Wake-Up Radio Cryptographic Authentication Against Replay Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
WUR devices are susceptible to replay attacks, where malicious entities capture and replay WUR signals to cause unnecessary power consumption, leading to battery drainage.
Innovation Solution
Implement secure WUR signal transmission and reception methods, including cryptographic authentication and unique salt values to verify the authenticity of WUR frames, ensuring only genuine signals trigger device wake-up.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If WUR devices operate in low power mode with simplified signals, then power consumption is reduced and battery life is extended, but security vulnerability increases due to ease of signal capture and reproduction
Solution Approach 1:
The patent applies preliminary action by incorporating cryptographic authentication mechanisms and unique salt values into WUR frames before transmission. The access point pre-generates cryptographic context including salt values and authentication data, which are embedded in the WUR frames. This preliminary preparation ensures that even though the WUR signal itself is simple and low-power, the embedded cryptographic elements provide security protection against replay attacks, thus resolving the contradiction between low power consumption and security vulnerability
Solution Approach 2:
The patent uses cryptographic authentication data and salt values as intermediaries between the low-power WUR signal and the security requirements. These intermediary elements are embedded within the WUR frame structure, allowing the simple low-power signal to carry sufficient authentication information. The cryptographic intermediaries enable the receiver to verify authenticity without requiring complex signal processing, thus maintaining low power consumption while improving security
2Reliability
If cryptographic authentication is added to WUR frames, then security against replay attacks is improved, but frame complexity and processing overhead increase
Solution Approach 1:
The patent applies universality by designing the cryptographic authentication mechanism to serve multiple functions simultaneously. The same cryptographic context and salt values are used for both authentication purposes and for generating unique frame identifiers. The authentication data embedded in WUR frames serves both to verify legitimacy and to prevent replay attacks, eliminating the need for separate complex authentication protocols. This multi-functionality reduces overall frame complexity while maintaining strong security
Solution Approach 2:
The patent changes parameters by using variable salt values that are incorporated into the cryptographic context for each WUR frame or frame batch. By dynamically changing the salt parameter, the system generates different authentication data for different frames without requiring fundamentally different frame structures. This parameter-based approach allows flexible security implementation that adapts to different scenarios while keeping the basic frame format relatively simple and minimizing processing overhead
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure provides a communication apparatus comprising a cryptographic circuitry which, in operation, uses a shared cryptographic secret Key and a cryptographic salt to generate a cryptographically encoded Message Integrity Code (MIC) that is computed over the address field of a Wake Up Radio (WUR) frame; and a transmission signal generator which, in operation, generates a secure WUR signal by replacing the address field of the WUR frame with the MIC; and a transmitter which, in operation, transmits the secure WUR signal.