Secure Direct Link Setup in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless network standards, such as IEEE 802.11e/D13.0, lack adequate security measures for direct links between stations, leading to insufficient security levels and design flaws like unspecified key generation, lack of identity binding, and absence of a handshake procedure for verifying key derivation.
Innovation Solution
Implementing a secure direct link setup using Robust Security Network Association (RSNA) links with fresh key generation for each session, a 4-Way Handshake for key verification, and computationally secure key distribution mechanisms to ensure only intended recipients can access the shared session key, addressing the security flaws in existing standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If direct links between stations are established using DLS protocol, then network flexibility and reach are improved, but security level deteriorates due to insufficient security measures
Solution Approach 1:
The patent introduces an access point as an intermediary to facilitate secure key distribution between stations establishing direct links. The access point generates and distributes pairwise transient keys to stations, ensuring that even though stations communicate directly, the key management remains centralized and secure through the intermediary access point.
Solution Approach 2:
The patent implements preliminary key generation and distribution before direct link communication begins. The access point pre-establishes pairwise transient keys with each station and distributes them before the stations initiate direct communication, ensuring security measures are in place before data transmission starts.
2Reliability
If security measures are added to DLS protocol, then security level is improved, but protocol complexity worsens due to unspecified key generation and lack of handshake procedures
Solution Approach 1:
The patent applies the existing Robust Security Network Association (RSNA) framework, designed for station-access point communication, to also handle direct station-to-station link security. This universal application of RSNA provides a proven, standardized security mechanism that reduces protocol complexity compared to designing a completely new security system for direct links.
Solution Approach 2:
The patent implements a 4-way handshake procedure between stations to verify key derivation and ensure mutual authentication. This feedback mechanism allows stations to confirm that they have correctly derived the same pairwise transient key, providing verification without requiring complex external authentication infrastructure.
3Reliability
If fresh key generation is implemented for each session, then security is improved, but key management complexity worsens
Solution Approach 1:
The patent enables stations to autonomously generate and derive their own pairwise transient keys using the pre-distributed pairwise master key and the 4-way handshake procedure. Each station independently completes the key derivation process without requiring manual key management or complex external key distribution systems, making the process self-service and reducing overall key management complexity.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
Method and system of secured direct link set-up (DLS) for wireless networks. In accordance with aspects of the method, techniques are disclosed for setting up computationally secure direct links between stations in a wireless network in a manner that is computationally secure. A direct link comprising a new communication session is set up between first and second stations in a wireless local area network (WLAN) hosted by an access point (AP), the direct link comprising a new communication session. The AP generates a unique session key for the new communication session and transfers secured copies of the session key to each of the first and second stations in a manner under which only the first and second stations can obtain the session key. A security mechanism is then implemented on the unsecured direct link to secure the direct link between the first and second stations using a secure session key derived from the session key.