Wireless Distance Measurement Integrity Code Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The IEEE 802.11mc Wi-Fi Round Trip Time (RTT) methods are vulnerable to security threats, as rogue devices can manipulate distance measurements by impersonating legitimate responders, leading to incorrect range calculations.
Innovation Solution
Incorporating integrity codes generated using a shared key through arithmetic-logic operations, such as cryptographic hash functions, within wireless distance measurement messages to authenticate and verify the authenticity of these messages between devices, ensuring secure and accurate range calculations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Wi-Fi RTT measurement operations are implemented without integrity codes, then measurement operations can be performed in legacy systems, but security vulnerabilities allow rogue devices to impersonate legitimate responders and manipulate distance measurements
Solution Approach 1:
An integrity code (IC) is introduced as an intermediary element that mediates between the measurement data and the authentication mechanism. The IC is generated by executing an arithmetic-logic operation on measurement data using a shared key, and is included in measurement frames to enable verification without requiring full encryption infrastructure. This resolves the contradiction by providing security (improving reliability) through a relatively simple additive component (worsening device complexity minimally).
Solution Approach 2:
The patent changes the parameter of message authentication from none (in legacy systems) to integrity codes generated via arithmetic-logic operations. By modifying the measurement frames to include IC fields and changing the authentication state from unverified to verified, the system achieves security enhancement without requiring complete protocol redesign, thus balancing reliability improvement with acceptable complexity increase.
2Reliability
If integrity codes are generated and verified using shared keys, then authentication of measurement messages is achieved, but additional computational operations are required
Solution Approach 1:
The integrity code mechanism uses computationally inexpensive arithmetic-logic operations (such as hash functions) that can be executed quickly and with minimal energy consumption. Rather than employing heavy cryptographic protocols, the patent uses lightweight IC generation and verification that consume minimal energy, making the authentication process efficient enough for battery-powered wireless devices while still providing reliable message authentication.
3Reliability
If rogue devices send FTM measurement frames without proper authentication, then they can trick initiating devices into deriving wrong distance measurements, but implementing authentication requires IEEE 802.11ax or future technologies which are not yet available
Solution Approach 1:
The integrity code mechanism is designed to be universal and compatible with legacy IEEE 802.11mc systems while also being applicable to future standards. The IC can be included in various measurement frame types (FTM requests, FTM measurements, NDP frames) and works with existing shared key mechanisms. This multi-functionality allows the same authentication approach to protect measurement operations across different Wi-Fi standards and time periods, resolving the contradiction between security reliability and standard compatibility.
Data Source
AI summary
A method can include transmitting a request with a request integrity code (IC), receiving a first message at a time t2, executing a validation operation on the first measurement message that includes an operation on at least a portion of the first measurement message with a key. In response to the first measurement message being determined invalid, indicating time t2 as invalid. A second measurement message can be transmitted at a time t3. A third measurement message can be received that includes two remote time values t1 and t4. In response to times t1 to t4 being determined to be valid, a first distance value can be calculated with the times t1 to t4. First and second messages can include ICs generated by executing the operation on the corresponding messages with the key. Corresponding devices and systems are also disclosed.


