Multiple link layer addresses for a device
Patent Information
- Application Number
- CN202111060318.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-09-03
- Filing Date
- 2021-09-10
- Publication Date
- 2026-08-18
- Estimated Expiration
- 2041-09-10
AI Technical Summary
没有适当凭证或权限的设备将无法连接到LAN
Smart Images

Figure CN114257567B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this disclosure relate to multiple link layer addresses for a device. Background Technology
[0002] Electronic devices can communicate via wired or wireless networks. An example of a network is a Local Area Network (LAN), which is a network that allows devices within a specific area (physical or logical area) to communicate with each other. Devices without proper credentials or permissions will not be able to connect to a LAN.
[0003] A LAN can be either a wired LAN or a wireless LAN. A wireless LAN (WLAN) includes a wireless access point (AP) that a device can wirelessly connect to. Summary of the Invention
[0004] According to some implementations, a device is disclosed, including: a link layer, the link layer including hardware processing circuitry and configured to: use a first link layer address and a second link layer address, maintain the first link layer address unchanged for a duration of association between the device and a wireless network, and change the second link layer address from a first value to a second value during the duration.
[0005] According to some implementations, an access point (AP) for a wireless network is disclosed, comprising: a link layer including hardware processing circuitry and configured to: transmit to a device via the wireless network an indication of support for a link layer address protection feature providing multiple link layer addresses, the multiple link layer addresses including a first link layer address that will remain unchanged during the duration of association between the device and the AP, and a second link layer address that will change to a different value during the duration.
[0006] According to some implementations, a non-transient machine-readable storage medium including instructions that, when executed, cause the device to: use a first link layer address and a second link layer address at the link layer of the device, maintain the first link layer address unchanged for a duration of association between the device and the wireless network, and change the second link layer address from a first value to a second value during the duration. Attached Figure Description
[0007] Some implementations of this disclosure are described with reference to the following figures.
[0008] Figure 1 This is a block diagram of a device based on some implementations of this disclosure.
[0009] Figure 2 This is a block diagram illustrating an example layout of access points (APs) and stations (STAs) based on some implementations of this disclosure.
[0010] Figure 3This is a message flow diagram of the process between the STA and AP according to some implementations of this disclosure.
[0011] Throughout the accompanying drawings, the same reference numerals indicate similar but not necessarily identical elements. The drawings are not necessarily drawn to scale, and the dimensions of some parts may be exaggerated to more clearly illustrate the examples shown. Furthermore, the drawings provide examples and / or implementations consistent with the description; however, the description is not limited to the examples and / or implementations provided in the drawings. Detailed Implementation
[0012] In this disclosure, unless the context clearly indicates otherwise, the use of the terms “a,” “an,” or “the” is also intended to include the plural form. Furthermore, when used in this disclosure, the terms “includes,” “including,” “comprises,” “comprising,” “have,” or “having” specify the presence of the stated element but do not exclude the presence or addition of other elements.
[0013] 1. Background, abbreviations and acronyms
[0014] Table 1 below lists various abbreviations and acronyms.
[0015] Table 1
[0016]
[0017]
[0018]
[0019] Table 2 below lists the various terms used and their corresponding brief descriptions.
[0020] Table 2
[0021]
[0022]
[0023] 2. question
[0024] 2.1 General Principles
[0025] Devices operating within a Local Area Network (LAN) use their Media Access Control (MAC) address as the source address for frames transmitted and received on the LAN. The LAN uses the device's MAC address to route LAN traffic to the correct device on the LAN. Additionally, the device's MAC address is used to maintain other state information, such as its IP address. If a device changes its MAC address, both LAN and IP communication are interrupted. The device must be stripped and reattached to the LAN to re-establish state information, which may disrupt any application-level communication.
[0026] 2.2 User privacy
[0027] Devices operating on a LAN can be assigned globally unique MAC addresses. Traditionally, devices use globally unique MAC addresses as their addresses when operating on a LAN. As user privacy becomes increasingly important, some devices now assign their MAC addresses to randomly derived addresses within a locally managed address space for communication. These randomly derived addresses are used to communicate with other devices during discovery processes and when connecting and operating on the LAN.
[0028] There are conflicting behavioral requirements for devices regarding LAN communication and privacy protection. An example of these conflicting requirements includes using MAC addresses for a security key algorithm that operates for a duration associated with the LAN (generating security keys based on MAC addresses), and privacy enhancements based on frequently changing MAC addresses to prevent tracking by passive observers. Solutions should be developed to address these conflicting behavioral requirements.
[0029] 3. Example Implementation
[0030] Figure 1 A device 100 is shown that is capable of communicating via a network 102 such as a wired LAN or a wireless LAN (WLAN). Examples of the device may include any or a combination of the following: desktop computer, laptop computer, tablet computer, smartphone, Internet of Things (IoT) device, vehicle, controller in vehicle, gaming device, home appliance, etc.
[0031] Device 100 includes one or more hardware processors 104 capable of executing machine-readable instructions 106 stored in a non-transient machine-readable or computer-readable storage medium 108. The hardware processor may include a microprocessor, the core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuitry.
[0032] Storage medium 108 can be implemented using one or more storage devices. Storage devices can include volatile memory devices or non-volatile memory devices. Another example of a storage device can be a persistent storage device, such as a disk-based storage device, a solid-state drive, etc.
[0033] Device 100 also includes a protocol stack 110, which includes various layers that allow communication between device 100 and network 102.
[0034] In some examples, network 102 is a wireless network, such as a WLAN, a cellular network, etc. In other examples, network 102 (or another network) may include a wired network, such as a LAN. Although only one network 102 is depicted, it should be noted that multiple networks may exist with which device 100 can communicate, including both wireless and wired networks. For example, device 100 may communicate with a WLAN as well as with a wired LAN.
[0035] Protocol stack 110 includes a physical layer 112, which includes physical circuitry (including transceivers) for transmitting and receiving signals over network 102. Protocol stack 110 also includes a link layer 114 above the physical layer 112. In some examples, link layer 114 includes a media access control (MAC) layer.
[0036] Protocol stack 110 also includes one or more higher layers 116 above link layer 114. Examples of higher layers 116 may include any or a combination of the following: IP layer, security protocol layer, etc.
[0037] Note that the higher layers 116 and the possible link layer 114 can be implemented as machine-readable instructions executable by one or more hardware processors 104. In another example, the link layer 114 (and the possible one or more higher layers 116) can be implemented using hardware processing circuitry.
[0038] According to some implementations of this disclosure, link layer 114 can use multiple link layer addresses (e.g., multiple MAC addresses) for communication to or from device 100. The multiple link layer addresses include a first link layer address that remains unchanged during the duration of the association between device 100 and the wireless network. The multiple link layer addresses also include a second link layer address that changes from a first value to a second value (and may change to other values) during the duration of the association between device 100 and the wireless network.
[0039] In some examples, the first link layer address that remains unchanged during the duration of association with the wireless network is referred to as LAN link address 118. The second link layer address that can change during the duration of association between device 100 and the wireless network is referred to as air link address 120. LAN link address 118 and air link address 120 can be stored in storage medium 108 (e.g., memory) for use in communication 100 of the device.
[0040] 3.1 Implementation 1: LAN MAC Protection
[0041] In some implementations, the feature that supports the use of multiple link-layer addresses for communication of a specific device (e.g., 100) is referred to as LAN MAC protection. In other examples, this feature may also be referred to as LAN MAC privacy, MAC address rotation, AIR MAC change protocol, etc.
[0042] More generally, this feature is known as the link-layer address protection feature.
[0043] Figure 2 An example arrangement including access points (APs) 202-1 and 202-2 is shown, which are wireless access network nodes in a WLAN to which wireless devices (referred to as stations or STAs) can establish wireless connections. An AP can also be referred to as a STA. Wireless devices that are not APs are referred to as non-AP STAs.
[0044] Figure 2 Multiple STAs (A, B, C, D, and E) capable of communicating with APs 202-1 and 202-2 are shown. STAs A, B, C, and E are wireless devices capable of communicating wirelessly with APs 202-1 and 202-2 in WLAN 204. STA D is a wired device connected to APs 202-1 and 202-2 via wired LAN 206.
[0045] WLAN 204 is considered the airside, where the STA communicates with AP 202-1 or 202-2 via air (wireless). Wired LAN 206 is part of the LAN side, where the STA communicates with AP 202-1 or 202-2 via a wired communication medium.
[0046] exist Figure 2 In the example, STAs A, B, and C support the LAN MAC protection feature, while STA E is a legacy device that does not support the LAN MAC protection feature. In the following discussion, STAs that support the LAN MAC protection feature may be referred to as "LAN MAC protected STAs".
[0047] LAN MAC protected STAs (any of STAs A, B, and C) can use LAN MAC protection features to work with STAs using a single static MAC address (e.g., Figure 1 Interoperability with legacy devices (e.g., ST E) with LAN link address 118.
[0048] In WLAN 204, AP 202-1 or 202-2 uses message or information elements transmitted by the AP to announce support for LAN MAC protection features, such as in beacon, probe response frames, etc. For example, support for LAN MAC protection features can be specified by announcement in the LAN MAC protection element (e.g., LAN MAC protection bit) within the extended capability element of an over-the-air communication frame. More generally, the AP may include a link layer (in some examples including hardware processing circuitry or in other examples including machine-readable instructions) configured to transmit, via the wireless network (e.g., WLAN 204), an indication to a device (STA A, B, or C) that supports a link layer address protection feature providing multiple link layer addresses, including a first link layer address that remains unchanged during the associated duration between the device and the AP, and a second link layer address that will change to a different value during the duration.
[0049] The link layer 114 of device 100 is configured to detect in information (e.g., messages or information elements) transmitted by the AP in WLAN 204 that the AP supports a link layer address protection feature, which allows device 100 to use a different link layer address. Link layer 114 is configured to send an indication to the AP to request information about whether the AP supports the link layer address protection feature.
[0050] In some examples, a STA with LAN MAC protection can request the use of the LAN MAC protection feature by including a LAN MAC protection element or by setting a LAN MAC address privacy indicator in a (re)association request frame.
[0051] LAN MAC protected STAs A, B, and C maintain two MAC addresses: a LAN MAC address that remains unchanged during the duration of their association with the AP, and an AIR MAC address that can change during that duration. The AIR MAC address is used in frames transmitted between the LAN MAC protected STAs and the AP. The LAN MAC address is used to forward frames destined for wired LAN 206. Each LAN MAC protected STA A, B, or C maintains its corresponding LAN MAC address for the duration of its association with the AP in the ESS. Each LAN MAC protected STA A, B, or C maintains its AIR MAC address according to the STA's MAC address rotation / change policy.
[0052] The AP (202-1 or 202-2) manages address resolution for STAs (where LAN MAC protection is enabled) used for LAN MAC protection. Each STA A, B, or C under LAN MAC protection can use Proxy ARP for address resolution. STA D on wired LAN 206 can also use Proxy ARP for address resolution.
[0053] The AP (202-1 or 202-2) responds to ARP requests from the STA (STA D) on the LAN side using the LAN MAC address of STA D. The AP (202-1 or 202-2) further responds to ARP requests from the STA A, B, or C protected by the LAN MAC on the airside using both the STA's LAN MAC address and AIR MAC address (i.e., the AP responds to ARP requests from the STA protected by the LAN MAC on the airside using both the STA's LAN MAC address and AIR MAC address).
[0054] like Figure 2 As further illustrated, each AP 202-1 or 202-2 includes a corresponding LAN MAC-AIR MAC mapping table (or mapping information in another format) 208-1 or 208-2. Each LAN MAC-AIR MAC mapping table 208-1 or 208-2 includes multiple entries, where each entry maps the LAN MAC address of the corresponding STA to the AIR MAC address of the corresponding STA. For example, each entry in the LAN MAC-AIR MAC mapping table 208-1 or 208-2 may be a double tuple containing two elements: the LAN MAC address and the corresponding AIR MAC address mapped to the LAN MAC address.
[0055] In some examples, the LAN MAC-AIR MAC mapping tables 208-1 and 208-2 in the corresponding APs 202-1 and 202-2 are synchronized with each other (210), that is, any change in one of the LAN MAC-AIR MAC mapping tables 208-1 and 208-2 is propagated to the other of the LAN MAC-AIR MAC mapping tables 208-1 and 208-2.
[0056] Note that each STA (A, B, or C) protected by LAN MAC can also maintain a corresponding LAN MAC-AIR MAC tuple, which includes the AP's LAN MAC address and the corresponding AIR MAC address mapped to the LAN MAC address.
[0057] The following describes an example of data routing that uses the LAN MAC protection feature.
[0058] 1. LAN MAC-protected STAs use a randomized MAC address (AIR MAC address) on the air link to WLAN 204 to discover and establish LAN access. When a LAN MAC-protected STA establishes a state with LAN 206, it uses the randomized MAC address in the IEEE 802.11 header of the data frame to address frames sent over the air link.
[0059] 2. LAN MAC protected STAs use different MAC addresses (LAN MAC addresses), such as their globally unique MAC address or locally managed (e.g., assigned by IEEE 802.1CQ) MAC addresses, to communicate over a LAN (wired LAN 206).
[0060] 3. For unicast services (services transmitted from a transmission device to an individual destination device), AP 202-1 or 202-2 maintains a mapping for associated STAs (associated with the AP) using double tuples for unicast communication, each including a corresponding AIR MAC address and a corresponding LAN MAC address. The double tuple is part of the LAN MAC-AIR MAC mapping table 208-1 or 208-2 as indicated above. Management services between LAN MAC-protected STAs and APs use the AIR MAC address as the source or destination MAC address for addressing. In some examples, two mechanisms exist for handling MAC addressing within the LAN:
[0061] (a) The LAN header is tunneled over the air link. The IP stack of a LAN MAC-protected STA is bound to the LAN MAC address. Unicast traffic between the AP and a LAN MAC-protected STA uses the AIR MAC address.
[0062] (b) LAN MAC-protected STAs and APs communicate over the air link using AIR MAC addresses. When an AP receives frames from or destined for a LAN MAC-protected STA, it replaces the AIR MAC address in the frame with the LAN MAC address, and vice versa.
[0063] Note: For mechanism (a) above, the existence of the AIR MAC address is completely transparent to the operating system (OS) and (multiple) upper layers (e.g., IP stack) of the LAN MAC-protected STA or AP. Furthermore, the translation between the LAN MAC address and the AIR MAC address (in the double tuple) is handled by the WLAN driver of the LAN MAC-protected STA or AP. A tunnel is established between the LAN MAC-protected STA and AP.
[0064] For mechanism (b) above, the double tuple is known to the OS of the STA or AP protected by the LAN MAC, and the OS uses the correct address (AIR MAC address or LAN MAC address) when transmitting frames.
[0065] 4. For broadcast / multicast services (which are services transmitted from a source device to multiple destination devices using a group address), uplink services (from a LAN MAC-protected STA to an AP) are treated as unicast services as discussed above. Downlink broadcast / multicast services do not use the MAC address of the LAN MAC-protected STA; therefore, downlink broadcast / multicast services are sent in the manner used by traditional devices (using the group address in the header field).
[0066] 5. During the lifetime of the association between the STA and AP under LAN MAC protection, the AIR MAC address can change, while the LAN MAC address remains unchanged. This allows for seamless connectivity with LAN 206 while reducing the need for observers to track LAN MAC-protected STAs for extended periods.
[0067] LAN MAC protected STAs and APs use AIR MAC addresses to exchange management frames; therefore, wireless communication does not use LAN MAC addresses. Specifically, the value of any of the three or four addresses in the 802.11 header is not set to the LAN MAC address in any communication to or from the AP. LAN MAC addresses are only exchanged between the AP and STA using tunneling within encrypted frames (data frames or management frames).
[0068] In some examples, the AP's link layer receives frames destined for the destination device from the STA, translates the AIR MAC address in the received frame (using the LAN MAC-AIR MAC mapping table in the AP) to the corresponding LAN MAC address, and includes the corresponding LAN MAC address in the frame sent to the destination device.
[0069] In a further example, the AP's link layer receives a frame destined for the STA from the source device, (using the LANMAC-AIRMAC mapping table in the AP) transforms the LAN MAC address in the frame into the corresponding AIR MAC address, and includes the corresponding AIR MAC address in the frame sent to the STA.
[0070] When the LAN MAC protection feature is enabled, the security association used for STA and AP is bound to the AIR MAC address. For example, device 100 includes a security layer as part of protocol stack 110, wherein the security layer is configured to use the AIR MAC address to bind the security association between device 100 and the AP of WLAN 204.
[0071] This is consistent with traditional STA behavior. From a security perspective, the LAN MAC address protection features function as follows: Figure 3 As shown in the image.
[0072] Based on the transmission of management frames (in 302) from STA 300 (LAN MAC protected STA) to AP 202 (one of AP 202-1 or 202-2), the PMK (Pair Master Key) and PTK (Pair Temporary Key) are derived and bound to the AIR MAC address, which is used for the initial association with the AP in WLAN 204. The security layer is configured to use the AIR MAC address to derive the PMK and PTK. The security association of device 100 bound to the AP is PTKSA (PTK Security Association).
[0073] Due to the change in the AIR MAC address at STA 300, the management frame includes the new AIR MAC address. Note that even though the change in the AIR MAC address results in a new association (at link layer 114), the connections or other associations of (multiple) higher layers (116) remain unchanged. The higher layers above link layer 114 are configured to maintain connectivity with LAN 206 based on the LAN MAC address when the AIR MAC layer address changes.
[0074] In response to the management frame, STA 300 shuts down (at 304) its 802.1x port, and AP 202 shuts down (at 306) its 802.1x port. Shutting down an 802.1x port refers to the deletion of a virtual port specified in IEEE 802.1X.
[0075] A four-way handshake is performed between STA 300 and AP 202 (at point 308) to establish the association between them. In message 4 of the four-way handshake, STA 300 encrypts and sends its LAN MAC address to AP 202 in a Key Descriptor Element (KDE).
[0076] When STA 300 rotates (changes) its AIR MAC address, STA 300 sends a signal to AP 200 to negotiate a new PTK. The process works as follows.
[0077] (A) STA 300 rotates its AIR MAC address and (re)associates with AP 202 by signaling a LAN MAC address privacy indicator. STA 300 and AP 202 negotiate a new PTKSA (Paired Temporary Key Security Association) using any of the following protocols: RSNA (Robust Secure Network Association), SAE (Simultaneous Peer Authentication), FT (Fast Basic Service Set (BSS) Transition), or FILS (Fast Initial Link Setup). During the last message of the 4-way handshake, FT, or FILS exchange, STA 300 sends its LAN MAC address to AP 202 in KDE (Key Data Encapsulation).
[0078] (B)STA 300 can use alternative management frames to signal the negotiation of a new PTKSA. For example, the SA (Security Association) query frame can be modified to trigger AP 202 to initiate a four-way handshake to derive a new PTKSA.
[0079] When the four-way handshake is completed (as indicated by the success indication sent from AP 202 to STA 300 at 310), the IEEE 802.1X control port is opened by STA 300 and AP 202 (at 312 and 314 respectively), and STA 300 and AP 202 each store (at 316 and 318 respectively) a tuple containing the mapped AIR MAC address and LAN MAC address.
[0080] To protect privacy, additional identifiers can be changed in sync with changes to the AIR MAC address. This includes the MAC frame sequence counter, the PHY OFDM (Orthogonal Frequency Division Multiple Access) data scrambler, and / or other identifiers.
[0081] Rotating MAC addresses means changing the MAC address. MAC address changes can be made using random or pseudo-random address selection, or by using other algorithms. The changed MAC address does not need to be cyclical. MAC address changes can be negotiated when they occur, or the MAC address can be determined by both the AP and STA independently calculating the next AIR MAC address.
[0082] In some examples, STAs with LAN MAC protection use extended capability bits or other indicators to announce their support for LAN MAC protection features.
[0083] In some examples, the AP uses extended capability bits or other indicators to announce its support for LAN MAC protection features.
[0084] In some examples, STAs with LAN MAC protection can determine whether to associate with the AP based on the AP's LAN MAC protection capabilities. STAs with LAN MAC protection can be configured in several different ways. If the AP does not support the LAN MAC protection feature, STAs with LAN MAC protection can associate in legacy mode. If the AP supports the LAN MAC protection feature, STAs with LAN MAC protection can avoid associating in legacy mode. STAs with LAN MAC protection can prompt the user before associating in legacy mode.
[0085] Any use of the foregoing content may be based on different user preferences regarding privacy, and on the privacy losses incurred by using legacy patterns. Alternatively, a list of networks permitted for legacy patterns may be stored in the LAN MAC-protected STA, or no whitelist or blacklist mechanism may be used.
[0086] Similarly, an AP can have policies that allow or prohibit STAs from connecting in legacy modes.
[0087] STA's scanning algorithm can take LAN MAC protection features into account and connect to APs that support those features with a higher priority than those that do not.
[0088] 3.2 Implementation 2: TDLS
[0089] Peer devices will include their LAN MAC protection elements or extended capability bits as part of the TDLS (Tunnel Direct Link Setup) link setup and TDLS discovery frames.
[0090] TDLS allows direct communication between STAs operating within the same WLAN. Without TDLS, all frames must be transmitted from the source STA to the AP, and then from the AP to the destination STA. TDLS technology reduces the use of wireless media by nearly half by enabling the source STA to transmit data directly to the destination STA. TDLS technology has been standardized in the IEEE 802.11z amendment and has been tested in the Wi-Fi Alliance certification program since 2012. It is widely deployed in consumer and enterprise WLAN equipment.
[0091] According to some implementations of this disclosure, if the initiating TDLS STA is associated with an AP that has LAN MAC address privacy enabled, the initiating TDLS STA includes a LAN MAC privacy element or capability bit set to a specified value (to indicate support for LAN MAC protection features) in the TDLS link setup frame. If the responding STA is associated with an AP with LAN MAC protection and receives a TDLS link setup frame including a LAN MAC privacy element or capability bit set to a specified value, the responding STA responds by including a LAN MAC protection element or extended capability in its response. This information allows either TDLS peer to gracefully handle the teardown of the TDLS link—if the other peer changes its MAC address.
[0092] Once the TDLS link setup is successful, the two peer devices will use their AIR MAC addresses to exchange frames. If one of the peer devices changes its AIR MAC address, the TDLS link will be dropped. The TDLS link will then be re-established using the new address after the change.
[0093] 3.3 Implementation 3: Encrypt MAC Address
[0094] The aforementioned refers to rotating the AIR MAC address, changing the AIR MAC address, or selecting a random AIR MAC address. One mechanism for doing this is to select a random MAC address from the local address space (such as a 46-bit numeric space). The probability of this conflicting with other devices that also randomly select addresses is very small, but not zero. Some standards further divide the local address space into four quadrants, each 44 bits. After the device selects a new address, it notifies the AP of the new address. This may involve the exchange of management frames. In the long term, there are other alternative methods for selecting new MAC addresses that use fewer management frames.
[0095] The use of encrypted MAC addresses reduces communication associated with negotiating or notifying the AP or STA what the new AIR MAC address will be after a change. Only the AP and STA know the encrypted sequence of the sequence and / or seed, allowing both devices to independently derive the next AIR MAC address in the sequence. This can be achieved using a deterministic pseudo-random number generator. The cryptographic properties of this algorithm prevent intermittent passive observers from associating the old and new addresses, while each AP and STA knowing these values can compute the same next address in the sequence.
[0096] 3.4 Implementation 4: 802.11be multi-link address
[0097] This implementation is based on what the current task group IEEE 802.11be is doing for multi-link devices.
[0098] The IEEE 802.11be amendment, described in IEEE 802.11-19 / 1899r7 “MLAMAC Addresses Considerations” dated January 2020, proposes technologies or mechanisms for next-generation WLANs. The IEEE 802.11be amendment will define an Ultra High Throughput (EHT) PHY and MAC layer capable of supporting a maximum throughput of at least 30 Gbps. The IEEE 802.11be amendment is also investigating a multi-link aggregation technology known as Multi-Link Device (MLD).
[0099] IEEE 802.11be introduced the "MLD address," which is used on a LAN when multiple links are used. Multiple links of a device (such as device 100) are used to connect the device to a wireless network (such as...). Figure 2 The association of each AP in the WLAN 204.
[0100] The concept of multi-link devices introduces a mapping between individual LINK MAC addresses and MLD (device) addresses. In IEEE 802.11be, individual LINK MAC addresses are treated as AIR MAC addresses, which can be mapped to LAN MAC addresses (MLD addresses) that are not transmitted over the air.
[0101] According to some implementations of this disclosure, authentication and PTK generation are based on MLD MAC addresses (LAN MAC addresses), while only (multiple) LINK MAC addresses ((multiple) AIR MAC addresses) are used in the SA / TA / RA / DA address fields.
[0102] The implementation of this disclosure introduces changes to the MLD proposal to make the long-lived MLD MAC address immune to eavesdropping. For this purpose, only the LINK MAC address is visible to an airborne observer. The implementation of this disclosure also uses techniques similar to those discussed in Section 3.1 above to add a protocol that allows the LINK MAC address to change during association without being discarded.
[0103] Using this scheme with LINK MAC address (AIR MAC address) and MLD address (LAN MAC address), it is an example implementation that provides the LAN MAC protection features described in Section 3.1 above, even when the STA is connected via only a single link.
[0104] More generally, a device can establish associations with multiple access points (APs) for multiple links with the APs. The device's link layer is configured to maintain distinct over-the-air (OTA) addresses for each of the multiple links, with each OTA being variable during the duration of the association.
[0105] 4. Example benefits
[0106] The implementation of this disclosure allows for the protection of user privacy by preserving the first link-layer address (which remains unchanged during the association between the wireless device and the access point) based on the use of the second link-layer address, which may change once or multiple times during the association. In this way, the first link-layer address does not need to be transmitted over the air in an unencrypted form, such as in the IEEE 802.11 MAC header. Instead, the second link-layer address is contained in the unencrypted IEEE 802.11 MAC header, while the first link-layer address can be tunneled (and encrypted) as the payload in a frame including the IEEE 802.11 MAC header.
[0107] For example, the benefit of using MAC addresses in the local address space instead of globally assigned MAC addresses for all WLAN services is that it prevents prolonged tracking. In cases where the tracking adversary is a passive observer, it prevents tracking across different locations, as most implementations randomize the addresses used in scanning operations and use a different address for each SSID when associating with the network. In some cases, MAC address changing implementations also provide privacy from the network provider.
[0108] Storage media (e.g., Figure 1108) may include any or a combination of the following: semiconductor memory devices, such as dynamic or static random access memory (DRAM or SRAM), erasable and programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory or other types of non-volatile memory devices; magnetic disks, such as fixed disks, floppy disks, and removable disks; other types of magnetic media, including magnetic tape; optical media such as compact discs (CDs) or digital video discs (DVDs); or other types of storage devices. Note that the instructions discussed above may be provided on a single computer-readable or machine-readable storage medium, or alternatively, the instructions discussed above may be provided on multiple computer-readable or machine-readable storage media distributed across a large system that may have multiple nodes. One or more such computer-readable or machine-readable storage media are considered part of an article (or article of manufacture). An article or article of manufacture may refer to any single or multiple manufactured components. The storage medium may be located in a machine that executes the machine-readable instructions, or at a remote site from which machine-readable instructions can be downloaded for execution via a network.
[0109] In the foregoing description, numerous details have been set forth to provide an understanding of the subject matter disclosed herein. However, various implementations can be practiced without some of these details. Other implementations may include modifications and variations to the foregoing details. The appended claims are intended to cover such modifications and variations.
Claims
1. A device for communication, the device comprising: The link layer includes hardware processing circuitry and is configured to: Send an indication to the access point (AP) to request information about whether the AP supports link-layer address protection features. Receive an indication in the information transmitted by the AP in the wireless network, the indication indicating that the AP supports the link-layer address protection feature, which provides different link-layer addresses for use. Using the different link layer addresses, including the first link layer address and the second link layer address, The first link layer address remains unchanged during the duration of the association between the device and the wireless network. During the duration, the second link layer address is changed from a first value to a second value.
2. The device of claim 1, wherein the association is with the AP, and the link layer is configured as follows: Multiple links are established with each AP of the wireless network, wherein the second link layer address is used for the first link among the multiple links, and Maintain a third link layer address for a second of the plurality of links, wherein the third link layer address is changeable during the duration of the association between the device and another AP.
3. The device of claim 2, wherein the first link layer address is a multi-link device (MLD) address, and the second link layer address and the third link layer address are part of a plurality of link layer addresses for the respective links of the plurality of links between the device and the respective APs.
4. The device according to claim 1, wherein the first link layer address is a first media access control (MAC) address, and the second link layer address is a second MAC address.
5. The device of claim 1, wherein the link layer is configured to include the first link layer address in a data frame destined for a wired network.
6. The device of claim 1, wherein the link layer is configured to include the first link layer address in a management frame transmitted to the AP.
7. The device according to claim 1, further comprising: Processor, the processor being configured to: Send an address resolution request to the AP, and The device receives the first link layer address and the second link layer address from the AP in response to the address resolution request.
8. The device according to claim 1, wherein the second link layer address is a randomized address.
9. The device of claim 1, wherein the second link layer address is a cryptographic address that can be independently derived at the device and at the AP.
10. The apparatus of claim 1, wherein the link layer is configured to tunnel a LAN header containing the first link layer address in the payload of a data frame including a header containing the second link layer address.
11. The device according to claim 1, comprising: Above the link layer, another layer is configured to maintain connectivity with the local area network (LAN) based on the first link layer address when the second link layer address is changed.
12. The device according to claim 1, comprising: A security layer configured to use the second link layer address to bind a security association between the device and the AP.
13. The device of claim 12, wherein the security layer is configured to use the second link layer address to derive a pair of master keys PMK and a pair of temporary keys PTK, and wherein the security association is a PTK security association PTKSA.
14. The device of claim 13, wherein the security layer is configured to negotiate a new PTK in response to the change of the second link layer address.
15. The device of claim 1, wherein the link layer is configured to perform Tunnel Direct Link Setup (TDLS) with a peer device to establish a direct wireless link between the device and the peer device, the TDLS including the link layer sending an indication to the peer device of support for the link layer address protection feature.
16. The device of claim 15, wherein the link layer is configured to send frames to the peer device using the second link layer address.
17. An access point (AP) for a wireless network, comprising: The link layer includes hardware processing circuitry and is configured to: Receive an instruction from the device to request information about whether the AP supports link-layer address protection features; The wireless network transmits to the device an indication of support for the link layer address protection feature that provides multiple link layer addresses, including a first link layer address that will remain unchanged during the duration of the association between the device and the AP, and a second link layer address that will change to a different value during the duration.
18. The AP of claim 17, wherein the link layer is configured as follows: Receive address resolution requests from the device via the wireless network, and In response to the address resolution request, the first link layer address and the second link layer address are sent to the device.
19. The AP of claim 17, wherein the link layer is configured as follows: Receive a second address resolution request from the second device via a wired local area network (LAN), and In response to the second address resolution request, a third link layer address that remains unchanged for the duration of the association between the second device and the AP is sent to the second device.
20. The AP of claim 17, wherein the link layer is configured to maintain a mapping that maps the first link layer address to the second link layer address.
21. The AP of claim 20, wherein the link layer is configured as follows: Receive frames from the device that are targeted at the destination device. Transform the second link layer address in the frame into the first link layer address, and The first link layer address is included in the frame sent to the destination device.
22. The AP of claim 20, wherein the link layer is configured as follows: Receive frames destined for the source device from the source device. Transform the first link layer address in the frame into the second link layer address, and The second link layer address is included in the frame sent to the device.
23. A non-transient machine-readable storage medium comprising instructions that, when executed, cause a device to: Send an indication to the access point (AP) to request information about whether the AP supports link-layer address protection features; Receive an indication in the information transmitted by the AP in the wireless network, the indication indicating that the AP supports the link-layer address protection feature, which provides different link-layer addresses for use. At the link layer of the device, the different link layer addresses, including a first link layer address and a second link layer address, are used. The first link layer address remains unchanged during the duration of the association between the device and the wireless network, and During the duration, the second link layer address is changed from a first value to a second value.
24. The non-transient machine-readable storage medium of claim 23, wherein the second link layer address is a randomized address or a cryptographic address.
Citation Information
Patent Citations
Wi-fi privacy in a wireless station using media access control address randomization
US20160135041A1