AP Key Verification for Downlink Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless local area networks (WLANs), the lack of a security protection mechanism for the PS-POLL frame allows third-party stations to impersonate target stations, leading to data theft and communication disruption, compromising network security and performance.

Innovation Solution

Generating and verifying a key by the access point (AP) and station (STA) to secure downlink data requests, ensuring only authorized STAs receive data, thereby preventing impersonation attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the PS-POLL frame is used without security protection to allow STAs to request downlink data, then the ease of operation is improved, but the network security deteriorates due to impersonation attacks

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing a security mechanism before the impersonation attack can occur. The AP generates a unique identifier for each STA in advance, and this identifier is embedded in the downlink data packets. When an STA requests data, the AP can verify the request against the pre-established identifier, preventing third-party impersonation before it can compromise network security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a security verification mechanism is implemented for downlink data requests, then the network security is improved, but the device complexity increases due to key generation and verification processes

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming the security verification approach from complex cryptographic key exchange to a simpler identifier-based verification system. Instead of implementing full encryption/decryption protocols, the system changes the verification parameter to use pre-generated unique identifiers that are easier to process and verify, thereby reducing device complexity while maintaining network security.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If the AP sends downlink data to any STA that sends a PS-POLL frame, then the productivity is improved, but the loss of information increases due to data theft by third-party stations

Engineering Contradiction:
ImproveproductivityVSAvoiddata theft
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies feedback by implementing a verification loop where the AP checks whether the STA sending the PS-POLL frame is the legitimate recipient of the downlink data before actually transmitting the data. The feedback mechanism involves comparing the requester's identity with the intended recipient identified in the downlink data packet, preventing data theft while maintaining efficient data delivery to authorized STAs.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2874423B1Data transmission method, access point and station
Publication Date: 2017.10.04 HUAWEI TECH CO LTD
  • EP2874423B1 patent drawingFigure 1~2
  • EP2874423B1 patent drawingFigure 3~5
  • EP2874423B1 patent drawingFigure 6~7

AI summary

The present invention provides a method for transmitting data, an access point and a station. The method includes: generating a key; sending the key to a station; receiving a downlink data request frame; verifying the downlink data request frame according to the key and obtaining a verification result; sending downlink data to the station if the verification result is that the downlink data request frame is correct. In the embodiments of the present invention, the key is generated, the key is sent to the station, and after the downlink data request frame is received, if the downlink data request frame is verified to be correct according to the key, the downlink data is sent to the station, thus a third party station may be prevented from pretending to be the station to steal the downlink data, such that the network security may be ensured.