the central node is to use the custom preamble for PLC network communications from the second node.

33. The first node according to claim 23, in, The processor is configured to generate correlation data associated with the denial of service attack, the correlation data associated with the amplitude, phase, signal strength, or any combination thereof, of at least one standard preamble included in the one or more transmissions; and The communication unit is configured to ignore a subsequent transmission of the one or more transmissions that includes the standard preamble matching the correlation data.

34. A method for a first node in a power line communication (PLC) network, comprising: Establishing a PLC network via a communication medium, the PLC network including at least the first node and the second node; negotiating a custom priority resolution symbol for the PLC network; as well as activating a countermeasure in the PLC network associated with a denial of service attack associated with one or more transmissions injected onto the communication medium to disrupt PLC network communications, wherein activating the countermeasure comprises utilizing the custom priority resolution symbol for priority contention in the PLC network communications.

35. The method according to claim 34, wherein Activating the countermeasure includes ignoring one or more standard priority resolution symbols associated with the PLC standard specification.

36. The method according to claim 34, in, the PLC network is associated with a PLC standard specification that specifies operation of the PLC network, The PLC standard specification includes a standard priority contention mechanism, in which the first node or the second node uses a standard priority resolution symbol to signal the respective priority of the first node or the second node during a priority resolution slot (PRS), and the method further includes: A custom priority contention mechanism is utilized in association with a modification of the standard priority contention mechanism, wherein the custom priority contention mechanism includes monitoring the custom priority resolution symbol instead of the standard priority resolution symbol.

37. The method of claim 34, wherein: The custom priority resolution symbol differs from a standard priority resolution symbol of a PLC standard specification, such that the custom priority resolution symbol is known to the first node and the second node but is unknown to an attacking node associated with the denial of service attack, and wherein activating the countermeasure comprises: A priority contention mechanism of the first node is adjusted to monitor the custom priority resolution symbol instead of the standard priority resolution symbol.

Citation Information

Patent Citations

  • Systems and methods for network destination based flood attack mitigation

    US20150207815A1