Multi-Link Wireless Security with MAC Address Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-link wireless communication environments, the exchange of information during the association process between access points (APs) and stations (STAs) is vulnerable to attacks, as the medium access control (MAC) addresses can be spoofed, leading to insecure and potentially failed communications.

Innovation Solution

The proposed solution involves exchanging MAC addresses of APs and STAs during the beacon discovery or association process, verifying their authenticity through a handshake operation, and generating encryption keys to secure subsequent data communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If MAC addresses are exchanged during association process, then communication establishment is enabled, but security vulnerability increases due to MAC address spoofing

Engineering Contradiction:
Improveassociation processVSAvoidMAC address spoofing
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing MAC address verification during the association process before actual data transmission begins. The AP verifies the STA's MAC address against the list of authorized MAC addresses in the beacon frame, preventing spoofed devices from establishing secure connections before they can transmit sensitive data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the association process as an intermediary mechanism to verify MAC addresses. By embedding the verified MAC addresses in the beacon frame and using them during association, the system creates an intermediary verification layer that prevents direct spoofing attacks without affecting normal communication operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are generated during handshake operation, then communication security is improved, but processing time increases

Engineering Contradiction:
Improvecommunication securityVSAvoidhandshake operation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary action by generating encryption keys during the handshake operation before any actual data transmission occurs. This ensures that security credentials are established in advance, allowing for faster data transmission afterward without repeated key generation overhead.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If MAC address verification is performed, then unauthorized access is prevented, but association process complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidassociation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using the existing beacon frame and association process to serve multiple functions: network announcement, authorized device listing, and MAC address verification. This multi-functionality approach adds security without requiring separate verification protocols or additional message exchanges.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12401995B2Multi-link wireless communication security
Publication Date: 2025.08.26 QUALCOMM INC
  • US12401995B2 patent drawing
  • US12401995B2 patent drawing
  • US12401995B2 patent drawing

AI summary

This disclosure provides systems, methods, and apparatuses for wireless communication performed by a wireless communication device. An example wireless communication device includes an access point (AP) multi-link device (MLD). The AP MLD transmits a beacon frame to a wireless station (STA) MLD, the beacon frame including a plurality of AP medium access control (MAC) addresses of respective APs belonging to the AP MLD. The AP MLD receives an association request from the STA MLD, the association request including a plurality of STA MAC addresses of respective STAs belonging to the STA MLD. The AP MLD generates, during a handshake operation with the STA MLD, one or more encryption keys configured to encrypt communications between the AP MLD and the STA MLD. The AP MLD verifies the plurality of STA MAC addresses based at least in part on the one or more encryption keys.