Multi-link Operating Channel Validation via OCI Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless local area networks (WLANs) face challenges in efficiently managing multi-link operating channels, particularly in mixed environments with legacy and new devices, leading to potential security vulnerabilities like man-in-the-middle attacks due to unvalidated operating channels.

Innovation Solution

Incorporating Operating Channel Information (OCI) elements and sub-elements during key protocols like Fast Initial Link Setup (FILS), 4-way handshake, and Wireless Network Management (WNM) sleep mode requests to verify and validate operating channel parameters across all setup links, preventing multi-channel man-in-the-middle attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If operating channel information is not validated during key protocols, then device compatibility and ease of operation are improved, but security reliability deteriorates due to potential man-in-the-middle attacks

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by validating operating channel information during the establishment phase of wireless connections (FILS, 4-way handshake, BSS transition, SA queries) before actual data transmission begins. This ensures security parameters are verified upfront, preventing man-in-the-middle attacks without complicating ongoing operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent makes the operating channel validation mechanism universal by implementing it across multiple key protocols (FILS, 4-way handshake, fast BSS transition, SA queries). This single validation approach serves multiple security functions across different connection scenarios, maintaining security without requiring protocol-specific customizations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If operating channel validation is implemented across all protocols, then security against multi-channel attacks is improved, but processing time and complexity increase

Engineering Contradiction:
Improvechannel validation accuracyVSAvoidprotocol processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by selectively validating operating channel information only during specific key protocols (FILS, 4-way handshake, fast BSS transition, SA queries) rather than all wireless communications. This targeted approach provides sufficient security validation without the excessive time cost of validating every single transmission.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If operating channel information is verified during establishment protocols, then prevention of unauthorized access is improved, but device compatibility with legacy systems worsens

Engineering Contradiction:
Improvenetwork security integrityVSAvoidlegacy device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary validation of operating channel information during the establishment phase (FILS, 4-way handshake, etc.) before full security protocols engage. This allows newer devices to verify channel integrity upfront while legacy devices that skip these protocols can still connect using traditional methods, maintaining backward compatibility.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230097045A1Multi-link operating channel validation
Publication Date: 2023.03.30 INTEL PRODUCTS IP LLC
  • US20230097045A1 patent drawing
  • US20230097045A1 patent drawing
  • US20230097045A1 patent drawing

AI summary

Methods, apparatuses, and computer readable media for dynamic puncturing with dynamic signaling are disclosed. Apparatuses of a non-access point (AP) station (STA) or of an AP are disclosed, where the apparatuses comprise processing circuitry configured to: encode, by a first non-AP station (STA) of the non-AP MLD, a first physical (PHY) protocol data unit (PPDU) for transmission to a first AP of an AP MLD, the first PPDU comprising a MLO OCI element, MLO OCI KDE 1000, or a MLO OCI. The processing circuitry is further configured to decode, by the first non-AP STA of the non-AP MLD, a second PPDU in response to the first PPDU, the second PPDU including a MLO OCI element, MLO OCI KDE, or a MLO OCI. The non-AP STA is configured to verify the information in an MLO OCI element, MLO OCI KDE, or an MLO OCI.