802.11 Multi-Link Encryption Using Link-Independent Address Fields

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-link operations (MLO) compliant with the IEEE 802.11 standard, the immutable fields in frame headers cannot be changed after encryption, leading to decryption issues as the recipient lacks necessary link information, rendering the message undecryptable.

Innovation Solution

Setting certain address fields in the AAD to known values, such as all zeros, allows encryption to occur without knowledge of the specific link, enabling decryption by the intended recipient.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If address fields in frame headers are set to link-specific values before encryption, then decryption can be performed correctly, but the system cannot adapt to dynamic link selection in multi-link operations

Engineering Contradiction:
Improveadaptability to different linksVSAvoiddecryption reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the address fields into two categories: immutable fields (BSSID, transmitter address, receiver address) that remain unchanged and are used for encryption, and mutable fields (duration, identifier, sequence control) that can be modified after encryption. This segmentation allows the encryption process to use stable link-independent values while permitting link-specific modifications after encryption, resolving the contradiction between adaptability and decryption reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by performing encryption before link selection and transmission. The address fields are set to predetermined values (such as BSSID for transmitter address and receiver address for receiver address) before encryption occurs, ensuring that the encryption process is link-independent. After encryption, the mutable fields can be updated with link-specific information, allowing the system to adapt to different links while maintaining decryption capability.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If address fields are modified after encryption to reflect link information, then the message can be routed correctly, but the recipient cannot decrypt the message due to missing link information

Engineering Contradiction:
Improvemessage routingVSAvoidlink information for decryption
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the frame structure into immutable address fields used for encryption and mutable information fields that can be modified. The immutable fields (BSSID, transmitter address, receiver address) contain the necessary link-independent information for decryption, while the mutable fields (duration, identifier, sequence control) can be updated with link-specific routing information after encryption without affecting decryption capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary approach where the encryption process uses predetermined address values as intermediaries that bridge the gap between link-independent encryption requirements and link-specific transmission needs. These intermediary values (BSSID, receiver address) serve as stable references for both encryption and decryption while allowing flexible link selection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If link-specific address values are used in encryption, then decryption works correctly, but the system lacks flexibility for multi-link operations

Engineering Contradiction:
Improvedecryption correctnessVSAvoidmulti-link operation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by using link-independent address values (BSSID for transmitter address, receiver address for receiver address) that serve multiple functions: they enable correct encryption and decryption while also being applicable across multiple links. This universal approach allows the same encryption process to work regardless of which specific link is selected for transmission, providing both reliability and flexibility for multi-link operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260032433A1Encryption enhancement for multi-link operation in 802.11
Publication Date: 2026.01.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20260032433A1 patent drawing
  • US20260032433A1 patent drawing
  • US20260032433A1 patent drawing

AI summary

Systems and methods are provided for encryption enhancement for a multi-link operation. Various subsets of addresses (or all addresses) associated with the frame are set to a determined known value, allowing encryption of the mac protocol data unit (MPDU) at a controller without knowledge of which particular link the frames will be sent. The multi-link devices (MLDs) used in the above communication may conduct communications in compliance with the IEEE 802.11be standard.