Secure Block Acknowledgment with Protected MAC Sequence Number

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IEEE 802.11 security methods fail to protect the sequence number field in transmitted data frames and control frames, making them vulnerable to denial of service attacks and sequence number manipulation.

Innovation Solution

Implementing a method to protect the sequence number field by generating a packet number value based on the sequence number, which is then used to encrypt the payload data and message integrity code, ensuring that only valid sequence numbers are used in communication, thereby preventing forged sequence numbers and denial of service attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sequence number field is left unprotected in IEEE 802.11 frames, then device complexity and processing overhead are reduced, but the system becomes vulnerable to denial of service attacks and sequence number manipulation

Engineering Contradiction:
Improvesecurity against denial of service attacksVSAvoidcomplexity of security processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the sequence number protection mechanism with the existing payload encryption process by using the same packet number (PN) derivation function. The PN is derived from the sequence number and used both to encrypt the payload and to protect the sequence number field, eliminating the need for separate protection mechanisms and reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a packet number (PN) as an intermediary value that mediates between the sequence number and the encryption process. The PN is derived from the sequence number using a deterministic function and is then used to encrypt both the payload and protect the sequence number field, providing a unified security mechanism that prevents denial of service attacks without significantly increasing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If sequence number protection is implemented using encryption, then security against manipulation is improved, but processing time and energy consumption increase

Engineering Contradiction:
Improveintegrity of sequence numberVSAvoidprocessing time for frame encryption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines sequence number protection with payload encryption into a single operation. The packet number (PN) derived from the sequence number is used as the encryption key for both the payload and the sequence number field itself, eliminating the need for separate encryption operations and reducing total processing time while ensuring integrity of the sequence number.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If forged sequence numbers are allowed, then ease of operation and compatibility are maintained, but system security and data integrity are compromised

Engineering Contradiction:
Improvesimplicity of communication protocolVSAvoidvulnerability to sequence number forgery
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses the packet number (PN) as an intermediary that provides cryptographic protection for the sequence number field. The PN is derived from the sequence number using a deterministic function known to both transmitter and receiver, allowing legitimate devices to maintain simple operations while forged sequence numbers are automatically detected and rejected due to invalid PN verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8473732B2Method and system for secure block acknowledgment (block ACK) with protected MAC sequence number
Publication Date: 2013.06.25 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8473732B2 patent drawing
  • US8473732B2 patent drawing
  • US8473732B2 patent drawing

AI summary

Aspects of a method and system for protected MAC sequence numbers, as well as secure block acknowledgment (block ACK) with protected MAC sequence number are presented. In one aspect of the system a communicating station (STA) may protect the sequence number (SN) field portion of transmitted protocol data units (PDUs), for example data MAC layer PDUs (MPDUs), or frames. In another aspect of the system, starting sequence number (SSN) information communicated via control frames, such as block acknowledgment request (BAR) and block acknowledgment (BA) frames, may be protected. In another aspect of the system, communicating STAs may exchange management frames to enable the protection of SN information in data MPDUs and/or the protection of SSN values in control MPDUs.