Secure MU Ranging via Randomized LTF and SAC Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication technologies are vulnerable to security attacks such as spoofing, denial of service, and perturbation attacks when determining distances between wireless devices, particularly in high-efficiency and very high-throughput modes, which can compromise the integrity of ranging measurements in critical applications.

Innovation Solution

A signaling procedure between initiating and responding wireless stations is implemented to protect randomized Long Training Field (LTF) sequences, using Sequence Authentication Codes (SAC) and error recovery mechanisms to secure ranging measurements in both single-user and multi-user modes, especially in High Efficiency (HEz) and Very High Throughput (VHTz) modes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If randomized LTF sequences are used for secure ranging measurements, then spoofing attack resistance is improved, but system complexity increases due to the need for SAC signaling and error recovery mechanisms

Engineering Contradiction:
Improvespoofing attack resistanceVSAvoidsignaling procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing Sequence Authentication Codes (SAC) and configuring randomized LTF sequences before ranging measurements begin. The ISTA and RSTA exchange and store SAC information in advance through signaling procedures, so that when ranging measurements occur, the authentication is already in place. This prevents spoofing attacks without requiring complex real-time authentication mechanisms during the actual measurement process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses Sequence Authentication Codes (SAC) as an intermediary element that mediates between the randomized LTF sequences and the authentication process. The SAC acts as a key that links the randomized sequences to verified identities, allowing the system to authenticate ranging measurements without exposing the actual LTF sequences. This intermediary mechanism provides security while maintaining system manageability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If LTF sequences are protected against VHT/HE Type B adversary attacks, then measurement security is improved, but the fields over which range measurements are performed become more restricted

Engineering Contradiction:
Improvemeasurement securityVSAvoidranging mode flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing security measures specifically targeted at the LTF sequences and their associated SAC fields, rather than restricting entire ranging modes. The randomized LTF sequences and SAC protection are applied locally to the measurement fields where needed, while allowing different ranging modes (SU and MU) to operate with appropriate configurations. This enables security without unnecessarily limiting adaptability across different operating scenarios.

Inventive Principle:
Principle #3Local quality

3Reliability

If error recovery mechanisms are implemented in HEz mode, then measurement reliability under attack is improved, but processing time and system overhead increase

Engineering Contradiction:
Improvemeasurement integrityVSAvoiderror recovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action for error recovery by pre-configuring SAC information and randomized LTF sequences during the initial signaling phase. When errors or attacks are detected during ranging measurements, the system can quickly switch to alternative pre-configured sequences or request retransmission of specific fields rather than performing complex real-time recovery. This reduces processing time while maintaining measurement integrity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3429248B1Secure MU ranging measurement procedure and system of same
Publication Date: 2021.06.30 MEDIATEK SINGAPORE PTE LTD
  • EP3429248B1 patent drawingFigure 1
  • EP3429248B1 patent drawingFigure 2
  • EP3429248B1 patent drawingFigure 3

AI summary

Embodiments of the present invention provide secure ranging measurements for wireless devices in multi-user (MU) mode. Specifically, a signaling procedure between an initiating wireless station (ISTA) and a responding wireless station (RSTA) is used to enable protection of randomized LTF sequences used in the secure ranging measurements. The signaling procedure may be performed in a HEz or VHTz mode and may include performing error recovery when operating in the HEz mode.