Invalid Location Measurement Report Indication for Replay Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems lack a mechanism to differentiate between range estimation errors caused by noise and those caused by replay attacks or jamming during the ranging procedure in IEEE 802.11az, which can lead to incorrect security measures and compromised ranging services.
Innovation Solution
The introduction of an Invalid LMR indication system that includes a parameter field in the location measurement report (LMR) to indicate the presence of a replay attacker or jammer, allowing the initiator to distinguish between noise-induced and interference-induced errors, enabling appropriate security actions such as disabling the ranging service or switching to another responder.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If no invalid measurement indication is provided in the measurement report, then the device complexity is reduced, but the reliability of ranging service is compromised due to inability to detect replay attacks or jamming
Solution Approach 1:
The measurement report is segmented to include a separate invalid measurement indication field that specifically flags replay attacks or jamming conditions. This segmentation allows the system to maintain the existing measurement report structure while adding a dedicated security indicator, thus improving reliability without significantly increasing overall complexity.
Solution Approach 2:
An intermediary invalid measurement indication field is introduced as a mediator between the measurement processing system and the security verification system. This intermediary element carries security status information without requiring fundamental changes to either the measurement reporting mechanism or the security protocol, resolving the contradiction between reliability and complexity.
2Object-affected harmful factors
If an invalid measurement indication system is implemented, then the security against replay attacks is improved, but the difficulty of detecting and measuring attacks increases due to need for additional detection mechanisms
Solution Approach 1:
The attack detection function is extracted from the general measurement processing and isolated into a specific invalid measurement indication mechanism. By taking out the security verification aspect as a separate, dedicated function, the system can improve replay attack resistance without significantly increasing the overall difficulty of attack detection, as the extraction allows for specialized, optimized detection logic.
Solution Approach 2:
The system performs preliminary validation of measurement data by checking for invalid measurement indications before processing ranging calculations. This preliminary action detects potential replay attacks or jamming early in the measurement report processing chain, improving security while keeping detection complexity manageable through early filtering rather than complex analysis throughout the entire processing pipeline.
3Loss of information
If measurement reports include attack indication, then the loss of information about attack conditions is reduced, but the quantity of data transmitted increases
Solution Approach 1:
The invalid measurement indication is implemented as a lightweight, single-bit or small-field indicator that is discarded after its security verification purpose is fulfilled. This disposable information element provides crucial attack condition information without significantly increasing the quantity of data transmitted, as it uses minimal bandwidth compared to full measurement data.
Solution Approach 2:
Rather than transmitting comprehensive attack analysis data throughout the entire measurement report, the system applies local quality by inserting a specific, targeted invalid measurement indication field only where needed for security verification. This localized approach reduces information loss about attack conditions while minimizing the quantity of additional data transmitted.
Data Source
AI summary
This disclosure describes systems, methods, and devices related to an invalid location measurement report (LMR) indication. A device may identify a first null data packet (NDP) received from a first station device during, wherein the first NDP is used for channel sounding. The device may perform a time of arrival (ToA) calculation based on the NDP. The device may determine an invalid indication associated with the first NDP based on the ToA calculation. The device may generate an LMR comprising of the invalid measurement indication. The device may cause to send the LMR to the first device.


