Multi-link Device Security Association Query Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless local-area networks (WLANs), ensuring secure communication and managing security associations between multi-link devices (MLDs) is challenging, especially when dealing with attacks or restarts that disrupt key management, leading to potential unauthorized associations or disassociations.

Innovation Solution

Implementing a multi-link device (MLD) security association query system that expands the existing security association query mechanism to include retry timeouts and maximum timeouts for SA query requests and responses between MLDs, allowing for verification of association states and key management through protected SA query requests and responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security association query mechanism is implemented in multi-link devices, then security against unauthorized associations is improved, but device complexity and protocol overhead increase

Engineering Contradiction:
Improvesecurity association validityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security association query mechanism is segmented into distinct components: individual SA query request frames for each link, separate timeout parameters (retry timeout and maximum timeout) for each link, and link-specific security association information elements. This segmentation allows the complex security verification to be broken down into manageable per-link operations rather than requiring complex global state management across all links simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new temporal dimension to the security association query by adding timeout mechanisms (retry timeout and maximum timeout) that operate independently for each link. This temporal dimensionality allows the system to handle security verification asynchronously and independently per link, reducing the complexity of synchronous coordination across multiple links while maintaining security integrity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If retry timeouts and maximum timeouts are added to SA query requests, then security against attacks is improved, but communication overhead and processing time increase

Engineering Contradiction:
Improvesecurity against attacksVSAvoidquery processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The timeout parameters (retry timeout and maximum timeout) are pre-configured and stored in the device before actual security association queries are performed. These preliminary timeout settings allow the device to immediately enforce time constraints on SA query requests without requiring real-time calculation or coordination, thereby preventing attack scenarios while minimizing processing delays during actual operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The retry timeout mechanism implements periodic re-attempts of security association queries at predetermined intervals. Instead of continuous polling or immediate re-transmission, the system waits for the configured retry timeout period before attempting another query, which reduces communication overhead and processing time while still providing robust security verification against attacks.

Inventive Principle:
Principle #19Periodic action

3Reliability

If MLD expands SA query mechanism to include multiple links, then network security is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security association query mechanism is designed with universal applicability across multiple links by using a common frame structure that can carry link-specific security association information elements. The same SA query request frame format and processing logic can be applied to any number of links, allowing the system to maintain enhanced network security across multi-link configurations without requiring separate management procedures for each link.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12010516B2Multi-link device security association query
Publication Date: 2024.06.11 INTEL CORP
  • US12010516B2 patent drawing
  • US12010516B2 patent drawing
  • US12010516B2 patent drawing

AI summary

Multi-link device (MLD) security association (SA) query and query response procedures are described. Any of the links between an access point (AP) MLD and a non-AP MLD may be used to initiate association, reassociation, or disassociation procedures using the SA query requests and responses. The SA query request or response from one of the stations (STAs) associated with the MLD is sent to a corresponding linked one of the STAs associated with the other MLD. The SA request or response is addressed to the other MLD rather than the STA of the other MLD. Retry timeouts and maximum timeouts for resending SA query requests are set by the AP MLD and the same across each of the links.