Protected pre-association station identification

The method and system address privacy and identification challenges by allowing access points to request and secure unique identifiers from workstations, ensuring consistent service provision and user privacy through UUIDs or random numbers.

TWI931565BActive Publication Date: 2026-07-11洛克斯IP控股有限責任公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TW111131277
Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-19
Filing Date
2022-08-19
Publication Date
2026-07-11
Estimated Expiration
2042-08-18

AI Technical Summary

Technical Problem

The increasing adoption of random MAC addresses in wireless devices poses challenges for WLAN infrastructure, as it complicates user identification and tracking, leading to privacy concerns and loss of utility for users who require consistent identification for services like parental controls.

Method used

A method and system that allows an access point to request and establish a secure connection with a workstation, receiving a unique identifier different from the MAC address, and providing access based on this identifier, enabling flexible privacy settings and consistent identification across associations.

Benefits of technology

Enables secure and flexible user identification, allowing workstations to maintain privacy while ensuring consistent service provision, such as parental controls, by using unique identifiers like UUIDs or random numbers, and supporting different privacy preferences.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMG-2_DRAW_111131277-A0304-14-0001-1
    Figure IMG-2_DRAW_111131277-A0304-14-0001-1
  • Figure IMG-2_DRAW_111131277-A0304-14-0002-2
    Figure IMG-2_DRAW_111131277-A0304-14-0002-2
  • Figure IMG-2_DRAW_111131277-A0304-14-0002-3
    Figure IMG-2_DRAW_111131277-A0304-14-0002-3
Patent Text Reader

Abstract

Methods, systems, and computer-readable media are operable to facilitate message exchange between an access point and a workstation, wherein the access point requests a unique identifier from the workstation. Before associating with the access point, the workstation initiates a secure connection with the access point. The workstation may respond via the secure connection with a message refusing to provide a unique identifier, or with a message containing a unique identifier to be used by the workstation's access point. The response from the workstation may include additional restrictions on the access point's use of the unique identifier. The access point can implement different policies for the workstation depending on how it responds to the unique identifier request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to an improved processing of the unique identification code for workstations. Prior Technology

[0002] Wireless devices (such as WLAN (Wireless Local Area Network) or Wi-Fi devices) are increasingly adopting random MAC (Media Access Control) addresses. This poses a problem for many parts of the WLAN infrastructure (such as Wi-Fi), which may use the wireless device's MAC address as a unique identifier for the wireless device.

[0003] Different users may have different requirements or expectations regarding privacy. Some users may prioritize privacy over other considerations. For example, end users in public areas may not want their presence to be tracked, while end users at home may see the value in allowing identification and tracking devices so that other functions, such as parental controls, can operate as expected.

[0004] Because many users will utilize the current system, they will experience a loss of utility each time they are forced to log in, as access point 115 or the monitoring system will be unable to identify workstation 105. These users may perceive the ability to use a stored, randomized MAC address as providing their privacy when they are not actually providing it.

[0005] Therefore, there is a need for an improved method and system for processing unique identifiers of workstations. Summary of the Invention

[0006] This disclosure provides a method for providing an access point to a workstation with one or more functions. The method includes outputting a unique identifier request to the workstation before association with the workstation, wherein the unique identifier request includes a request from the workstation in response to a unique identifier to be used by the access point of the workstation; establishing a secure connection with the workstation, receiving a unique identifier response from the workstation through the secure connection, determining that the workstation supports creating and providing the unique identifier based on an instruction provided in the unique identifier response; determining that the unique identifier response provides the unique identifier to be used by the workstation, wherein the unique identifier is different from a Media Access Control (MAC) address of the workstation; and providing access to the workstation with the one or more functions based on the unique identifier received in the unique identifier response.

[0007] In the disclosed example, the method enables establishing the secure connection with the workstation to include exchanging one or more cryptographic keys with the workstation.

[0008] In the disclosed example, the method makes establishing the secure connection involve a pre-association security negotiation.

[0009] In the disclosed sample, the unique identifier includes a universally unique identifier, a random number, a pseudo-random number, a pre-configured identifier, or any combination thereof.

[0010] In the disclosed sample, the method further includes associating the workstation with the access point.

[0011] In this disclosed embodiment, the method further includes, after associating the workstation with the access point, providing network information to the workstation, the network information specifying a network or network access for the workstation.

[0012] In this disclosed embodiment, the method enables the workstation to access one or more functions based on the unique identifier received in the unique identifier response, including providing one or more benefits associated with a retail business or an online business.

[0013] This disclosure provides an access point for providing access to one or more functions of a workstation. The access point includes a memory storing one or more computer-readable instructions and a processor configured to execute the one or more computer-readable instructions to output a unique identifier request to the workstation before association with it. The unique identifier request includes a request from the workstation in response to a unique identifier to be used by the access point of the workstation, establishing a secure connection with the workstation, receiving a unique identifier response from the workstation through the secure connection, determining that the workstation supports creating and providing the unique identifier based on an instruction provided in the unique identifier response, determining that the unique identifier response provides the unique identifier to be used by the workstation, wherein the unique identifier is different from a media access control (MAC) address of the workstation, and providing access to the one or more functions to the workstation based on the unique identifier received in the unique identifier response.

[0014] In the disclosed example, establishing the secure connection with the workstation includes exchanging one or more cryptographic keys with the workstation.

[0015] In the disclosed configuration, establishing the secure connection involves a pre-association security negotiation.

[0016] In the disclosed sample, the unique identifier includes a universally unique identifier, a random number, a pseudo-random number, a pre-configured identifier, or any combination thereof.

[0017] In this disclosed embodiment, the processor is further configured to execute one or more computer-readable instructions to associate the workstation with the access point.

[0018] In this disclosed embodiment, the processor is further configured to execute one or more computer-readable instructions to provide network information to the workstation after associating the workstation with the access point, the network information specifying a network or network access for the workstation.

[0019] In the form disclosed herein, providing access to one or more functions to the workstation based on the unique identifier received in the unique identifier response includes providing one or more benefits associated with a retail business or an online business.

[0020] This disclosure provides a non-transitory computer-readable medium for an access point, storing one or more computer-readable instructions for providing access to one or more functions of a workstation. When executed by a processor of the access point, the one or more computer-readable instructions cause the access point to perform one or more operations of any one or more of the above method steps. Simple Explanation of the Diagram

[0021] Figure 1 is a block diagram illustrating an example network environment operable to facilitate the management of unique identifiers for workstations.

[0022] Figure 2A shows a sample format for a unique identifier request.

[0023] Figure 2B shows an example format for a unique identifier response.

[0024] Figure 3A shows a sample format for a unique identifier request, which includes an ID (identifier) ​​lookup action field.

[0025] Figure 3B shows an example format for a unique identifier response, which includes an ID lookup action field.

[0026] Figure 4 is a block diagram illustrating an example access point that can be operated to facilitate the management of unique identifiers for workstations.

[0027] Figure 5 is a flowchart illustrating an example process operable to facilitate the management of unique identifiers recovered from a unique identifier response received from a workstation.

[0028] Figure 6 is a flowchart illustrating an example process operable to facilitate the management of unique identifiers recovered from unique identifier responses received from workstations that support the exchange of unique identifier messages.

[0029] Figure 7 is a flowchart illustrating an example process operable to facilitate the management of unique identifiers recovered from a unique identifier response received from a workstation, wherein the unique identifier response includes an identifier duration field.

[0030] Figure 8 is a flowchart illustrating an example process operable to facilitate the management of unique identifiers recovered from unique identifier responses received from workstations, wherein the access point permanently stores the unique identifier when no identifier duration response is provided.

[0031] Figure 9 is a flowchart illustrating an example process operable to facilitate a response to a unique identifier request.

[0032] Figure 10 is a flowchart illustrating an example process operable to facilitate the management of unique identifiers recovered from a unique identifier response, which is received from the workstation after a second or subsequent association between the access point and the workstation.

[0033] Figure 11 is a block diagram of the hardware configuration that can be operated to facilitate the management of the workstation's unique identifier.

[0034] Figure 12 is a flowchart illustrating an example process operable to facilitate receiving an unsolicited unique identifier response from a workstation.

[0035] Figure 13 is a flowchart illustrating an example process operable to facilitate communication via a unique identifier response through a secure connection.

[0036] Similar reference numbers and names in various diagrams indicate similar elements. Implementation

[0037] This application is a partial successive application which contends to apply on 15 January 2020 for Non-Provisional Application No. 16 / 743,623, in Title to Non-Provisional Application No. 17 / 390,147 filed on July 30, and Non-Provisional Application No. 17 / 390,076 filed on July 30, 2021. The all non-temporary Applications claim filed on January 15, 2019, U.S. Provisional Filing Sequence No. 62 / 792,744 titled “Treatment of Random MAC Addresses in 802.11,” and in the processing of random MAC addresses” of interest in both U.S. Temporary Filings Sequence No. 62 / 875,279, and Non-Provisional Filings Nos. 16 / 743,623, Non-Provisional Filings Nos. 17 / 390,147 , Non-Provisional Filing No. 17 / 390,076, U.S. Provisional Filing Sequence No. 62 / 792,744, and U.S. Provisional Filing Sequence No. 62 / 875,279 are incorporated herein by reference in their entirety.

[0038] It is expected to improve the methods and systems used to process unique identifiers for workstations. The method, system, and computer-readable media can be operated to facilitate the exchange of messages between the access point and the workstation, where the access point requests a unique identifier from the workstation. The workstation may respond to a message that refuses to provide a unique identifier or to a message that contains a unique identifier that will be used by the access point of the workstation. Responses from workstations may include additional restrictions on access points using unique identifiers. The access point can implement different policies for the workstation depending on how the workstation responds to unique identifier requests.

[0039] This article describes the addition of a new message to 802.11, which explicitly allows the access point to ask the workstation for a unique identifier it wishes to know. This message cannot force workstations to disclose information, as some workstations may choose to reduce performance to maintain their privacy, but allows workstations to share information that is substandard today.

[0040] Figure 1 is a block diagram illustrating an example network environment 100 operable to facilitate the management of unique identifiers for workstations. In a specific example, video, voice, and / or data services may be transmitted to one or more workstations 105 via one or more signal paths. Workstations 105 may include laptops, mobile devices, tablets, computers, set-top boxes (STBs), gaming devices, wearable devices, and any other devices operable to receive video, voice, and / or data services. It should be understood that various data, multimedia, and / or voice services may be transmitted to workstations 105, including but not limited to streaming video, streaming audio, file transfer, email, telephone services, and others.

[0041] Multiple services can be delivered to workstation 105 via one or more local wireless networks 110. Local wireless networks 110 may include wireless local area networks (WLANs), personal area networks (PANs), mobile hotspot networks, and others. Local network 110 may be provided at the orderer's premises by one or more access points 115. Access points 115 may be, for example, CPE (Customer Premises Equipment) devices and may include any device configured to facilitate communication between a wide area network (WAN) and one or more workstations 105 (such as modems, multimedia terminal adapters (MTAs), embedded MTAs (EMTAs), gateway devices, network extenders, or other access devices). Access points 115 may be integrated with other devices. For example, access point 115 may include a broadband access modem (e.g., the modem may be located in a gateway device, STB, or other device). It should be understood that multiple services can be delivered via local network 110 using various standards and formats. Those skilled in the art will understand that workstation 105 can interact and communicate with each other and / or with access point 115 via various wireless communication standards (e.g., Wi-Fi, Bluetooth, etc.).

[0042] In a specific example, access point 115 may be connected to a broadband access network 120, and communication may be routed between one or more workstations 105 and the WAN (Wide Area Network) 125 via the connection to the broadband access network 120. Note that the broadband access network itself may be wired or wireless.

[0043] Generally, according to wireless communication standards, if workstation 105 is not currently connected, it will continuously probe for new networks. Typically, the probe messages include fields such as the workstation 105's MAC (Media Access Control) address. If the network already knows the MAC address of the end-user device, the cooperating network can track the end-user's movement by tracking probe messages received at different access points.

[0044] To provide additional privacy for end users, MAC address randomization can be used. Randomized MAC addresses can be accelerated by using MAC addresses from the local MAC address space. The local MAC address can be identified if the "local" bit is set (e.g., the second bit of the first byte of the MAC address). Using the local MAC address space minimizes the possibility that the device may select a MAC address that is already in use by another device. Using this MAC address space also suggests to the receiving device (e.g., an access point) that it has received a randomized MAC (rMAC) address, which may affect its actions towards the workstation.

[0045] Different device vendors choose to utilize random MAC addresses in different ways. For example, when a workstation is not associated, it can be configured to use a random MAC address that changes periodically when a probe request is transmitted (e.g., the rMAC changes after a specific time interval, or with each probe request, etc.). The workstation can be configured to use the rMAC as a default option or as an option selected by the end user. When a workstation is associated with an SSID (Service Group Identifier) ​​provided by an access point, the workstation can be configured to consistently use the same rMAC for a given SSID, use a new rMAC for each associated SSID, or change the rMAC after a specific time interval (e.g., daily, weekly, etc.). After association is complete, the workstation can be configured to use the same rMAC, or configured to periodically change the rMAC used by the workstation after certain events, such as loss and reacquisition of the association. The association of workstation 105 with access point 115 may include the process of workstation 105 joining a service group (e.g., an SSID) or a network provided by access point 115.

[0046] In a specific example, access point 115 can be configured to provide various functions such as parental controls and device redirection based on its ability to consistently identify workstation 105 across associated events. Furthermore, the infrastructure system may use past behavior to provide improved redirection and other services to workstation 105, which would be ineffective if workstation 105 cannot recognize the infrastructure ESS (Extended Service Group) / BSS (Basic Service Group) upon return.

[0047] To allow for flexibility, this document defines secure communication exchanges (e.g., action frame exchanges) to allow access point 115 to request additional unique identifiers from workstation 105. The communication exchange may include a unique identifier request output by access point 115 and received by workstation 105, and a unique identifier response transmitted from workstation 105 to access point 115 in response to the unique identifier request. Access point 115 may implement different policies for workstation 105 depending on how workstation 105 responds to the unique identifier request. The communication exchange between access point 115 and workstation 105 is secure and maintains privacy. The unique identifier request and response messages may be wireless communications (e.g., 802.11 messages).

[0048] In a specific example, a request for a unique identifier may include identification of the network type (e.g., the network associated with the SSID) provided by access point 115 (e.g., a private data network, a private guest network, a hotspot network, a public network, etc.) and / or an indication of whether the network provided by access point 115 is encrypted or unencrypted. Workstation 105 may be configured to respond to a unique identifier request based on the network type identified in the request and / or whether encryption is enabled. For example, workstation 105 may apply a filter to the identification of the network type in the request to determine whether to respond. Based on the information in the request, workstation 105 may determine the encryption of the information it provides. In a specific example, a unique identifier request may include identification of the network encryption type.

[0049] In a specific example, the unique identifier response may include an indication of whether workstation 105 provides a unique identifier to access point 115. For example, workstation 105 may be configured to determine whether to provide a unique identifier based on the network type and / or encryption provided by access point 115. The unique identifier response may include an identification of the length of the unique identifier associated with workstation 105, and may include the unique identifier associated with workstation 105. In a specific example, the unique identifier response may include an optional field for an identifier duration value. If an identifier duration value is not included, access point 115 may use the unique identifier of workstation 105 for a preset duration (e.g., only during the current association between workstation 105 and access point 115, permanently, etc.). Alternatively, the identifier duration value may indicate that the unique identifier will be used by workstation 105 only during the current association between workstation 105 and access point 115, during which time access point 115 will store the unique identifier of workstation 105 until the current association between workstation 105 and access point 115 ends. As another example, the identifier duration value may include a specific duration (e.g., time in seconds) for which access point 115 stores the unique identifier of workstation 105. In a specific example, the unique identifier response may include optional fields, which may include vendor-specific options.

[0050] During the initial association between access point 115 and workstation 105, when access point 115 is authorized to permanently store the unique identifier of workstation 105, access point 115 may continue to store and / or use the unique identifier of workstation 105. After the first association ends, and during the second or subsequent association between workstation 105 and access point 115, workstation 105 may use a different identifier (e.g., rMAC) that differs from the identifier used by workstation 105 during the first association between access point 115 and workstation 105. However, during the second or subsequent association, workstation 105 may use the same unique identifier used by workstation 105 during the first association (e.g., the unique identifier provided to access point 115 via a unique identifier response). In a specific example, during the second association between access point 115 and workstation 105, access point 115 may recognize that workstation 105 is using the same unique identifier previously used by the workstation during the previous association. In response, access point 115 may use authorized and / or actions, and / or enable one or more services or functions used and / or enabled during the previous association between access point 115 and workstation 105. During a second or subsequent association between access point 115 and workstation 105, access point 115 may use these authorizations and / or licenses, and / or enable these services or functions, without requesting corresponding authorizations and / or licenses from workstation 105 during the second / subsequent association between access point 115 and workstation 105.

[0051] In a specific example, workstation 105 may be configured with one or more requirements and / or restrictions to be placed on the associated unique identifier. For example, workstation 105 may refuse to provide a unique identifier to access point 115 when the network type and / or network encryption status associated with workstation 105 does not meet certain criteria. Based on the network type and / or network encryption status, workstation 105 may respond to a unique identifier request with a unique identifier response, which does not include the unique identifier. Alternatively, if the network type and / or network encryption status meets certain criteria, workstation 105 may generate a unique identifier response that provides access point 115 with its unique identifier, but restricts the use or duration of access point 115's use / storage of the unique identifier (e.g., the unique identifier response may include usage restrictions).

[0052] In a specific example, workstation 105 may generate a unique identifier based on an algorithm configured in workstation 105 and / or based on user input or a criterion for generating a unique identifier. For example, the end user may input a unique identifier to be used by workstation 105, or workstation 105 may be configured to generate a random unique identifier based on a key. The unique identifier provided by workstation 105 may be an identifier other than the MAC address of workstation 105, or it may be the MAC address of workstation 105.

[0053] Once workstation 105 is associated, the action frame is valid for access point 115. The action frame and response can be encrypted, assuming the association has a secure SSID, so that the unique identifier provided by workstation 105 in the response is protected from influence by an individual receiving wireless transmissions. If the SSID is secure, workstation 105 may consider responding only to unique identifier requests. For example, workstation 105 can be configured to ignore unique identifier requests when workstation 105 is associated with an insecure network (e.g., a public network or an unencrypted network).

[0054] It should be understood that various requirements and / or restrictions may be imposed on the form of the unique identifier. For example, the unique identifier may need to come from the local MAC address space or be in a specific form, such as the widely used Microsoft UUID form. Only specific configurations may exist that can be accepted by the access point as unique identifiers. In a specific example, access point 115 may request a permanently unique identifier (e.g., a permanent MAC address, serial number, or other identifier) ​​from any workstation 105.

[0055] Workstation 105 may present a local MAC address or other random MAC address during probing or after association. For certain access points 115 and associated network services, a local MAC address that may change with each ESS association may limit the services that access point 115 can provide without additional authentication. Access points can use a Unique Identifier Request message to request associated workstation 105 to provide an identification value that can be used across association events to consistently identify a particular workstation 105, even if its MAC address changes. The Unique Identifier Request message may also include vendor-specific information. Because the Unique Identifier Request message is sent after secure association is in place and the PMF has negotiated between the requesting access point 115 and the target workstation 105, the unique identifier in the Unique Identifier response is secure and remains private.

[0056] After the security association is established, workstation 105 may receive a unique identifier request message from its associated access point 115. Workstation 105 may respond with a unique identifier response that refuses to provide the unique identifier to the requesting access point 115, for example, if workstation 105 does not trust access point 115. Workstation 105 may respond with a unique identifier, also indicating to access point 115 the amount of time the unique identifier may be valid in the identifier duration field. If workstation 105 does not indicate the identifier duration, access point 115 may treat the unique identifier as permanent. The unique identifier response may also include vendor-specific information. Access point 115 may restrict access to the DS (downstream) in a specific manner based on a unique identifier response from workstation 105 or the absence of a unique identifier response.

[0057] Figure 2A shows an example format of a unique identifier request 205. The unique identifier request 205 can be transmitted from access point 115 of Figure 1 to workstation 105 of Figure 1 after workstation 105 is associated with access point 115. For example, the unique identifier request 205 can be a security action framework. The unique identifier request 205 may include a request network type field 210 and an encryption enable field 215. The value in the request network type field 210 (e.g., a 1-byte) can be used to identify the network type associated with the workstation (e.g., 1 = private data network; 2 = private guest network; 3 = hotspot network; etc.). The value in the encryption enable field 215 (e.g., a 1-byte) can be used to identify whether the network associated with the workstation is encrypted (e.g., 0 = unencrypted; 1 = encrypted; etc.).

[0058] Figure 2B shows an example format of a unique identifier response 220. The unique identifier response 220 can be transmitted from workstation 105 to access point 115 in response to a request for a unique identifier received from access point 115. For example, the unique identifier response 220 can be a security action framework. The unique identifier response 220 may include a response code field 225, a selective identifier length field 230, a selective unique identifier field 235, a selective identifier duration field 240, and / or a selective vendor-specific information field 245. The value in the response code field 225 (e.g., a 1-byte) can be used to determine whether the workstation provides the unique identifier that the workstation's access point will use (e.g., value 0 = refuse to provide a unique identifier; 1 = provide a unique identifier, etc.). The value in the identifier length field 230 (e.g., a 1-byte) can be used to identify the length of the unique identifier provided. The unique identifier used by the workstation's access point can be provided within the unique identifier field 235. The value in the Identifier Duration field 240 (e.g., 2 bytes) can be used to identify the duration for which the access point uses the unique identifier provided by the workstation (e.g., 0 = unique identifier used only for the current association; 1-FFFF = the unique identifier will be used for the duration in seconds, etc.). If the Identifier Duration field 240 is left blank, the access point can use the unique identifier for a preset duration (e.g., permanently or for some other specific duration). The Vendor-Specific Information field 245 can be used to provide any additional information or parameters associated with the workstation.

[0059] Figure 3A shows an example format of a unique identifier request 305, which includes an ID (identifier) ​​lookup action field. After workstation 105 is associated with access point 115, a unique identifier request 305 can be transmitted from access point 115 in Figure 1 to workstation 105 in Figure 1. A unique identifier request 305 may include a category field 310, an ID lookup action field 315, and an optional vendor-specific information field 320. In a specific example, the ID lookup action field may be included within the unique identifier request and / or unique identifier response. Two action framework formats are defined to allow access point 115 to query workstation 105 for a unique identifier. The ID lookup action field, located in the octet field, immediately follows the category field distinction format. An ID lookup can be sent regardless of whether workstation 105 provides a local MAC address.

[0060] The ID query request framework uses an action framework body format. It is transmitted from the access point to the workstation, requesting the workstation to provide a unique identifier that the access point can store and use for future identification by the workstation. The action field format in the ID query request framework is shown in Figure 3A. The vendor-specific information field 320 is optional and may include one or more vendor-specific elements.

[0061] Figure 3B shows an example format of a unique identifier response 325, which includes an ID query action field. To respond to a unique identifier request received from access point 115, a unique identifier response 325 can be transmitted from workstation 105 to access point 115. The unique identifier response 325 may include a category field 330, an ID query action field 335, an ID query response field 340, a selective identifier length field 345, a selective unique identifier field 350, a selective identifier duration field 355, and an optional vendor-specific information field 360. The ID query response frame uses the action frame body format. The unique identifier response 325 is transmitted from the workstation to the access point in response to the workstation's request for a unique, non-transient identifier.

[0062] Figure 3B shows a specific example of the format of the action field in the ID query response framework. The value in the ID query response field can be used to identify whether the workstation refuses to provide a unique identifier or provides one. The workstation can choose to indicate that it will not provide or will provide a unique identifier value. When the ID query response field value is 0, the identifier length field, unique identifier field, identifier duration field, and vendor-specific information field are not present. When the ID query response field value is 1, the identifier length field, unique identifier field, identifier duration field, and vendor-specific information field may be selectively present. The identifier length field indicates the length of the response in octets. The unique identifier field provides the required access point that can be used to identify this workstation, regardless of the MAC address used by the workstation in the MAC header. The unique identifier field 350 can have one or more minimum requirements (e.g., 16 octets, large enough to use a UUID, etc.). The value in the Identifier Duration field can be used to identify the duration for which the access point will use the unique identifier provided by the workstation (e.g., 0 = unique identifier used only for the current association; 1-65535 = the time in minutes the unique identifier will be used, etc.). By omitting this field while including the unique identifier in the unique identifier response 325, the workstation can indicate that the unique identifier is permanent. Otherwise, the unique identifier's retention period is as indicated.

[0063] Workstation capability information elements exchanged during association may include extended capability bits to indicate whether the workstation supports the ID lookup action framework. For example, an extended capability bit could be set to 1 to indicate that the workstation supports the ID lookup action framework. At a higher level, a user can instruct a workstation not to share permanent or semi-permanent identifiers, so the workstation may still refuse to provide a unique identifier, even if the message indicates support for that identifier. When the ID lookup response field is 0 or 1 and contains one or more vendor-specific elements, the vendor-specific information field may be selectively present.

[0064] Figure 4 is a block diagram illustrating an example access point 115 operable to facilitate the management of unique identifiers for workstation 105. Access point 115 may include a subscriber interface 405, a network interface 410, a unique identifier exchange module 415, and a unique identifier data storage area 420. Workstation 105 may include a LAN interface 425 and a unique identifier exchange module 430.

[0065] In a specific example, communications can be output and / or received from one or more workstations 105 via the orderer interface 405. Wireless communications and messages, including data, video, and / or voice communications, can be output and / or received via the orderer interface 405. It should be understood that the orderer interface 405 can be configured to receive and / or output communications using various communication technologies, protocols, and standards (e.g., Wi-Fi). In a specific example, communications can be output to one or more upstream networks and / or received from one or more upstream networks (e.g., broadband access network 120 of Figure 1, WAN 125 of Figure 1, etc.) via the network interface 410.

[0066] In a specific example, the unique identifier exchange module 415 can generate and output a unique identifier request message. The unique identifier exchange module 415 can receive a unique identifier response message from workstation 105, and can ignore or store the unique identifier provided in the unique identifier response message based on various restrictions and / or usage / storage requirements gleaned from the unique identifier response message. For example, the unique identifier exchange module 415 can store one or more unique identifiers of workstation 105 in the unique identifier data storage area 420 (e.g., the association between the unique identifier and the workstation can be stored, and the unique identifier is received from that workstation). The unique identifier provided in the unique identifier response received from the workstation can be stored as an identifier to be used to identify a specific workstation.

[0067] The unique identifier exchange module 415 can facilitate the use of unique identifiers from one or more stations to enable or disable one or more services or functions provided to workstation 105 by access point 115 (e.g., parental controls, device tracking, etc.). For example, when workstation 105 provides a unique identifier for access point 115 to use, access point 115 can enable one or more functions or services provided to the workstation by the access point, wherein one or more services require the use of a consistent and unique identifier from the workstation. When workstation 105 refuses to provide a unique identifier for access point 115 to use, access point 115 can disable one or more functions or services provided to the workstation by the access point, wherein one or more services require the use of a consistent and unique identifier from the workstation.

[0068] In a specific example, workstation 105 can transmit communications to access point 115 and receive wireless communications from access point via LAN interface 425.

[0069] The unique identifier exchange module 430 may receive a unique identifier request message from access point 115 and generate and output a unique identifier response message. In a specific example, the unique identifier exchange module 430 may capture and / or generate a unique identifier for workstation 105, and the unique identifier exchange module 430 may fill in a unique identifier response message containing the workstation's unique identifier and / or one or more other field values ​​(e.g., identifier duration value, vendor-specific information, etc.). The unique identifier exchange module 430 may be configured with parameters and requirements (e.g., network type and / or encryption status requirements) for responding to unique identifier request messages.

[0070] Figure 5 is a flowchart illustrating an example process 500 operable to facilitate the management of unique identifiers recovered from a unique identifier response received from a workstation. Process 500 can begin after an access point (e.g., access point 115 in Figure 1) is associated with a workstation (e.g., workstation 105 in Figure 1). Unique identifier response / request messages can be facilitated by unique identifier exchange modules 415 and / or 430 in Figure 4. Process 500 can begin at 505 when a unique identifier request is output to workstation 105. When workstation 105 is associated with access point 115, access point 115 can generate and send a unique identifier request (e.g., unique identifier request 205 in Figure 2A or 305 in Figure 3A) to workstation 105. The unique identifier request includes a request for a unique identifier response from the workstation, which will be used by the workstation's access point.

[0071] At 510, a unique identifier response can be received from the workstation. For example, access point 115 can receive a unique identifier response from workstation 105 (unique identifier response 220 in Figure 2B or 325 in Figure 3B), and the unique identifier response may include an indication that the workstation provides or does not provide a unique identifier to be used by the workstation. This indication is provided in response code field 225 in Figure 2B or ID query response field 340 in Figure 3B.

[0072] At 515, a decision can be made as to whether the unique identifier response provides a unique identifier to be used for the workstation. In a specific example, access point 115 can make this decision based on whether a unique identifier exists in the unique identifier response or based on whether the unique identifier response provides an indication of whether the unique identifier is provided by the response.

[0073] If at 515, a decision is made regarding the unique identifier provided by the unique identifier response, then process 500 can continue to 520. At 520, access point 115 can store the unique identifier of workstation 105. For example, access point 115 (e.g., unique identifier exchange module 415 of FIG4) can retrieve a unique identifier from the unique identifier response and store it (e.g., in the unique identifier data storage area 420 of FIG4) as an identifier to be used by workstation 105. It will be understood that access point 115 can then provide various functions (e.g., parental controls, end-user tracking, etc.) to the user by utilizing the stored association between the workstation and the unique identifier retrieved from the unique identifier response. For example, access point 115 can enable one or more functions for workstation 105 that are provided to workstations with known unique identifiers.

[0074] If at 515 a decision is made that the unique identifier is not provided by a unique identifier response, process 500 may continue to 525. At 525, workstation 105 may be marked as a workstation without a unique identifier. The access point may mark workstation 105 as having refused or being unable to provide access point 115 with a unique identifier other than a known identifier (e.g., the MAC address of workstation 105). Alternatively, access point 115 may simply take no action in response to the decision that the unique identifier is not provided by a unique identifier response.

[0075] Figure 6 is a flowchart illustrating an example process 600 operable to facilitate the management of unique identifiers recovered from unique identifier responses received from a workstation that supports the exchange of unique identifier messages. Process 600 may begin after an access point (e.g., access point 115 in Figure 1) is associated with a workstation (e.g., workstation 105 in Figure 1). Unique identifier response / request messages may be facilitated by unique identifier exchange modules 415 and / or 430 in Figure 4. Process 600 may begin at 605 when a unique identifier request is output to workstation 105. When workstation 105 is associated with access point 115, access point 115 may generate and send a unique identifier request (e.g., unique identifier request 205 in Figure 2A or 305 in Figure 3A) to workstation 105. The unique identifier request may include a request responded to by the workstation with a unique identifier, which is used by the workstation's access point.

[0076] At 610, a unique identifier response can be received from the workstation. For example, access point 115 can receive a unique identifier response from workstation 105 (e.g., unique identifier response 220 in Figure 2B or 325 in Figure 3B), and the unique identifier response may include an indication of whether workstation 105 supports creating and delivering a unique identifier to access point 115 (e.g., an indication provided in response code field 225 in Figure 2B, ID query action field 335 in Figure 3B, ID query response field 340 in Figure 3B, or other response fields). The unique identifier response may include whether the workstation provides or does not provide a unique identifier to be used by the workstation. This indication is provided in response code field 225 in Figure 2B or ID query response field 340 in Figure 3B.

[0077] At 615, a decision can be made as to whether the workstation supports creating and delivering a unique identifier to the access point. For example, access point 115 can determine whether workstation 105 can provide a unique identifier (other than a known identifier, such as a MAC address) based on an indication provided in the unique identifier response. In a specific example, this decision can be made based on the value of the capability bits. For example, if the capability bits are not set, access point 115 may not request a unique identifier from workstation 105.

[0078] If at 615, a decision is made that the workstation does not support the creation and delivery of a unique identifier, then process 600 can proceed to 620. At 620, workstation 105 can be marked as a workstation without a unique identifier. Access point 115 can mark workstation 105 as unable to provide access point 115 with a unique identifier other than a known identifier (e.g., the MAC address of workstation 105). Alternatively, access point 115 may take no action in response to the decision that the workstation cannot provide a unique identifier.

[0079] If at 615, a determination is made that the workstation is capable of establishing and transmitting a unique identifier, then process 600 can continue to 625. At 625, a determination can be made as to whether the unique identifier response provides a unique identifier to be used by the workstation. In a specific example, access point 115 can make this decision based on whether a unique identifier exists in the unique identifier response or based on whether the unique identifier response provides an indication of whether the unique identifier was provided by that response.

[0080] If at 625 a decision is made that the unique identifier is not provided by a unique identifier response, process 600 may continue to 620. At 620, workstation 105 may be marked as a workstation without a unique identifier. The access point may mark workstation 105 as having refused or being unable to provide access point 115 with a unique identifier other than a known identifier (e.g., the MAC address of workstation 105). Alternatively, access point 115 may simply take no action in response to the decision that the unique identifier is not provided by a unique identifier response.

[0081] If at 625, a decision is made regarding the unique identifier provided by the unique identifier response, then process 600 can continue to 630. At 630, access point 115 can store the unique identifier of workstation 105. For example, access point 115 (e.g., unique identifier exchange module 415 of FIG4) can retrieve the unique identifier from the unique identifier response and store the unique identifier (e.g., in the unique identifier data storage area 420 of FIG4) as an identifier for workstation 105. It will be understood that access point 115 can then provide various functions (e.g., parental controls, end-user tracking, etc.) to the user by utilizing the stored association between the workstation and the unique identifier retrieved by the unique identifier response. For example, access point 115 can enable one or more functions for workstation 105 that are provided to workstations with known unique identifiers.

[0082] Figure 7 is a flowchart illustrating an example process 700 operable to facilitate the management of unique identifiers recovered from a unique identifier response received from a workstation, wherein the unique identifier response includes an identifier duration field. Process 700 may begin after an access point (e.g., access point 115 in Figure 1) is associated with a workstation (e.g., workstation 105 in Figure 1). Unique identifier response / request messages may be facilitated by unique identifier exchange modules 415 and / or 430 in Figure 4. Process 700 may begin at 705 when a unique identifier request is output to workstation 105. When workstation 105 is associated with access point 115, access point 115 may generate and send a unique identifier request (e.g., unique identifier request 205 in Figure 2A or 305 in Figure 3A) to workstation 105. The unique identifier request may include a request responded to by the workstation with a unique identifier, which is used by the workstation's access point.

[0083] At 710, a unique identifier response can be received from the workstation. For example, access point 115 can receive a unique identifier response (unique identifier response 220 in Figure 2B or 325 in Figure 3B) from workstation 105, and the unique identifier response may include an indication that the workstation provides or does not provide a unique identifier to be used by the workstation. This indication is provided in response code field 225 in Figure 2B or ID query response field 340 in Figure 3B.

[0084] At 715, a decision can be made as to whether the unique identifier response provides a unique identifier to be used for the workstation. In a specific example, access point 115 can make this decision based on whether a unique identifier exists in the unique identifier response or based on whether the unique identifier response provides an indication of whether the unique identifier is provided by the response.

[0085] If at 715 a decision is made that the unique identifier is not provided by a unique identifier response, process 700 may continue to 720. At 720, workstation 105 may be marked as a workstation without a unique identifier. The access point may mark workstation 105 as having refused or being unable to provide access point 115 with a unique identifier other than a known identifier (e.g., the MAC address of workstation 105). Alternatively, access point 115 may simply take no action in response to the decision that the unique identifier is not provided by a unique identifier response.

[0086] If at 715, a decision is made regarding whether the unique identifier is provided by the unique identifier response, then process 700 may continue to 725. At 725, a decision is made regarding whether the identifier duration is provided in the unique identifier response. In a specific example, the unique identifier response may include an identifier duration field (e.g., identifier duration field 240 in Figure 2B or identifier duration field 355 in Figure 3B). If the identifier duration field has a value of zero (0) or is otherwise blank, access point 115 (e.g., unique identifier exchange module 415) may determine that no identifier duration is provided. If the identifier duration field has a value other than zero (0), access point 115 (e.g., unique identifier exchange module 415) may determine that an identifier duration is provided.

[0087] If at 725, a decision is made regarding the duration of the no-identification code provided by the unique identification code response, then process 700 can continue to 730. At 730, access point 115 can store the unique identification code of workstation 105 for a preset duration. For example, access point 115 can store the unique identification code of the workstation for a preset duration (this preset duration is the duration currently associated between workstation 105 and access point 115, permanently stored in access point 115) or some other duration set as the preset duration. In a specific example, access point 115 (e.g., unique identification code exchange module 415 of FIG. 4) can retrieve a unique identification code from the unique identification code response and store the unique identification code (e.g., in the unique identification code data storage area 420 of FIG. 4) as an identification code for workstation 105. It will be understood that access point 115 can then provide various functions (e.g., parental controls, end-user tracking, etc.) to the user by utilizing the stored association between the workstation and the unique identification code retrieved from the unique identification code response. For example, access point 115 may enable one or more functions for workstation 105 that are provided to workstations with known unique identifiers.

[0088] If, at 725, a decision is made regarding the duration of the unique identifier provided by the unique identifier response, procedure 700 can continue to 735. At 735, access point 115 can store the unique identifier of workstation 105 for a specific duration provided by the unique identifier response. For example, the value in the identifier duration field of the unique identifier response can indicate the duration (e.g., seconds, minutes, etc.) during which the unique identifier will be used by access point 115, and access point 115 can only use the unique identifier during that specified duration. In a specific example, access point 115 (e.g., unique identifier exchange module 415 of FIG. 4) can retrieve the unique identifier from the unique identifier response and store it (e.g., in the unique identifier data storage area 420 of FIG. 4) as an identifier for workstation 105. It will be understood that access point 115 can then provide various functions (e.g., parental controls, end-user tracking, etc.) to the user by utilizing the stored association between the workstation and the unique identifier retrieved by the unique identifier response. For example, access point 115 may enable one or more functions for workstation 105 that are provided to workstations with known unique identifiers.

[0089] Figure 8 is a flowchart illustrating an example process 800 operable to facilitate the management of unique identifiers recovered from unique identifier responses received from a workstation, wherein the access point permanently stores the unique identifier when no identifier duration response is provided. Process 800 may begin after an access point (e.g., access point 115 in Figure 1) is associated with a workstation (e.g., workstation 105 in Figure 1). Unique identifier response / request messages may be facilitated by unique identifier exchange modules 415 and / or 430 in Figure 4. Process 800 may begin at 805 when a unique identifier request is output to workstation 105. When workstation 105 is associated with access point 115, access point 115 may generate and send a unique identifier request (e.g., unique identifier request 205 in Figure 2A or 305 in Figure 3A) to workstation 105. The unique identifier request may include a request responded to by the workstation with a unique identifier, which is used by the workstation's access point.

[0090] At 810, a unique identifier response can be received from the workstation. For example, access point 115 can receive a unique identifier response from workstation 105 (unique identifier response 220 in Figure 2B or 325 in Figure 3B), and the unique identifier response may include an indication that the workstation provides or does not provide a unique identifier to be used by the workstation. This indication is provided in response code field 225 in Figure 2B or ID query response field 340 in Figure 3B.

[0091] At 815, a decision can be made as to whether the unique identifier response provides a unique identifier to be used for the workstation. In a specific example, access point 115 can make this decision based on whether a unique identifier exists in the unique identifier response or based on whether the unique identifier response provides an indication of whether the unique identifier is provided by the response.

[0092] If at 815 a decision is made that the unique identifier is not provided by a unique identifier response, process 800 may continue to 820. At 820, workstation 105 may be marked as a workstation without a unique identifier. Access point 115 may mark workstation 105 as having refused or being unable to provide access point 115 with a unique identifier other than a known identifier (e.g., the MAC address of workstation 105). Alternatively, access point 115 may simply take no action in response to the decision that the unique identifier is not provided by a unique identifier response.

[0093] If at 815, a decision is made regarding whether the unique identifier is provided by the unique identifier response, then process 800 can continue to 825. At 825, a decision is made regarding whether an identifier duration response is provided in the unique identifier response. In a specific example, the unique identifier response may include an identifier duration field (e.g., identifier duration field 240 in Figure 2B or identifier duration field 355 in Figure 3B). If identifier duration field 240 is excluded from the unique identifier response, access point 115 may determine that no identifier duration response is provided. If identifier duration field 240 is included in the unique identifier response, access point 115 may determine that an identifier duration response is provided.

[0094] If a decision is made at 825 regarding the duration of the unprovided identification code response, process 800 may continue to 830. At 830, the access point may store / use the workstation's unique identification code for a period of time. For example, the access point may not remove or terminate the use of the unique identification code after a specific duration or after the current association between the access point and the workstation ends. In a specific example, access point 115 (e.g., the unique identification code exchange module 415 of FIG4) may retrieve the unique identification code from the unique identification code response and store the unique identification code (e.g., in the unique identification code data storage area 420 of FIG4) as an identification code for workstation 105. It will be understood that access point 115 may then provide various functions (e.g., parental controls, end-user tracking, etc.) to the user by utilizing the stored association between the workstation and the unique identification code retrieved from the unique identification code response. For example, access point 115 may enable one or more functions for workstation 105 that are provided to the workstation with a known unique identification code.

[0095] If a decision is made at 825 regarding whether to provide an identification code duration response, then procedure 800 may continue to 835. At 835, a decision is made regarding whether a specific duration is provided by the identification code duration response. For example, if the identification code duration response includes a value of zero (0) or some other preset value, access point 115 may determine that no specific duration is provided, and if the identification code duration response includes any other value, access point 115 may determine that a specific duration is provided.

[0096] If at 835, the determination of a specific identifier duration is not provided by the identifier duration response, then process 800 may continue to 840. At 840, access point 115 may store the unique identifier of workstation 105 for a preset duration. For example, the preset duration might be the current association duration between workstation 105 and access point 115, in which case access point 115 will remove or otherwise discontinue the use of the workstation's unique identifier after the current association between the workstation and access point ends. In a specific example, access point 115 (e.g., unique identifier exchange module 415 of FIG. 4) may retrieve a unique identifier from the unique identifier response and store the unique identifier (e.g., in the unique identifier data storage area 420 of FIG. 4) as an identifier for workstation 105. It will be understood that access point 115 may then provide various functions (e.g., parental controls, end-user tracking, etc.) to the user by utilizing the stored association between the workstation and the unique identifier retrieved from the unique identifier response. For example, access point 115 may enable one or more functions for workstation 105 that are provided to workstations with known unique identifiers.

[0097] If at 835, the determination of a specific identifier duration is provided by the identifier duration response, then process 800 can continue to 845. At 845, access point 115 can store the unique identifier of workstation 105 provided by the identifier duration response for a specific duration. For example, the value in the identifier duration field of the unique identifier response can indicate the duration (e.g., seconds, minutes, etc.) during which the unique identifier will be used by access point 115, and access point 115 can only use the unique identifier during that specified duration. In a specific example, access point 115 (e.g., the unique identifier exchange module 415 of FIG4) can retrieve a unique identifier from the unique identifier response and store the unique identifier (e.g., in the unique identifier data storage area 420 of FIG4) as an identifier for workstation 105. It will be understood that access point 115 can then provide various functions (e.g., parental controls, end-user tracking, etc.) to the user by utilizing the stored association between the workstation and the unique identifier retrieved by the unique identifier response. For example, access point 115 may enable one or more functions for workstation 105 that are provided to workstations with known unique identifiers.

[0098] Figure 9 is a flowchart illustrating an example process 900 operable to facilitate a response to a unique identifier request. Process 900 may begin after an access point (e.g., access point 115 of Figure 1) is associated with a workstation (e.g., workstation 105 of Figure 1). Unique identifier response / request messages may be facilitated by unique identifier exchange modules 415 and / or 430 of Figure 4. When a unique identifier request is received at workstation 105, process 900 may begin at 905, where the unique identifier request is output from access point 115 to workstation 105. Once workstation 105 is associated with access point 115, access point 115 may generate and send a unique identifier request (e.g., unique identifier request 205 of Figure 2A or 305 of Figure 3A) to workstation 105. The unique identifier request may include a request responded to by the workstation with a unique identifier, which is used by the workstation's access point.

[0099] At 910, the network type can be determined from a unique identifier request. In a specific example, the unique identifier request may include an indication of the network type currently associated with workstation 105, provided by access point 115 (e.g., the indication may be provided in the network type field 210 of Figure 2A, the category field 310 of Figure 3A, the ID lookup action field 315 of Figure 3A, etc.). The unique identifier request may also include an indication of whether the network is encrypted or unencrypted (e.g., the indication may be provided in the encryption enable field 215 of Figure 2A, the category field 310 of Figure 3A, the ID lookup action field 315 of Figure 3A, etc.). From the unique identifier request, workstation 105 (e.g., unique identifier exchange module 430) can determine the network type associated with the workstation (e.g., private network, public network, hotspot network, etc.), and / or whether the network is encrypted or unencrypted.

[0100] At 915, a decision is made regarding whether to enable the unique identifier generation function based on the identified network type and / or encryption status. For example, workstation 105 (e.g., unique identifier exchange module 430) may decide whether to provide a unique identifier to access point 115 based on the identification of the network type and / or an indication that the network is encrypted or unencrypted. Workstation 105 may be configured, for example, with filters to allow workstation 105 to provide a unique identifier to access point 115 only when the network associated with workstation 105 is of a specific type and / or utilizes a specific encryption status or level. For example, workstation 105 may be configured to provide only access points with unique identifiers when the network associated with the workstation is a private network and / or an encrypted network.

[0101] If at 915 a decision is made that the identification code generation function cannot be enabled for the identified network type and / or encryption status, process 900 may continue to 920. At 920, a unique identification code response may be generated, wherein the unique identification code response does not include the workstation's unique identification code. For example, the workstation may generate a unique identification code response with specific field values ​​(e.g., response code field 225 in Figure 2B or ID query response field 340 in Figure 3B may be given a zero (0) value), which instructs access point 115 that workstation 105 has rejected the option to provide access point 115 with the unique identification code of workstation 105. Alternatively, workstation 105 may generate a unique identification code response that provides access point 115 with the unique identification code of workstation 105, but restricts the access point 115's use / storage of the unique identification code or its duration (e.g., usage restrictions may be included in identification code duration field 240 in Figure 2B or 355 in Figure 3B, or in some other field of the unique identification code response).

[0102] If, at 915, a decision is made to enable the identification code generation function for the identified network type and / or encryption status, process 900 may continue to 925. At 925, a unique identification code response may be generated, which includes a unique identification code for the workstation. For example, workstation 105 may be configured to generate a unique identification code to be used by access point 115 (e.g., randomly generated, pre-configured, user-inputted, etc.). In a specific example, workstation 105 may fill values ​​into one or more other fields of the unique identification code response to indicate additional requirements / restrictions on access point 115's use of the unique identification code (e.g., identification code duration value, vendor-specific options, etc.).

[0103] At 930, the unique identification code response generated by workstation 105 can be output to access point 115, and the unique identification code request is received from access point 115.

[0104] Figure 10 is a flowchart illustrating an example process 1000 operable to facilitate the management of unique identifiers recovered from a unique identifier response, which is received from a workstation after a second or subsequent association between the access point and the workstation. Process 1000 may begin after an access point (e.g., access point 115 in Figure 1) is associated with a workstation (e.g., workstation 105 in Figure 1). The association between access point 115 and workstation 105 may occur after a previous association between access point 115 and workstation 105 has ended. It should be understood that during the current association between access point 115 and workstation 105, workstation 105 may use a different identifier (e.g., rMAC) than it used during previous associations with access point 115, but during the current association, workstation 105 may use the same unique identifier (e.g., the unique identifier provided in the unique identifier response) as it used during previous associations with access point 115. The unique identifier response / request message can be facilitated by the unique identifier exchange module 415 and / or the unique identifier exchange module 430 of Figure 4. Process 1000 can begin at 1005 when a unique identifier request is output to workstation 105. When workstation 105 is associated with access point 115, access point 115 can generate and send a unique identifier request (e.g., unique identifier request 205 of Figure 2A or 305 of Figure 3A) to workstation 105. The unique identifier request includes a request for a unique identifier response from the workstation, which will be used by the workstation's access point.

[0105] At 1010, a unique identifier response can be received from the workstation. For example, access point 115 can receive a unique identifier response from workstation 105 (unique identifier response 220 in Figure 2B or 325 in Figure 3B), and the unique identifier response may include an indication that the workstation provides or does not provide a unique identifier to be used by the workstation. This indication is provided in response code field 225 in Figure 2B or ID query response field 340 in Figure 3B.

[0106] At 1015, a decision can be made as to whether the unique identifier response provides a unique identifier to be used for the workstation. In a specific example, access point 115 can make this decision based on whether the unique identifier exists in the unique identifier response or based on whether the unique identifier response provides an indication of whether the unique identifier is provided by the response.

[0107] If at 1015 a decision is made that the unique identifier is not provided by a unique identifier response, process 1000 may continue to 1020. At 1020, workstation 105 may be marked as a workstation without a unique identifier. The access point may mark workstation 105 as having refused or being unable to provide access point 115 with a unique identifier other than a known identifier (e.g., the MAC address of workstation 105). Alternatively, access point 115 may simply take no action in response to the decision that the unique identifier is not provided by a unique identifier response.

[0108] If at 1015, a decision is made regarding the unique identifier provided by the unique identifier response, then process 1000 can continue to 1025. At 1025, a decision is made as to whether the provided unique identifier has already been stored at access point 115. In a specific example, access point 115 may have stored the unique identifier of workstation 105 during a previous association between workstation 105 and access point 115, where the previous association has ended. For example, at 1005, the unique identifier provided in the unique identifier response received by access point 115 may be the same as the unique identifier provided by workstation 105 during its previous association with access point 115 (e.g., the unique identifier provided in the unique identifier response received during the previous association between access point 115 and workstation 105).

[0109] If, at step 1025, the unique identifier has not yet been stored at the access point, process 1000 may continue to step 1030. At step 1030, access point 115 may store the unique identifier of workstation 105. For example, access point 115 (e.g., the unique identifier exchange module 415 of FIG4) may retrieve the unique identifier from the unique identifier response and store it (e.g., in the unique identifier data storage area 420 of FIG4) as an identifier for workstation 105. It will be understood that access point 115 may then provide various functions (e.g., parental controls, end-user tracking, etc.) to the user by utilizing the stored association between the workstation and the unique identifier retrieved from the unique identifier response. For example, access point 115 may enable one or more functions for workstation 105 that are provided to workstations with known unique identifiers.

[0110] If, at 1025, a determination is made that a unique identifier has been stored at the access point, process 1000 can proceed to 1035. At 1035, access point 115 can use the authorizations and / or actions used during the previous association between access point 115 and workstation 105. For example, access point 115 can use authorizations and / or actions, and / or enable one or more services or functions that were used and / or enabled during the previous association between access point 115 and workstation 105. In a specific example, during the current association between access point 115 and workstation 105, access point 115 can use authorizations and / or actions, and / or enable one or more services and functions that were used and / or enabled during the previous association between access point 115 and workstation 105, without needing to request corresponding authorizations and / or licenses from workstation 105 during the current association between access point 115 and workstation 105.

[0111] Figure 11 is a block diagram of a hardware configuration 1100 operable to facilitate the management of unique identifiers for workstations. The hardware configuration 1100 may include a processor 1110, memory 1120, storage device 1130, and input / output device 1140. For example, components 1110, 1120, 1130, and 1140 may be interconnected using a system bus 1150. The processor 1110 is capable of processing instructions executed within the hardware configuration 1100. In one implementation, the processor 1110 may be a single-threaded processor. In another implementation, the processor 1110 may be a multi-threaded processor. The processor 1110 is capable of processing instructions stored in memory 1120 or storage device 1130.

[0112] Memory 1120 can store information within hardware configuration 1100. In one implementation, memory 1120 can be a computer-readable medium. In one implementation, memory 1120 can be a volatile memory unit. In another implementation, memory 1120 can be a non-volatile memory unit.

[0113] In some implementations, storage device 1130 can provide a large amount of storage space for hardware configuration 1100. In one implementation, storage device 1130 may be a computer-readable medium. In various implementations, storage device 1130 may include, for example, a hard disk drive, an optical disk drive, flash memory, or some other high-capacity storage device. In other implementations, storage device 1130 may be a device external to hardware configuration 1100.

[0114] Input / output device 1140 provides input / output operations for hardware configuration 1100. In specific examples, input / output device 1140 may include one or more network interface devices (e.g., Ethernet cards), serial communication devices (e.g., RS-232 ports), one or more Universal Serial Bus (USB) interfaces (e.g., USB 2.0 ports), one or more wireless interface devices (e.g., 802.11 cards), and devices for outputting video, voice, and / or data services to workstation 105 of FIG1 (such as a television, STB, computer, mobile device, tablet, telephone, wearable device, etc.). In specific examples, the input / output device may include drive mechanisms configured to transmit communications to one or more networks (e.g., local network 110 of FIG1, broadband access network 120 of FIG1, WAN 125 of FIG1, etc.) and receive communications from one or more networks.

[0115] Figure 12 is a flowchart illustrating an example process 1200 operable to facilitate the receipt of an unsolicited unique identifier response from a workstation. Process 1200 begins before the workstation (e.g., workstation 105 of Figure 1) is associated with an access point (e.g., access point 115 of Figure 1). The unique identifier response may be facilitated by the unique identifier exchange module 430 of workstation 105 in Figure 4. Process 1200 may begin at 1205 when a secure connection (e.g., a secure protected connection, secure communication path, secure channel, any other secure connection, or any combination thereof) is established between the access point and the workstation. Establishing a secure connection may include exchanging one or more cryptographic keys between access point 115 and workstation 105, any of the following: Pre-Associated Security Negotiation (PASN) enabling the establishment of a PASN channel between access point 115 and workstation 105, performing a robust secure network (RSN) association between workstation 105 and access point 115, or any combination thereof. In one or more specific examples, workstation 105 may initiate a secure connection with access point 115.

[0116] After a secure connection has been established in step 1210, for example in step 1205 (e.g., after the workstation has verified that the infrastructure (e.g., access point or network) is trusted or known and / or has unilaterally determined that the workstation's unique identifier is available or stored at the workstation, after establishing a PASN channel, any other type of secure connection, or any combination thereof), or after a secure connection has been established via association (e.g., RSN association), the access point device may receive an unsolicited unique identifier response from the workstation via the secure connection (e.g., unique identifier response 220 in Figure 2 or 325 in Figure 3B). The unique identifier response includes a unique identifier, such as any universally unique identifier (UUID), a random or pseudo-random number, a pre-configured identifier (e.g., an identifier stored or configured for workstation 105, including but not limited to identifiers specified by the system administrator, membership numbers, employee identifiers, unique identifiers of any other enterprise or entity, or any combination thereof), or any combination thereof, for use by the workstation's access point. In one or more specific cases, the workstation may decide, based on network parameters, that a unique identifier for the workstation, or a unique identifier associated with the workstation, should be transmitted to the access point device. Sending the unique identifier over a secure connection ensures that the unique identifier is not intercepted by unauthorized, malicious, or otherwise unexpected devices, networks, or systems.

[0117] For example, network parameters may include a network identifier or information associated with establishing a secure connection. The workstation can identify the network indicated by the network identifier and then, based on its ability to establish a secure connection, confirm or verify that the network is indeed the one indicated by the network identifier (e.g., not a fraudulent attempt). For example, a user with a workstation can switch to a specific network location, such as a storage area with a "STORE-A NETWORK" network identifier. The workstation can detect networks (or Wi-Fi connections) claiming to be associated with a specific network location (e.g., "STORE-A NETWORK"). As part of the verification, the workstation can confirm that the network identified as "STORE-A NETWORK" is genuine or has not been subjected to malicious or intentional activity, such as by executing PASN. Workstations can transmit a unique identifier associated with a user and a specific network location (such as a shop shopper ID number) to the network, enabling users to receive advanced or improved network experiences. For example, workstations can receive personalized notifications for users (such as coupons), any other services or features, or any combination thereof.

[0118] Steps 1215, 1220, and 1225 are similar to or identical to steps 515, 520, and 525, as discussed with reference to FIG5. In step 1222, the access point can provide one or more functions and / or one or more services associated with a unique identifier received from the workstation. For example, the unique identifier exchange module 415 of access point 115 can enable or disable one or more functions provided to the corresponding one or more workstations 105 using one or more unique identifiers. These one or more functions may include any of one or more services provided by an enterprise, entity, and / or network; access to a specific network (e.g., a public network, a private network, a secure network, a password-controlled network, etc.); access to one or more benefits associated with an enterprise or entity; receiving push notifications or messages (e.g., advertisements, coupons, rewards, cash discounts, vouchers, and / or subscriptions); any other type of notification, message, or reminder; or any combination thereof. Access point 115 may provide one or more benefits associated with a business (such as a retail business or online business), such as one or more frequent shopper benefits, to users of workstation 105 based on a unique identifier received from workstation 105 in response to an unsolicited unique identifier. Alternatively, if no unique identifier is received by access point 115, access point 115 may deactivate the service or prevent users of the corresponding workstation 105 from accessing the service.

[0119] In one or more specific examples, step 1222 may occur before or after associating workstation 105 with access point 115, or even if no association occurs. For example, the network or access point may determine that the workstation has been moved to the vicinity of the network or access point, such that the network can send one or more notifications (e.g., notifications customized for the workstation user, the workstation, or both) to the workstation using one or more network communication protocols, one or more digital communication types, etc. For example, when a user moves a workstation to the vicinity of STORE-A NETWORK, a customized coupon may still be sent to the workstation via text message even if the workstation is not associated with the network, or the user can be identified as existing in a specific network location, such as being listed (e.g., a restaurant waiting list). As another example, a user may move a workstation to a network location, which includes a router provided by an internet service provider (e.g., a home, residence, office, etc., with private Wi-Fi networks and public / communication Wi-Fi networks). This access point or network does not determine the identity of users and / or workstations until the workstation provides a unique identifier. Once the router receives the unique identifier, the access point or network can determine the services or functions associated with the workstation, such as whether certain functions or services of the workstation are enabled, disabled, allowed, or disallowed. The access point or network can determine the association of a workstation with a user or user profile. A user or user profile is associated with one or more functions, such that one or more functions provided by the access point to the workstation are based on the user or user profile. The access point can provide one or more functions based on the following decision: the workstation is associated with a user profile, allowing the access point to implement different policies for the workstation based on the user profile. For example, the access point can determine whether a workstation is associated with a resident or an employee, and based on this decision, the access point can allow or permit the workstation to connect to a private network instead of a public network.

[0120] In one or more specific examples, after access point 115 is associated with workstation 105, access point 115 may provide network information to workstation 105. For example, network information may include information specifying a network or network access for workstation 105. In one or more specific examples, network information may be provided before or without associating access point 115 with workstation 105.

[0121] In one or more specific examples, after step 1210, any or more of the following steps may be performed: steps 715, 720, 725, 730 and 735 of FIG. 7, steps 815, 820, 825, 830, 835, 840 and 845 of FIG. 8, and steps 1015, 1020, 1025, 1030 and 1035 of FIG. 10. Although the steps of FIG. 5 through 10 and FIG. 12 are presented in a specific order, this disclosure contemplates that any one or more steps may be performed simultaneously, substantially simultaneously, repeatedly or not at all (omitted).

[0122] Figure 13 is a flowchart illustrating an example process 1300 operable to facilitate communication via a unique identifier response over a secure connection. Process 1300 begins before a workstation (e.g., workstation 105 of Figure 1) is associated with an access point (e.g., access point 115 of Figure 1). Unique identifier responses and / or unique identifier requests can be facilitated by the unique identifier exchange module 415 of Figure 4 and / or the unique identifier exchange module 430 of workstation 105 of Figure 4. Process 1300 may begin at 1305 when a unique identifier request is output from access point 115 to workstation 105.

[0123] In step 1307, a secure connection (e.g., a secure protected link, a secure communication path, a secure channel, any other secure connection, or any combination thereof) is established between the access point and the workstation. For example, a secure channel, such as a pre-associated security negotiation (PASN) channel, may be established between the access point and the workstation. For instance, workstation 105 may determine whether a secure connection should be established or whether a secure connection is needed between access point 115 and workstation 105 based on a unique identifier request from access point 115, such that the unique identifier associated with workstation 105 is sent to access point 115 via the secure connection. Based on this determination, workstation 105 may initialize a secure connection with access point 115, and once the secure connection is established, workstation 105 may transmit the unique identifier to access point 115. Sending the unique identifier over the secure connection ensures that the unique identifier is not intercepted by unauthorized, malicious, or otherwise unexpected devices, networks, or systems.

[0124] In step 1310, before workstation 105 is associated with access point 115 and after a secure connection has been established (e.g., after the workstation has verified that the infrastructure (e.g., access point or network) is trusted or known, and / or unilaterally determined that the workstation's unique identifier is available or stored on the workstation), the access point can receive a unique identifier response from the workstation via the secure connection (e.g., unique identifier response 220 of FIG. 2B or 325 of FIG. 3B), for example, as discussed with respect to step 120 of FIG. 12. The unique identifier response includes a unique identifier that will be used by the workstation's access point. In one or more specific examples, the workstation may determine whether to send the workstation or a unique identifier associated with the workstation to the access point based on a unique identifier request from access point 115, the establishment of a secure connection, or both.

[0125] Steps 1315, 1320, and 1325 are similar to or identical to steps 515, 520, and 525, as discussed with respect to Figure 5. In step 1322, the access point can provide one or more functions associated with a unique identifier received from the workstation, for example, as discussed with respect to step 1222 of Figure 12. For example, the unique identifier exchange module 415 of access point 115 can facilitate the use of one or more unique identifiers to enable or disable one or more services and / or one or more functions provided by the corresponding one or more workstations 105. Access point 115 can provide one or more benefits associated with a business (e.g., a retail business or online business), such as one or more frequent shopper benefits, to users of workstation 105 based on a unique identifier received from workstation 105 in response to an unsolicited unique identifier. Alternatively, if no unique identifier is received by access point 115, access point 115 can disable a service or prevent users of the corresponding workstation 105 from accessing the service. For example, in step 1322, access point 115 may associate workstation 105 with access point 115, determine whether workstation 105 should be located in the network and facilitate connection to the network, determine whether workstation 115 should not be located in the network, provide access services or functions associated with applications or network resources, such as frequent shopper services, and provide access to enable or disable one or more services or functions, or any combination thereof.

[0126] In one or more specific examples, after step 1310, any or more of the following steps may be performed: steps 715, 720, 725, 730 and 735 of FIG. 7, steps 815, 820, 825, 830, 835, 840 and 845 of FIG. 8, and steps 1015, 1020, 1025, 1030 and 1035 of FIG. 10. Although the steps of FIG. 5 to 10 and FIG. 12-13 are presented in a specific order, this disclosure contemplates that any one or more steps may be performed simultaneously, substantially simultaneously, repeatedly or not at all (omitted).

[0127] Those skilled in the art will understand that the present invention improves the method and system for processing unique identifiers for workstations. The method, system, and computer-readable medium are operable to facilitate message exchange between an access point and a workstation, wherein the access point requests a unique identifier from the workstation. The workstation may respond with a message refusing to provide a unique identifier, or with a message containing a unique identifier to be used by the workstation's access point. The response from the workstation may include additional restrictions on the access point's use of the unique identifier. The access point can implement different functions, such as different policies, for the workstation depending on how the workstation responds to the unique identifier request.

[0128] The subject matter and components thereof disclosed herein may be implemented by instructions that, upon execution, cause one or more processing devices to perform the processes and functions described above. For example, such instructions may include interpretation instructions, such as script instructions, such as JavaScript or ECMAScript instructions, or executable code, or other instructions stored in computer-readable media.

[0129] The implementation of the subject matter and functional operations described in this specification may be provided in digital electronic circuits, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or combinations thereof. Specific examples of the subject matter described in this specification may be implemented as one or more computer program products, that is, one or more modules of computer program instructions encoded on a physical program carrier for performing or controlling the processing of a data processing device.

[0130] Computer programs (also known as programs, software, software applications, instruction code, or code) can be written in any form of programming language, including compiled or interpreted languages ​​or declarative or procedural languages, and can be deployed in any form, including as standalone programs or as modules, components, subroutines, or other units suitable for use in a computing environment. A computer program does not necessarily correspond to a file in a file system. A program may be stored as part of a file containing other programs or data (e.g., one or more scripts stored in a markup language file), in a single file dedicated to the problematic program, or in multiple collaborating files (e.g., multiple files storing one or more modules, subroutines, or code portions). A computer program can be deployed and executed on one or more computers located in one place or distributed across multiple locations interconnected by a communications network.

[0131] The processes and logic flows described in this specification are implemented by one or more programmable processors that execute one or more computer programs to perform multiple functions by manipulating input data and producing outputs, thereby integrating the processes into a specific machine (e.g., a machine programmed to perform the processes described herein). The processes and logic flows can also be implemented by special-purpose logic circuits, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits), and devices can also be implemented as special-purpose logic circuits.

[0132] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, including, for example, semiconductor memory devices (such as EPROM, EEPROM, and flash memory devices); magnetic disks (e.g., internal hard disks or removable disks); magneto-optical disks; and CD-ROM and DVD-ROM disks. Processors and memory may be supplemented or integrated into dedicated logic circuits by special-purpose logic circuits.

[0133] While this specification contains numerous specific implementation details, it should not be construed as a limitation on the scope or possible claims of any invention, but rather as a description of the function of a particular embodiment of a particular invention. Certain functions described in the context of multiple separate embodiments in this specification may also be implemented in combination in a single embodiment. Conversely, various functions described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments. Furthermore, while functions may be described as being performed in certain combinations, and even initially claimed as such functions, in some instances, one or more functions from the claimed combination may be removed from that combination, and the claimed combination may lead to sub-combinations or variations thereof.

[0134] Similarly, when operations are depicted in a specific order in a diagram, it should not be construed as requiring such operations to be performed in the specific order or sequentially shown, or to execute all depicted operations to achieve the desired result. In some cases, multiplexing and parallel processing may be advantageous. Furthermore, the separation of various system components in the above specific examples should not be construed as requiring such separation in all specific examples, and it should be understood that the program components and systems can generally be integrated into a single software product or packaged into multiple software products.

[0135] Specific examples of the subject matter described in this specification have been described. Other specific examples fall within the scope of the following claims. For example, unless otherwise expressly stated, the actions cited in the claims can be performed in different orders and still achieve the desired result. As an example, the methods depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired result. In some cases, multiplexing and parallel processing may be advantageous.

[0136] 100: Network Environment 105: Workstation 110: Local Wi-Fi 115: Access Point 120: Broadband Access Network 125: WAN (Wide Area Network) 205: Unique Identifier Request 210: Requested network type field 215: Encryption Enabled Field 220: Unique Identifier Response 225: Response code field 230: ID query response field 235: Selective Unique Identifier Field 240: Selective Identification Code Duration Field 245: Selective Salesperson Specific Information Section 305: Request for Unique Identifier 310: Category Field 315: ID query action field 320: Optional vendor-specific information field 325: Unique Identifier Response 330: Category Field 335: ID query action field 340: ID query response field 345: Selective Identification Code Length Field 350: Selective Unique Identifier Field 355: Selective Identification Code Duration 360: Optional vendor-specific information sections 405: Orderer Interface 410: Network Interface 415: Unique Identifier Exchange Module 420: Unique Identifier Data Storage Area 425: LAN Interface 430: Unique Identifier Exchange Module 500: Process 505, 510, 515, 520, 525: Steps 600: Process 605, 610, 615, 620, 625, 630: Steps 700: Process 705, 710, 720, 715, 720, 725, 730, 735: Steps 800: Process 805, 810, 815, 820, 825, 830, 835, 840, 845: Steps 900: Process 905, 910, 915, 920, 925, 930: Steps 1000: Process 1005, 1010, 1015, 1020, 1025, 1030, 1035: Steps 1100: Process 1110, 1120, 1130, 1140, 1150: Steps 1200: Process 1205, 1210, 1215, 1220, 1222, 1225: Steps 1300: Process 1305, 1307, 1310, 1315, 1320, 1325: Steps

Claims

1. A method for providing one or more functions from an access point to a workstation, the method comprising: Prior to associating with the workstation, a unique identifier request is sent to the workstation, wherein the unique identifier request includes a request from the workstation in response to a unique identifier to be used by the access point of the workstation; a secure connection is established with the workstation; a unique identifier response is received from the workstation through the secure connection; it is determined that the workstation supports creating and providing the unique identifier based on an instruction provided in the unique identifier response; it is determined that the unique identifier response provides the unique identifier to be used by the workstation, wherein the unique identifier is different from a media access control (MAC) address of the workstation; and based on the unique identifier received in the unique identifier response, access to the workstation for one or more functions is provided.

2. As in request item 1, where, Establishing a secure connection to the workstation involves exchanging one or more cryptographic keys with the workstation.

3. As in request item 1, where, Establishing this secure connection involves a pre-association security negotiation.

4. As in request item 1, where, The unique identifier may include a universally unique identifier, a random number, a pseudo-random number, a pre-configured identifier, or any combination thereof.

5. The method of request item 1 further includes: associating the workstation with the access point.

6. The method of request item 5 further includes: after associating the workstation with the access point, providing network information to the workstation, the network information specifying a network or network access for the workstation.

7. As in request item 1, wherein, Providing access to one or more functions to the workstation based on the unique identifier received in the response includes providing one or more benefits associated with a retail business or an online business.

8. An access point for providing access to one or more functions to a workstation, the access point comprising: A memory storing one or more computer-readable instructions; and a processor configured to execute the one or more computer-readable instructions for: outputting a unique identifier request to the workstation prior to association with the workstation, wherein the unique identifier request includes a request from the workstation in response to a unique identifier to be used by the access point of the workstation; establishing a secure connection with the workstation; receiving a unique identifier response from the workstation through the secure connection; determining that the workstation supports creating and providing the unique identifier based on an instruction provided in the unique identifier response; determining that the unique identifier response provides the unique identifier to be used by the workstation, wherein the unique identifier is different from a media access control (MAC) address of the workstation; and providing the workstation with access to the one or more functions based on the unique identifier received in the unique identifier response.

9. As in the access point of request item 8, where, Establishing a secure connection to the workstation involves exchanging one or more cryptographic keys with the workstation.

10. As in the access point of request item 8, where, Establishing this secure connection involves a pre-association security negotiation.

11. As in the access point of request item 8, where, The unique identifier may include a universally unique identifier, a random number, a pseudo-random number, a pre-configured identifier, or any combination thereof.

12. As in the access point of request item 8, where, The processor is further configured to execute one or more computer-readable instructions to: associate the workstation with the access point.

13. As in the access point of request item 12, where, The processor is further configured to execute one or more computer-readable instructions for: providing network information to the workstation after associating the workstation with the access point, the network information specifying a network or network access for the workstation.

14. As in the access point of request item 8, where, Providing access to one or more functions to the workstation based on the unique identifier received in the response includes providing one or more benefits associated with a retail business or an online business.

15. A non-transitory computer-readable medium for an access point, storing one or more computer-readable instructions for providing access to one or more functions to a workstation, wherein the one or more computer-readable instructions, when executed by a processor of the access point, cause the access point to perform one or more operations, including: Prior to associating with the workstation, a unique identifier request is sent to the workstation, wherein the unique identifier request includes a request from the workstation in response to a unique identifier to be used by the access point of the workstation; a secure connection is established with the workstation; a unique identifier response is received from the workstation through the secure connection; it is determined that the workstation supports creating and providing the unique identifier based on an instruction provided in the unique identifier response; it is determined that the unique identifier response provides the unique identifier to be used by the workstation, wherein the unique identifier is different from a media access control (MAC) address of the workstation; and based on the unique identifier received in the unique identifier response, access to the workstation for one or more functions is provided.

16. The non-transitory computer-readable medium as described in claim 15, wherein, Establishing the secure connection involves exchanging one or more cryptographic keys or at least one of a pre-association security negotiation with the workstation.

17. The non-transitory computer-readable medium as described in claim 15, wherein, The unique identifier may include a universally unique identifier, a random number, a pseudo-random number, a pre-configured identifier, or any combination thereof.

18. The non-transitory computer-readable medium as described in claim 15, wherein, When executed by the processor, the one or more computer-readable instructions further cause the access point to perform one or more other operations, including associating the workstation with the access point.

19. The non-transitory computer-readable medium as described in claim 18, wherein, When the access point is further caused to perform one or more further operations by the one or more computer-readable instructions executed by the processor, the operations include: after associating the workstation with the access point, providing network information to the workstation, the network information specifying a network or network access for the workstation.

20. Non-transitory computer-readable media as in claim 15, wherein, Providing access to one or more functions to the workstation based on the unique identifier received in the response includes providing one or more benefits associated with a retail business or an online business.