Trusted Device Cluster for Secure Wi-Fi Direct Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, particularly those based on the IEEE 802.11 standard, face challenges in the setup and coordination of direct communication between Wi-Fi mobile stations without an intermediate access point, leading to security vulnerabilities and synchronization issues in peer-to-peer networking.

Innovation Solution

The establishment of a trusted device cluster using Neighbor Awareness Networking (NAN) protocols, where wireless stations perform authentication, secure data path setup, and out-of-band verification to create a secured cluster, protecting transmissions with shared security credentials and verifying identities through Management Message Integrity Check (MIC) elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If peer-to-peer wireless communication is implemented without an intermediate access point, then device autonomy and communication flexibility are improved, but security vulnerabilities and synchronization issues worsen

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trusted device cluster as an intermediary structure among peer devices. This cluster acts as a mediator that provides authentication services, beacon protection, and synchronization coordination without requiring a central access point. The cluster head or designated authenticator verifies identities and manages security credentials for members, enabling secure peer-to-peer communication while maintaining the flexibility of direct connection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and security credentials are implemented in peer-to-peer clusters, then security protection is improved, but device complexity and setup procedures worsen

Engineering Contradiction:
Improvesecurity protectionVSAvoidsetup procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication actions during the cluster formation phase. Devices perform mutual authentication and establish security credentials before regular communication begins. The trusted device cluster pre-configures authentication mechanisms and distributes security information to members, so that once joined, devices can communicate securely without repeated complex authentication procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs feedback mechanisms where devices receive and verify authenticated beacons from trusted cluster members. The Management Message Integrity Check (MIC) provides feedback on message authenticity, allowing devices to confirm they are communicating with authorized members. This feedback loop simplifies ongoing security verification by automatically validating credentials and synchronization information.

Inventive Principle:
Principle #23Feedback

3Reliability

If beacon protection and MIC verification are implemented, then synchronization reliability is improved, but processing overhead and communication latency worsen

Engineering Contradiction:
Improvesynchronization reliabilityVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic beacon transmissions with integrated MIC verification. Instead of continuous verification, trusted devices transmit authenticated beacons at regular intervals, and members verify these beacons periodically to maintain synchronization. This periodic approach reduces processing overhead compared to constant verification while ensuring synchronization reliability through consistent time reference updates.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20220353682A1NAN Trusted Device Cluster
Publication Date: 2022.11.03 APPLE INC
  • US20220353682A1 patent drawing
  • US20220353682A1 patent drawing
  • US20220353682A1 patent drawing

AI summary

One or more wireless stations operate to configure direct communication with neighboring mobile stations, e.g., direct communication between the wireless stations without utilizing an intermediate access point. A wireless station may enter an unsynchronized discovery mode, transmit, in response to receiving a subscribe message from a neighboring device, a publish message to the neighboring device, perform authentication and trusted device cluster provisioning with the neighboring wireless device, and protect transmissions using the security credentials. In the unsynchronized discovery mode, the wireless device may monitor a discovery channel for subscribe messages, e.g., from neighboring peer devices. Additionally, the trusted device cluster provisioning may provide security credentials to the wireless device. Note that protecting transmissions using the security credentials may include protecting a trusted device cluster identity, transmitted beacons, transmitted management frames, or transmitted action frames using the security credentials acquired via the trusted device cluster provisioning.