Communication system with secure access point discovery function

By employing a pre-association security negotiation process between the access point and the site, and using the AP identity key to encrypt the privacy beacon and generate the STA identifier, the problems of excessive latency and resource consumption in the communication system are solved, achieving secure and efficient data transmission.

CN122373003APending Publication Date: 2026-07-10APPLE INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
APPLE INC
Filing Date
2026-01-08
Publication Date
2026-07-10

Smart Images

  • Figure CN122373003A_ABST
    Figure CN122373003A_ABST
Patent Text Reader

Abstract

A communication system with secure access point discovery capability is provided. The system allows communication between a Basic Service Set (BSS) Privacy Enhancement (BPE) Access Point (AP) and a BPE Site (STA). Prior to association, the STA generates an STA-ID by inputting the current addresses of both the AP and the STA, along with the AP's identity key, into a hash algorithm. The STA can discover the AP using a Pre-Association Security Negotiation (PASN) procedure. The STA can send a PASN MSG1 containing the STA-ID to the AP. The AP can use the STA-ID to verify that the STA is authorized to receive AP security parameters. In response to successful verification, the AP can send a PASN MSG2 to the STA. The STA and AP can use information from the PASN message to derive a Transient Key (TK) and can transmit a management frame encrypted using the TK. The management frame can be used to associate the STA with the AP.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to U.S. Patent Application No. 19 / 427,792, filed December 19, 2025, and U.S. Provisional Patent Application No. 63 / 743,540, filed January 9, 2025, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This disclosure relates in its entirety to wireless communications, including wireless communications conducted by electronic devices. Background Technology

[0003] Communication systems and methods are used to transmit wireless data between nodes in a communication network. Nodes may include user equipment, wireless access points, wireless base stations, or other electronic devices.

[0004] Ensuring that a communication system exhibits sufficient performance can be challenging. If not handled carefully, communication between nodes in a network may exhibit excessive latency, consume too many resources, or fail to provide adequate data security. Summary of the Invention

[0005] A communication system is provided in which an access point (AP) communicates with a station (STA) (e.g., under the 802.11 protocol). The AP may be a Basic Service Set (BSS) Privacy Enhancement (BPE) AP. The STA may be a BPE STA. The AP may send a privacy beacon to the STA. The AP may use its identity key to encrypt the privacy beacon. The privacy beacon may identify the AP's current address. Before associating with the AP, the STA may generate an STA identifier (STA-ID) by inputting at least the AP's current address, the STA's current address, and the AP's identity key into a cryptographic function.

[0006] A STA can perform a scanning process to discover and associate with an AP. This scanning process can be a Pre-Association Security Negotiation (PASN) process. The STA can send a first PASN message (PASN MSG1) to the AP, including its STA-ID. The AP can use the STA-ID from PASNMSG1 to verify that the STA is authorized to receive a set of AP security parameters. In response to verifying the STA's authorization, the AP can send a second PASN message (PASN MSG2) to the STA. The STA and AP can use the information from the PASN messages to derive the same transient key (TK). The STA can then send a management frame encrypted using the TK along with the AP. The STA can use the management frame to associate with the AP.

[0007] If needed, the PASN MSG1 sent by the STA may include an AP security parameter request field, indicating that the STA requires AP security parameters from the AP. The AP may send the AP security parameters to the STA, which is TK encrypted. If needed, the AP may send the AP security parameters to the STA after a delay period for the instantaneous key adoption. If needed, the delay period may be selected based on the instantaneous key adoption delay of the STA included in PASN MSG1 and / or the instantaneous key adoption delay of the AP included in PASN MSG2. Attached Figure Description

[0008] Figure 1 This is a diagram illustrating an exemplary wireless communication system based on some implementation schemes.

[0009] Figure 2 This is a schematic diagram of an exemplary wireless station (STA) based on some implementation schemes.

[0010] Figure 3 This is a schematic diagram of an exemplary wireless access point (AP) based on some implementation schemes.

[0011] Figure 4 It is a flowchart illustrating the exemplary operation of performing wireless communication between an AP and a STA according to some implementation schemes.

[0012] Figure 5 This is a timing diagram of the pre-scanning of an exemplary association between STA and AP according to some implementation schemes.

[0013] Figure 6 This is a diagram illustrating how an exemplary STA can be generated for use in a pre-association scan according to some embodiments.

[0014] Figure 7 It is a sequence diagram of the security parameter query prior to the exemplary association between STA and AP according to some implementation schemes.

[0015] Figure 8 These are illustrations of two examples of exemplary payloads for pre-association security negotiation messages that may be transmitted between the STA and AP during pre-association communication according to some implementation schemes.

[0016] Figure 9 This is another exemplary sequence diagram of the pre-security parameter query between STA and AP according to some implementation schemes. Detailed Implementation

[0017] Figure 1An example of a wireless communication system 108 (sometimes referred to herein as wireless communication network 108, communication network 108, network 108, or system 108) is shown. It should be noted that... Figure 1 This represents one of many possibilities, and the features of this disclosure can be implemented as needed through any of various systems. For example, the embodiments described herein can be implemented in any type of wireless device. The wireless implementation described below is an example implementation.

[0018] like Figure 1 As shown, an exemplary wireless communication system 108 includes an access point (AP) 104 that communicates with one or more wireless devices 106 (e.g., a first wireless device 106A, a second wireless device 106B, etc.) via a transmission medium. Wireless devices 106A and 106B may be user equipment (e.g., user equipment (UE) devices), such as a station (STA), a non-AP STA, or a wireless local area network (WLAN) device. Wireless device 106 is sometimes referred to herein as STA 106 or client 106.

[0019] STA 106 can be a device with wireless network connectivity, such as a mobile (e.g., cellular) phone, a handheld device, a wearable device (e.g., a wristwatch, a pendant, a ringer, a head-mounted device, such as a virtual, mixed, and / or augmented reality headset, goggles, a helmet, or glasses), a computer (e.g., a desktop computer, a laptop computer, a computer monitor containing an embedded computer, etc.), a tablet computer, a media player, headphones, one or two wireless earbuds, a television, a gaming device or console, a navigation device, an embedded system (such as a system in which electronic equipment with a display is installed in a kiosk or a car), a voice-controlled speaker with wireless internet connectivity, a home entertainment device, a remote control device, a game controller, a user input device, a peripheral device or accessory, an electronic stylus or pen, an unmanned aerial vehicle (UAV), an unmanned control unit (UAC), a car, computing equipment integrated into a vehicle or kiosk, equipment that enables the functionality of two or more of these devices, or virtually any type of wireless device.

[0020] STA 106 may include a processor (processing element) configured to execute program instructions stored in memory. STA 106 may execute any method implementation of the method embodiments described herein by executing such stored instructions. Alternatively or additionally, STA 106 may include any of the following programmable hardware elements: a field-programmable gate array (FPGA), an integrated circuit, and / or various other possible hardware components configured to (e.g., individually or in combination) execute any method implementation of the method embodiments described herein or any portion thereof.

[0021] The wireless communication system 108 may include one or more wireless access points (APs), such as AP 102. AP 102 may be a standalone AP or a corporate AP, and may include hardware capable of enabling wireless communication with STA 106, such as STA 106A and STA 106B. AP 102 may also be equipped to communicate with network 100 (e.g., a WLAN, a corporate network, and / or another communication network connected to the Internet, and various other possible networks). Thus, AP 102 may facilitate communication between STA 106 and / or between STA 106 and network 100. AP 102 may be configured to provide communication via one or more wireless technologies such as IEEE 802.11 a, b, g, n, ac, ad, ax, ay, be, bn and / or other 802.11 versions, or cellular protocols such as 5G or LTE, including in an unlicensed frequency band (LAA).

[0022] Network 100 may include any desired number of network nodes, terminals, and / or end hosts communicatively coupled together using communication paths including wired and / or wireless links. Wired links may include cables (e.g., Ethernet cables, fiber optic cables or other optical cables that transmit signals using light, telephone cables, radio frequency cables such as coaxial cables, or other transmission lines, etc.). Wireless links may include short-range wireless communication links operating within a range of a few inches, a few feet, or tens of feet; medium-range wireless communication links operating within a range of hundreds of feet, thousands of feet, several miles, or tens of miles; and / or long-range wireless communication links operating within a range of hundreds or thousands of miles.

[0023] The nodes of network 100 may be organized into one or more relay networks, mesh networks, local area networks (LANs), wireless local area networks (WLANs), ring networks (e.g., optical rings), cloud networks, virtual / logical networks, the Internet (e.g., networks communicatively coupled to each other via the Internet), combinations of these, and / or any other desired network topology. Network nodes, endpoints, and / or end hosts of network 100 may include network switches, network routers, optical add-drop multiplexers, other multiplexers, repeaters, modems, portals, gateways, servers, network interface cards (NICs) (line cards), wireless access points, wireless base stations, and / or any other desired network components. Network nodes in network 100 may include physical components such as electronic devices, servers, computers, network cabinets, line cards, user equipment, etc., and / or may include virtual components logically defined in software and distributed across two or more underlying physical devices (above them) (e.g., in a cloud network configuration).

[0024] The communication area (or coverage area) of AP 102 (or AP 104) may be referred to as the Basic Service Area (BSA) or cell. AP 102 (or AP 104) and STA 106 can be configured to communicate over a transmission medium using any of a variety of Radio Access Technologies (RATs) or wireless communication technologies such as Wi-Fi, LTE, LTE-A Advanced, 5G NR, Ultra Wideband (UWB), etc. A given RAT may, for example, specify the physical method used to implement the corresponding communication protocol (e.g., WLAN protocol, Wireless Personal Area Network (WPAN) protocol, cellular phone protocols such as 3G, 4G (LTE), 5G (NR), etc., UWB protocol, satellite communication protocol, satellite navigation protocol, device-to-device (D2D) protocol, etc.).

[0025] Therefore, AP 102, AP 104, and other similar access points (not shown) operating according to one or more wireless communication technologies can be configured as a network that can, for example, provide continuous or nearly continuous overlapping services to STA106A and 106B and similar devices within a geographical area via one or more communication technologies. For example, a STA can roam directly from one AP to another, or can switch between APs and cellular network cells.

[0026] It should be noted that, at least in some cases, the STA 106 may be able to communicate using any of a variety of wireless communication technologies. For example, the STA 106 can be configured to communicate using one or more of Wi-F, LTE, LTE-A, 5G NR, Bluetooth, UWB, one or more satellite systems, etc. Other combinations of wireless communication technologies (including more than two wireless communication technologies) are also possible. Similarly, in some cases, the STA 106 can be configured to communicate using only a single wireless communication technology.

[0027] like Figure 1 As shown, the exemplary wireless communication system 108 may also include an access point (AP) 104, which communicates with the wireless device 106B via a transmission medium. AP 104 also provides a communication connection to network 100. Therefore, according to some embodiments, a wireless device may be able to connect to one or both of AP 102 (or a cellular base station (BS)) and AP 104 (or another access point) to access network 100. For example, a STA may roam from AP 102 to AP 104 based on one or more factors such as coverage, interference, and capability. It should be noted that AP 104 may also allow access to networks different from those allowed by AP 102 (e.g., enterprise Wi-Fi networks, home Wi-Fi networks, etc.).

[0028] In some specific implementations, STA 106 (e.g., STA 106A and 106B) may include handheld devices such as smartphones or tablets, wearable devices such as smartwatches or smart glasses, and / or may include any device of various types with wireless communication capabilities. For example, one or more of STA 106A and / or STA 106B may be wireless devices designed for stationary or nomadic deployments, such as home appliances, measuring devices, control devices, etc.

[0029] STA 106B can also be configured to communicate with STA 106A. For example, STA 106A and STA 106B may be able to perform direct device-to-device (D2D) communication. In some implementations, this direct communication between STAs may also be referred to as, or alternatively as, peer-to-peer (P2P) communication. Direct communication may be supported by AP 102 (e.g., easily discoverable by AP 102, and with various possible forms of assistance), or may be performed in a manner not supported by AP 102. Depending on the implementation, this P2P communication may be performed using any of the following communication technologies: 3GPP-based D2D communication technology, Wi-Fi-based P2P communication technology, UWB, Bluetooth (BT), and / or various other direct communication technologies.

[0030] STA 106 may include one or more devices or integrated circuits for facilitating wireless communication, potentially including WLAN (e.g., Wi-Fi) modems, cellular modems, and / or one or more other wireless modems. The wireless modem may include one or more processors (processor elements) and various hardware components as described herein. STA 106 may execute any method embodiment (or any portion thereof) of the method embodiments described herein by executing instructions on one or more programmable processors. Alternatively or additionally, the one or more processors may be one or more programmable hardware elements, such as an FPGA (Field-Programmable Gate Array) or other circuitry configured to perform any method embodiment or any portion thereof of the method embodiments described herein. The wireless modem described herein may be used as an STA as defined herein, a wireless device as defined herein, or a communication device as defined herein. The wireless modem described herein may also be used as an AP, base station, picocell, femtocell, or other similar network-side device.

[0031] STA 106 may include one or more antennas for communicating using one or more wireless communication protocols or radio access technologies. In some embodiments, STA 106 may be configured to communicate using a single shared radio component. The shared radio component may be coupled to a single antenna or to multiple antennas (e.g., for multiple-input multiple-output (MIMO)) for performing wireless communication. Alternatively, STA 106 may include two or more radio components, each configured to communicate via a corresponding wireless link. Other configurations are also possible.

[0032] Figure 2 This is a possible block diagram of a STA device (such as STA 106). STA 106 is sometimes also referred to herein as UE 106, UE device 106, device 106, electronic device 106, or client 106. STA 106 may also be referred to herein as a non-AP STA 106, non-AP device 106, or non-AP client 106. Figure 2 As shown, STA 106 may include wireless circuits such as wireless communication circuitry 230, subsystems such as system-on-chip (SOC) 200, displays such as display 260, and one or more interfaces such as connector interface (I / F) 220.

[0033] The SOC 200 may include one or more parts configured for various purposes. For example, such as Figure 2As shown, the SOC 200 may include one or more processors 202 and display circuitry 204. The processor 202 executes program instructions for the STA 106. The display circuitry 204 performs graphics processing and provides display signals to the display 260. The display 260 may be a touch-sensitive display, a force-sensitive display, or a display without touch or force sensitivity. For example, the display 260 may include one or more arrays of display pixels that emit light containing an image.

[0034] SOC 200 may also include sensor circuitry, such as motion sensing circuitry 270. Motion sensing circuitry 270 may use any of the following components: such as a gyroscope, accelerometer, inertial measurement unit (IMU), compass, and / or various other motion sensing components, to detect motion of STA 106. Processor 202 may also be coupled to memory management unit (MMU) 240, which may be configured to receive addresses from processor 202 and translate these addresses into locations in memory or other storage circuitry (e.g., memory 206, read-only memory (ROM) 250, flash memory (NAND) 210, etc.). MMU 240 may be configured to perform memory protection and page table translation or setup. In some embodiments, MMU 240 may be included as part of processor 202.

[0035] SOC 200 can be coupled to various other circuits in STA 106. For example, SOC 200 can be coupled to various types of memory (e.g., flash memory 210), connector interface 220 (e.g., for coupling to computer systems, docking stations, charging stations, etc.), display 260, and wireless communication circuitry 230 (e.g., for performing wireless communication under LTE, LTE-A, 5G NR, Bluetooth, Wi-Fi, NFC, GPS, UWB, etc.).

[0036] STA 106 may include at least one antenna 235. If desired, STA 106 may include multiple antennas 235, such as at least a first antenna 235A and a second antenna 235B. STA 106 may use antennas 235 to perform wireless communication with access points, base stations, and / or other devices. For example, STA 106 may use antennas 235A and 235B to perform wireless communication with... Figure 1 Wireless communication of AP 102 and / or 104. As described above, in some implementations, STA 106 can be configured to perform wireless communication using a variety of wireless communication standards or radio access technologies (RAT).

[0037] Wireless communication circuitry 230 may include one or more modems, such as a WLAN (e.g., Wi-Fi) modem 232, a cellular modem 234, and a Bluetooth modem 236. If needed, wireless communication circuitry 230 may include additional modems for handling other RAT or wireless communication technologies. STA 106 may use WLAN modem 232 (sometimes referred to herein as Wi-Fi modem 232) to perform communication with one or more external devices (e.g., Figure 1 STA 106 may use AP104 and / or 102 for Wi-Fi or other WLAN communication (e.g., on an 802.11 network). STA 106 may use Bluetooth modem 236 to perform Bluetooth communication or other WPAN communication with one or more external devices (e.g., another STA 106). STA 106 may use cellular modem 234 to perform cellular communication with one or more wireless base stations according to one or more cellular communication technologies (e.g., according to one or more 3GPP specifications).

[0038] As described herein, STA 106 may include hardware and software components for implementing embodiments of the present disclosure. For example, one or more components of the wireless communication circuitry 230 of STA 106 (e.g., Wi-Fi modem 232, cellular modem 234, BT modem 236) may be configured to implement some or all of the methods described herein, for example, by executing one or more processors that execute program instructions stored on a memory medium (e.g., a non-transitory computer-readable storage medium), a processor configured as an FPGA (Field-Programmable Gate Array), and / or using dedicated hardware components that may include an ASIC (Application-Specific Integrated Circuit). STA 106 may include a support structure, such as a housing. The housing may include conductive and / or dielectric housing walls, layers, and / or other structures.

[0039] If needed, STA 106 may include additional input-output devices (not shown for clarity). Input-output devices may be used to allow data to be supplied to STA 106 and to allow data to be supplied from STA 106 to external devices. Input-output devices may include user interface devices, data port devices (interface 220), touch sensors, displays (e.g., display 260), light-emitting components such as displays without touch sensor capability, buttons (mechanical, capacitive, optical, etc.), scroll wheels, touchpads, keypads, keyboards, microphones, cameras, buttons, speakers, status indicators, audio jacks and other audio port components, digital data port devices, motion sensors (accelerometers, gyroscopes, and / or compasses for detecting motion), capacitive sensors, proximity sensors, magnetic sensors, force sensors (e.g., force sensors coupled to the display to detect pressure applied to the display), temperature sensors, etc. In some configurations, keyboards, headsets, displays, pointing devices such as touchpads, mice and joysticks, and other input-output devices can be coupled to the STA 106 via wired or wireless connections (e.g., some input-output devices may be peripherals coupled to the main processing unit or other parts of the STA 106 via wired or wireless links).

[0040] Figure 3 Such as AP 104 (or equivalent, Figure 1 Example block diagram of an electronic device such as AP 102. In some cases (e.g., in the context of 802.11 communication), AP 104 may also be referred to as AP STA. Note that, Figure 3 The AP is merely one example of a possible access point. As shown, AP 104 may include one or more processors 304 capable of executing program instructions for AP 104. Processor 304 may also be coupled to MMU 340, which may be configured to receive addresses from processor 304 and translate these addresses into locations in memory (e.g., memory 360 and ROM 350), or into other storage circuitry, circuitry, or devices.

[0041] AP 104 may include at least one network port 370. Network port 370 may be configured to couple to a network and provide access to the network (e.g., to multiple devices such as STA 106) Figure 1Access to network 100. Network port 370 (or an additional network port) may also be configured, or alternatively configured, to be coupled to a cellular network (e.g., the cellular service provider's core network (CN)). The core network may provide mobility-related services and / or other services to multiple UE devices (e.g., STA 106). In some cases, network port 370 may be coupled to a telephone network via the core network, and / or the core network may provide a telephone network (e.g., between other UE devices served by the cellular service provider).

[0042] AP 104 may include one or more radio components 330A-330N, each radio component being coupled to a corresponding communication link 332 and at least one antenna 334, and may be coupled to multiple antennas (e.g., a first radio component 330A is coupled to antenna 334A via communication link 332A, an Nth radio component 330N is coupled to antenna 334N via communication link 332N, and so on). Radio component 330 may be configured to function as a wireless transceiver communicating with STA 106 via communication link 332 and antenna 334. Antennas 334A-334N communicate with their corresponding radio components 330A-330N via communication links 332A-332N. Communication link 332 may be a receive link, a transmit link, or may include both a transmit link and a receive link. Radio components 330A-330N may be configured to communicate according to various wireless communication standards (including but not limited to LTE, LTE-A, 5G NR, 6G, UWB, WLAN (Wi-Fi), WPAN (BT), etc.). If needed, the AP 104 can be configured to operate on multiple wireless links using one or more radio components 330A-330N, with each radio component used to operate on a corresponding wireless link.

[0043] AP 104 can be configured to perform wireless communication using one or more wireless communication standards. In some cases, AP 104 may include multiple radio components that enable network entities to communicate according to a variety of wireless communication technologies. For example, as one possibility, AP 104 may include LTE or 5G radio components for performing communication according to LTE or 5G NR and Wi-Fi radio components for performing communication according to Wi-Fi. In this case, AP 104 may be able to operate as both a cellular base station and a Wi-Fi access point. As another possibility, AP 104 may include multimode radio components capable of performing communication according to any of the various wireless communication technologies (e.g., NR and Wi-Fi, NR and LTE, etc.). As yet another possibility, AP 104 may be configured to be used exclusively as a Wi-Fi access point, for example, in the absence of cellular communication capabilities.

[0044] As further described herein, AP 104 may include hardware and software components for implementing or supporting the implementation of the features described herein. The processor 304 of AP 104 may be configured, for example, to implement or support some or all of the methods described herein by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium) to operate multiple wireless links using multiple corresponding radio components. Alternatively, processor 304 may be configured as a programmable hardware element, such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit), or a combination thereof. Alternatively (or additionally), the processor 304 of AP 104, together with one or more other components 330, 332, 334, 340, 350, 360, 370, may be configured to implement or support some or all of the features described herein.

[0045] The radio component 330 on AP 104 can use antenna 334 ( Figure 3 Furthermore, the wireless communication circuit 230 on STA 106 can use antenna 235 ( Figure 2 This is used to transmit and / or receive radio frequency signals within different frequency bands (sometimes referred to herein as communication bands or simply "bands") at the radio frequency. The frequency bands processed by AP 104 and STA 106 may include satellite communication bands (e.g., C-band, S-band, L-band, X-band, W-band, V-band, K-band, K-band). a Bandwidth, K u Frequency bands, etc.); Wireless Local Area Network (WLAN) frequency bands (e.g., Wi-Fi) ® (IEEE 802.11) or other WLAN communication bands such as the 2.4 GHz WLAN band (e.g., 2400 MHz to 2480 MHz), the 5 GHz WLAN band (e.g., 5180 MHz to 5825 MHz), Wi-Fi ® 6E band (e.g., 5925MHz to 7125MHz) and / or other Wi-Fi ® Frequency bands (e.g., 1875MHz to 5160MHz); Wireless Personal Area Network (WPAN) bands such as 2.4GHz Bluetooth. ®Frequency bands or other WPAN communication bands, cellular phone bands (e.g., bands from about 600 MHz to about 5 GHz, 3G bands, 4G LTE bands, 5G New Radio Frequency Range 1 (FR1) band below 10 GHz, 5G New Radio Frequency Range 2 (FR2) band between 20 GHz and 60 GHz, 6G bands, etc.), other centimeter or millimeter wave bands between 10 GHz and 300 GHz; near field communication (NFC) bands (e.g., 13.56 MHz); satellite navigation bands (e.g., GPS bands from 1565 MHz to 1610 MHz, Global Navigation Satellite System (GLONASS) bands, BeiDou Navigation Satellite System (BDS) bands, etc.); ultra-wideband (UWB) bands operating under the IEEE 802.15.4 protocol and / or other ultra-wideband communication protocols; communication bands under the 3GPP wireless communication standard family; communication bands under the IEEE 802.XX standard family; and / or any other desired bands of interest.

[0046] Antenna 334 can be formed using any desired antenna structure. Figure 3 ) and Antenna 235 ( Figure 2 For example, the antenna may include an antenna having a resonant element formed from a loop antenna structure, patch antenna structure, inverted-F antenna structure, slot antenna structure, planar inverted-F antenna structure, helical antenna structure, monopole antenna, dipole antenna, a mixture of these designs, etc. If desired, one or more antennas may include an antenna resonant element formed by a conductive portion of the device housing (e.g., a peripheral conductive housing structure extending around the periphery of the display on the STA 106). Adjustable filter circuitry, switching circuitry, impedance matching circuitry, and / or other antenna tuning components can be used to adjust the frequency response and wireless performance of the antenna over time. If desired, multiple antennas may be implemented as phased array antennas (e.g., where each antenna forms a radiator or antenna element of a phased array antenna (sometimes also referred to as a phased antenna array)). In these cases, the phased array antenna can deliver radio frequency signals within a signal beam. The phase and / or amplitude of each radiator in the phased array antenna can be adjusted such that the radio frequency signals of each radiator interfere constructively and destructively to guide or direct the signal beam along a specific pointing direction (e.g., the direction of peak signal gain). The signal beam can be adjusted or guided over time.

[0047] Wireless communication circuit 230 can use antenna 235 ( Figure 2 Radio component 330 can use antenna 334 to transmit radio frequency signals. Figure 3An antenna transmits radio frequency (RF) signals. As used herein, the term "transmit RF signals" means the transmission and / or reception of RF signals (e.g., for performing one-way and / or two-way wireless communication with external wireless communication equipment). As used herein, the term "transmit wireless data" means the transmission and / or reception of wireless data (e.g., as performed by a corresponding RF signal). An antenna can transmit RF signals by radiating them into free space (or through an intermediary device structure such as a dielectric overlay). Additionally or alternatively, an antenna can receive RF signals from free space (or through an intermediary device structure such as a dielectric overlay). The transmission and reception of RF signals by an antenna each involve the excitation or resonance of an antenna current on an antenna resonant element in the antenna by the RF signal within the antenna's operating frequency band.

[0048] The wireless communication circuit 230 can be coupled to the antenna 235 via one or more radio frequency transmission lines. Figure 2 Radio component 330 can be coupled to antenna 334 via one or more radio frequency transmission lines. Figure 3 Communication link 332 ( Figure 3 A radio frequency (RF) transmission line may be disposed between antenna 334 and radio component 330. The RF transmission line may include coaxial cable, microstrip transmission line, stripline transmission line, edge-coupled microstrip transmission line, edge-coupled stripline transmission line, or a combination of these types of transmission lines. If desired, the RF transmission line may be integrated into a rigid and / or flexible printed circuit board. If desired, one or more RF lines may be shared between radio components or modems. If desired, an RF front-end (RFFE) module may be inserted into one or more RF transmission lines (e.g., in…). Figure 3 Within communication link 332 or in Figure 2 (Within the wireless communication circuit 230). The RF front-end module may include a substrate, integrated circuit, chip, or package separate from the radio components or modem, and may include filter circuitry, switching circuitry, amplifier circuitry, impedance matching circuitry, RF coupling circuitry, and / or any other desired RF circuitry for operating on RF signals transmitted via RF transmission lines.

[0049] Processor 202 ( Figure 2 ) and processor 304 ( Figure 3 Each of these components may include one or more processors, such as microprocessors, microcontrollers, digital signal processors, host processors, baseband processing circuitry (e.g., one or more baseband processors or baseband processor integrated circuits), application-specific integrated circuits (ASICs), FPGAs, central processing units (CPUs), graphics processing units (GPUs), etc. If necessary, radio component 330 ( Figure 3The STA 106 and / or wireless communication circuitry 230 may also include one or more processors. The baseband circuitry in the STA 106 and / or AP 104 may, for example, access corresponding memory circuitry (e.g., Figure 2 memory 206 or Figure 3 The communication protocol stack on the memory 360 performs user plane functions at the physical (PHY) layer, data link or media access control (MAC) layer, RLC layer, PDCP layer, SDAP layer and / or PDU layer; and / or performs control plane functions at the PHY layer, MAC layer, RLC layer, PDCP layer, RRC layer and / or non-access layer.

[0050] AP 104 (or Figure 1 AP 102 can communicate with STA 106 via a corresponding wireless communication link. Radio frequency (RF) signals can be wirelessly transmitted between the radio components and antennas on AP 104 and STA 106 to support the wireless communication link. The RF signals may include wireless data modulated onto one or more carriers of the RF signal (e.g., modulated by a transmitter in the radio component 330 of AP 104 or a transmitter in a modem on the wireless communication circuit 230 of STA 106). The wireless data may be organized, modulated onto, and demodulated from the RF signal according to a corresponding communication protocol or standard (e.g., the IEEE 802.11 protocol or standard) (e.g., by a receiver in the radio component 330 of AP 104 or a receiver in a modem on the wireless communication circuit 230 of STA 106). RF signals can be transmitted in one or more frequency bands associated with the communication protocol.

[0051] This document describes, as an example, a specific implementation of communication between AP 104 and STA 106 according to the IEEE 802.11 protocol or standard. Under the 802.11 protocol, wireless data is organized into a series of frames or frame streams carried by radio frequency signals (e.g., Media Access Control (MAC) frames). Frames, sometimes also referred to as packets, may include management frames, control frames, data frames, beacon frames, association frames, authentication frames, acknowledgment (ACK) frames, block ACK frames, trigger frames, trigger response frames, and / or other types of frames. Each frame may include a frame header, a body (e.g., after the header), and a trailer (e.g., after the body). The header may include, for example, source address (SA) information identifying the sender of the frame (sometimes referred to herein as sender address (TA) information, which identifies the corresponding TA), destination address information identifying the intended recipient of some or all of the frames in the frame (sometimes referred to herein as receiver address (RA) information, which identifies the corresponding RA), routing information, identifier information identifying one or more aspects of some or all of the frames in the frame (e.g., information identifying the type of frame), association identifier (AID) field, control information, etc. The body may include, for example, a data payload (e.g., a payload of voice data, video data, web browsing data, application data, etc.). The trailer may include verification information to help verify the frame to the receiver. As an example, verification information may include a Frame Check Sequence (FCS) or Cyclic Redundancy Check (CRC) field. If desired, the header, body, and / or trailer may include one or more Message Integrity Check (MIC) fields (e.g., hash values ​​or the output of other cryptographic functions that take different parts of the frame as input and are used to verify the integrity of the frame when received by the receiver). Fields of a frame or message are sometimes referred to herein as elements.

[0052] In the bidirectional communication link between AP 104 and STA 106, frames are transmitted from AP 104 to STA 106 and from STA 106 to AP 104. STA 106 may send one or more ACK frames or block ACK frames to AP 104 to acknowledge successful reception of one or more frames sent by AP 104. AP 104 may send one or more ACK frames or block ACK frames to STA 106 to acknowledge successful reception of one or more frames sent by AP STA 106.

[0053] Radio frequency (RF) signals are transmitted from AP 104 to STA 106 along the downlink (DL) direction. RF signals transmitted along the DL direction are sometimes referred to herein as DL signals. DL signals may carry DL data (e.g., DL frames transmitted from AP 104 to STA 106). Radio frequency (RF) signals are transmitted from STA 106 to AP 104 along the uplink (UL) direction. RF signals transmitted along the UL direction are sometimes referred to herein as UL signals. UL signals may carry UL data (e.g., UL frames transmitted from STA 106 to AP 104).

[0054] A given AP 104 may support, maintain, and / or implement a Basic Service Set (BSS) for communicating with at least one STA 106 (e.g., according to the corresponding 802.11 protocol). If needed, a single physical AP 104 may concurrently support, maintain, and / or implement multiple BSSs (e.g., supporting wireless communication with different STAs associated with multiple BSSs). The AP may, for example, communicate with a first set of one or more STAs 106 using a first BSS, communicate with a second set of one or more STAs 106 using a second BSS, and so on. When communication is initiated between AP 104 and a given STA 106, the STA associates with (registers with) AP 104 and subsequently associates with the corresponding BSS of the AP (this process is referred to as association). The BSS may include and / or identify corresponding communication / operation parameters, device capabilities, security level information, and / or other information associated with the communication services provided by AP 104 to one or more STAs under that BSS.

[0055] Each BSS can be identified by a corresponding BSS identifier (BSSID). This BSSID may, for example, represent or correspond to a specific network address (e.g., MAC address) and / or wireless network name established, owned, and / or maintained by the AP for wireless communication using the corresponding BSS. If needed, a given AP 104 may concurrently or simultaneously support, implement, and / or maintain multiple BSSIDs in a communication scheme sometimes referred to herein as performing multi-BSSID (M-BSSID) operation or M-BSSID communication. When configured to perform M-BSSID communication, each BSSID maintained by AP 104 corresponds to a different network address (e.g., MAC address) and wireless network name maintained and operated by that AP.

[0056] Consider an example where AP 104 is a Wi-Fi router or hotspot on a university campus and is configured to perform M-BSSID communication. In this example, AP 104 may concurrently maintain a first BSSID named "Student" for STA 106 operated by students on the university campus, corresponding to AP 104's first MAC address; a second BSSID named "Employee" for STA 106 operated by university campus staff, corresponding to AP 104's second MAC address; a third BSSID named "Visitor" for STA 106 operated by university campus visitors, and so on. Each BSSID may have different corresponding operating characteristics, security configurations, and / or settings. When STA 106 enters the AP's wireless coverage area, the STA's user can interact with the STA's user interface to select one of the AP's BSSIDs to connect to. The AP can then associate or link a STA to the BSSID (e.g., if the STA meets one or more security conditions associated with the BSSID, such as registering with a user authorized to access the BSSID, providing the correct password to access the BSSID, etc.). Once associated with a given BSSID, the STA and AP use that BSSID (e.g., the BSS identified by that BSSID) to transmit wireless data. This example is illustrative and not limiting.

[0057] In the specific implementation described herein as an example, AP 104 and STA 106 support and communicate according to a BSS Privacy Enhancement (BPE) scheme (e.g., as defined by the 802.11 communication protocol that manages communication between AP 104 and STA 106). AP 104, which supports BPE communication, is sometimes referred to as a BPE AP, but for simplicity, it is simply referred to as AP 104 herein. STA 106, which supports BPE communication, is sometimes referred to as a BPE STA or a BPE non-AP STA, but for simplicity, it is simply referred to as STA 106 herein. The BPE scheme helps protect the privacy of both APs and STAs. STAs that do not support BPE communication may not be able to associate with a BPE AP.

[0058] According to the BPE scheme, both the AP and STA can periodically update and anonymize their corresponding link-specific network addresses (e.g., MAC addresses) to help increase privacy and security. For example, the AP can update its network (e.g., MAC) address to different corresponding anonymized or randomized addresses during different time periods (sometimes called periods). Similarly, the STA can update its network (e.g., MAC) address to different corresponding anonymized or randomized addresses during each period within different time periods. Furthermore, according to BPE, all management frames sent by the AP and STA can be encrypted before transmission.

[0059] Figure 4 This involves communication system 108 ( Figure 1 A flowchart illustrating the exemplary operation of wireless communication between a given STA 106 and the corresponding AP 104 (e.g., according to the BPE scheme). Figure 4 At operation 400, STA 106 and AP 104 may perform pre-association communication (e.g., before AP 104 associates with, registers with, or connects to AP 104). AP 104 may use the pre-association communication to authenticate STA 106. STA 106 may use the pre-association communication to associate with AP 104. AP 104 and / or STA 106 may send one or more management frames (“MGMT”) during the pre-association communication. The management frame may carry information used by AP 104 to authenticate STA 106, and / or may carry information used by STA 106 to associate with AP 104. Once AP 104 has successfully authenticated STA 106 and STA 106 has associated with AP 104, processing may proceed to operation 408.

[0060] At operation 408, STA 106 and AP 104 may perform associated communications (e.g., when STA 106 associates with, registers with, and connects to AP 104). This may involve sending UL data from STA 106 to AP 104 and / or sending DL data from AP 104 to STA 106 (e.g., in Physical Protocol Data Unit (PPDU) frames or other types of data or unmanaged frames). Depending on the BPE scheme, AP 104 and STA 106 may periodically change / anonymize their respective network addresses (e.g., MAC addresses) during different periods to help enhance privacy. If needed, AP 104 and STA 106 may also randomly change the packet number (PN) and / or sequence number (SN) of the transmitted frames between periods. If / when STA 106 disconnects or deassociates from AP 104, the process may loop back to operation 400.

[0061] For STA 106 to successfully associate with AP 104, AP 104 may first need to successfully authenticate STA 106 (e.g., to ensure STA 106 is authorized to access the network via AP 104). For AP 104 to successfully authenticate STA 106, STA 106 may need to know the minimum set of AP security parameters of AP 104 (sometimes referred to herein as AP configuration parameters or simply AP parameters). STA 106 can use AP security parameters to associate with AP 104. AP security parameters may include, for example, at least the Robust Secure Network Element (RSNE) and Robust Secure Network Extension Element (RSNXE) of AP 104. As an example, STA may need to correctly configure the RSNE and RSNXE parameters to successfully associate with the AP (e.g., the Personal Cryptography and Authentication Key Management (AKM) protocol used by STA needs to be supported by the AP, STA needs to use the AP's Correct Group Cipher (GTK) and Group Integrity Verification Cipher (IGTK), STA needs to support the same RSNXE settings as the AP, etc.). If the RSNE and RSNXE parameters are incorrectly configured by the STA, the STA may be unable to associate with the AP.

[0062] According to the BPE scheme, pre-association communication between AP 104 and STA 106 (operation 400) may include AP 104 sending privacy beacons (at operation 402). AP 104 may, for example, periodically send privacy beacons (sometimes also referred to as privacy beacon frames, privacy beacon signals, or privacy beacon messages), which include information used by STA 106 to identify or determine whether the sending AP is already known to STA 106. Alternatively, AP 104 may send privacy beacons in response to a privacy beacon request frame sent by STA 106. AP 104 may use a corresponding AP identity key associated with that particular AP 104 to encrypt the payload of the privacy beacon. The AP identity key may be known to the STA, and the STA may use the AP identity key to decrypt the privacy beacon received from the AP. However, prior to association, the STA may not know the BSSID of AP 104 and may not obtain any AP security parameters from the sent privacy beacons.

[0063] At operation 404, STA 106 may perform a BPE AP scan against AP 104. This may also include, if desired, an optional AP security parameter query, where AP 104 securely sends its AP security parameters to STA 106. After STA 106 has successfully scanned AP 104 and knows AP 104's AP security parameters, AP 104 may authenticate STA 106, and STA 106 may associate with AP 104 using (based on) the AP security parameters. In some implementations, authentication of STA 106 by AP 104 may involve STA 106 sending an authentication request (e.g., including or identifying some or all of the AP security parameters known to STA 106), AP 104 authenticating the authentication request, and AP 104 sending an authentication response in response to successful authentication of the authentication request. In some implementations, association between STA 106 and AP 104 may involve STA 106 sending an association request (e.g., including or identifying some or all AP security parameters and / or STA link parameters as known to STA 106) after receiving an authentication response, and AP 104 sending an association response (e.g., including or identifying some or all AP security parameters and / or other AP link parameters) in response to receiving the association request. Upon receiving the association response, STA 106 becomes associated with AP 104 and can perform associated communications. The association request and association response may be encrypted using a transient key shared between AP 104 and STA 106 or known to both.

[0064] Operations 404 and 406 are sometimes collectively referred to as the BPE AP discovery process or the protected AP discovery process. The protected AP discovery process can be, for example, a pre-association security negotiation (PASN) process, which involves sending a series of PASN messages between AP 104 and STA 106. In some implementations, prior to operation 400, the BPE STA is pre-configured with AP security parameters (e.g., pre-shared RSNE and RSNXE) for the corresponding AP. However, pre-configuring the STA with AP security parameters may only allow the pre-configured STA to detect the BPE AP from its transmitted privacy beacons. Furthermore, the pre-shared AP security parameters only work if all APs support the same pre-shared AP security parameter values, which may not be the case depending on the deployment of APs in communication system 108. As an alternative, the STA can attempt to associate with the AP by testing different RSNE and RSNXE settings one by one (e.g., using brute force). However, this results in excessive communication overhead, complexity, and power consumption for the STA, and may cause the AP to interpret repeated association attempts by the STA as a security attack, thereby triggering the AP to stop responding to the STA's attempts.

[0065] Generally, knowing the BPE AP's AP security parameters is important for the STA. While parameter mismatch itself may not reject authentication or association, the STA can use the parameters to optimize the association (e.g., if the STA knows the available links and their parameters). Encrypting the AP security parameters to protect the privacy of both the AP and the STA is also important. Integrity protection schemes can, for example, help ensure the correctness of shared parameters. The BPE AP can verify that the scanning STA is authorized to receive its AP security parameters before sharing them with the STA. To help protect STA privacy, it may not be necessary for the STA to identify itself, but the AP can still detect whether the STA is authorized to access the AP security parameters before sharing them with the STA. Furthermore, the scan should be as simple and fast as possible to minimize overhead (e.g., authentication and temporary key setup should be fast, and if necessary, a BPE AP can respond on behalf of other BPE APs in the network). This document sometimes describes specific implementations where the STA performs an active scan as examples. Passive scans (e.g., using encryption and knowing the encryption at the STA's location) can also be used in implementations.

[0066] If needed, a PASN-protected AP discovery process can be used to allow STAs to discover APs (e.g., as specified by the 802.11 communication protocol that manages communication between APs and STAs). The PASN-protected AP discovery process allows STAs to create a transient key (TK) (sometimes also called a temporary key TK or ephemeral key TK) used to protect (encrypt) management frames subsequently sent between APs and STAs before association (e.g., the transient key can be used to protect against active scanning), regardless of whether the STA is authenticated. The PASN-protected AP discovery process involves the STA sending a first PASN message (sometimes referred to herein as PASN message 1, PASN MSG1, or simply MSG1) that includes or otherwise identifies the STA's Diffie-Hellman (DH) key public DHss (sometimes also referred to herein as the DH public key DH_s). The AP then sends a second PASN message (sometimes referred to herein as PASN message 2, PASN MSG2, or simply MSG2) that includes or otherwise identifies the AP's DH public key DHss (sometimes also referred to herein as the DH public key DH_a). The STA then sends a third PASN message (sometimes referred to herein as PASN message 3, PASN MSG3, or simply MSG3), which includes or otherwise identifies the Message Integrity Check (MIC). The STA and AP may generate the same transient key TK (e.g., using the DH public key DHss from the first and second PASN messages). After the third PASN message is sent, pre-association management frames transmitted between the AP and STA (e.g., authentication requests / responses, association requests / responses, etc.) can be protected (encrypted and decrypted) using the transient key TK. A key different from the transient key TK can be used in... Figure 4 During operation 408, the associated communications are protected.

[0067] In some implementations, the first PASN message may include or otherwise identify a Paired Master Key Identifier (PMKID) that serves as a pointer to a previous association between the same STA and AP (e.g., to allow the AP to re-identify / authenticate the STA based on a previous association). If the STA has not previously been associated with an AP, the PMKID is omitted from the first PASN message. Utilizing the PMKID in the first PASN message presents two challenges. First, the PMKID can introduce privacy issues for the STA. This is because the PMKID remains the same throughout all operations, making it usable for tracking both the STA and the AP. Second, the PMKID is created during the initial authentication of the STA by the AP. For STAs that have not been previously authenticated, no PMKID may be available. Furthermore, while the PMKID identifies the STA / authentication, scanning the STA may preferably not be identified to protect its privacy.

[0068] To help mitigate these issues, STA 106 may include a unique STA identifier (STA-ID) in the first PASN message sent to AP 104 (e.g., in addition to PMKID or replacing PMKID in the first PASN message). Figure 5 This illustrates the pre-association communication between STA 106 and AP 104 (e.g., in...). Figure 4 The timing diagram during operation 400) shows that the associated pre-communication includes a PASN-protected AP scanning and discovery process based on the STA identifier STA-ID.

[0069] like Figure 5 As shown, STA 106 may have a corresponding network address ADD2 (e.g., the link-specific MAC address of STA 106), and AP 104 may have a corresponding network address ADD1 (e.g., the link-specific MAC address of AP 104). Network address ADD1 may be referenced by or associated with the corresponding BSSID of AP 104, for example. Before time T0, STA 106 may periodically change / anonymize the value of its network address ADD2, and AP 104 may periodically change / anonymize the value of its network address ADD1 (e.g., according to a BPE scheme implemented by the STA and AP).

[0070] Before time T0, AP 104 may periodically send privacy beacons (e.g., during processing). Figure 4 During operation 402), the most recent one is in Figure 5As shown in the diagram. The privacy beacon may include or otherwise identify the current network address ADD1 of AP 104 (e.g., in the beacon header field). The privacy beacon may also include or otherwise identify a corresponding checksum (e.g., in the beacon tail field). AP 104 may use the AP identity key associated with the AP to encrypt the payload of the privacy beacon. The STA may already know the AP identity key in advance (e.g., as previously shared with the STA or as pre-configured on the STA), and may use the AP identity key to decrypt the payload if needed.

[0071] The privacy beacon may, for example, have a MAC header including a first address field (“Address 1” or “A1”), followed by a second address field (“Address 2” or “A2”), and then a third address field (“Address 3” or “A3”). The first address field may be set to a broadcast address (e.g., identifying the privacy beacon as a broadcast message / frame). The second address field may include or otherwise identify the network address ADD1 of AP 104 and / or the corresponding BSSID of network address ADD1. The third address field may include or otherwise identify a secure cryptographic hash value calculated based on the content of the second address field. The value of the second address field (e.g., network address ADD1) and therefore the hash in the third address field may be periodically changed / anonymized over time (e.g., according to a BPE scheme as specified by the 802.11 communication protocol). The privacy beacon may include a Time Synchronization Function (TSF) offset field between the MAC header and its encrypted payload (e.g., to allow for synchronization maintenance with the AP). The encrypted payload may include a Change Serial Number (CSN) field. Changes in the CSN field can signal to AP 104 that one or more AP parameter values ​​(e.g., AP security parameter values) have been changed. The encrypted payload may also include a Service Indication Map (TIM) field (e.g., indicating whether the AP has buffered unicast or multicast frames from the STA) and a Reduced Neighbor Report (RNR) field (e.g., as needed to maintain other links).

[0072] STA 106 can receive privacy beacons from AP 104. STA 106 can use a checksum to verify the content of the received privacy beacon. For example, if STA 106 can calculate the checksum included in the privacy beacon based on the value of the network address ADD1 included in the privacy beacon and the AP identity key, then STA can confirm that AP is known to STA. However, STA does not need to know AP in advance to proceed. Figure 5 The remaining operations. STA 106 can store information from the privacy beacon (e.g., at least the contents of the second address field, including the current value of network address ADD2) for subsequent processing.

[0073] Figure 5 Operation 500 may represent an associated pre-BPE AP scan operation performed by STA 106 for scanning AP 104 (e.g., in processing...). Figure 4 (At operation 404). At operation 502, STA 106 may generate its STA identifier STA-ID based on the content of the most recently received privacy beacon. For example, STA 106 may generate the STA identifier STA-ID based on the current value of its own network address ADD2, the current value of AP 104's network address ADD1 (e.g., as identified by the A2 field of the received privacy beacon), and the corresponding cryptographic identity key.

[0074] Figure 6 This example illustrates how STA 106 can generate the STA identifier STA-ID. For example... Figure 6 As shown, STA 106 may include cryptographic functions 600 (e.g., using digital and / or analog logic, Figure 2 The cryptographic function 600 includes a processor 202, etc., to implement and / or execute the cryptographic function 600, and a cryptographic identity key such as identity key 602 (e.g., stored in a cryptographic key storage device on STA 106). The cryptographic function 600 includes a hash function / algorithm. The current network address ADD2 of STA 106 may be formed as an input to the cryptographic function 600. The current network address ADD1 of AP 104 (e.g., identified by a recently received privacy beacon) may be formed as an input to the cryptographic function 600. Identity key 602 (sometimes also called identification key 602) may be formed as an input to the cryptographic function 600. Identity key 602 may, for example, be the AP identity key of AP 104, which is used by AP 104 to encrypt sent privacy beacons. In other specific implementations, identity key 602 may be the STA identity key of STA 106.

[0075] Cryptographic function 600 can generate (e.g., compute, operate, output, etc.) an STA identifier STA-ID as a unique identifier (e.g., a hash value) based on the current value of network address ADD2, the current value of network address ADD1, and identity key 602 (e.g., by hashing network address ADD2 with network address ADD1 and identity key 602). As an example, cryptographic function 600 can be based on a hash-based Message Authentication Code (HMAC) Secure Hash Algorithm (SHA), such as the 256-bit digest HMAC-SHA-256 function / algorithm. In this example, STA 106 can generate the STA identifier STA-ID by concatenating identity key 602 and network address ADD1 with network address ADD2 into the HMAC-SHA-256 algorithm (e.g., where STA-ID is formed by truncating 48 bits of the output of the HMAC-SHA-256 algorithm). The STA identifier STA-ID can be generated, for example, using the formula STA-ID = truncated - 48((HMAC-SHA-256(“BPE non-AP MLD identifier”), identity key, ADD1|ADD2)), where “identity key” (e.g., Figure 6 The identity key 602 is the AP identity key (e.g., a 128-bit value) associated with AP 104. STA 106 may, for example, randomly select its network address ADD2, and may subsequently send the first PASN message from that randomly selected network address ADD2.

[0076] If needed, the random value sequence number SN used for subsequent transmissions of the first PASN message can also be provided as input to the cryptographic function 600 used to generate the STA identifier STA-ID (e.g., where STA-ID = truncated-48((HMAC-SHA-256(“BPE non-AP MLD identifier”, identity key, SN|ADD1|ADD2)). If needed, the random value sequence number SN can be replaced with a timestamp value, or the timestamp value can be formed as additional input to the cryptographic function. Using the AP identity key in the cryptographic function 600 (e.g., as identity key 602) can, for example, allow STA 106 to signal to AP 104 that STA 106 is authorized to receive AP security parameters from AP 104.

[0077] As another example, identity key 602 could be a STA identity key specific to STA 106 or a group of STAs including STA 106, rather than an AP identity key. In these implementations, the AP can store separate keys for different STAs or groups of STAs. Each STA or group of STAs using a specific STA identity key can use that STA identity key to be identified by the AP. If necessary, the AP can revoke the STA identity key, such as when the corresponding STA or group of STAs is no longer authorized to receive AP security parameters from the AP. However, using STA identity keys may increase the key storage size in the AP and STAs.

[0078] return Figure 5 At time T0 (e.g., after STA 106 has generated the STA identifier STA-ID), STA 106 may send a first PASN message (PASN MSG1) to AP 104. PASN MSG1 may include or otherwise identify the DH public key DH_s of STA 106, and may include the STA identifier STA-ID generated by STA 106. As an example, PASN MSG1 may have a first (receiver) address field (sometimes also referred to as the "address 1" or "A1" field of PASN MSG1) including the current network address ADD1 of AP 104, a second (sender) address field (sometimes also referred to as the "address 2" or "A2" field of PASN MSG1) including the current network address ADD2 of STA 106, and a third (BSSID) address field (sometimes also referred to as the "address 3" or "A3" field of PASN MSG1) including the current network address ADD1 of AP 104 (e.g., corresponding to a specific BSSID of AP).

[0079] AP 104 can receive a first PASN message and can authenticate / certify STA 106 based on the STA identifier STA-ID included in the first PASN message. AP 104 can authenticate / certify STA 106, for example, based on its current address ADD1, STA 106's current address ADD2 (e.g., identified or included in the header field of PASN MSG1), identity key 602 (e.g., AP identity key or STA identity key, both known to AP 104), and a random value sequence number SN optionally included in or identified by PASN MSG1 (e.g., by performing a checksum with PASN MSG1). Figure 6The same cryptographic operation as shown for STA 106 is used to generate a candidate (test) STA identifier STA-ID' for STA 106. If / when the candidate STA identifier STA-ID' calculated at AP 104 matches the STA identifier STA-ID included in PASN MSG1, AP 104 can successfully verify / authenticate STA 106, indicating that STA 106 is authorized to receive AP security parameters from AP 104. If / when the candidate STA identifier STA-ID' calculated at AP 104 does not match the STA identifier STA-ID included in PASN MSG1, verification / authentication may fail, indicating that STA 106 is not authorized to receive AP security parameters from AP 104. If / when AP 104 successfully verifies STA 106, the process can proceed to... Figure 5 The remaining operations. Processing can end if / when AP 104 cannot verify STA 106.

[0080] In this way, the STA identifier STA-ID can be generated and used by both STA 106 and AP 104 to indicate whether STA 106 is allowed to obtain AP 104's AP security parameters. Simultaneously, the STA identifier STA-ID does not directly indicate the identity of STA 106, thus helping to protect the STA's privacy. The AP can quickly verify STA 106 using only a single hash function (e.g., a single iteration of cryptographic function 600), where PASN only continues if the STA identifier STA-ID is successfully verified. Furthermore, the specific value of the STA identifier STA-ID is only valid for a single use, because the network address ADD1 of AP 104 and the network address ADD2 of STA 106 change in each period according to the BPE scheme (e.g., at least STA 106 can change the value of its network address ADD2 before or at the start of each BPE AP scan operation performed by the STA).

[0081] In the specific implementation where the AP identity key is used to generate the STA identifier STA-ID, STA 106 uses the AP identity key (sometimes also called the AP identification key) to signal to AP 104 that STA 106 is authorized / permitted to receive AP security parameter information protected by PASN. If needed, the secure hash in PASN MSG1 (e.g., used to generate the STA identifier STA-ID) can be used to verify that AP information has been pre-shared with STA 106. In any case, the AP identity key can be stored at STA 106 without requiring additional memory consumption at the STA or AP. The AP does not need to identify the specific STA sending PASN MSG1 (sometimes referred to herein as a PASN query), but only needs to calculate a single hash value to determine whether the STA sending PASN MSG1 is authorized to use the network. The AP identity key can be reused if needed, but reusing the AP identity key may increase the attack surface of the key.

[0082] In response to successful verification of the STA identifier STA-ID, AP 104 may send a second PASN message (PASN MSG2) to STA 106. PASN MSG2 may include or otherwise identify AP 104's DH public key DH_a and the corresponding message integrity verification MIC. STA 106 may receive the second PASN message. At operation 506 (e.g., at or after time T1), STA 106 may derive (e.g., calculate, operate, generate, output, produce, identify, etc.) a transient key TK, which is used to encrypt / decrypt subsequent management frames transmitted between STA 106 and AP 104 prior to association (e.g., based on its DH public key DH_s and the DH public key DH_a included in PASN MSG2). If needed, AP 104 may also derive the same transient key TK based on the DH public key DH_s and its DH public key DH_a of STA 106 included in PASNMSG1 (e.g., at or after time T0, simultaneously with operation 506, after time T1, etc.) for use in encrypting / decrypting subsequent management frames transmitted between STA 106 and AP 104 prior to association.

[0083] At time T2, STA 106 may send a third PASN message (PASN MSG3) to AP 104. PASN MSG3 may include or otherwise identify the Message Integrity Check (MIC). After sending PASN MSG3, the transient key TK shared by STA 106 and AP 104 can be used to encrypt and decrypt management frames MGMT (e.g., authentication requests, authentication responses, AP security parameter requests, AP security parameter responses, association requests, association responses, etc.) transmitted between STA 106 and AP 104.

[0084] In this way, the PASN process can be used as a Diffie-Hellman key exchange, which creates a shared secret (e.g., a transient key TK) owned by both STA 106 and AP 104 for use in delivering the protected associated pre-management frame MGMT. In DH key exchange, a first entity (e.g., STA 106) and a second entity (e.g., AP 104) agree on common parameters. The first entity combines its own secret key (first secret key) with the common parameters to generate a corresponding first public key (e.g., DH public key DH_s). This first public key is then sent to the second entity, which combines its own secret key (second secret key) with the common parameters to generate a corresponding second public key (e.g., DH public key DH_a). This second public key is then sent to the first entity, which then combines the received second public key with its first secret key to generate a secret value. The second entity also combines the received first public key with its second secret key to generate the same secret value, which is used as a shared secret (e.g., a transient key TK). This shared secret is used to encrypt / decrypt subsequent messages (e.g., management frames MGMT) between the first and second entities.

[0085] Depend on Figure 5 The PASN scheme implements DH key exchange by creating only a transient key TK between the AP and the real / authenticating STA (e.g., to prevent a man-in-the-middle (MITM) attacker from deriving the transient key). The STA identifier STA-ID allows an attacker to replay frames. However, even if an attacker replays the first PASN message, subsequent frames are encrypted and the attacker cannot derive the transient key TK. This is because the AP periodically changes its network address ADD1 according to the BPE scheme, and the STA 106 is configured for each scan (e.g., for Operation 500 or...). Figure 4 The network address ADD2 is changed in each iteration of operation 404, so the possibility of STA-ID replay tracing is limited.

[0086] As an example, a management frame MGMT encrypted with a transient key TK may include an AP security parameter request (query) sent by the STA to the AP and an AP security parameter response sent by the AP to the STA. In this example, the STA can use the transient key TK to encrypt the AP security parameter request. The AP can use the transient key TK to decrypt the parameter request. The AP can then send an AP security parameter response in response to receiving the AP security parameter request. The AP security parameter response may include the AP security parameters required for the STA 106 to successfully associate with the AP 104. The AP can use the transient key TK to encrypt the AP security parameter response. The STA can use the transient key TK to decrypt the AP security parameter response. The MIC of the third PASN message helps ensure that the correct transient key TK is derived for these management frames. However, this type of AP security parameter query is overhead-intensive, requiring the exchange of at least five different messages between the AP and the STA. In addition, the STA cannot scan multiple channels in parallel and exhibits increased power consumption. Therefore, it is desirable to increase the speed and flexibility of the STA in using the PASN scheme to scan the AP.

[0087] To help mitigate these issues, the STA can use PASN MSG1 to signal that it needs AP security parameters from AP 104 (e.g., in a scenario where STA 106 is not pre-configured to know the AP parameters), and AP 104 can send the AP security parameters encrypted with the transient key TK to STA 106 before or instead of STA 106 sending PASN MSG3. Figure 7 This is a timing diagram illustrating such an example, starting at time T0. For clarity, Figure 7 The middle part is omitted Figure 5 Operations performed before time T0.

[0088] like Figure 7As shown, in addition to the DH public key DH_s and the STA identifier STA-ID, the PASNMSG1 sent by STA 106 may include an AP security parameter request AP_PARAM_REQ (sometimes referred to herein as an AP security parameter request tag, field, flag, or bit). The AP security parameter request AP_PARAM_REQ signals to AP 104 that STA 106 does not know the AP security parameters required by STA 106 in association with AP 104. If / when STA 106 does not know the AP security parameters, and / or if / when STA 106 is requesting AP 104 to send its AP security parameters to STA 106, the AP security parameter request AP_PARAM_REQ may, for example, have a first value (e.g., a single bit value set to binary "1"). On the other hand, if / when STA 106 already knows the AP security parameters, and / or if / when STA 106 does not request AP 104 to send its AP security parameters to STA 106, the AP security parameter request AP_PARAM_REQ may have a second value (e.g., a single bit value set to binary "0"). Thus, the AP security parameter request AP_PARAM_REQ can be used as a trigger or query for AP 104 to send AP security parameters.

[0089] If needed, the PASN MSG1 sent by STA 106 may also include a transient key adoption delay request TK_DEL1 (sometimes referred to herein as a TK adoption delay tag, field, or marker). The transient key adoption delay request TK_DEL1 may, for example, inform AP 104 of the amount of time or delay required for STA 106 to generate or adopt the transient key TK. At operation 702 (e.g., in response to receiving PASN MSG1), AP 104 may verify the STA identifier STA-ID from PASN MSG1 (e.g., similar to...). Figure 5 (Operation 504). AP 104 may also begin deriving the transient key TK. During implementation, AP 104 may require a non-zero amount of time or a non-zero amount of delay to generate or use the transient key TK (e.g., the same amount of time or a different amount of time as required by STA 106).

[0090] The PASN MSG2 sent by AP 104 at time T1 may include a transient key adoption delay request TK_DEL2 (sometimes referred to herein as a TK adoption delay tag, field, or marker). The transient key adoption delay request TK_DEL2 may, for example, inform STA 106 of the amount of time or delay required for AP 104 to generate or adopt the transient key TK. At operation 705 (e.g., in response to receiving PASN MSG2), STA 106 may begin deriving the transient key TK (e.g., similar to...). Figure 5 Operation 506).

[0091] At time T3, in response to an AP security parameter request AP_PARAM_REQ with a first value indicating that STA 106 requests AP security parameters from AP 104, AP 104 may send its AP security parameters AP_PARAMS (sometimes referred to herein as AP security parameter message AP_PARAMS or AP security parameter frame AP_PARAMS) to STA 106. AP 104 may use a transient key TK to encrypt the AP security parameters AP_PARAMS (e.g., in the encrypted payload of the AP security parameter message or frame). As an example, AP 104 may send a MAC management protocol data unit (MMPDU) containing the AP security parameters AP_PARAMS that have been encrypted using the transient key TK.

[0092] If needed, AP 104 can use a delay period TK_DEL (e.g., the time period between times T1 and T3) for the transmission delay TK of the AP security parameter AP_PARAMS. The TK-adopting delay period TK_DEL can be the minimum duration between the transmission of the instantaneous key encryption frame between PASN MSG2 and STA 106 and PA 104. If needed, AP 104 can select the TK-adopting delay period TK_DEL based on the instantaneous key delay request TK_DEL2 included in PASN MSG2 and the instantaneous key delay request TK_DEL1 received in PASN MSG1. For example, AP 104 can select a sufficiently long TK-adopting delay period TK_DEL to allow STA 106 sufficient time to derive the instantaneous key TK (e.g., based on the instantaneous key adoption delay request TK_DEL1 received from STA 106 in PASN MSG1), and to allow AP 104 sufficient time to derive the instantaneous key TK. Alternatively, the TK adoption delay period TK_DEL can be specified or set by the 802.11 communication protocol (e.g., specified or set to a period long enough to support instantaneous key adoption for most potential STA implementations). AP 104 may refrain from sending the AP security parameter AP_PARAMS if / when the AP security parameter request AP_PARAM_REQ in PASN MSG1 has a second value indicating that STA 106 already knows the AP security parameters of AP 104.

[0093] At time T4, STA 106 has sufficient time to employ the instantaneous key TK for encrypting the subsequent management frame MGMT. STA 106 can then continue transmitting the management frame MGMT, encrypted and decrypted using the instantaneous key TK, along with AP 104. In this specific implementation, the transmission of PASN MSG3, including the MIC, can be omitted (see example...). Figure 5 If necessary, if / when AP 104 does receive PASN MSG 3 from STA 106 ( Figure 5 When the TK adoption delay period TK_DEL is not received, AP 104 may choose not to wait for it to pass and instead immediately send the TK-encrypted AP security parameter AP_PARAMS in response to receiving a satisfactory MIC in PASN MSG3. The TK adoption delay period TK_DEL configured by AP 104 may, for example, allow the AP to skip one or more transmission opportunities (TXOPs) during active scanning. This can be used to reduce response time and channel contention.

[0094] As an example, STA 106 may send PASN MSG1 during the first TXOP. AP 104 may then send PASN MSG2 during the second TXOP (e.g., the next TXOP after the first TXOP). Depending on the length of the TK-adopted delay period TK_DEL, AP 104 may send the TK-encrypted AP security parameter AP_PARAMS within the second TXOP or within the third TXOP (e.g., the next TXOP after the second TXOP). In the specific implementation where the AP security parameter is sent in the second TXOP, STA 106 is able to receive the AP security parameter from AP 104 within only two TXOPs, thereby minimizing the time required for STA 106 to associate with AP 104. By delaying the transmission of the AP security parameter to the third TXOP (e.g., through a suitable configuration of TK-adopted delay period TK_DEL), AP 104 can help accommodate STAs with hardware that cannot immediately decrypt the AP parameter because the transient key TK has not yet been installed.

[0095] Compared to sending a TK-protected AP security parameter request and response after sending PASN MSG3, querying and delivering protected AP security parameters to STA 106 in this way is likely much faster and requires less overhead (e.g., because PASN MSG3 is omitted from the PASN process, such as...). Figure 7As shown), and allows the STA to concurrently scan other APs or save power (e.g., during radio shutdown or sleep mode) during the TK-advanced delay period TK_DEL. This scan transmission order can also be used in PMKID-based AP scanning implementations if needed (e.g., where PMKID identifies the STA and PASN protects the response).

[0096] Figure 8 This is a diagram illustrating two examples of PASN message payloads that can be included in PASN MSG1 and / or PASN MSG2 sent by STA 106 and / or AP 104. Figure 8 Part 800 illustrates the different fields of the PASN message payload in PASN parameter element format (with corresponding field lengths in octet bytes). Figure 8 Part 802 illustrates a portion of the PASN message payload in the format of PASN parameter element control information field (with a corresponding field length in bits).

[0097] like Figure 8 As shown in section 800, the PASN message payload may include an element identifier (ID) field, followed by a length field, an element ID extension field, a control field, an encapsulated data field, a variable-length rework information field, a finite cycle group identifier (ID) field, a temporary public key length field, a temporary public key field 804, a TK adoption delay field 806, and an STA identifier field 808 (e.g., the TK adoption delay field 806 may be between the temporary public key field 804 and the STA identifier field 808). This is illustrative, and these fields may be in a different order if desired, one or more of these fields may be omitted, and / or additional fields may be included in the PASN message payload.

[0098] TK uses a delay field 806 that may include or otherwise identify the instantaneous key sent by STA 106 within PASN MSG1 using a delay request TK_DEL1 ( Figure 7If needed, AP 104 can use the information within the TK adoption delay field 806 to generate the TK adoption delay period TK_DEL between the transmission of PASN MSG2 and the transmission of the TK-encrypted frame. If needed, and if / when STA 106 does not require the TK adoption delay period to install the transient key TK, STA 106 may set the TK adoption delay field 806 to zero (empty), or may omit the TK adoption delay field 806 (e.g., AP 104 may send the AP security parameter AP_PARAMS within the same TXOP as PASN MSG2 in response to the TK adoption delay field 806 having an empty value or being omitted from PASN MSG1, and may send the AP security parameter AP_PARAMS after the TK adoption delay period TK_DEL in response to the TK adoption delay field 806 having a non-zero value). The STA identifier field 808 may include the STA identifier STA-ID generated by STA 106 (e.g., in PASN MSG1). AP 104 can use the contents of STA identifier field 808 to verify STA 106 (e.g., in...). Figure 5 Operation 504 or Figure 7 (Operation 702).

[0099] like Figure 8 As shown in section 802, the PASN message payload may include a comeback delay field, followed by a group and key parameter field 810, a TK adoption delay presence field 812, a STA-ID presence field 814, an AP information request field 816, and a reserved field 818 (e.g., the TK adoption delay presence field 812 may be between fields 810 and 814, field 814 may be between fields 812 and 802, and field 802 may be between fields 814 and 818). This is illustrative, and these fields may be in a different order if desired, one or more of these fields may be omitted, and / or additional fields may be included in the PASN message payload.

[0100] The TK adoption delay presence field 812 may indicate whether the PASN MSG includes or otherwise identifies the TK adoption delay period TK_DEL. Field 812 may have a first value (such as binary "1"), for example, when the TK adoption delay period TK_DEL is present, and a second value (such as binary "0") when the TK adoption delay period TK_DEL is not present in the PASN MSG. If needed, AP 104 may send the AP security parameter AP_PARAMS within the same TXOP as PASN MSG2 in response to field 812 having a second value, and may send the AP security parameter AP_PARAMS after the TK adoption delay period TK_DEL in response to field 812 having a first value.

[0101] The STA-ID presence field 814 indicates whether the PASN MSG includes or otherwise identifies the STA identifier STA-ID generated by STA 106. Field 814 may have a first value (such as binary "1") if the STA identifier STA-ID is present, and a second value (such as binary "0") if the STA identifier STA-ID is not present in the PASN MSG. AP 104 may, for example, search for the STA identifier STA-ID (e.g., in...). Figure 8 (in field 808), and can use the STA identifier to verify the STA in response to field 814 having a first value, and can abandon these operations in response to field 814 having a second value.

[0102] AP Information Request field 816 can be used as Figure 7 The AP security parameter request AP_PARAM_REQ in PASN MSG1. AP information request field 816 indicates whether the sending STA needs or is requesting protected transmission of AP security parameters for AP 104. When STA 106 does not know the required AP security parameter AP_PARAMS associated with AP 104... Figure 7When STA 106 is requesting protected transmission of AP security parameter AP_PARAMS from AP 104, and / or when STA 106 additionally needs AP security parameter AP_PARAMS from AP 104, field 816 may have a first value (such as binary "1"). When STA 106 already knows the required AP security parameter AP_PARAMS associated with AP 104, when STA 106 is not requesting transmission of AP security parameter AP_PARAMS from AP 104, and / or when STA 106 does not additionally need AP security parameter AP_PARAMS from AP 104, field 816 may have a second value (such as binary "0"). AP 104 may, for example, abandon TK-protected transmission of AP security parameter AP_PARAMS in response to field 816 having a second value, and may perform TK-protected transmission of AP security parameter AP_PARAMS in response to field 816 having a first value (e.g., in...). Figure 7 (at time T3).

[0103] As a non-limiting example, STA 106 may include an RSNE of a PASN authentication frame with any of the following settings: (1) if the STA-ID subfield of the PASN parameter element exists, the RSNE does not have a PMKID field, the AKM suite count field is set to 0, and the pairwise cipher field is set to Galois Counter Mode Protection (GCMP)-256; and / or (2) if the STA-ID subfield of the PASN parameter element does not exist, the RSNE has a PMKID field, and the AKM field and pairwise cipher field are set to values ​​used to calculate PMKID. The STA-ID field in the PASN parameter element of the first PASN authentication frame (if present) may indicate whether the transmitter is allowed to set a transient key TK with the BPE AP (e.g., AP 104).

[0104] The STA identifier can be calculated, for example, by the formula STA-ID = truncated - 48(HMAC-SHA-256(“BPE non-AP MLD identifier”, identity key, address 1 | address 2)), where the identity key is the 128-bit identifier of the AP MLD, address 1 is A1 of the PASN authentication frame and is set to the link address of the BPE AP, and address 2 is A2 of the PASN authentication frame and is set to the link address of the STA. The STA can use randomization and change address 2 for each BPE active scan operation. If the BPE AP receives a first PASN authentication frame with STA-ID, the BPE AP can respond with a PASN authentication frame. If the BPE AP can calculate the STA identifier based on address 1 and address 2 of the received PASN frame, the calculated STA identifier STA-ID is equal to the value of the STA-ID field of the received PASN authentication frame.

[0105] If needed, STA 106 can set the AP Information Request subfield of the PASN element in the first PASN authentication frame to indicate that the STA expects to receive an AP capability and operation parameter response frame with a complete set of AP MLD parameters. If this subfield is set to the value 1, the first PASN authentication frame (e.g., PASN MSG1) may include a TK Adoption Delay subfield, which is set to the duration after PASN authentication frame 2 that the STA needs to put the TK into use. If AP 104 receives such a first PASN authentication frame and the STA-ID field matches, the BPE AP can respond with a second PASN authentication frame (e.g., PASN MSG2). If the TK Adoption Delay of the responding AP is longer than the TK Adoption Delay of the requesting STA, the second PASN authentication frame may include a TK Adoption Delay field. The AP may send a TK-protected AP capability and operation response frame at the maximum TK Adoption Delay value after the second PASN authentication frame is sent. If the STA expects to continue sending TK-protected management frames with the BPE AP, the STA may send any TK-encrypted frame or a third PASN authentication frame (e.g., PASN MSG3). The STA may send the TK-encrypted frame after the maximum TK adoption delay value following the transmission of the second PASN authentication frame.

[0106] exist Figure 8The presence of the Return Information subfield indicates whether the Return Information field is included in the PASN parameter element. The presence of the Group and Key subfield indicates whether the PASN parameter element includes the Finite Cyclic Group ID, Temporary Public Key Length, and Temporary Public Key fields. The presence of the TK Adoption Delay subfield indicates whether the TK Adoption Delay field is included in the PASN parameter element. The presence of the STA-ID subfield indicates whether the STA-ID field is included in the PASN parameter element. The AP Information Request subfield indicates whether AP capability and operational information are requested. As an example, the TK Adoption Delay field can be a time interval of 64 microseconds after the second PASN authentication frame, after which TK-protected frames can be sent. The STA-ID field can be an identifier for a non-AP STA of the BPE. Figure 8 The examples are illustrative, and in general, fields may be in a different order in the payload, the payload may include different / additional fields, and / or may be omitted. Figure 8 One or more fields are shown.

[0107] In another specific implementation, STA 106 can use the AP public key of AP 104 (e.g., the same public key used by the AP to encrypt the payload of the privacy beacon) to perform a protected BPE AP scan. Figure 9 This is a timing diagram illustrating an example of how the STA 106 can perform a protected BPE AP scan using the AP public key of the AP104. Figure 9 The operation can be performed after receiving a privacy beacon from AP 104. For example, this might happen when STA 106 knows the AP public key (e.g., via pre-configuration or sharing at operation 900) to set a new set of keys. At time TA, STA 106 may send a frame encrypted (protected) using the AP public key. The frame protected by the AP public key may include or otherwise identify STA 106's DH public key DHss, the TSF of the most recently received privacy beacon, and the AP security parameter request AP_PARAM_REQ. At time TB (e.g., in response to receiving the frame protected by the AP public key), AP 104 may send a key setting frame to STA 106. The key setting frame (e.g., a clearframe) may include or otherwise identify AP 104's DH public key DHss, AP 104's AP private key (e.g., corresponding to the AP public key), and / or AP signature.

[0108] In these specific implementations, only the pre-shared STA knows the AP public key. The AP assumes that any correctly received frame protected by the AP public key was sent by a valid (real) STA. The STA can add the TSF of the most recently received privacy beacon to the frame protected by the AP public key to prevent replay. The pre-shared STA can use the AP public key to protect requests to set a symmetric key (e.g., the AP private key) for use during pre-association signaling. The AP can transmit the DH temporary public key (e.g., the DH public key DHss sent at time TB) for creation of a pairwise transient key (PTK) in the frame (plaintext frame). If needed, the same TXOP can also include the AP security parameter AP_PARAMS encrypted with the PTK. A separate PPDU with the current PPDU type (e.g., plaintext or encrypted) may be required.

[0109] Although the 802.11bi protocol and / or earlier protocols assume that... Figure 4 Before operation 400, the required BPE AP security parameters for authenticating the STA and associating it with the BPE AP (e.g., RSNE, RSNXE, etc.) are pre-shared with the STA, but this is achieved by utilizing the security parameters described herein. Figures 1 to 9 One or more of these systems and methods can provide PASN TK-protected AP capabilities and operational elements that allow AP 104 to securely provide its BPE AP security parameters to STA 106. The corresponding PASN signaling described herein allows the AP to check whether requesting STA 106 is permitted to receive AP security parameters before sending them to the STA in a protected manner.

[0110] The AP security parameter query protected by TK described in this article offers several advantages over AP security parameters pre-shared with STA. For example, in Figure 4 Prior to operation 400, it may only be necessary to share the AP identity key and master key with STA 106. This helps reduce memory consumption at the STA. As another example, AP 104 can easily and quickly verify whether STA 106 is authorized to receive its AP security parameters (e.g., without needing to specifically identify STA 106 to the AP). This helps prevent AP security parameters from being leaked to potential attackers. As another example, privacy can be improved when scanning STA 106, thus helping to prevent scan request parameters from being leaked to third-party devices. As yet another example, RSNE and RSNXE mismatch between STA and AP may not itself prevent authentication, and STA can optimize association by knowing the available links and AP parameters. As yet another example, AP security parameters can be integrity protected, allowing STAs to verify the integrity of the received AP security parameters. Protected scan optimization can also reduce the number of frames sent and scan latency, thus helping to reduce the time and resources required to securely associate with the AP.

[0111] As used herein, the term "concurrent" means at least partially overlapping in time. In other words, the first and second events are referred to herein as "concurrent" if at least some of the first events occur simultaneously with at least some of the second events (e.g., if at least some of the first events occur during, concurrently with, or when at least some of the second events occur). The first and second events can be concurrent if they are synchronized (e.g., if the entire duration of the first event overlaps with the entire duration of the second event in time), but they can also be concurrent if they are asynchronous (e.g., if the first event begins before or after the second event, ends before or after the second event, or does not partially overlap in time). As used herein, the term "at the time of" is synonymous with "concurrent". The term "when" also implies at least some concurrency (e.g., "when" event B occurs, "when" event A occurs means that at least some of events A occur simultaneously with at least some of events B).

[0112] STA 106 and AP 102 / 104 ( Figure 1 It may collect and / or use personally identifiable information. It is well known that the use of personally identifiable information should comply with privacy policies and measures generally recognized as meeting or exceeding industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.

[0113] The above text combined Figures 1 to 9 The described methods and operations can be performed by components of the STA and / or AP using software, firmware, and / or hardware (e.g., dedicated circuitry or hardware). Software code for performing these operations may be stored on a non-transitory computer-readable storage medium (e.g., a tangible computer-readable storage medium) on one or more components of the STA and / or AP. This software code may sometimes be referred to as software, data, instructions, program instructions, or code. The non-transitory computer-readable storage medium may include drives, non-volatile memory such as non-volatile random access memory (NVRAM), removable flash drives or other removable media, other types of random access memory, etc. The software stored on the non-transitory computer-readable storage medium can be executed by processing circuitry on one or more components of the STA and / or AP. The processing circuitry may include a microprocessor, a central processing unit (CPU), an application-specific integrated circuit (ASIC) with processing circuitry, or other processing circuitry.

[0114] For one or more aspects, at least one of the components shown in one or more of the foregoing figures may be configured to perform one or more operations, techniques, processes, or methods described in the Embodiments section below. For example, circuitry associated with an electronic device, authentication server, one or more processors, etc., described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more embodiments shown in the Embodiments section below.

[0115] Example Further exemplary aspects are provided in the following sections.

[0116] Example 1 includes a method for an operating station (STA) to communicate with an access point (AP). The method may include: generating a station identifier (STA-ID) using one or more processors based on a first network address of the AP, a second network address of the STA, a cryptographic key, and a cryptographic function. The method may include: transmitting the STA-ID to the AP in a first message using one or more antennas. The method may include: receiving a second message sent by the AP based on the STA-ID in the first message using the one or more antennas. The method may include: after receiving the second message, associating with the AP using one or more encrypted management frames transmitted between the STA and the AP.

[0117] Example 2 includes the method according to Example 1 or some other example or combination of examples herein, the method further comprising: receiving a privacy beacon from the AP before sending the first message, wherein the privacy beacon identifies the first network address.

[0118] Example 3 includes the method according to any one of Example 1 or 2 or some other example or combination of examples herein, wherein at least some of the privacy beacons are encrypted by the AP using the AP's public key, and wherein the cryptographic key includes the AP's public key.

[0119] Example 4 includes the method according to any one of Examples 1 to 3 or some other example or combination of examples herein, wherein the first address includes a first media access control (MAC) address of the AP, and the second address includes a second MAC address of the STA.

[0120] Example 5 includes the method according to any one of Examples 1 to 4 or some other example or combination of examples herein, wherein the cryptographic function includes a secure hash algorithm (SHA), and generating the STA-ID includes: inputting the first MAC address, the second MAC address and the public key of the AP into the SHA.

[0121] Example 6 includes the method according to any one of Examples 1 to 5 or some other example or combination of examples herein, wherein the first message includes Associated Pre-Security Negotiation (PASN) message 1 (MSG1) and the second message includes PASN message 2 (MSG2).

[0122] Example 7 includes the method according to any one of Examples 1 to 6 or some other example or combination of examples herein, wherein the PASN MSG1 includes a first Diffie-Hellman (DH) public key of the STA and the PASN MSG2 includes a second DH public key of the AP, the method further comprising: generating a transient key (TK) using the one or more processors based on the first DH public key and the second DH public key; and encrypting at least one of the one or more encrypted management frames using the one or more processors based on the TK.

[0123] Example 8 includes the method according to any one of Examples 1 to 7 or some other embodiment or combination of embodiments herein, wherein the PASN MSG2 includes a message integrity check (MIC), and the method further includes: using the one or more antennas to transmit a PASN message 3 (MSG3) including the MIC.

[0124] Example 9 includes a method according to any one of Examples 1 to 48 or some other example or combination of examples herein, wherein the PASN MSG1 includes a field identifying whether the STA is requesting a set of AP security parameters associated with the AP from the AP.

[0125] Example 10 includes the method according to any one of Examples 1 to 9 or some other embodiment or combination of embodiments herein, the method further comprising: deriving a transient key (TK) using the one or more processors at least based on the PASN MSG2 received from the AP; after receiving the PASN MSG2, using the one or more antennas to receive a third message containing a set of AP security parameters; decrypting the third message using the TK; and associating with the AP based on the set of AP security parameters from the decrypted third message.

[0126] Example 11 includes the method according to any one of Examples 1 to 10 or some other example or combination of examples herein, wherein the set of AP security parameters includes the robust secure network element (RSNE) of the AP and the robust secure network extension element (RSNXE) of the AP.

[0127] Example 12 includes the method according to any one of Examples 1 to 11 or some other example or combination of examples herein, wherein the PASN MSG1 includes a field identifying the instantaneous key use delay of the STA, and wherein the third message is received from the AP after a certain period of time has elapsed since the PASN MSG2 was received, wherein the period of time is greater than or equal to the instantaneous key use delay of the STA.

[0128] Example 13 includes the method according to any one of Examples 1 to 12 or some other example or combination of examples herein, wherein the PASN MSG2 includes a field identifying the instantaneous key of the AP using a delay, and wherein the third message is received from the AP after a certain period of time has elapsed since the PASN MSG2 was received, wherein the period of time is greater than or equal to the instantaneous key of the AP using a delay.

[0129] Example 14 includes a method of operating an access point (AP) to communicate with a station (STA), the method comprising: using one or more antennas to transmit a privacy beacon encrypted using a cryptographic key of the AP; using one or more antennas to receive a first message including a station identifier (STA-ID) from the STA; attempting to verify the STA-ID in the first message using one or more processors based on a first network address of the AP, a second network address of the STA, the cryptographic key, and a cryptographic function; and in response to verifying the STA-ID, using the one or more antennas to transmit a second message to the STA, the second message including information that can be used by the STA to encrypt management frames used when associating the STA with the AP.

[0130] Example 15 includes the method according to Example 14 or some other example or combination of examples herein, wherein attempting to verify the STA-ID includes inputting the first network address, the second network address and the cryptographic key into the cryptographic function and comparing the output of the cryptographic function with the STA-ID in the first message.

[0131] Example 16 includes the method according to any one of Examples 14 or 15 or some other example or combination of examples herein, wherein the first message includes Associated Pre-Security Negotiation (PASN) message 1 (MSG1) and the second message includes PASN message 2 (MSG2).

[0132] Example 17 includes the method according to any one of Examples 14 to 16 or some other embodiment or combination of embodiments herein, wherein PASN message 1 includes an AP security parameter request and a first instantaneous key adoption delay, PASN message 2 includes a second instantaneous key adoption delay, and the method further includes: after sending PASN MSG2 and before the STA is associated with the AP, using the one or more antennas to send a set of AP security parameters to the STA, wherein the set of AP security parameters is encrypted using an instantaneous key derived by the AP at least in part based on PASN MSG1, the AP sending the set of AP security parameters after a period of time has elapsed since sending PASN MSG2, and the period of time is longer than the greater of the first instantaneous key adoption delay and the second instantaneous key adoption delay.

[0133] Example 18 includes a method for an operating site (STA) to communicate with an access point (AP), the method comprising: sending a pre-association security negotiation (PASN) message to the AP using a radio component and one or more antennas communicatively coupled to the radio component, wherein the PASN message includes a payload comprising: a STA identifier (STA-ID) field, the STA-ID field including a STA-ID that can be used by the AP to verify that the STA is authorized to receive a set of security parameters from the AP; and associating with the AP using the radio component based on the set of security parameters.

[0134] Example 19 includes the method according to Example 18 or some other example or combination of examples herein, wherein the payload of the PASN message further includes: a Transient Key (TK) Adoption Delay field; a TK Adoption Delay Existence field corresponding to the TK Adoption Delay field; a STA-ID Existence field corresponding to the STA-ID field; and an AP Information Request field.

[0135] Example 20 includes the method according to any one of Examples 18 or 19 or some other example or combination of examples herein, wherein: the TK uses a delay field and the STA-ID field in PASN parameter element format, the TK uses a delay field between the STA-ID field and the temporary public key field of the payload, the temporary public key field is in PASN parameter element format, the TK uses a delay presence field, the STA-ID presence field and the AP information request field in PASN parameter element control information field format, and the STA-ID presence field is between the delay presence field and the AP information request field of the TK in the payload.

[0136] Example 21 may include an apparatus comprising one or more elements for performing a method or process described or associated with any one of Examples 1 to 20 or a combination thereof, or any other method or process described herein.

[0137] Example 22 may include one or more non-transitory computer-readable media, the one or more non-transitory computer-readable media including instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform one or more elements of a method or process described in or related to any one of Examples 1 to 20 or any other method or process described herein.

[0138] Example 23 may include an apparatus comprising logic components, modules, or circuitry for performing one or more elements of a method or process described herein or related to any one of Examples 1 to 20, or a combination thereof.

[0139] Example 24 may include a method, technique, or process, or a part or component thereof, described or associated with any of Examples 1 to 20 or a combination thereof.

[0140] Example 25 may include an apparatus comprising: one or more processors and one or more non-transitory computer-readable storage media, the one or more non-transitory computer-readable storage media including instructions that, when executed by the one or more processors, cause the one or more processors to perform a method, technique, or process, or part thereof, according to any one of Examples 1 to 20 or a combination thereof.

[0141] Example 26 may include signals, or portions or components thereof, described or associated with any one of Examples 1 to 20 or a combination thereof.

[0142] Example 27 may include datagrams, information elements, packets, frames, segments, PDUs, or messages, or portions or components thereof, as described or associated with any of Examples 1 to 20, or otherwise described in this disclosure.

[0143] Example 28 may include a signal encoded with data, or a portion or component thereof, as described in or related to any one of Examples 1 to 20, or a combination thereof, or otherwise described in this disclosure.

[0144] Example 29 may include signals, or portions or components thereof, encoded as datagrams, IEs, packets, frames, segments, PDUs or messages according to any one of Examples 1 to 20 or in combination thereof, or otherwise described in this disclosure.

[0145] Example 30 may include an electromagnetic signal carrying computer-readable instructions, wherein execution of the computer-readable instructions by one or more processors will cause the one or more processors to perform a method, technique, or process, or part thereof, as described or associated with any one of Examples 1 to 20 or a combination thereof.

[0146] Example 31 may include a computer program comprising instructions, wherein execution of the program by a processing element will cause the processing element to perform a method, technique, or process, or part thereof, as described or associated with any one of Examples 1 to 20 or a combination thereof.

[0147] Example 32 may include signals in a wireless network as shown and described herein.

[0148] Example 33 may include methods for communicating in a wireless network as shown and described herein.

[0149] Example 34 may include a system for providing wireless communication as shown and described herein.

[0150] Example 35 may include a device for providing wireless communication as shown and described herein.

[0151] According to one embodiment, a method for an operating site (STA) to communicate with an access point (AP) includes: generating a site identifier (STA-ID) using one or more processors based on a first network address of the AP, a second network address of the STA, a cryptographic key, and a cryptographic function; transmitting the STA-ID to the AP in a first message using one or more antennas; receiving a second message transmitted by the AP based on the STA-ID in the first message using the one or more antennas; and, upon receiving the second message, associating with the AP using one or more encrypted management frames transmitted between the STA and the AP.

[0152] According to another embodiment, the method selectively includes: receiving a privacy beacon from the AP before sending the first message, wherein the privacy beacon identifies the first network address.

[0153] According to another embodiment, at least some of the privacy beacons are optionally encrypted by the AP using the AP's public key, and the cryptographic key optionally includes the AP's public key.

[0154] According to another embodiment, the first address optionally includes the first media access control (MAC) address of the AP, and the second address optionally includes the second MAC address of the STA.

[0155] According to another embodiment, the cryptographic function optionally includes a secure hash algorithm (SHA), and generating the STA-ID optionally includes inputting the first MAC address, the second MAC address, and the public key of the AP into the SHA.

[0156] According to another embodiment, the first message optionally includes Associated Pre-Security Negotiation (PASN) message 1 (MSG1), and the second message optionally includes PASN message 2 (MSG2).

[0157] According to another embodiment, the PASN MSG1 optionally includes a first Diffie-Hellman (DH) public key of the STA, and the PASN MSG2 optionally includes a second DH public key of the AP. The method further includes: generating a transient key (TK) using the one or more processors based on the first DH public key and the second DH public key; and encrypting at least one of the one or more encrypted management frames using the one or more processors based on the TK.

[0158] According to another embodiment, the PASN MSG2 optionally includes a message integrity check (MIC), and the method optionally further includes: using the one or more antennas to transmit a PASN message 3 (MSG3) including the MIC.

[0159] According to another embodiment, the PASN MSG1 optionally includes a field identifying whether the STA is requesting a set of AP security parameters associated with the AP from the AP.

[0160] According to another embodiment, the method optionally includes: deriving a transient key (TK) using the one or more processors, at least based on the PASN MSG2 received from the AP; after receiving the PASN MSG2, using the one or more antennas to receive a third message containing a set of AP security parameters; decrypting the third message using the TK; and associating with the AP based on the set of AP security parameters from the decrypted third message.

[0161] According to another embodiment, the set of AP security parameters optionally includes the robust security network element (RSNE) of the AP and the robust security network extension element (RSNXE) of the AP.

[0162] According to another embodiment, the PASN MSG1 optionally includes a field identifying the instantaneous key adoption delay of the STA, and wherein the third message is received from the AP after a certain period of time has elapsed since the PASN MSG2 was received, wherein the period of time is greater than or equal to the instantaneous key adoption delay of the STA.

[0163] According to another embodiment, the PASN MSG2 optionally includes a field identifying the instantaneous key adoption delay of the AP, and wherein the third message is received from the AP after a certain period of time has elapsed since the PASN MSG2 was received, wherein the period of time is greater than or equal to the instantaneous key adoption delay of the AP.

[0164] According to one embodiment, a method of operating an access point (AP) to communicate with a station (STA) includes: using one or more antennas to transmit a privacy beacon encrypted using a cryptographic key of the AP; using one or more antennas to receive a first message including a station identifier (STA-ID) from the STA; attempting to verify the STA-ID in the first message using one or more processors based on a first network address of the AP, a second network address of the STA, the cryptographic key, and a cryptographic function; and in response to verifying the STA-ID, using the one or more antennas to transmit a second message to the STA, the second message including information that can be used by the STA to encrypt management frames used when associating the STA with the AP.

[0165] According to another embodiment, attempting to verify the STA-ID optionally includes inputting the first network address, the second network address, and the password key into the cryptographic function, and comparing the output of the cryptographic function with the STA-ID in the first message.

[0166] According to another embodiment, the first message optionally includes Associated Pre-Security Negotiation (PASN) message 1 (MSG1), and the second message optionally includes PASN message 2 (MSG2).

[0167] According to another embodiment, PASN message 1 optionally includes an AP security parameter request and a first instantaneous key adoption delay, PASN message 2 optionally includes a second instantaneous key adoption delay, and the method optionally further includes: after sending PASN MSG2 and before the STA associates with the AP, using the one or more antennas to send a set of AP security parameters to the STA, wherein the set of AP security parameters is encrypted using an instantaneous key derived by the AP at least in part based on PASN MSG1, the AP sending the set of AP security parameters after a period of time has elapsed since sending PASN MSG2, and the period of time is longer than the greater of the first instantaneous key adoption delay and the second instantaneous key adoption delay.

[0168] According to one embodiment, an operating site (STA) communicates with an access point (AP) in a manner comprising: sending a pre-association security negotiation (PASN) message to the AP using a radio component and one or more antennas communicatively coupled to the radio component, wherein the PASN message includes a payload including an STA identifier (STA-ID) field, the STA-ID field including an STA-ID that can be used by the AP to verify that the STA is authorized to receive a set of security parameters from the AP; and associating with the AP using the radio component based on the set of security parameters.

[0169] According to another embodiment, the payload of the PASN message optionally includes: a TK adoption delay field; a TK adoption delay presence field corresponding to the TK adoption delay field; a STA-ID presence field corresponding to the STA-ID field; and an AP information request field.

[0170] According to another embodiment, the TK uses a delay field and the STA-ID field optionally in PASN parameter element format, the TK uses a delay field between the STA-ID field and the temporary public key field of the payload, the temporary public key field is in PASN parameter element format, the TK uses a delay presence field, the STA-ID presence field and the AP information request field in PASN parameter element control information field format, and the STA-ID presence field is between the delay presence field and the AP information request field of the TK of the payload.

[0171] Unless otherwise expressly stated, any embodiment described above may be combined with any other embodiment (or combination of embodiments). The foregoing description of one or more specific embodiments provides illustration and description, but is not intended to be exhaustive or to limit the scope of the aspects to the precise forms disclosed.

Claims

1. A method for an operating station (STA) to communicate with an access point (AP), the method comprising: One or more processors are used to generate a station identifier (STA-ID) based on the first network address of the AP, the second network address of the STA, the cryptographic key, and the cryptographic function. The STA-ID is sent to the AP in the first message using one or more antennas; The one or more antennas are used to receive a second message sent by the AP based on the STA-ID in the first message; as well as Upon receiving the second message, one or more encrypted management frames transmitted between the STA and the AP are used to associate with the AP.

2. The method according to claim 1, further comprising: Before sending the first message, a privacy beacon is received from the AP, wherein the privacy beacon identifies the first network address.

3. The method of claim 2, wherein at least some of the privacy beacons are encrypted by the AP using the AP's public key, and wherein the cryptographic key includes the AP's public key.

4. The method of claim 3, wherein the first address includes the first media access control (MAC) address of the AP, and the second address includes the second MAC address of the STA.

5. The method of claim 4, wherein the cryptographic function includes a secure hash algorithm (SHA), and generating the STA-ID includes inputting the first MAC address, the second MAC address, and the public key of the AP into the SHA.

6. The method of claim 1, wherein the first message includes Associated Pre-Security Negotiation (PASN) message 1 (MSG1), and the second message includes PASN message 2 (MSG2).

7. The method of claim 6, wherein the PASN MSG1 includes the first Diffie-Hellman (DH) public key of the STA, and the PASN MSG2 includes the second DH public key of the AP, the method further comprising: The one or more processors are used to generate a transient key (TK) based on the first DH public key and the second DH public key. as well as The one or more processors are used to encrypt at least one of the one or more encrypted management frames based on the TK.

8. The method of claim 6, wherein the PASN MSG2 includes a message integrity check (MIC), and the method further includes: The one or more antennas are used to transmit PASN message 3 (MSG3) including the MIC.

9. The method of claim 6, wherein the PASN MSG1 includes a field identifying whether the STA is requesting a set of AP security parameters associated with the AP from the AP.

10. The method according to claim 9, further comprising: The transient key (TK) is derived using one or more processors based at least on the PASN MSG2 received from the AP. After receiving the PASN MSG2, the one or more antennas are used to receive a third message containing a set of AP security parameters; Use the TK to decrypt the third message; as well as The AP is associated with a set of security parameters derived from the decrypted third message.

11. The method of claim 10, wherein the set of AP security parameters includes the robust security network element (RSNE) of the AP and the robust security network extension element (RSNXE) of the AP.

12. The method of claim 10, wherein the PASN MSG1 includes a field identifying the instantaneous key adoption delay of the STA, and wherein the third message is received from the AP after a time period has elapsed since the PASN MSG2 was received, wherein the time period is greater than or equal to the instantaneous key adoption delay of the STA.

13. The method of claim 10, wherein the PASN MSG2 includes a field identifying a delay in the instantaneous key use of the AP, and wherein the third message is received from the AP after a time period has elapsed since the PASN MSG2 was received, wherein the time period is greater than or equal to the delay in the instantaneous key use of the AP.

14. A method of operating an access point (AP) to communicate with a station (STA), the method comprising: One or more antennas are used to transmit privacy beacons encrypted with the cryptographic key of the AP; Use one or more antennas to receive a first message, including a station identifier (STA-ID), from the STA; Try using one or more processors to verify the STA-ID in the first message based on the first network address of the AP, the second network address of the STA, the cryptographic key, and the cryptographic function; as well as In response to verifying the STA-ID, a second message is sent to the STA using the one or more antennas. The second message includes information that the STA can use to encrypt management frames used when associating the STA with the AP.

15. The method of claim 14, wherein attempting to verify the STA-ID comprises inputting the first network address, the second network address, and the cryptographic key into the cryptographic function, and comparing the output of the cryptographic function with the STA-ID in the first message.

16. The method of claim 14, wherein the first message includes Associated Pre-Security Negotiation (PASN) message 1 (MSG1), and the second message includes PASN message 2 (MSG2).

17. The method of claim 16, wherein the PASN message 1 includes an AP security parameter request and a first transient key adoption delay, the PASN message 2 includes a second transient key adoption delay, and the method further comprises: After transmitting the PASN MSG2 and before the STA associates with the AP, the one or more antennas are used to transmit a set of AP security parameters to the STA, wherein... The set of AP security parameters is encrypted using a transient key derived by the AP, at least in part, based on the PASN MSG1. The AP sends a set of AP security parameters after a period of time has elapsed since the PASN MSG2 was sent, and The time period is longer than the greater of the first instantaneous key adoption delay and the second instantaneous key adoption delay.

18. A method for an operating station (STA) to communicate with an access point (AP), the method comprising: A pre-association security negotiation (PASN) message is sent to the AP using a radio component and one or more antennas communicatively coupled to the radio component, wherein the PASN message includes a payload comprising: The STA identifier (STA-ID) field includes a STA-ID that the AP can use to verify that the STA is authorized to receive a set of security parameters from the AP; and The radio component is used to associate with the AP based on the set of security parameters.

19. The method of claim 18, wherein the payload of the PASN message further comprises: The instantaneous key (TK) uses a delay field; The TK uses a delayed existence field, which corresponds to the TK using a delayed field. The STA-ID field corresponding to the STA-ID field exists; and AP Information Request Field.

20. The method of claim 19, wherein: The TK uses a delay field and the STA-ID field in a PASN parameter element format. The TK uses a delay field between the STA-ID field and the temporary public key field in the payload. The temporary public key field is in the format of the PASN parameter element. The TK uses a delay presence field, the STA-ID presence field, and the AP information request field in a PASN parameter element control information field format, and The STA-ID presence field is located between the TK delay presence field and the AP information request field of the payload.