Multi-band Wireless Security via Unified Key Negotiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security aspects of IEEE 802.11 wireless communication systems, particularly with the Extremely High Throughput (EHT) protocol and multi-band devices, have not been fully standardized, leading to challenges in maintaining security during band-switching and wireless operations.

Innovation Solution

The method involves securing multi-link Access Point (AP) and Station (STA) devices by negotiating a group of keys in a key negotiation (KN) link, which authenticates devices across multiple frequency bands, and encrypting frames using a Packet Number (PN) and Additional Authentication Data (AAD) to ensure secure communication across all supported frequency links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices perform separate authentication for each frequency band, then security is maintained across all bands, but authentication overhead increases and power consumption rises

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines authentication operations across multiple frequency bands into a single unified authentication process. When a device authenticates on one band, the authentication credentials and security context are shared across all bands, eliminating the need for separate authentication procedures on each band while maintaining security across the entire multi-band system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication mechanism is designed to be universal across all frequency bands. A single authentication credential obtained on any band can be used to access all other bands, making the authentication system multi-functional rather than band-specific. This reduces authentication overhead while maintaining security across the multi-band wireless communication system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If devices perform separate authentication for each frequency band, then security is maintained across all bands, but power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges authentication operations across multiple frequency bands into a single unified process. By combining authentication credentials and security contexts, the system eliminates redundant authentication transactions that would otherwise consume additional power, while maintaining security across all bands through shared authentication state.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If devices reauthenticate when switching between bands, then security is maintained, but communication bandwidth and reliability decrease

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication bandwidth
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs authentication in advance on a single band, and the resulting credentials are cached and reused when switching between bands. This preliminary authentication action eliminates the need for reauthentication during band switching, maintaining security while ensuring continuous communication without interruptions that would reduce bandwidth and reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11272364B2Security in a multi-band wireless communication system
Publication Date: 2022.03.08 NXP USA INC
  • US11272364B2 patent drawing
  • US11272364B2 patent drawing
  • US11272364B2 patent drawing

AI summary

A method for securing a multi-band wireless communication system includes authenticating a first station (STA) multi-link device (MLD) with a second STA MLD comprising negotiating a group of keys in a key negotiation (KN) band, the group of keys comprising a Pair-Wise Transient Key and a Group Transient Key. The KN band is one of a plurality of frequency bands. The first STA MLD includes a plurality of first STA links. The second STA MLD includes a plurality of second STA links. Each of first STA links and each corresponding second STA link are configured to transceive over a respective one of the plurality of frequency bands. Authenticating the first STA MLD in the KN band authenticates the first STA MLD for each of the frequency bands.