Secure Direct Link Setup in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless network standards, such as IEEE 802.11e/D13.0, lack adequate security measures for direct links between stations, leading to insufficient security levels and design flaws like unspecified key generation, lack of identity binding, and absence of a handshake procedure for verifying key derivation.

Innovation Solution

Implementing a secure direct link setup using Robust Security Network Association (RSNA) links with fresh key generation for each session, a 4-Way Handshake for key verification, and computationally secure key distribution mechanisms to ensure only intended recipients can access the shared session key, addressing the security flaws in existing standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If direct links between stations are established using DLS protocol, then network flexibility and reach are improved, but security level deteriorates due to insufficient security measures

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an access point as an intermediary to facilitate secure key distribution between stations establishing direct links. The access point generates and distributes pairwise transient keys to stations, ensuring that even though stations communicate directly, the key management remains centralized and secure through the intermediary access point.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary key generation and distribution before direct link communication begins. The access point pre-establishes pairwise transient keys with each station and distributes them before the stations initiate direct communication, ensuring security measures are in place before data transmission starts.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security measures are added to DLS protocol, then security level is improved, but protocol complexity worsens due to unspecified key generation and lack of handshake procedures

Engineering Contradiction:
Improvesecurity levelVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the existing Robust Security Network Association (RSNA) framework, designed for station-access point communication, to also handle direct station-to-station link security. This universal application of RSNA provides a proven, standardized security mechanism that reduces protocol complexity compared to designing a completely new security system for direct links.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a 4-way handshake procedure between stations to verify key derivation and ensure mutual authentication. This feedback mechanism allows stations to confirm that they have correctly derived the same pairwise transient key, providing verification without requiring complex external authentication infrastructure.

Inventive Principle:
Principle #23Feedback

3Reliability

If fresh key generation is implemented for each session, then security is improved, but key management complexity worsens

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables stations to autonomously generate and derive their own pairwise transient keys using the pre-distributed pairwise master key and the 4-way handshake procedure. Each station independently completes the key derivation process without requiring manual key management or complex external key distribution systems, making the process self-service and reducing overall key management complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP1943812B1Method and readable storage medium for setting up secure direct links between wireless network stations using direct link set-up (DLS) protocol
Publication Date: 2015.09.09 INTEL CORP
  • EP1943812B1 patent drawingFigure 1
  • EP1943812B1 patent drawingFigure 2~3
  • EP1943812B1 patent drawingFigure 4

AI summary

Method and system of secured direct link set-up (DLS) for wireless networks. In accordance with aspects of the method, techniques are disclosed for setting up computationally secure direct links between stations in a wireless network in a manner that is computationally secure. A direct link comprising a new communication session is set up between first and second stations in a wireless local area network (WLAN) hosted by an access point (AP), the direct link comprising a new communication session. The AP generates a unique session key for the new communication session and transfers secured copies of the session key to each of the first and second stations in a manner under which only the first and second stations can obtain the session key. A security mechanism is then implemented on the unsecured direct link to secure the direct link between the first and second stations using a secure session key derived from the session key.