Multi-Link Wireless MAC Verification During Secure Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-link wireless communication environments, the exchange of unencrypted information during the association process between access points and stations is vulnerable to attacks, leading to potential manipulation of medium access control addresses and subsequent communication failures or delays.

Innovation Solution

The proposed solution involves exchanging medium access control addresses of individual access points and stations during the beacon discovery or association process, followed by a handshake operation to verify authenticity and generate encryption keys, ensuring secure communication links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unencrypted information is exchanged during the association process, then the association process is simple and fast, but the security of the communication is compromised and MAC addresses can be manipulated

Engineering Contradiction:
ImprovesecurityVSAvoidassociation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing MAC address verification and encryption key generation during the association process itself, rather than as a separate subsequent step. The AP MLD verifies the STA MLD's MAC addresses and generates encryption keys before establishing the communication link, thereby preventing unauthorized access and address manipulation from the outset while maintaining association process efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces encryption keys as an intermediary mechanism that mediates between the association process and secure communication. These keys are generated during the association process and used to encrypt subsequent communications, thereby providing security without requiring complex separate authentication protocols while preventing MAC address manipulation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MAC addresses are verified using encryption keys during handshake, then security is improved, but the association process time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidassociation process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the authentication verification and encryption key generation operations into the existing handshake process. By combining these security functions with the standard association procedures rather than implementing them as separate sequential steps, the patent achieves robust MAC address verification and authentication while minimizing additional time overhead

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies self-service by having the STA MLD and AP MLD autonomously perform mutual verification of MAC addresses and generate encryption keys during their own association process without requiring additional external authentication infrastructure or prolonged external verification procedures, thereby maintaining speed while improving security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250358610A1Multi-link wireless communication security
Publication Date: 2025.11.20 QUALCOMM INC
  • US20250358610A1 patent drawing
  • US20250358610A1 patent drawing
  • US20250358610A1 patent drawing

AI summary

This disclosure provides systems, methods, and apparatuses for wireless communication performed by a wireless communication device. An example wireless communication device includes an access point (AP) multi-link device (MLD). The AP MLD transmits a beacon frame to a wireless station (STA) MLD, the beacon frame including a plurality of AP medium access control (MAC) addresses of respective APs belonging to the AP MLD. The AP MLD receives an association request from the STA MLD, the association request including a plurality of STA MAC addresses of respective STAs belonging to the STA MLD. The AP MLD generates, during a handshake operation with the STA MLD, one or more encryption keys configured to encrypt communications between the AP MLD and the STA MLD. The AP MLD verifies the plurality of STA MAC addresses based at least in part on the one or more encryption keys.