Preventing MAC header and control frame playback attacks in wireless communications
By setting the data packet number as a time value in wireless communication and utilizing TSF timestamps, the problem of MAC header and control frame replay attacks is solved, achieving more efficient security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-09
- Publication Date
- 2026-03-31
AI Technical Summary
In the prior art, the receiver cannot determine whether the packet number (PN) of the Media Access Control (MAC) header is incremented, which makes it impossible to effectively prevent MAC header and control frame replay attacks.
By setting the packet number (PN) as a time value and using the partial time synchronization function (TSF) timestamp as the value of PN, MAC header and control frame replay attacks can be prevented.
It effectively avoids or prevents replay attacks, ensures that the PN is not repeated in different MAC header protections, and enhances the security of wireless communication.
Smart Images

Figure CN121773648A_ABST
Abstract
Description
[0001] Cross-references
[0002] This disclosure is part of a non-provisional patent application filed on August 10, 2023, which claims priority to U.S. Provisional Patent Application No. 63 / 518,570, the contents of which are incorporated herein by reference in their entirety. Technical Field
[0003] This disclosure generally relates to wireless communications, and more specifically, to preventing Media Access Control (MAC) header and control frame replay attacks in wireless communications. Background Technology
[0004] Unless otherwise stated herein, the methods described in this section are not prior art to the claims listed below, and are not recognized as prior art by virtue of being included in this section.
[0005] In wireless communications, such as Wi-Fi (or WiFi) and wireless local area networks (WLANs) conforming to one or more Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards, preventing medium access control (MAC) header replay attacks may involve MAC header integrity checks and / or MAC header replay detection. The packet number (PN) is typically used for replay detection of MAC protocol data units (MPDUs). Specifically, the PN increments by a positive number (e.g., 1) for each MPDU. That is, the PN increments by 1 in steps, used to construct MPDUs composed of segmented MAC session data units (MSDUs), aggregated MSDUs (A-MSDUs), and MAC management protocol data units (MMPDUs). For Protocol Version 0 (PV0) MPDUs, the PN should not be repeated in a series of encrypted MPDUs using the same temporary key. For the same temporary key, the PN is incremented by a positive number (e.g., 1) for all transmitted MPDUs, and the PN used for MAC header protection will not be repeated in another MAC header protection. However, the receiver may not be able to determine whether the PN is incremented. Therefore, a protection mechanism is needed to prevent MAC header and control frame replay attacks in wireless communication. Summary of the Invention
[0006] The following summary is for illustrative purposes only and is not intended to be limiting in any way. That is, the following summary aims to introduce the concepts, highlights, benefits, and advantages of the novel and non-obvious techniques described herein. Selected embodiments will be further illustrated in the detailed description below. Therefore, the following summary is not intended to identify the essential features of the claimed subject matter, nor is it intended to determine the scope of the claimed subject matter.
[0007] The objective of this disclosure is to provide schemes, concepts, designs, techniques, methods, and apparatus relating to protection mechanisms against Media Access Control (MAC) header and control frame replay attacks in wireless communications. It is believed that implementation of the proposed schemes can solve or mitigate the aforementioned problems.
[0008] In one aspect, one approach might involve the sender generating a frame containing a packet number (PN) whose value is set to a time value. Another approach might involve the sender transmitting the frame.
[0009] In another approach, one method might involve the receiver receiving a frame containing a packet number (PN) whose value is set to a timing value. Another method might involve the receiver sending an acknowledgment (ACK) in response to the received frame.
[0010] In another aspect, a device may include a transceiver configured for wireless communication and a processor coupled to the transceiver. The processor may generate a frame containing a packet number (PN), the value of which is set to a time value. The processor may also transmit the frame.
[0011] It is worth noting that although the descriptions provided herein may be made in the context of certain wireless access technologies, networks, and network topologies (such as Wi-Fi), the proposed concepts, schemes, and any variations / derivatives thereof can be implemented in other types of wireless access technologies, networks, and network topologies, such as, but not limited to, Bluetooth, ZigBee, and 5G (5G). th Generation (5G) / New Radio (NR), Long-Term Evolution (LTE), LTE-Advanced, LTE-Advanced Pro, Internet of Things (IoT), Industrial IoT (IIoT), and Narrowband IoT (NB-IoT). Therefore, the scope of this disclosure is not limited to the examples described herein. [Attached Figure Description]
[0013] The accompanying drawings are included to provide a further understanding of this disclosure and form part of this disclosure. These drawings illustrate embodiments of the present disclosure and, together with the description, serve to explain the principles of the disclosure. It is understood that the drawings are not necessarily drawn to scale, as some components may be shown out of proportion to actual dimensions in order to clearly illustrate the concepts of the disclosure.
[0014] Figure 1This is a schematic diagram of an example network environment that can implement various solutions and schemes according to this disclosure.
[0015] Figure 2 This is a schematic diagram of an example scenario based on this disclosure.
[0016] Figure 3 This is a schematic diagram of an example scenario based on the proposed scheme of this disclosure.
[0017] Figure 4 This is a block diagram of an example communication system based on the proposed scheme of this disclosure.
[0018] Figure 5 This is a flowchart of an example process based on the proposed scheme of this disclosure.
[0019] Figure 6 This is a flowchart of an example process based on the proposed scheme of this disclosure. Detailed Implementation
[0020] This document discloses detailed embodiments and implementations of the claimed subject matter. However, it should be understood that the disclosed embodiments and implementations are merely illustrative of the claimed subject matter, which can be embodied in various forms. This disclosure can be embodied in many different forms and should not be construed as being limited to the exemplary embodiments and implementations described herein. Rather, these exemplary embodiments and implementations are intended to make the description of this disclosure comprehensive and complete, and to fully convey the scope of this disclosure to those skilled in the art. Details of well-known features and techniques may be omitted in the following description to avoid unnecessarily obscuring the presented embodiments and implementations.
[0021] Overview
[0022] Implementations of this disclosure relate to various technologies, methods, schemes, and / or solutions, concerning protection mechanisms against Media Access Control (MAC) header and control frame replay attacks in wireless communications. According to this disclosure, multiple possible solutions can be implemented individually or in combination. That is, although these possible solutions may be described separately below, two or more of these possible solutions can be implemented in one or another combination.
[0023] Figure 1 An example network environment 100 is shown in which various solutions and schemes according to this disclosure can be implemented. Figures 2 to 6 Examples of various proposed schemes implemented in network environment 100 according to this disclosure are shown. The following description of the various proposed schemes is for reference only. Figures 1 to 6 Provided.
[0024] refer to Figure 1Network environment 100 may involve at least one communication entity 110 wirelessly communicating with communication entity 120. Either communication entity 110 or communication entity 120 can act as an access point (AP) station (STA) or as a non-AP STA. In some cases, communication entity 110 (referred to herein as "STA 110") and communication entity 120 (referred to herein as "STA 120") can be associated with a basic service set (BSS) according to one or more IEEE 802.11 standards (e.g., IEEE 802.11be and / or future standards such as IEEE 802.11bn). Each of communication entity 110 and communication entity 120 can be configured to communicate by utilizing protection mechanisms against MAC header and control frame replay attacks, according to various proposed schemes described below. That is, either or both of communication entity 110 and communication entity 120 can act as a "user" in the proposed schemes and examples described below. It is worth noting that while various proposed solutions may be described individually or separately below, in practice, some or all of the proposed solutions may be used or implemented in combination. Of course, each proposed solution may be used or implemented individually or separately.
[0025] Figure 2 Example scenario 200 illustrates a protection mechanism to prevent MAC header replay attacks. In scenario 200, for the same temporary key, the PN is incremented by a positive number (e.g., 1) for all transmitted MPDUs. The PN used for MAC header protection will not be repeated in another MAC header protection. Reference Figure 2The sender (e.g., STA 110) can initially transmit an MPDU whose MAC header (for both data and management frames) contains certain information. For example, this information might indicate the power management mode (PM), sequence number (SEQ), and PN (e.g., PM = 1, SEQ = 1, PN = 1). The encrypted MSDU of the MPDU can contain another PN (e.g., PN = 10), independent of the PN contained in the MAC header. If the sender does not receive an acknowledgment (ACK) from the intended receiver (e.g., STA 120), the sender can transmit another MPDU with the PN in its MAC header incremented by 1 (e.g., PN = 2), and this time the PM can be set to a different value than the one contained in the initial MAC header (e.g., PM = 0). In the case of a replay attack, an attacker can change the power management mode of a victim STA (e.g., STA 110) by selecting one of the sets of information indicated in the MAC header of multiple MPDUs input by the sender (e.g., [PM = 1, SEQ = 1, PN = 1] or [PM = 0, SEQ = 1, PN = 2]).
[0026] Figure 3 Example scenario 300 is illustrated under a proposed scheme for preventing MAC header and control frame replay attacks according to this disclosure. Under the proposed scheme, a timing synchronization function (TSF) timestamp can be used as the value of PN to prevent MAC header and control frame replay attacks. For the same temporary key, the receiver may be able to determine whether PN is incremented and whether the receiver's protection is duplicated with another MAC header.
[0027] refer to Figure 3The sender (e.g., STA 110) can initially send an MPDU whose MAC header (for data frames and management frames) contains information indicating PM, SEQ, and PN (e.g., PM = 1, SEQ = 1, PN = TSF1). The encrypted MSDU of the MPDU can contain another PN (e.g., PN = 10), independent of the PN contained in the MAC header. If the sender does not receive an ACK from the intended receiver (e.g., STA 120), the sender can transmit another MPDU with the PN in its MAC header set to a different TSF timestamp value (e.g., PN = TSF2), and this time the PM can be set to a different value than the one contained in the initial MAC header (e.g., PM = 0). In the event of a replay attack, the attacker may be unable to generate a valid message integrity code (MIC) with the PN equal to another TSF timestamp value (e.g., PN = TSF3). Therefore, replay attacks can be effectively avoided or prevented.
[0028] It is worth noting that although the problems and examples described in this paper may be within the context of the MAC header, control frames may also be subject to similar replay attack issues. Therefore, according to the proposed scheme, in addition to MAC header protection for data frames and management frames, a portion of the TSF timestamp can also be used as the PN for control frames to prevent replay attacks.
[0029] Example Implementation
[0030] Figure 4 An example system 400, comprising at least one example device 410 and an example device 420, is illustrated according to embodiments of this disclosure. Each of devices 410 and 420 can perform various functions to implement the schemes, techniques, processes, and methods described herein for preventing MAC header and control frame replay attacks in wireless communications, including the various schemes, designs, concepts, systems, and methods described above, as well as the processes described below. For example, device 410 may be an example embodiment of a sender (e.g., STA 110), and device 420 may be an example embodiment of a receiver (e.g., STA 120).
[0031] Each of devices 410 and 420 can be part of an electronic device, which can be a STA or AP, such as a portable or mobile apparatus, a wearable apparatus, a wireless communication apparatus, or a computing apparatus. For example, each of devices 410 and 420 can be implemented in a smartphone, a smartwatch, a personal digital assistant, a digital camera, or a computing device such as a tablet computer, laptop computer, or notebook computer. Each of devices 410 and 420 can also be part of a machine-type device, such as an IoT device, such as a fixed or stationary apparatus, a home apparatus, a wire communication apparatus, or a computing device. For example, each of devices 410 and 420 can be implemented in a smart thermostat, a smart fridge, a smart door lock, a wireless speaker, or a home control center. When implemented in or as a network device, devices 410 and / or 420 can be implemented in a network node, such as an access point (AP) in a WLAN.
[0032] In some implementations, each of devices 410 and 420 may be implemented as one or more integrated circuit (IC) chips, such as, but not limited to, one or more single-core processors, one or more multi-core processors, one or more reduced-instruction-set computing (RISC) processors, or one or more complex-instruction-set computing (CISC) processors. In all the above-described embodiments, each of devices 410 and 420 may be implemented as a STA or AP. Each of devices 410 and 420 may include... Figure 4 At least some of the components shown, such as processor 412 and processor 422. Each of devices 410 and 420 may also include one or more other components (e.g., internal power supply, display device, and / or user interface device) unrelated to the proposed solutions of this disclosure; therefore, for simplicity and brevity, these components of devices 410 and 420 are not included in the above description. Figure 4 The text is not shown below.
[0033] In one aspect, each of processors 412 and 422 may be implemented as one or more single-core processors, one or more multi-core processors, one or more RISC processors, or one or more CISC processors. That is, although the singular term "processor" is used herein to refer to processors 412 and 422, each of processors 412 and 422 may include multiple processors in some embodiments and a single processor in others, according to embodiments of this disclosure. In another aspect, each of processors 412 and 422 may be implemented as hardware (and optionally firmware) whose electronic components include, for example, but not limited to, one or more transistors, one or more diodes, one or more capacitors, one or more resistors, one or more inductors, one or more memristors, and / or one or more varactors, which are configured and arranged to achieve a specific purpose according to this disclosure. In other words, in at least some embodiments, each of processors 412 and 422 is a dedicated machine specifically designed, arranged, and configured to perform a specific task, including protection mechanisms against MAC header and control frame replay attacks in wireless communications according to various embodiments of this disclosure. For example, each of processors 412 and 422 may be configured with hardware components or circuitry to implement one, some, or all of the examples described and shown herein.
[0034] In some embodiments, device 410 may further include a transceiver 416 coupled to processor 412. Transceiver 416 can wirelessly transmit and receive data. In some embodiments, device 420 may further include a transceiver 426 coupled to processor 422. Transceiver 426 may include a transceiver capable of wirelessly transmitting and receiving data.
[0035] In some embodiments, device 410 may further include a memory 414 coupled to processor 412, which can be accessed by processor 412 and stores data. In some embodiments, device 420 may further include a memory 424 coupled to processor 422, which can be accessed by processor 422 and stores data. Each of memory 414 and memory 424 may include a random-access memory (RAM), such as dynamic RAM (DRAM), static RAM (SRAM), thyristor RAM (T-RAM), and / or zero-capacitor RAM (Z-RAM). Alternatively, each of memories 414 and 424 may include a read-only memory (ROM), such as a mask ROM, a programmable ROM (PROM), an erasable programmable ROM (EPROM), and / or an electrically erasable programmable ROM (EEPROM). Alternatively, each of memories 414 and 424 may include a non-volatile random-access memory (NVRAM), such as flash memory, solid-state memory, ferroelectric RAM (FeRAM), magnetoresistive RAM (MRAM), and / or phase-change memory.
[0036] Each of devices 410 and 420 can be a communication entity capable of communicating with each other using the various schemes proposed in this disclosure. For illustrative purposes and without limitation, the capabilities of device 410 as a sender (e.g., STA 110) and device 420 as a receiver (e.g., STA 120) are described below in the context of example procedures 500 and 600. It is worth noting that although the example implementations described below are provided in the context of WLAN, the same implementations can also be implemented in other types of networks. Therefore, although the description of the following example implementations pertains to a scenario where device 410 is a sending device and device 420 is a receiving device, the same description also applies to another scenario where device 410 is a receiving device and device 420 is a sending device.
[0037] Example Process
[0038] Figure 5 An example flow 500 according to an embodiment of this disclosure is shown. Flow 500 may represent one aspect of implementing the various designs, concepts, schemes, systems, and methods proposed above. More specifically, flow 500 may represent one aspect of the concepts and schemes of this disclosure relating to protection mechanisms against MAC header and control frame replay attacks in wireless communications. Flow 500 may include one or more operations, actions, or functions represented by one or more blocks 510 and 520. Although shown as discrete blocks, the individual blocks of flow 500 may be divided into additional blocks, merged into fewer blocks, or eliminated, depending on the desired implementation. Furthermore, the blocks / sub-blocks of flow 500 may be arranged according to... Figure 5 The execution can proceed in the order shown, or in a different order. Furthermore, one or more blocks / sub-blocks of process 500 can be executed repeatedly or iteratively. Process 500 can be implemented by devices 410 and 420, and any variations thereof. For illustrative purposes only and without limitation, process 500 is described below in the context of a wireless network conforming to one or more IEEE 802.11 standards, where device 410 acts as the sender (e.g., STA 110) and device 420 acts as the receiver (e.g., STA 120). Process 500 may begin at block 510.
[0039] At 510, process 500 may involve the processor 412 of device 410 generating a frame containing a PN, the value of which is set to a time value. Process 500 can proceed from 510 to 520.
[0040] At 520, process 500 may involve processor 412 sending the frame via transceiver 416 (e.g., to device 420, which is the intended recipient).
[0041] In some implementations, in response to not receiving an ACK from the intended recipient of the frame, process 500 may involve processor 412 performing additional operations. For example, process 500 may involve processor 412 generating a second frame containing another PN, the value of which is set to a different time value. Furthermore, process 500 may involve processor 412 transmitting the second frame via transceiver 416 (e.g., to device 420, the intended recipient).
[0042] In some implementations, the time value may include a portion of the TSF timestamp value.
[0043] In some implementations, when generating the frame, process 500 may involve processor 412 generating the MAC header of a data frame or management frame. Alternatively, or additionally, when generating the frame, process 500 may involve processor 412 generating a control frame.
[0044] Figure 6 An example flow 600 according to an embodiment of this disclosure is shown. Flow 600 may represent one aspect of implementing the various designs, concepts, schemes, systems, and methods proposed above. More specifically, flow 600 may represent one aspect of the concepts and schemes of this disclosure relating to protection mechanisms against MAC header and control frame replay attacks in wireless communications. Flow 600 may include one or more operations, actions, or functions represented by one or more blocks 610 and 620. Although shown as discrete blocks, the individual blocks of flow 600 may be divided into additional blocks, merged into fewer blocks, or eliminated, depending on the desired implementation. Furthermore, the blocks / sub-blocks of flow 600 may be arranged according to... Figure 6 The execution can proceed in the order shown, or in a different order. Furthermore, one or more blocks / subblocks of process 600 can be executed repeatedly or iteratively. Process 600 can be implemented by devices 410 and 420, and any variations thereof. For illustrative purposes only and without limitation, process 600 is described below in the context of a wireless network conforming to one or more IEEE 802.11 standards, where device 410 acts as the sender (e.g., STA 110) and device 420 acts as the receiver (e.g., STA 120). Process 600 may begin at block 610.
[0045] At 610, process 600 may involve the processor 422 of device 420 receiving a frame containing a PN (e.g., from device 410 as the sender) via transceiver 426, the value of which is set to a time value. Process 600 may proceed from 610 to 620.
[0046] At 620, process 600 may involve processor 422 sending an ACK (e.g., to device 410) via transceiver 426 in response to receiving the frame.
[0047] In some implementations, process 600 may involve processor 422 performing additional operations. For example, process 600 may involve processor 422 receiving a second frame via transceiver 426 containing another PN, the value of which is set to a different time value. Furthermore, process 600 may involve processor 422 sending another ACK via transceiver 426 in response to receiving the second frame.
[0048] In some implementations, the time value may include a portion of the TSF timestamp value.
[0049] In some implementations, upon receiving the frame, process 600 may involve processor 422 receiving the MAC header of a data frame or management frame. Alternatively, upon receiving the frame, process 600 may involve processor 422 receiving a control frame.
[0050] Additional Notes
[0051] The topics described herein sometimes demonstrate that different components are contained within or connected to other different components. It should be understood that the architectures depicted are merely examples, and many other architectures can actually be implemented to achieve the same functionality. Conceptually, any arrangement of components to achieve the same functionality can be effectively considered as “associated” in order to achieve the desired functionality. Therefore, any two components combined in this document to achieve a particular function can be considered as “associated” in order to achieve the desired functionality, regardless of the architecture or intermediate components. Similarly, any two such associated components can also be considered as “operably connected” or “operably coupled” in order to achieve the desired functionality, and any two components that can be suchly associated can also be considered as “operably coupled” in order to achieve the desired functionality. Specific examples of operational coupling include, but are not limited to, physically connectable and / or physically interacting components and / or wirelessly interactable and / or components undergoing wireless interaction and / or logically interacting and / or logically interactive components.
[0052] Furthermore, regarding the use of virtually any plural and / or singular terms in this document, those skilled in the art can appropriately translate them from plural to singular and / or from singular to plural based on the context and / or application. For clarity, various singular / plural permutations may be explicitly listed herein.
[0053] Furthermore, those skilled in the art will understand that the terms generally used herein, particularly in the claims, such as in the body of the claims, are generally intended to be “open” terms. For example, the word “comprising” should be interpreted as “including but not limited to,” the word “having” should be interpreted as “having at least,” and the word “including” should be interpreted as “including but not limited to,” etc. Those skilled in the art will also further understand that if a specific number of statements are explicitly introduced in the claims, this intention will be explicitly stated in the claims, and without such statements, this intention does not exist. For example, to aid understanding, the claims may include the use of introductory phrases “at least one” and “one or more” to introduce the claim statements. However, the use of these phrases should not be construed as implying that a claim introducing a claim statement by the indefinite article “one” or “a” is limited to containing only one such statement, even if the same claim includes the introductory phrases “one or more” or “at least one” and indefinite articles, for example, “one” and / or “a” should be interpreted as “at least one” or “one or more”; the same applies to the use of definite articles introducing the claim statements. Furthermore, even if a specific number of introductory claim statements are explicitly stated, those skilled in the art will recognize that such statements should be interpreted as at least the stated number; for example, simply stating "two statements" without further modification implies at least two statements, or two or more statements. Additionally, in conventions such as "at least one A, B, and C, etc.", this structure is generally intended for those skilled in the art to understand the manner of the convention; for example, "a system having at least one A, B, and C" will include, but is not limited to, systems having only A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. In conventions such as "at least one A, B, or C, etc.", this structure is generally intended for those skilled in the art to understand the manner of the convention; for example, "a system having at least one A, B, or C" will include, but is not limited to, systems having only A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. Those skilled in the art will also further understand that virtually any extractive word and / or phrase presenting two or more alternative terms, whether in the description, claims, or figures, should be understood to cover the possibility of one, any, or both of these terms. For example, the phrase “A or B” would be understood to include the possibility of “A” or “B” or “A and B”.
[0054] As can be seen from the foregoing, the various implementations of this disclosure described herein are for illustrative purposes, and various modifications can be made without departing from the scope and spirit of this disclosure. Therefore, the various embodiments disclosed herein are not intended to be limiting, and their true scope and spirit are indicated by the claims.
Claims
1. A method comprising: generating, by a processor of a device, a frame containing a packet number, the frame having a value set to a time value; and sending, by the processor, the frame. in response to not receiving an acknowledgement of the frame from an intended recipient of the frame:
2. The method of claim 1, further comprising: generating, by the processor, a second frame containing another packet number, the second frame having a value set to a different time value; and sending, by the processor, the second frame.
3. The method of claim 1, wherein the time value comprises a value of a partial time synchronization function timestamp.
4. The method of claim 1, wherein the generating of the frame comprises generating a medium access control header of a data frame or a management frame.
5. The method of claim 1, wherein the generating of the frame comprises generating a control frame.
6. A method comprising: receiving, by a processor of a device, a frame containing a packet number, the frame having a value set to a time value; and sending, by the processor, an acknowledgement in response to receiving the frame.
7. The method of claim 6, further comprising: receiving, by the processor, a second frame containing another PN, the second frame having a value set to a different time value; and sending, by the processor, another acknowledgement in response to receiving the second frame.
8. The method of claim 6, wherein the time value comprises a value of a partial time synchronization function timestamp.
9. The method of claim 6, wherein the receiving of the frame comprises receiving a medium access control header of a data frame or a management frame.
10. The method of claim 6, wherein the receiving of the frame comprises receiving a control frame.
11. A device implemented in shared in a multi-access point system, comprising: a transceiver configured to wirelessly transmit and receive; and a processor coupled with the transceiver, configured to perform operations comprising: generating a frame containing a packet number, the frame having a value set to a time value; and sending, by the transceiver, the frame. in response to not receiving an acknowledgement of the frame from an intended recipient of the frame, the processor is further configured to perform operations comprising: generating a second frame containing another PN, the second frame having a value set to a different time value; and sending, by the transceiver, the second frame.
13. The device of claim 11, wherein the time value comprises a value of a partial time synchronization function timestamp.
12. The apparatus of claim 11, wherein, 14. The device of claim 11, wherein the generating of the frame comprises generating a medium access control header of a data frame or a management frame.
15. The device of claim 11, wherein the generating of the frame comprises generating a control frame.