KEK Derivation in Authentication Frames via RSNXE Capability Bit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication standards, such as 802.11bh D2.0, lack an extensible mechanism for deriving and encrypting Key Encryption Keys (KEK) in Pre-Association Security Negotiation (PASN) frames, which is necessary for secure data exchange in advanced Wi-Fi applications like Wi-Fi Direct.

Innovation Solution

A KEK frame encryption system is proposed that introduces a new capability bit in the Robust Security Network Extension Element (RSNXE) to indicate support for KEK derivation during authentication frame exchange. This system allows for the derivation of KEK if both devices support it and if a Pairwise Transient Key Security Association (PTKSA) is derived, enabling encryption of contents beyond device ID and IRM using the NIST AES Key Wrap procedure or AES-SIV.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing wireless communication standards (802.11bh D2.0) are used for PASN frame exchange, then device compatibility is maintained, but extensibility for advanced applications like Wi-Fi Direct is limited

Engineering Contradiction:
Improveextensibility for advanced applicationsVSAvoidcomplexity of encryption mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal KEK derivation mechanism that can be applied across multiple authentication scenarios including Wi-Fi Direct, Fine Timing Measurement (FTM), and other location-based services. The capability bit in RSNXE indicates support for this extensible mechanism, allowing a single framework to serve multiple advanced applications without requiring separate encryption mechanisms for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If KEK derivation is implemented for all authentication frames, then security is improved, but processing overhead and complexity increase

Engineering Contradiction:
Improvesecurity of data exchangeVSAvoidcomplexity of key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies encryption selectively based on local requirements. The capability bit in RSNXE allows devices to indicate support for KEK derivation, and encryption is applied only when both devices support it and when specific authentication scenarios require enhanced security. This localized application of encryption avoids unnecessary processing overhead while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The KEK is derived in advance during the authentication frame exchange before actual data transmission. The capability negotiation happens preliminarily through the RSNXE element, allowing both devices to agree on the encryption mechanism before committing to the security protocol, thus avoiding last-minute complexity during data exchange.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If encryption of authentication frame contents is enabled, then confidentiality is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveconfidentiality of authentication dataVSAvoidauthentication frame processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent encrypts only specific portions of the authentication frame that contain sensitive information, rather than encrypting the entire frame. The NIST AES Key Wrap procedure or AES-SIV is applied selectively to authentication data elements, achieving necessary confidentiality while reducing computational overhead compared to full-frame encryption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250126482A1Eapol-key encryption key derivation and encryption in authentication frame
Publication Date: 2025.04.17 INTEL CORP
  • US20250126482A1 patent drawing
  • US20250126482A1 patent drawing
  • US20250126482A1 patent drawing

AI summary

This disclosure describes systems, methods, and devices related to KEK frame encryption. A device may identify, within a received authentication frame, a capability bit in a Robust Security Network Extension Element (RSNXE) indicating peer device support for Key Encryption Key (KEK) derivation during an authentication frame exchange. The device may derive the KEK during the authentication frame exchange based on mutual support for KEK derivation and derivation of a Pairwise Transient Key Security Association (PTKSA) during the exchange. The device may use a cryptographic key protection process for deriving the KEK. The device may encrypt a portion of the authentication frame using the derived KEK.