KEK Derivation in Authentication Frames via RSNXE Capability Bit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication standards, such as 802.11bh D2.0, lack an extensible mechanism for deriving and encrypting Key Encryption Keys (KEK) in Pre-Association Security Negotiation (PASN) frames, which is necessary for secure data exchange in advanced Wi-Fi applications like Wi-Fi Direct.
Innovation Solution
A KEK frame encryption system is proposed that introduces a new capability bit in the Robust Security Network Extension Element (RSNXE) to indicate support for KEK derivation during authentication frame exchange. This system allows for the derivation of KEK if both devices support it and if a Pairwise Transient Key Security Association (PTKSA) is derived, enabling encryption of contents beyond device ID and IRM using the NIST AES Key Wrap procedure or AES-SIV.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing wireless communication standards (802.11bh D2.0) are used for PASN frame exchange, then device compatibility is maintained, but extensibility for advanced applications like Wi-Fi Direct is limited
Solution Approach 1:
The patent implements a universal KEK derivation mechanism that can be applied across multiple authentication scenarios including Wi-Fi Direct, Fine Timing Measurement (FTM), and other location-based services. The capability bit in RSNXE indicates support for this extensible mechanism, allowing a single framework to serve multiple advanced applications without requiring separate encryption mechanisms for each application.
2Reliability
If KEK derivation is implemented for all authentication frames, then security is improved, but processing overhead and complexity increase
Solution Approach 1:
The patent applies encryption selectively based on local requirements. The capability bit in RSNXE allows devices to indicate support for KEK derivation, and encryption is applied only when both devices support it and when specific authentication scenarios require enhanced security. This localized application of encryption avoids unnecessary processing overhead while maintaining security where needed.
Solution Approach 2:
The KEK is derived in advance during the authentication frame exchange before actual data transmission. The capability negotiation happens preliminarily through the RSNXE element, allowing both devices to agree on the encryption mechanism before committing to the security protocol, thus avoiding last-minute complexity during data exchange.
3Loss of information
If encryption of authentication frame contents is enabled, then confidentiality is improved, but processing time and computational resources increase
Solution Approach 1:
The patent encrypts only specific portions of the authentication frame that contain sensitive information, rather than encrypting the entire frame. The NIST AES Key Wrap procedure or AES-SIV is applied selectively to authentication data elements, achieving necessary confidentiality while reducing computational overhead compared to full-frame encryption.
Data Source
AI summary
This disclosure describes systems, methods, and devices related to KEK frame encryption. A device may identify, within a received authentication frame, a capability bit in a Robust Security Network Extension Element (RSNXE) indicating peer device support for Key Encryption Key (KEK) derivation during an authentication frame exchange. The device may derive the KEK during the authentication frame exchange based on mutual support for KEK derivation and derivation of a Pairwise Transient Key Security Association (PTKSA) during the exchange. The device may use a cryptographic key protection process for deriving the KEK. The device may encrypt a portion of the authentication frame using the derived KEK.


