Secure Ranging via Zeroed Guard Interval NDP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face challenges in accurately determining distances between devices, especially in environments where GPS is unavailable or unreliable, and are vulnerable to malicious attacks that can manipulate distance measurements.
Innovation Solution
The method involves generating a null data packet (NDP) with specific training fields for range measurement signal exchange sessions, using orthogonal frequency division multiplexing (OFDM) symbols, and setting guard interval samples to zero, to prevent replay attacks and ensure accurate time-of-arrival determination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional ranging methods are used in WLAN systems, then distance measurement capability is provided, but the system becomes vulnerable to replay attacks and malicious manipulation
Solution Approach 1:
The patent applies asymmetry by setting guard interval samples to zero while maintaining non-zero training field samples. This asymmetric configuration creates a unique signal pattern that prevents replay attacks, as malicious devices cannot replicate the exact zeroed guard interval structure. The asymmetric treatment of different signal portions (zeroing GI but not training fields) provides security while maintaining measurement capability.
Solution Approach 2:
The patent changes the parameter values of guard interval samples from their traditional non-zero values to zero. This parameter modification creates a detectable signature that authenticates the ranging signal. By changing the GI parameter to zero while keeping training field parameters non-zero, the system establishes a verifiable signal structure that resists replay attacks without compromising the ranging function.
2Measurement precision
If guard intervals are preserved in training fields, then signal structure is maintained, but time of arrival determination becomes vulnerable to manipulation
Solution Approach 1:
The patent extracts the guard interval portion from the training field structure and sets its samples to zero. This extraction and zeroing isolates the vulnerable GI component from the measurement process. By removing the GI's traditional protective function and replacing it with a zeroed signature, the patent eliminates the vulnerability while preserving the essential training field structure needed for accurate time of arrival determination.
3Reliability
If complex number values are used for OFDM subcarriers, then security against replay attacks is enhanced, but signal processing complexity increases
Solution Approach 1:
The patent employs periodic action through the use of complex number values in OFDM subcarriers, which create a structured, repeating pattern in the frequency domain. This periodic structure in the complex values provides security because it creates a predictable yet unique signature that can be verified without requiring complex processing. The periodic nature of complex exponential sequences in OFDM enables efficient generation and verification while maintaining security.
Data Source
AI summary
In a range measurement signal exchange session between a first communication device and a second communication device, the first communication device generates an NDP, which includes: generating a plurality of training fields to be used by the second communication device to determine a time of arrival of the NDP. Each training field corresponds to a respective orthogonal frequency divisional multiplexing (OFDM) symbol. Generating the plurality of training fields includes: i) setting signal samples corresponding to guard intervals between the OFDM symbols to zero, and ii) for each OFDM symbol, setting a plurality of frequency domain values corresponding to OFDM sub carriers of the OFDM symbol to complex number values. The first communication device transmits the NDP as part of the range measurement signal exchange session.


