Multi-Link Security Key Management for Replay Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, particularly in multi-link operations, face challenges in securing management frames against replay attacks and ensuring secure key management across different links.

Innovation Solution

The proposed system introduces mechanisms for secure multi-link operation by allowing options for using the same or different pairwise master keys (PMK), pairwise transient keys (PTK), group temporal keys (GTK), and integrity group temporal keys (IGTK) across links, along with advanced key management and replay detection protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If different pairwise master keys (PMK) are used for each link in multi-link operation, then security against replay attacks is improved, but key management complexity and storage requirements increase

Engineering Contradiction:
Improvesecurity against replay attacksVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management approach by allowing different PMKs to be used for different links (e.g., 2.4 GHz link and 5 GHz link). Each link can have its own PMK, PTK, GTK, and IGTK, which are managed independently. This segmentation enables replay attack detection per link while maintaining organized key storage through separate key hierarchies for each link.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If the same pairwise master key (PMK) is used across all links, then key negotiation and storage are simplified, but security against replay attacks across different links is compromised

Engineering Contradiction:
Improvekey negotiation simplicityVSAvoidsecurity against replay attacks
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces dynamic key selection capability where the system can adaptively choose between using the same PMK across all links or different PMKs per link based on security requirements. The key management is made flexible through dynamic key derivation functions that can generate link-specific keys from a common PMK when needed, or use separate PMKs when enhanced security is required.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If separate pairwise transient keys (PTK) are generated for each link, then replay detection accuracy is improved, but key negotiation overhead increases

Engineering Contradiction:
Improvereplay detection accuracyVSAvoidkey negotiation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary key derivation where Pairwise Transient Keys (PTKs) are derived in advance from the Pairwise Master Key (PMK) before actual data transmission begins. The key negotiation process includes pre-establishing the key hierarchy and deriving all necessary keys (PTK, GTK, IGTK) during the initial association phase, so that when data transmission starts, the keys are already ready and no additional negotiation time is needed.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple integrity group temporal keys (IGTK) are used for different links, then broadcast/multicast frame security is improved, but key management complexity increases

Engineering Contradiction:
Improvebroadcast/multicast frame securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by allowing different IGTKs to be used for different links based on their specific security requirements. Each link can have its own IGTK for protecting broadcast and multicast frames, enabling tailored security approaches for each link's characteristics while maintaining overall system security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12212970B2Security for multi-link operation
Publication Date: 2025.01.28 INTEL CORP
  • US12212970B2 patent drawing
  • US12212970B2 patent drawing
  • US12212970B2 patent drawing

AI summary

This disclosure describes systems, methods, and devices related to security for multi-link operation. A device may determine a multi-link communication with a first multi-link device comprising two or more links associated with two or more station devices (STAs) included in the first multi-link device. The device may determine a first medium access control (MAC) address associated with a first link of the two or more links. The device may determine a second MAC address associated with a second link of the two or more links. The device may generate one or more pairwise security keys to be used in the multi-link communication on the two or more links. The device may cause to send a frame to the first multi-link device using at least one combination of the one or more pairwise security keys.