Multi-link Device Security Association Query Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless local-area networks (WLANs), ensuring secure communication and managing security associations between multi-link devices (MLDs) is challenging, especially when dealing with attacks or restarts that disrupt key management, leading to potential unauthorized associations or disassociations.
Innovation Solution
Implementing a multi-link device (MLD) security association query system that expands the existing security association query mechanism to include retry timeouts and maximum timeouts for SA query requests and responses between MLDs, allowing for verification of association states and key management through protected SA query requests and responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security association query mechanism is implemented in multi-link devices, then security against unauthorized associations is improved, but device complexity and protocol overhead increase
Solution Approach 1:
The security association query mechanism is segmented into distinct components: individual SA query request frames for each link, separate timeout parameters (retry timeout and maximum timeout) for each link, and link-specific security association information elements. This segmentation allows the complex security verification to be broken down into manageable per-link operations rather than requiring complex global state management across all links simultaneously.
Solution Approach 2:
The patent introduces a new temporal dimension to the security association query by adding timeout mechanisms (retry timeout and maximum timeout) that operate independently for each link. This temporal dimensionality allows the system to handle security verification asynchronously and independently per link, reducing the complexity of synchronous coordination across multiple links while maintaining security integrity.
2Reliability
If retry timeouts and maximum timeouts are added to SA query requests, then security against attacks is improved, but communication overhead and processing time increase
Solution Approach 1:
The timeout parameters (retry timeout and maximum timeout) are pre-configured and stored in the device before actual security association queries are performed. These preliminary timeout settings allow the device to immediately enforce time constraints on SA query requests without requiring real-time calculation or coordination, thereby preventing attack scenarios while minimizing processing delays during actual operations.
Solution Approach 2:
The retry timeout mechanism implements periodic re-attempts of security association queries at predetermined intervals. Instead of continuous polling or immediate re-transmission, the system waits for the configured retry timeout period before attempting another query, which reduces communication overhead and processing time while still providing robust security verification against attacks.
3Reliability
If MLD expands SA query mechanism to include multiple links, then network security is improved, but device complexity and management overhead increase
Solution Approach 1:
The security association query mechanism is designed with universal applicability across multiple links by using a common frame structure that can carry link-specific security association information elements. The same SA query request frame format and processing logic can be applied to any number of links, allowing the system to maintain enhanced network security across multi-link configurations without requiring separate management procedures for each link.
Data Source
AI summary
Multi-link device (MLD) security association (SA) query and query response procedures are described. Any of the links between an access point (AP) MLD and a non-AP MLD may be used to initiate association, reassociation, or disassociation procedures using the SA query requests and responses. The SA query request or response from one of the stations (STAs) associated with the MLD is sent to a corresponding linked one of the STAs associated with the other MLD. The SA request or response is addressed to the other MLD rather than the STA of the other MLD. Retry timeouts and maximum timeouts for resending SA query requests are set by the AP MLD and the same across each of the links.


