Secure Block Acknowledgment with Protected MAC Sequence Number
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IEEE 802.11 security methods fail to protect the sequence number field in transmitted data frames and control frames, making them vulnerable to denial of service attacks and sequence number manipulation.
Innovation Solution
Implementing a method to protect the sequence number field by generating a packet number value based on the sequence number, which is then used to encrypt the payload data and message integrity code, ensuring that only valid sequence numbers are used in communication, thereby preventing forged sequence numbers and denial of service attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sequence number field is left unprotected in IEEE 802.11 frames, then device complexity and processing overhead are reduced, but the system becomes vulnerable to denial of service attacks and sequence number manipulation
Solution Approach 1:
The patent merges the sequence number protection mechanism with the existing payload encryption process by using the same packet number (PN) derivation function. The PN is derived from the sequence number and used both to encrypt the payload and to protect the sequence number field, eliminating the need for separate protection mechanisms and reducing overall system complexity while maintaining security.
Solution Approach 2:
The patent introduces a packet number (PN) as an intermediary value that mediates between the sequence number and the encryption process. The PN is derived from the sequence number using a deterministic function and is then used to encrypt both the payload and protect the sequence number field, providing a unified security mechanism that prevents denial of service attacks without significantly increasing complexity.
2Reliability
If sequence number protection is implemented using encryption, then security against manipulation is improved, but processing time and energy consumption increase
Solution Approach 1:
The patent combines sequence number protection with payload encryption into a single operation. The packet number (PN) derived from the sequence number is used as the encryption key for both the payload and the sequence number field itself, eliminating the need for separate encryption operations and reducing total processing time while ensuring integrity of the sequence number.
3Ease of operation
If forged sequence numbers are allowed, then ease of operation and compatibility are maintained, but system security and data integrity are compromised
Solution Approach 1:
The patent uses the packet number (PN) as an intermediary that provides cryptographic protection for the sequence number field. The PN is derived from the sequence number using a deterministic function known to both transmitter and receiver, allowing legitimate devices to maintain simple operations while forged sequence numbers are automatically detected and rejected due to invalid PN verification.
Data Source
AI summary
Aspects of a method and system for protected MAC sequence numbers, as well as secure block acknowledgment (block ACK) with protected MAC sequence number are presented. In one aspect of the system a communicating station (STA) may protect the sequence number (SN) field portion of transmitted protocol data units (PDUs), for example data MAC layer PDUs (MPDUs), or frames. In another aspect of the system, starting sequence number (SSN) information communicated via control frames, such as block acknowledgment request (BAR) and block acknowledgment (BA) frames, may be protected. In another aspect of the system, communicating STAs may exchange management frames to enable the protection of SN information in data MPDUs and/or the protection of SSN values in control MPDUs.


