Privacy enhanced bss and discovery mechanisms
By introducing a privacy-enhanced BSS architecture, employing encrypted beacons and improved frame formats, the challenges of privacy protection in wireless communication systems are addressed, achieving a higher level of privacy protection and device security, suitable for modern wireless communication systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- APPLE INC
- Filing Date
- 2022-11-07
- Publication Date
- 2026-08-04
AI Technical Summary
Existing wireless communication systems face numerous challenges in terms of privacy protection, including the public discovery of MAC addresses and other identifying information of traditional sites, leakage of personally identifiable information, propagation of unencrypted beacons, passive and active scanning of privacy-enhanced BSSs, and the possibility of device tracking, making it difficult to meet the privacy requirements of modern wireless communication.
It adopts a privacy-enhanced BSS (PE BSS) architecture, which enhances the privacy protection of access points and wireless sites through encrypted beacons, random and variable MAC addresses, encrypted frame exchange, and improved frame formats, thereby achieving privacy enhancement for authentication, association, and discovery operations.
It improves the level of privacy protection in wireless communications, prevents information leakage and device tracking, supports the privacy requirements of modern wireless communications, and maintains backward compatibility with traditional systems.
Smart Images

Figure CN116095676B_ABST
Abstract
Description
Technical Field
[0001] This application relates to wireless communications, including technologies for privacy-enhanced BSS, including privacy enhancements for both access points and wireless sites, as well as privacy enhancements for authentication operations, association operations, and discovery operations. Background Technology
[0002] The use of wireless communication systems is growing rapidly. Furthermore, wireless communication technology has evolved from solely voice communication to also include the transmission of data such as the internet and multimedia content. A commonly used short- / mid-range wireless communication standard is Wireless Local Area Network (WLAN). Most modern WLANs are based on the IEEE 802.11 standard (or simply 802.11) and marketed under the Wi-Fi brand name. A WLAN network links one or more devices to a wireless access point, which in turn provides connectivity to the internet over a wider area.
[0003] In an 802.11 system, devices wirelessly connected to each other are called “sites,” “mobile stations,” “user equipment,” or simply STA or UE. A wireless site can be a wireless access point or a wireless client (or mobile station). An access point (AP), also known as a wireless router, acts as a base station for the wireless network. An AP transmits and receives radio frequency signals used to communicate with wireless client devices. APs are also typically wired to the Internet. Wireless clients operating on an 802.11 network can be any device in a variety of environments, such as laptops, tablets, smartphones, or fixed devices like desktop computers. This document refers to wireless client devices as user equipment (or simply UE). Some wireless client devices are also collectively referred to herein as mobile devices or mobile stations (but as mentioned above, wireless client devices can also generally be stationary devices). Summary of the Invention
[0004] The implementation schemes described herein relate to systems and methods associated with privacy-enhanced BSS, including privacy enhancements for both access points and wireless sites, and privacy strengthening for authentication, association, and discovery operations.
[0005] Some implementations relate to a wireless station comprising one or more antennas, one or more radio components, and one or more processors (directly or indirectly) coupled to the radio components. At least one radio component is configured to perform Wi-Fi communication, for example, via a Wi-Fi interface. The wireless station can perform voice and / or data communication, as well as any or all of the methods described herein.
[0006] For example, in some implementations, a wireless site may be configured to communicate with the traditional Basic Service Set (BSS) of the wireless network to transition to a Privacy Enhanced (PE) BSS of the wireless network. The wireless site may be configured to receive encrypted beacons from the PE BSS of the wireless network. The encrypted beacons may be decoded based on information received from the traditional BSS. Additionally, the wireless site may be configured to perform an encrypted handshake process with the PE BSS of the wireless network to authenticate and associate with the PE BSS of the wireless network.
[0007] For example, in some implementations, the wireless site can be and / or can be configured as an Internet of Things (IoT) site. The IoT site can be configured to operate in PE BSS mode. The IoT site can be configured to communicate with a configured wireless site of the wireless network to receive information associated with the PE IoT BSS. The information associated with the PE IoT BSS may include at least the channel on which the PE IoT BSS operates. Additionally, the IoT site can be configured to receive encrypted beacons from the PE IoT BSS. The encrypted beacons may be encrypted using a beacon key specific to the PE IoT BSS. Furthermore, the IoT site may perform an encrypted handshake process with the PE IoT BSS to authenticate and associate with the PE IoT BSS.
[0008] As another example, in some implementations, a wireless station may be configured to scan (or look up) the BSSID in a PE BSS beacon, for example, to receive a PE BSS beacon. The wireless station may be configured to attempt to match the BSSID with an address key stored at the wireless station, and if the BSSID matches the address key (and / or when it does), the wireless station may be configured to decrypt the BSS-specific beacon using a BSS-specific key stored at the wireless station.
[0009] For example, a wireless station, which may be a non-associated PE wireless station, can be configured to receive one or more discovery beacons from the PE access point that advertise a PE BSS hosted by the PE access point. The wireless station can be configured to send a request to the PE access point to establish pre-associated security protection. Furthermore, after establishing pre-associated security protection, the wireless station can be configured to send a protected request frame to the PE access point and receive a protected response from the PE access point including PE access point parameters. PE access point parameters may include PE BSS information.
[0010] Some implementations relate to an access point that includes one or more antennas, one or more radio components, and one or more processors (directly or indirectly) coupled to the radio components. At least one radio component is configured to perform Wi-Fi communication, for example, via a Wi-Fi interface. The access point can perform voice and / or data communication, as well as any or all of the methods described herein.
[0011] For example, in some implementations, the access point hosting the PE BSS can be configured to transmit encrypted beacons to the PE radio site. The encrypted beacons can be decoded based on information received from a traditional BSS. Furthermore, the access point can be configured to perform an encrypted handshake process with the PE radio site to authenticate the PE radio site and associate the PE radio site with the PE BSS.
[0012] For example, in some implementations, the access point may be configured to transmit encrypted beacons to the IoT site. The encrypted beacons may be decoded based on information received from a configured wireless site associated with the IoT site. The access point may be configured to perform an encrypted handshake process with the IoT site to authenticate the IoT site and associate the IoT site with the PE IoT BSS.
[0013] As another example, an access point (PE) can be configured to transmit one or more discovery beacons advertising a PE BSS hosted by the PE access point to non-associated PE radio stations. The access point can be configured to receive a request to establish pre-associated security protection from at least one non-associated PE radio station. Furthermore, after establishing pre-associated security protection, the access point can be configured to receive a protected request frame from at least one non-associated PE radio station and transmit a protected response including PE access point parameters to at least one non-associated PE radio station. PE access point parameters may include PE BSS information.
[0014] The present invention is intended to provide a brief overview of some of the subjects described in this document. Therefore, it should be understood that the features described above are merely examples and should not be construed as narrowing the scope or essence of the subjects described herein in any way. Other features, aspects, and advantages of the subjects described herein will become apparent from the following detailed description, drawings, and claims. Attached Figure Description
[0015] A better understanding of the subject matter can be obtained by considering the following specific description of the implementation scheme in conjunction with the accompanying drawings.
[0016] Figure 1 An example WLAN communication system according to some implementation schemes is shown.
[0017] Figure 2 An exemplary simplified block diagram of a WLAN access point (AP) according to some implementation schemes is shown.
[0018] Figure 3A An exemplary simplified block diagram of a mobile station (UE) according to some implementation schemes is shown.
[0019] Figure 3BAn exemplary simplified block diagram of an Internet of Things (IoT) site according to some implementation schemes is shown.
[0020] Figure 4 An example of an architecture for a privacy-enhanced BSS, based on some implementation schemes, is shown.
[0021] Figure 5 An example of signaling associated with a PE BSS for a PE wireless site and a public network, according to some implementation schemes, is shown.
[0022] Figure 6 An example of an access point supporting multiple networks / BSS is shown according to some implementation schemes.
[0023] Figure 7A and Figure 7B Examples of signaling for configuring IoT devices to the PE BSS are shown according to some implementation schemes.
[0024] Figure 8 An exemplary format of an encrypted beacon frame according to some implementation schemes is shown.
[0025] Figure 9 An example of a discovery beacon frame according to some implementation schemes is shown.
[0026] Figure 10A Examples of TBTT information fields / elements are shown according to some implementation schemes.
[0027] Figure 10B Examples of BSS parameter fields / elements are shown according to some implementation schemes.
[0028] Figure 10C Examples of MLD parameter fields / elements are shown according to some implementation schemes.
[0029] Figure 11A and Figure 11B Examples of encrypted beacon transmission and discovery beacon transmission according to some implementation schemes are shown.
[0030] Figure 12A , Figure 12B , Figure 12C and Figure 12D Examples of encrypted beacon transmission and discovery beacon transmission during a transmission opportunity are shown according to some implementation schemes.
[0031] Figure 13 and Figure 14 An example of an enhanced conventional beacon frame according to some implementation schemes is shown.
[0032] Figure 15An example of an encrypted beacon with multiple PE BSSs is shown according to some implementation schemes.
[0033] Figure 16A An example of an encrypted PE BSS field / element is shown according to some implementation schemes.
[0034] Figure 16B An example of a PE BSS profile SubE showing BSS fields / elements according to some implementation schemes is shown.
[0035] Figure 17A , Figure 17B and Figure 17C Examples of signaling for active scanning according to some implementation schemes are shown.
[0036] Figure 18A , Figure 18B and Figure 18C Examples of signaling for broadcasting PE BSS probes and / or queries are shown according to some implementation schemes.
[0037] Figure 19 Examples of signaling associated with PE wireless sites and PE access points according to some implementation schemes are shown.
[0038] Figure 20A and Figure 20B A block diagram illustrating an example of a method for associating a wireless site with a PE BSS of a wireless network, according to some implementation schemes, is shown.
[0039] Figure 21A and Figure 21B A block diagram illustrating an example of a method for associating an IoT site with a PE IoT BSS for a wireless network, according to some implementation schemes, is shown.
[0040] Figure 22A A block diagram illustrating an example of a method for a wireless site to receive a PE BSS beacon according to some implementation schemes is shown.
[0041] Figure 22B and Figure 22C A block diagram illustrating an example of a method, according to some implementations, for a PE access point to advertise a hosted PE BSS to an unassociated PE wireless site.
[0042] While the features described herein are susceptible to various modifications and alternatives, specific embodiments thereof are illustrated by way of example in the accompanying drawings and described in detail herein. However, it should be understood that the drawings and their detailed description are not intended to limit this document to the specific forms disclosed, but rather are intended to cover all modifications, equivalents, and alternatives falling within the substance and scope of the subject matter as defined by the appended claims. Detailed Implementation
[0043] acronym
[0044] Various acronyms are used throughout this patent application. The definitions of the most prominent acronyms that may appear throughout this patent application are as follows:
[0045] UE: User Equipment
[0046] AP: Access Point
[0047] DL: Downlink (from BS to UE)
[0048] UL: Uplink (from UE to BS)
[0049] TX: Transmit / Transmit
[0050] RX: Receive
[0051] LAN: Local Area Network
[0052] WLAN: Wireless LAN
[0053] RAT: Radio Access Technology
[0054] PE: Enhanced Privacy
[0055] BSS: Basic Services Set
[0056] the term
[0057] The following is a glossary of terms used in this disclosure:
[0058] Memory media—any device of any type of nontransitory memory device or storage device. The term "memory media" is intended to include mounting media such as CD-ROMs, floppy disks, or magnetic tape devices; computer system memory or random access memory such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; non-volatile memory such as flash memory, magnetic media, e.g., hard disk drives or optical storage devices; registers or other similar types of memory elements, etc. Memory media may also include other types of nontransitory memory or combinations thereof. Furthermore, memory media may reside in a first computer system executing a program, or may reside in a different second computer system connected to the first computer system via a network such as the Internet. In the latter case, the second computer system may provide program instructions to the first computer for execution. The term "memory media" may include two or more memory media that may reside in different locations on different computer systems, for example, connected via a network. Memory media may store program instructions (e.g., representing a computer program) that can be executed by one or more processors.
[0059] Carrier medium—the memory medium as described above, and physical transmission medium, such as buses, networks, and / or other physical transmission media for transmitting signals (such as electrical signals, electromagnetic signals, or digital signals).
[0060] Computer system—any of all types of computing or processing systems, including personal computer systems (PCs), mainframe computer systems, workstations, networked appliances, internet-connected appliances, personal digital assistants (PDAs), television systems, grid computing systems, or other devices or combinations of devices. In general, the term "computer system" can be broadly defined to encompass any device (or combination of devices) having at least one processor that executes instructions from a memory medium.
[0061] Mobile device (or mobile station) — any of a variety of computer system devices that are mobile or portable and perform wireless communication using WLAN communication. Examples of mobile devices include mobile phones or smartphones (e.g., iPhone). ™ Based on Android ™ (phones), and tablets such as iPads ™ Samsung Galaxy ™ Various other types of devices that include Wi-Fi, or both cellular and Wi-Fi capabilities, will fall into this category, such as laptops (e.g., MacBooks). ™ ), portable gaming devices (e.g., Nintendo DS) ™PlayStation Portable ™ Gameboy Advance ™ iPhone ™ Portable internet devices and other handheld devices, as well as wearable devices such as smartwatches, smart glasses, headphones, pendants, earbuds, etc. Generally, the term "mobile device" can be broadly defined as any electronic, computing, and / or communication device (or combination of devices) that is easily transportable by the user and capable of wireless communication.
[0062] Wireless device (or wireless site) — Any of a variety of computer system devices that perform wireless communication using WLAN communication. As used herein, the term “wireless device” can refer to a mobile device as defined above or a stationary device such as a stationary wireless client or wireless base station. For example, a wireless device can be any type of wireless site in an 802.11 system, such as an access point (AP) or client site (STA or UE). Other examples include televisions, media players (e.g., Apple TV). ™ Roku ™ Amazon FireTV ™ Google Chromecast ™ (etc.), refrigerators, washing machines, thermostats, etc.
[0063] User equipment (UE) (or “UE device”) — any of various types of computer systems or devices that are mobile or portable and perform wireless communication. Examples of UE devices include mobile phones or smartphones (e.g., iPhone). ™ Based on Android ™ (phones), tablet computers (e.g., iPads) ™ Samsung Galaxy ™ ), portable gaming devices (e.g., Nintendo DS) ™ PlayStation Portable ™ Gameboy Advance ™ iPhone ™ Wearable devices (e.g., smartwatches, smart glasses), laptops, PDAs, portable internet devices, music players, data storage devices, other handheld devices, automobiles and / or motor vehicles, unmanned aerial vehicles (UAVs) (e.g., drones), UAV controllers (UACs), etc. Generally speaking, the term "UE" or "UE device" can be broadly defined to encompass any electronic device, computing device, and / or telecommunications device (or a combination of these devices) that is easily transportable by the user and capable of wireless communication.
[0064] WLAN—The term “WLAN” has the full range of its common meaning and includes at least wireless communication networks, or RATs, which are provided by WLAN access points and through which connectivity to the Internet is provided. Most modern WLANs are based on the IEEE 802.11 standard and are marketed under the name “Wi-Fi.” WLAN networks are different from cellular networks.
[0065] Processing element—refers to various specific implementations of digital circuitry that perform functions in a computer system. Furthermore, processing element can refer to various implementations of analog or mixed-signal (combination of analog and digital) circuitry that perform functions (or multiple functions) in a computer or computer system. Processing elements include, for example, circuits (such as integrated circuits (ICs), ASICs (Application-Specific Integrated Circuits), portions or circuits of individual processor cores), entire processor cores, individual processors, programmable hardware devices (such as field-programmable gate arrays (FPGAs)), and / or larger portions of systems comprising multiple processors.
[0066] Wi-Fi—The term “Wi-Fi” encompasses the full range of its common meaning and includes at least wireless communication networks or RATs that are served by and provide connectivity to the Internet through wireless LAN (WLAN) access points. Most modern Wi-Fi networks (or WLAN networks) are based on the IEEE 802.11 standard and are marketed under the name “Wi-Fi.” Wi-Fi (WLAN) networks are distinct from cellular networks.
[0067] BLUETOOTH ™ –Term “BLUETOOTH” ™ "It has the full range in its ordinary sense, and includes at least any of the various specific implementations of the Bluetooth standard, including Bluetooth Low Energy (BTLE) and Bluetooth Low Energy for Audio (BTLEA), including future specific implementations of the Bluetooth standard, etc."
[0068] Personal Area Network (PAN) – The term “Personal Area Network” has the full range of its general meaning and includes at least any of the various types of computer networks used for data transfer between devices such as computers, telephones, tablets, and input / output devices. Bluetooth is an example of a PAN. PAN is an example of a short-range wireless communication technology.
[0069] Automatic—means an action or operation performed by a computer system (e.g., software executed by the computer system) or device (e.g., circuits, programmable hardware elements, ASICs, etc.) without requiring direct user input to specify or perform that action or operation. Therefore, the term "automatically" is the opposite of an operation performed or specified manually by a user, where the user provides input to directly perform the operation. An automatic process can be initiated by user-provided input, but the subsequent "automatically" performed actions are not specified by the user, for example, not performed "manually," where the user specifies each action to be performed. For example, a user filling out a form by selecting each field and providing input specifying information (e.g., by typing information, selecting a checkbox, radio selection, etc.) is considered manually filling out the form, even though the computer system must update the form in response to the user's actions. The form can be automatically filled out by a computer system (e.g., software executed on the computer system) which analyzes the fields of the form and fills it out without any user input specifying answers for the fields. As indicated above, a user can invoke the automatic filling of a form but does not participate in the actual filling of the form (e.g., the user does not manually specify answers for the fields, but they are completed automatically). This manual provides various examples of operations that are automatically performed in response to actions taken by the user.
[0070] Concurrency refers to the parallel execution or implementation of tasks, processes, signaling, messages, or programs in a manner that overlaps at least partially. For example, concurrency can be achieved using “strong” or strict parallelism, where tasks are executed in parallel (at least partially) on corresponding computing elements; or using “weak parallelism,” where tasks are executed in an interleaved manner (e.g., by time multiplexing of execution threads).
[0071] "Configured as"—Various components can be described as being "configured to" perform one or more tasks. In such contexts, "configured as" is a broad expression generally meaning "having" a "structure" that performs one or more tasks during operation. Thus, a component can be configured to perform a task even when it is not currently performing one (e.g., a set of electrical conductors can be configured to electrically connect one module to another, even when the two modules are not connected). In some contexts, "configured as" can also be a broad expression generally meaning a structure that "has" a "circuit" that performs one or more tasks during operation. Thus, a component can be configured to perform a task even when it is not currently switched on. Typically, the circuit forming the structure corresponding to "configured as" can include hardware circuitry.
[0072] For ease of description, various components may be described as performing one or more tasks. Such descriptions should be interpreted as including the phrase “configured to”. Statements describing a component as configured to perform one or more tasks are explicitly intended not to invoke the interpretation of 35 USC § 112(f) for that component.
[0073] The headings used herein are for organizational purposes only and are not intended to limit the scope of the specification. As used throughout this application, the word “may” is used in an permissive sense (e.g., meaning possible) rather than a mandatory sense (e.g., meaning must). The word “comprising” indicates an open relationship and therefore means including but not limited to. Similarly, the word “having” also indicates an open relationship and therefore indicates having but not limited to. The terms “first,” “second,” “third,” etc., as used herein are used as labels for nouns that follow them and, unless expressly indicated otherwise, do not imply any kind of ordering (e.g., spatial, temporal, logical, etc.). For example, unless otherwise specified, “a third component electrically connected to the module substrate” does not exclude the possibility that a “fourth component electrically connected to the module substrate” is connected before the third component. Similarly, unless otherwise specified, a “second” feature does not require a “first” feature to be implemented before the “second” feature.
[0074] Figure 1 - WLAN system
[0075] Figure 1 An exemplary WLAN system according to some embodiments is illustrated. As shown, the exemplary WLAN system includes multiple wireless client sites or devices, or user equipment (UE) 106, configured to communicate with an access point (AP) 112 via a wireless communication channel 142. AP 112 may be a Wi-Fi access point. AP 112 may communicate with one or more other electronic devices (not shown) and / or another network 152 (such as the Internet) via wired and / or wireless communication channels 150. Additional electronic devices, such as remote devices 154, may communicate with components of the WLAN system via network 152. For example, remote device 154 may be another wireless client site. The WLAN system may be configured to operate according to any of various communication standards, such as various IEEE 802.11 standards. In some embodiments, at least one wireless device 106 is configured to communicate directly with one or more adjacent mobile devices (e.g., via direct communication channel 140) without using access point 112.
[0076] In some implementations, as further described below, the wireless device 106 may be configured to perform methods associated with a privacy-enhanced BSS, including privacy enhancements for both access points and wireless sites, and privacy strengthening for authentication operations, association operations, and discovery operations.
[0077] Figure 2 —Access Point Diagram
[0078] Figure 2 An exemplary block diagram of access point (AP) 112 is shown. Note that... Figure 2 The block diagram of the AP is only one example of a possible system. As shown, AP 112 may include a processor 204 capable of executing program instructions for AP 112. Processor 204 may also be (directly or indirectly) coupled to a memory management unit (MMU) 240 or other circuitry or device, which may be configured to receive addresses from processor 204 and translate those addresses into locations in memory (e.g., memory 260 and read-only memory (ROM) 250).
[0079] AP 112 may include at least one network port 270. Network port 270 may be configured to couple to a wired network and provide internet access to multiple devices, such as mobile device 106. For example, network port 270 (or additional network ports) may be configured to couple to a local network, such as a home network or a business network. For example, port 270 may be an Ethernet port. The local network may provide connectivity to additional networks such as the internet.
[0080] AP 112 may include at least one antenna 234, which may be configured to operate as a wireless transceiver and further configured to communicate with mobile device 106 via wireless communication circuitry 230. Antenna 234 communicates with wireless communication circuitry 230 via communication link 232. Communication link 232 may include one or more receive links, one or more transmit links, or both. Wireless communication circuitry 230 may be configured to communicate via Wi-Fi or WLAN (e.g., 802.11). For example, in small cell scenarios where the AP coexists with a base station, or in other situations where it may be desirable for AP 112 to communicate via various different wireless communication technologies, wireless communication circuitry 230 may also or alternatively be configured to communicate via various other wireless communication technologies, including, but not limited to, LTE, LTE-A Advanced, GSM, WCDMA, CDMA2000, etc.
[0081] In some implementations, as further described below, AP 112 can be configured to perform methods for a privacy-enhanced BSS, including privacy enhancements for both access points and wireless sites, as well as privacy strengthening for authentication, association, and discovery operations.
[0082] Figure 3A —Client Site Diagram
[0083] Figure 3A An exemplary simplified block diagram of client site 106 is shown. Note that... Figure 3A The block diagram of the client site is merely one example of a possible client site. Depending on the implementation, client site 106 may be a user equipment (UE) device, a mobile device or mobile station, and / or a wireless device or wireless site. As shown, client site 106 may include a system-on-a-chip (SOC) 300, which may include components for various purposes. The SOC 300 may be coupled to various other circuitry of client site 106. For example, client site 106 may include various types of memory (e.g., including NAND flash memory 310), connector interface (I / F) (or docking station) 320 (e.g., for coupling to a computer system, taskbar, charging station, etc.), display 360, cellular communication circuitry 330 (such as for LTE, GSM, etc.), and medium-to-short-range wireless communication circuitry 329 (e.g., Bluetooth). ™ (And WLAN circuitry). Client site 106 may also include one or more smart cards 310 incorporating SIM (Subscriber Identity Module) functionality, such as one or more UICC (One or more Universal Integrated Circuit Cards) cards 345. Cellular communication circuitry 330 may be coupled to one or more antennas, such as antennas 335 and 336 as shown. Short-to-medium-range wireless communication circuitry 329 may also be coupled to one or more antennas, such as antennas 337 and 338 as shown. Alternatively, in addition to or instead of being coupled to antennas 337 and 338, short-to-medium-range wireless communication circuitry 329 may be coupled to antennas 335 and 336. This short-to-medium-range wireless communication circuitry 329 may include multiple receive chains and / or multiple transmit chains for receiving and / or transmitting multiple spatial streams in a configuration such as Multiple-Input Multiple-Output (MIMO).
[0084] As shown in the figure, the SOC 300 may include one or more processors 302 and display circuitry 304. The processors execute program instructions for client site 106, and the display circuitry performs graphics processing and provides display signals to display 360. The processors 302 may also be coupled to a memory management unit (MMU) 340 and / or other circuitry or devices (such as display circuitry 304, cellular communication circuitry 330, short-range wireless communication circuitry 329, connector interface (I / F) 320, and / or display 360). The MMU may be configured to receive addresses from the processors 302 and translate those addresses into locations in memory (e.g., memory 306, read-only memory (ROM) 350, NAND flash memory 310). The MMU 340 may be configured to perform memory protection and page table translation or setup. In some embodiments, the MMU 340 may be included as part of the processor 302.
[0085] As described above, client station 106 can be configured to directly communicate wirelessly with one or more adjacent client stations. Client station 106 can be configured to use WLAN RAT communication for communication in a WLAN network, such as... Figure 1 As shown in the diagram. Additionally, in some embodiments, as further described below, the client site 106 may be configured to perform methods associated with a privacy-enhanced BSS, including privacy enhancements for both the access point and the wireless site, and privacy strengthening for authentication, association, and discovery operations.
[0086] As described herein, client site 106 may include hardware and software components for implementing the features described herein. For example, processor 302 of client site 106 may be configured to implement some or all of the features described herein, for example by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable storage medium). Alternatively (or otherwise), processor 302 may be configured as a programmable hardware element, such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). Alternatively (or otherwise), in conjunction with one or more of other components 300, 304, 306, 310, 320, 330, 335, 340, 345, 350, 360, processor 302 of UE 106 may be configured to implement some or all of the features described herein.
[0087] Furthermore, as described in this invention, processor 302 may include one or more processing elements. Therefore, processor 302 may include one or more integrated circuits (ICs) configured to perform the functions of processor 302. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of one or more processors 204.
[0088] Furthermore, as described herein, both the cellular communication circuit 330 and the short-range wireless communication circuit 329 may include one or more processing elements. In other words, one or more processing elements may be included in either the cellular communication circuit 330 or the short-range wireless communication circuit 329. Thus, each of the cellular communication circuit 330 and the short-range wireless communication circuit 329 may include one or more integrated circuits (ICs) configured to perform the functions of the cellular communication circuit 330 and the short-range wireless communication circuit 329, respectively. Furthermore, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the cellular communication circuit 330 and the short-range wireless communication circuit 329.
[0089] Figure 3B IoT site
[0090] Figure 3B An exemplary simplified block diagram of an IoT site 107 according to some embodiments is shown. According to the embodiments, the IoT site 107 may include a system-on-a-chip (SOC) 400, which may include one or more portions for performing one or more purposes (or functions or operations). The SOC 400 may be coupled to one or more other circuits of the IoT site 107. For example, the IoT site 107 may include various types of memory (e.g., including NAND flash memory 410), connector interface (I / F) 420 (e.g., for coupling to a computer system, docking station, charging station, lights (e.g., for visual output), speakers (e.g., for auditory output), etc.), power supply 425 (which may be non-removable, removable and replaceable, and / or rechargeable), and communication circuitry (radio components) 451 (e.g., BT / BLE and / or WLAN).
[0091] IoT site 107 may include at least one antenna, and in some embodiments, may include multiple antennas 457 and 458 for wireless communication with accompanying devices (e.g., client site 106, AP 112, etc.) and other wireless devices (e.g., client site 106, AP 112, other IoT sites 107, etc.). In some embodiments, one or more antennas may be dedicated to use with a single radio component and / or radio protocol. In some other embodiments, one or more antennas may be shared between two or more radio components and / or radio protocols. Wireless communication circuitry 451 may include WLAN logic and / or BT / BLE logic. In some embodiments, wireless communication circuitry 451 may include multiple receive chains and / or multiple transmit chains for receiving and / or transmitting multiple spatial streams, such as in a multiple-input multiple-output (MIMO) configuration.
[0092] As shown in the figure, the SOC 400 may include a processor 402 capable of executing program instructions for the IoT site 107. The processor 402 may also be (directly or indirectly) coupled to a memory management unit (MMU) 440 and / or other circuitry or devices, which may be configured to receive addresses from the processor 402 and translate these addresses into locations in memory (e.g., memory 416, read-only memory (ROM) 450, NAND flash memory 410), such as wireless communication circuitry 451. The MMU 440 may be configured to perform memory protection and page table translation or setup. In some embodiments, the MMU 440 may be included as part of the processor 402.
[0093] As described above, IoT site 107 can be configured to wirelessly communicate with one or more neighboring wireless devices. In some embodiments, as further described below, IoT site 107 can be configured to perform (and / or assist in performing) methods associated with a privacy-enhanced BSS, including privacy enhancements for both the access point and the wireless site, and privacy strengthenings for authentication, association, and discovery operations.
[0094] Privacy-enhanced BSS
[0095] In current implementations, existing infrastructure networks present numerous privacy challenges and compromises. For example, legacy sites require access points to be publicly discoverable and retain the legacy site's MAC address and other identifying information. Furthermore, legacy sites are not privacy-optimized and may leak personally identifiable information (PIIs) (e.g., usernames, passwords, emails, sent messages, data entered online, online profiles, internet history, physical location while online, online purchase history, search history, social media posts, devices used, online tasks completed, viewed online videos, online music, playlists, etc.) or payment card information (e.g., cardholder data). Additionally, legacy sites may leak personally identifiable information (PCIs) that identifies the actions of the legacy site and / or end-user (e.g., running applications, visiting websites, making purchases) and / or where the legacy site operates (e.g., location). Additionally, traditional BSS features include unencrypted beacons (so all wireless stations can receive the beacon along with a complete set of access point parameters), passive and active scanning of privacy-enhanced BSSs (so all nearby wireless stations can discover the access point and identify it via its Service Set Identifier (SSID) and its Basic Service Set Identifier (BSSID), association and reassociation with PE BSSs (so all devices can receive access point and wireless station information and allow wireless station tracking), constant access point and wireless station MAC addresses (so access point and station tracking is possible via MAC address tracking), and unencrypted frames (so access point and station tracking is allowed). Furthermore, while privacy enhancements are needed, the market will continue to require traditional access points to support traditional wireless stations due to the large number of traditional WLAN devices in the market.
[0096] Therefore, WLAN offers two alternatives to improve wireless site privacy—enhancing legacy access points to include privacy-enhanced wireless sites or introducing new privacy-enhanced BSSs. Enhancing legacy access points improves wireless site privacy; however, legacy access point privacy will not be improved. Furthermore, legacy access points may not be suitable for newer use cases requiring access point privacy, such as mobile access points and / or vehicular access points.
[0097] The embodiments described herein provide systems, methods, and mechanisms for privacy-enhanced BSSs, including privacy enhancements for both access points and wireless sites, and privacy strengthening for authentication, association, and discovery operations. Additionally, the embodiments described herein provide systems, methods, and mechanisms for continuing to support legacy wireless sites. In other words, the embodiments described herein are (and are considered) backward compatible.
[0098] For example, Figure 4 An example architecture for a privacy-enhanced BSS according to some implementation schemes is shown. As shown, an access point such as access point 112 can support both a traditional BSS 422 and a privacy-enhanced (PE) BSS 424. The access point can be presented as two access points—a first access point broadcasting an SSID and supporting traditional radio stations (STAs) such as traditional STA 406, and a second access point not including its SSID in the beacon and supporting PE radio stations such as PE STA 106. It should be noted that the two access points (or BSSs) co-located within access point 112 can operate on the same channel.
[0099] like Figure 4 The architecture described herein, along with the systems, methods, and mechanisms discussed herein, provides and / or supports privacy improvements such as encrypted beacons, passive and active scanning of the PE BSS, association and reassociation with the PE BSS, random and variable MAC addresses for both the PE access point and the PE radio station, encrypted frame exchange, and privacy-enhancing formats for Physical Layer Protocol Data Units (PPDUs), MAC Layer Protocol Data Units (MPDUs), and Management MPDUs (MMPDUs), as well as for various other frame formats. Encrypted beacons allow PE access point elements and buffered traffic indicators (TIMs) to be available only to associated PE radio stations. Passive and active scanning of the PE BSS allows for improved privacy of the PE BSS because only previously associated PE radio stations can discover it. Furthermore, association and reassociation with the PE BSS provide mechanisms that allow encryption of both PE access point information and PE radio station information. Additionally, random and variable MAC addresses for both the PE access point and the PE radio station may hinder tracking of both. Furthermore, the encrypted frame exchange and privacy-enhancing formats for PPDU, MPDU, and MMPDU can provide improved privacy by eliminating element fingerprinting.
[0100] Figure 5 Examples of signaling associated with a PE BSS for a PE wireless site and a public network, according to some implementation schemes, are shown. Among other things, Figure 5The signaling shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the signaling shown may be executed concurrently in a different order than that shown, or may be omitted. Additional signaling may also be executed as needed. As shown in the figure, the signaling can follow the following flow.
[0101] A PE wireless site, such as PE STA 106, can receive a legacy beacon 502 from a legacy BSS 422. This legacy beacon indicates that an access point, such as access point 112 hosting legacy BSS 422, is PE-enabled; for example, it indicates that access point 112 also hosts PE BSS 424. In response, at 504, PE STA 106 can discover, authenticate, and associate with the legacy BSS. In some cases, legacy BSS 422 can move PE STA 106 to a PE BSS hosted by the access point. In some cases, PE STA 106 can optionally send a robust BSS transition query 506 to legacy BSS 422 requesting a recommendation from the PE access point. PE STA 106 can receive a robust BSS transition request 508 from legacy BSS 422, which may include a list of access point candidates, including neighbor reports and beacon reception parameters. PE STA 106 may send a robust BSS transition response 510 to conventional BSS 422, instructing PE STA 106 to transition to a PEBSS such as PE BSS 112. At 512, PE STA 106 may scan for a selected PE BSS and then transition to the selected PE BSS, for example, by using a pre-association security protocol such as Pre-Association Security Negotiation (PASN) to encrypt a four-way handshake (e.g., over-the-air fast BSS transition signaling), a public key for protecting the identifier such as an Identifier Protection Key (IPK), and / or by performing an artificial (or dummy) association for establishing security (e.g., encryption) before performing the actual, protected (e.g., encrypted) association. Thus, PE STA 106 may receive an encrypted beacon 514 from the PE BSS and may respond using a PASN encrypted authentication request 516. PE STA 106 may then receive a PASN encrypted authentication response 518 and may respond using a PASN encrypted association request 520. PE STA 106 can receive a PASN encrypted association response 522 from PE BSS. At 524, PE STA 106 can be associated with the encrypted PE BSS.
[0102] It should be noted that Figure 5 The signaling shown can also be employed and / or implemented, for example, via an access point with multiple networks on a residential network, such as... Figure 6As shown in the figure, a residential access point such as access point 112 can host multiple networks / BSS (e.g., traditional visitor BSS 622 and PE visitor BSS 624, traditional resident BSS 632 and PE resident BSS 634, traditional Internet of Things (IoT) BSS 642 and PE IoT BSS 644, where PE IoT BSS 644 can be a hidden network, PE backbone mesh BSS 654, and PE employee BSS 664), each BSS having a different security domain and / or key. Furthermore, each network can have both a traditional BSS and a PE BSS. However, it should be noted that if the network only serves PE wireless sites, such as PE wireless site 106, then the network can have only a PE BSS. Additionally, the traditional BSS provides simple network discovery to associate with traditional wireless sites, while also allowing initial authentication and association of PE wireless sites. Furthermore, as referenced above... Figure 5 As described, a traditional BSS (traditional visitor BSS 622 or traditional resident BSS 632) can guide a PE wireless site to operate with a PE BSS (e.g., PE visitor BSS 624 or PE resident BSS 634). Furthermore, for example, if the PE wireless site knows the key of the PE BSS, the PE wireless site can directly associate with the PE BSS (e.g., PE visitor BSS 624 or PE resident BSS 634).
[0103] As described above, some networks within a residential network may attempt to remain invisible and / or undiscoverable. For example, a mesh backbone network (e.g., PE backbone mesh BSS 654) may only be used between access points (e.g., within a residential mesh network), thus the backbone mesh access points may be configured to find certain beacon types. As another example, employee service (and / or government service and / or public safety service) networks (e.g., PE employee BSS 664) may be private networks that are discoverable only to / discovered by employee devices with applications and / or configurations for operating within the employee service network. As yet another example, IoT networks (e.g., traditional IoT BSS 642 and / or PE IoT BSS 644) may remain hidden. It should be noted that IoT devices may be configured to operate within a single network. Therefore, if IoT devices and / or configuration devices (e.g., wireless sites) do not support PE BSS, traditional IoT BSS 642 may be configured instead. Alternatively, if the IoT device supports a PE BSS, the PE IoT BSS 644 can be configured. However, the IoT network may not boot from the legacy IoT BSS 642 to the PE IoT BSS 644.
[0104] Figure 7A and Figure 7BExamples of signaling for configuring IoT devices to the PE BSS are shown according to some implementation schemes. Among other devices, Figure 7A and Figure 7B The signaling shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the signaling shown may be executed concurrently in a different order than that shown, or may be omitted. Additional signaling may also be executed as needed. As shown in the figure, the signaling can follow the following flow.
[0105] Go to Figure 7A At 702, IoT site 707, which can be IoT site 107, can be powered on and configured to operate in PE BSS mode. Furthermore, wireless site 106 can be configured to launch an application that knows the MAC address key of a PE IoT BSS, such as PE IoT BSS 644, and can discover PE IoT BSS 644. Wireless site 106 can receive encrypted beacons 704 from IoT site 707 using the randomized MAC address of IoT site 707. Then, at 706, wireless site 106 can discover the PE IoT BSS 644 of IoT site 707, and end users of wireless site 106 can choose to authenticate and associate with the PE IoT BSS 644 of IoT site 707. Additionally, wireless site 106 can use, for example, a pre-association security protocol to authenticate and associate with IoT site 707. For example, wireless station 106 can perform a four-way PASN encrypted handshake with IoT station 707 via messages 708, 710, 712, and 714 to authenticate and associate with IoT station 707. Alternatively, wireless station 106 can use a public key, such as an Identifier Protection Key (IPK), to protect an identifier to securely authenticate and associate with IoT station 707, and / or wireless station 106 can perform a secure (e.g., encrypted) artificial (or dummy) association with IoT station 707 before performing the actual, protected (e.g., encrypted) association. At 716, wireless station 106 has authenticated and associated with IoT station 707 and provides specific information to IoT station 707 when necessary for authentication of IoT services. Additionally, wireless station 106 can provide PE IoT BSS information to IoT station 707 via encrypted data frame 718.
[0106] Go to Figure 7BAt this point, IoT site 707 learns the channel of PE IoT BSS 644, and at 720, IoT site 707 can switch to the channel of PE IoT BSS 644. IoT site 707 can receive encrypted beacon 722 from PE IoT BSS 644 and can use, for example, a pre-association security protocol to authenticate and associate with PE IoT BSS 644. For example, IoT site 707 can perform a four-way PASN encrypted handshake with PE IoT BSS 644 via messages 724, 726, 728, and 730 to authenticate and associate with PE IoT BSS 644. Alternatively, IoT site 707 can use a public key to protect an identifier, such as an identifier protection key (IPK), to securely authenticate and associate with PE IoT BSS 644, and / or configure wireless site 707 to perform a secure (e.g., encrypted) artificial (or dummy) association with PE IoT BSS 644 before performing the protected (e.g., encrypted) actual association. At point 732, IoT site 707 is associated with PE IoT BSS 644 and can authenticate the IoT server via the Internet. Furthermore, IoT site 707 can begin programmed operation. Therefore, IoT site 707 can transmit encrypted application data 734 to PE IoT BSS 644.
[0107] In some cases, WLAN devices (e.g., wireless sites such as wireless site 106 and / or mobile access points such as access point 112) may be converted to (e.g., operate as) mobile access points, at least in some cases. Mobile access points may have short operating times and may cease operation, for example, if a mobile access point has no uplink or downlink data for a prolonged period and / or to (actively) conserve power. Furthermore, mobile access points may switch to discoverable mode if they sense other nearby wireless sites, have been switched to discoverable mode by an associated PE wireless site via a management frame request, sense numerous scan frames, and / or are activated by an end user. It should be noted that when activated, mobile access points can operate as PE BSS using the principles, methods, and mechanisms described herein.
[0108] Figure 8An exemplary format of an encrypted beacon frame according to some implementation schemes is shown. It should be noted that a PE access point (e.g., such as access point 112) may transmit an encrypted beacon for a PE BSS. The encrypted beacon may be encrypted by a BSS-specific beacon key. Furthermore, the encrypted beacon may contain minimal (and / or minimum) information to maintain association; for example, the goal is to minimize the size of the encrypted beacon. An associated PE radio station (e.g., such as radio station 106) may store a long-term beacon key to receive the encrypted beacon from the PE access point (e.g., the PE BSS). It should be noted that the beacon key enables beacon reception, for example, passive PE BSS discovery, which may be required to discover the associated PE BSS. As shown, the encrypted beacon frame may include a MAC header field, a Timed Synchronization Function (TSF) field, a Multi-Link Device (MLD) / Authentication Address field, a Reduced Neighbor Report (RNR) field, a Traffic Indication Graph (TIM) field, a Change Sequence field, a Management Message Integrity Check (MIC) element (MME), and various other optional elements. The MAC header may include the transmitter address of the transmitter used to detect the frame and / or the MAC address of the access point. Note that the MAC address may be randomized. The TSF field supports synchronization maintenance with the access point. The MLD / Authentication Address field may include the authentication address of the access point. The RNR field supports the detection of other suitable access points near the access point and / or maintaining MLD links with other affiliated access points. The TIM field indicates whether the access point has buffered unicast and / or multicast frames for the radio site. The Change Sequence field signals to the PE BSS whether there are critical parameter updates. The MME field may include an integrity checksum of the beacon frame content. Various optional elements may include elements that can be included in the beacon to prevent probe responses.
[0109] In some cases, to detect a PE BSS based on an encrypted beacon, a PE wireless station, such as wireless station 106, can verify whether the PE wireless station is aware of the PE BSS based on the over-the-air (OTA) BSSID of a PE access point, such as access point 112. For example, a non-access point PE wireless station (e.g., wireless station 106) can store an Access Point Address Resolution Key (ARK) key, an AP authentication address, SSID, PMKID, authentication key, authentication mode, and / or an access point pre-shared key. Therefore, the PE wireless station can have stored the ARK and can use it to determine whether the PE access point is a known PE access point. For example, if the checksum is equal to (and / or equal to) the ARK of random bits, the PE wireless station can confirm that the PE access point is a known PE access point. Additionally, if a PE access point is detected, the PE wireless station can continue to authenticate and associate the PE access point, for example, by using the stored parameters. In some cases, the ARK key can be the width of an Extended Service Set (ESS). Therefore, if the OTA BSSID of a PE access point matches, the PE wireless station can easily calculate whether other APs belong to an ESS.
[0110] In some cases, PE access points such as access point 112 can transmit discovery beacons, for example, such as Figure 9 As shown, this is to advertise the PE BSS, which does not have a beacon key, to PE wireless sites such as wireless site 106. Note that all PE wireless sites can receive discovery beacons. Figure 9 As shown, the discovery beacon may include, for example, references. Figure 8 The described encrypted discovery beacon is compared to a minimal set of elements to allow the discovery of the advertised PE BSS. For example, the discovery beacon may include a MAC header field, a country and / or transmit power envelope field, an RNR field, and / or an MME field. The MAC address included in the MAC header field may be randomized. The MAC header field may include the transmitter address and / or access point MAC address used to detect the frame. The country and / or transmit power envelope field may include elements required by the PE radio station to calculate and adjust its maximum transmit power. The RNR field may support the detection of the transmitting PE access point and other suitable access points in its vicinity. Therefore, the RNR field may also contain information about one or more traditional BSSs and PE BSSs in the same band / channel and / or other bands / channels as the transmitting PE access point. Note that the RNR field may be the main content of the discovery beacon. The MME field may include an integrity checksum of the beacon frame content. Furthermore, a complete set of BSS parameters can be obtained through active scanning. In some cases, the discovery beacon may contain PE BSS information in an unencrypted format. Additionally, the elements included in the discovery beacon allow PE BSS discovery from all non-associated radio stations receiving the discovery beacon.
[0111] In some cases, the RNR element of an encrypted beacon frame and / or discovery frame may include a Neighbor Access Point Information (NNIP) field. The NNIP field may include various fields, and specifically, may include a Target Beacon Transmission Time (TBTT) information field. Figure 10A As shown, the TBTT information field can then include various fields such as the neighbor access point (AP) TBTT offset field, BSSID field, short SSID field, BSS parameter field, 20MHz power spectral density (PSD) field, and MLD parameter field. The BSSID field provides the MAC address of the transmitting access point, for example, the MAC address of an over-the-air transmitter. Note that the MAC address provided in the BSSID field may not be the MAC address used for authentication. The short SSID field can be a 4-byte hash of the SSID. Note that the short SSID field can be used for BSS discovery in discovery beacons and / or for discoverable PE BSSs. Furthermore, as... Figure 10B As shown, the BSS parameter fields can then include various fields such as the OCT recommendation field, same SSID field, multiple BSSID field, transmit BSSID field, ESS member with 2.4 / 5GHz co-location AP field, unsolicited probe response activity field, co-location AP field, and / or reserved fields. In some cases, the PE BSS can set the same SSID field, multiple BSSID field, transmit BSSID field, and / or co-location AP field to a value of 0 to protect PE BSS privacy and not provide all information about the PE BSS. In other words, to protect PE BSS privacy and partially hide information associated with the PE BSS, the PE BSS can set these fields to zero when their values would otherwise be one. Additionally, as... Figure 10C As shown, the MLD parameter field can then include various fields such as the MLD identifier (ID) field, link ID field, altered sequence field, PE AP field, and reserved field. Note that the PE AP field, which can be one bit long, can be set to a value of one to indicate that the reported AP is privacy-enhanced, and otherwise set to zero.
[0112] In some cases, the number of encrypted beacons and / or discovery beacons emitted can be controlled and / or limited. For example, such as... Figure 11AAs shown, an access point (AP), such as access point 112 with a PE BSS, can transmit an encrypted beacon during a first time period, and then interleave the discovery beacon with the encrypted beacon during a second time period. It should be noted that this operation can be repeated periodically. It should also be noted that the PE access point may only be discoverable to non-access point wireless stations when transmitting a discovery beacon (e.g., during the second time period). Therefore, the PE access point may only be discoverable by previously associated non-access point wireless stations when only transmitting an encrypted beacon (e.g., during the first time period). Additionally, as... Figure 11B As shown, access points operating both the PE BSS and the traditional BSS can interleave encrypted beacons with traditional beacons that do not contain PE access point information during a first time period, and then interleave encrypted beacons with traditional beacons that do contain PE access point information during a second time period. It should be noted that when transmitting a traditional beacon with PE access point information (e.g., during the second time period), the PE access point may only be discoverable to non-access point radio stations. Therefore, the PE access point may only be discoverable by previously associated non-access point radio stations when transmitting a traditional beacon without PE access point information (e.g., during the first time period). It should be noted that... Figure 11A and Figure 11B The beacon transmission intervals shown are merely illustrative. It should be further noted that discovery beacons may be transmitted more or less frequently than traditional beacons. For example, discovery beacons may be transmitted as an unsolicited broadcast probe response, such as once every 20 TUs and / or at some other interval. Furthermore, it should be noted that encrypted beacon transmission intervals may be varied, for example, based on access point needs and / or requirements, to randomize the beacon transmission intervals.
[0113] In some cases, such as Figure 12A As shown, beacon frames can be transmitted individually within a single transmission opportunity. Therefore, as illustrated, once a transmission opportunity (TXOP) is obtained, encrypted beacons, traditional beacons, and discovery beacons can be transmitted in any order. As shown, the encrypted beacon is transmitted first at its TBTT, followed by the traditional beacon (transmitted after its TBTT) and then the discovery beacon (which may not have an associated TBTT). However, as noted, the transmission order can vary.
[0114] In some cases, for example, Figure 12BAs shown, PE BSS discovery information can be transmitted in the RNR of a conventional beacon, and each beacon (e.g., an encrypted beacon and a conventional beacon with PE BSS discovery information in the RNR) can be transmitted in a dedicated transmission opportunity. Therefore, as shown, once a first transmission opportunity (TXOP) has been obtained, the encrypted beacon can be transmitted at or after the associated TBTT. Then, once a second transmission opportunity (TXOP) has been obtained, the conventional beacon with PE BSS discovery information in the RNR can be transmitted at or after the associated TBTT.
[0115] In some cases, for example, Figure 12C As shown, once a launch opportunity (TXOP) is obtained, a conventional beacon with multiple BSSIDs of a conventional BSS, RNRs of conventional BSS and PE BSS discovery, and PE BSS elements of a PE BSS can be launched.
[0116] In some cases, for example, Figure 12D As shown, once a transmission opportunity (TXOP) is obtained, an encrypted beacon with multiple BSS information can be transmitted.
[0117] In some cases, legacy beacon frames can be enhanced to support multiple PE BSSs. For example, such as... Figure 13 As shown, a beacon frame may include traditional BBS information such as a traditional beacon transmitting BSS and multiple BSSID elements including a non-transmitting BSS, unencrypted discovery information of the PE BSS such as an RNR element, encrypted information of the PE BSS such as an encrypted PE BSS element including the PE BSS, and a beacon integrity checksum that may include an MME. Note that the RNR may include both traditional BSSs and discoverable PE BSSs. Furthermore, encrypted PE BSS elements can be added to the traditional beacon format. A PE BSS element may include one or more PE BSS beacon contents. Additionally, the extension capability can be set to 1 to signal the presence of encrypted PE BSS elements. Furthermore, a MIC management element (MME) can be computed across the entire beacon frame. For beacon integrity checksum computation, all BSSs may have the same key value to verify the MME element content.
[0118] In some cases, to reduce the size of traditional beacon frames, some non-transmitting BSSs within non-transmitting BSSs may be included only in the RNR element, for example, such as... Figure 14As shown. In some cases, this beacon may or may not have a multi-BSSID element. Furthermore, the RNR element may contain a non-transmitting BSS, where only the traditional BSS in the RNR field is set to 1. Note that setting only the traditional BSS in the RNR field to 1 means that the non-transmitting BSS is not included in the multi-BSSID element, and its information is only obtainable through the RNR. As shown, this beacon frame may include traditional BBS information such as the traditional beacon transmitting BSS and multi-BSSID elements including non-transmitting BSSs, unencrypted discovery information of the PE BSS such as the RNR element which may contain non-transmitting BSS information, encrypted information of the PE BSS such as encrypted PE BSS elements including the PE BSS, and a beacon integrity checksum that may include the MME. Additionally, a MIC management element (MME) can be computed across the entire beacon frame. For beacon integrity checksum computation, all BSSs may have the same key value to verify the MME element content.
[0119] In some cases, a PE access point can host multiple PE BSSs. In such cases, to reduce beacon sending overhead, the PE access point can send the same beacon to multiple PE BSSs, for example... Figure 15 As shown. It should be noted that each PE BSS in the encrypted PE BSS element can be encrypted using a PE BSS-specific key. Additionally, after the PE access point has encrypted the PE BSS information, it can then use a common key to encrypt the encrypted BSS element. The common key protects the number of PE BSS information or other common information elements. Furthermore, all PE BSSs in the encrypted PE BSS element can share the same common encryption key. Additionally, the ARK of the transmitter address in the MAC header can be known to all non-access point wireless stations (e.g., wireless station 106) that can associate the encrypted beacon with the PE BSS.
[0120] Figure 16A An example of an encrypted PE BSS element according to some implementation schemes is shown. As shown, an encrypted PE BSS element may include unencrypted fields such as an element ID field, a length field, and an element ID extension field. Additionally, an encrypted PE BSS element may include fields encrypted with a common key, such as the time to the next beacon field, the number of PE BSS fields, and one or more PE BSS profiles (SubE) for the BSS fields. The number of PE BSS fields may have an integer value representing the number of PE BSSs listed. The time to the next beacon field may indicate the next scheduled beacon launch time. It should be noted that, at least in some cases, the PS BSS element may be limited to a 256-byte payload and / or restricted to it. Figure 16BAs shown, each PE BSS profile SubE may include fields encrypted with a common key, such as the Sub-Element ID field, Length field, and BSSID OTA field, and fields encrypted with both the common key and a BSS-specific key, such as the MLD MAC Address / Authentication field, TSF field, Change Sequence field, RNR field, and TIM field. The BSSID OTA field may include and / or indicate the MAC address of the access point transmitting over the air. The MLD MAC Address / Authentication Address field may include and / or indicate the access point address used for authentication. Note that the over-the-air BSSID may not be used directly with the access point. The TSF field may be the TSF of the PS BSS and can be used for scheduled transmissions of the PE BSS. Note that beacon transmissions may have different TSFs and intervals. The Change Sequence field may include and / or indicate the last updated parameter in the BSS. The RNR field may include the RNR element for each BSS, and the PE radio station may not be aware of the RNRs of other PE BSSs. The TIM field may include the TIM for each BSS, and the PE radio station may not be aware of the buffered traffic of other PE BSSs.
[0121] In some cases, PE radio stations may require mechanisms for quickly discovering available PE access points in their vicinity. In some situations, such signaling may resemble a probe request frame with a wildcard SSID element broadcast addressing, as in... Figure 17A As shown in the figure, a legacy STA 1706 can transmit a broadcast probe request 1720 to a legacy AP 1712. The broadcast probe request 1720 may not include a PE AP request field, and / or the PE AP request field may be set to a value of 0. The legacy STA 1706 can then receive a broadcast probe response 1722 from the legacy AP. In some cases, the PE access point 112 can respond to broadcast or directed probe requests (without altered signaling or having signaling requesting a response from the PE BSS) and broadcast or directed PE query requests requesting a response from the PEBSS. Note that the query frame may have signaling further specifying the expected response type (e.g., encrypted beacon or discovery beacon). It should also be noted that the PE query request frame may only be received by the PE BSS. In some cases, broadcast PE query requests may be transmitted unencrypted. However, unicast PE query requests may be encrypted (robust) when addressed to an associated PE BSS but not when addressed to other PE BSSs.
[0122] For example, Figure 17B Examples of active scanning according to some implementation schemes are shown. Among other devices, Figure 17BThe signaling shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the signaling shown may be executed concurrently in a different order than that shown, or may be omitted. Additional signaling may also be executed as needed. As shown in the figure, the signaling can follow the following flow.
[0123] As shown in the figure, PE STA 106 can transmit a broadcast probe request 1730 to the traditional access point 8112. The broadcast probe request 1730 may include a PE AP request field with a value set to 1. PE STA 106 can receive a broadcast probe response 1732, which includes an indication of PE access point 112 and / or information associated with that PE access point. Therefore, using the indication and / or information included in the broadcast probe response 1732, PE STA 106 can receive a broadcast encrypted beacon and / or a broadcast discovery beacon 1734 from PE access point 112 and initiate an association process with PE access point 112.
[0124] For example, Figure 17C Another example of active scanning according to some implementation schemes is shown. Among other devices, Figure 17C The signaling shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the signaling shown may be executed concurrently in a different order than that shown, or may be omitted. Additional signaling may also be executed as needed. As shown in the figure, the signaling can follow the following flow.
[0125] As shown in the figure, PE STA 106 can broadcast a PE query request 1740 to PE access point 112. The broadcast PE query request 1740 can be broadcast unencrypted. The broadcast PE query request 1740 can request a response from the PE BSS. Furthermore, the broadcast PE query request 1740 can be a query frame and may include signaling further specifying the expected response type (e.g., an encrypted beacon or discovery beacon). Additionally, the broadcast PE query request 1740 can be received only by the PE BSS. It should be noted that while the broadcast PE query request 1740 can be broadcast unencrypted, a unicast PE query request can be encrypted when addressed to an associated or previously associated PE BSS and unencrypted when addressed to another PE. PE STA 106 can receive the broadcast encrypted beacon and / or broadcast discovery beacon 1742 from PE access point 112 and initiate the association process with PE access point 112.
[0126] In some cases, PE query request frames, such as PE query request 1740, may include a hash checksum. The hash checksum can identify a site such as PE STA 106 and / or the requested access point. For example, a PE query request may include a random ID and a checksum ID for the requested BSS. It should be noted that a PE query transmitter, such as PE STA 106, may include zero or more sets of random IDs and checksum IDs. It should also be noted that the PE query frame format may have a random ID field and multiple checksum IDs. All checksum IDs can be calculated based on the included random ID field.
[0127] In some cases, a PE access point, such as PE access point 112, may respond to a PE query request when it is expected to be discoverable. In some cases, a PE access point may respond using a PE beacon when the random ID and checksum ID included in the PE query request frame match the PE access point. It should be noted that when a PE access point is identified by the random ID and checksum ID included in the PE query request frame, the PE access point may respond by using different random ID and checksum ID values from the PE beacon.
[0128] In some cases, a traditional BSS may include an RNR that includes both the traditional BSS and a discoverable PE BSS in its probe response. Upon reception, the PE radio station may broadcast a PE query request to the PE access point. The PE access point, such as the PE BSS, may respond using a discovery beacon or an encrypted beacon. For a discovery beacon, the RNR may include PE BSS and traditional BSS information and may be transmitted as a response to the probe request to reduce the overhead of the probe response. For an encrypted beacon, it may include and / or include the same content while the BSS continues to transmit encrypted beacons normally, as if it were transmitted after the TBTT. The encrypted beacon may be considered a requested encrypted beacon. Note that in some cases, such as if the PE BSS determines that it needs to be more discoverable, the PE BSS may transmit an unsolicited beacon.
[0129] Figure 18A , Figure 18B and Figure 18C Examples of signaling for broadcasting PE BSS probes and / or queries, according to some implementation schemes, are shown. Among other things, Figure 18A , Figure 18B and Figure 18C The signaling shown can also be used with any of the systems, methods, or devices shown in the figures. In various embodiments, some of the signaling shown may be executed concurrently in a different order than that shown, or may be omitted. Additional signaling may also be executed as needed.
[0130] Go to Figure 18A As shown in the figure, the signaling can proceed as follows. Initially, PE STA 106 may receive an unsolicited broadcast probe response 1820 from legacy access point 1812. The unsolicited broadcast probe response 1820 may include RNR elements / fields indicating both the legacy BSS and the PE BSS. Next, based on the unsolicited broadcast probe response 1820, PE STA 106 may send a broadcast PE query request 1822 to PE access point 112, which may have been indicated in the RNR elements / fields. PE STA 106 may receive a broadcast discovery beacon 1824 from PE access point 112. The broadcast discovery beacon 1824 may include RNRs with both the PE BSS and the legacy BSS. Upon receipt, PE STA 106 may begin the authentication and association process with PE access point 112.
[0131] Go to Figure 18B As shown in the figure, the signaling can proceed as follows. Initially, PE STA 106 may receive an unsolicited broadcast probe response 1830 from legacy access point 1812. The unsolicited broadcast probe response 1830 may include RNR elements / fields indicating both the legacy BSS and the PE BSS. Next, based on the unsolicited broadcast probe response 1830, PE STA 106 may transmit a broadcast PE query request 1832 to PE access point 112, which may have been indicated in the RNR elements / fields. PE STA 106 may receive a broadcast encrypted beacon 1834 from PE access point 112. Upon receipt, PE STA 106 may begin the authentication and association process with PE access point 112.
[0132] Go to Figure 18C As shown in the figure, the signaling can proceed as follows: Initially, PE STA 106 may receive an unsolicited broadcast probe response 1840 from legacy access point 1812. The unsolicited broadcast probe response 1840 may include RNR elements / fields indicating both the legacy BSS and the PE BSS. Next, based on the unsolicited broadcast probe response 1840, PE STA 106 may transmit a unicast PE query request 1842 to PE access point 112, which may have been indicated in the RNR elements / fields. The unicast PE query request 1842 may be encrypted. PE STA 106 may receive a broadcast encrypted beacon 1844 from PE access point 112. Upon receipt, PE STA 106 may begin the authentication and association process with PE access point 112.
[0133] Figure 19 Examples of signaling associated with a PE wireless site and a PE access point, according to some implementation schemes, are shown. Among other things, Figure 19The signaling shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the signaling shown may be executed concurrently in a different order than that shown, or may be omitted. Additional signaling may also be executed as needed. As shown in the figure, the signaling can follow the following flow.
[0134] PE STA 106 may receive broadcast discovery beacon 1902 from PE access point 112. Then, in order to request more information from the PE BSS hosted by PE access point 112, PE STA 106 may secure a connection with PE access point 112 before association. For example, PE STA 106 may use a pre-association security protocol to secure a connection before association with PE access point 112. For example, PE STA 106 may use a public key to protect an identifier, such as an identifier protection key (IPK), to secure a connection before association with PE access point 112. Alternatively, PE STA 106 may perform an artificial (or dummy) association to establish security (e.g., encryption) to secure a connection before association with PE access point 112, and then perform a protected (e.g., encrypted) actual association. In another example, as shown, PE STA 106 may establish PASN protection via signaling 1904, 1906, and 1908. Once PASN protection is established, PE STA 106 can transmit a PASN protection probe request or PE query request frame 1910. Then, PE STA 106 can receive a PASN protection probe response from PE access point 112 that provides a complete set of PE access point parameters (e.g., PE BSS information). PE STA 106 can then directly associate with and receive the PE BSS parameters via association signaling with PE access point 112. Note that PASN protection can be BSS-specific; therefore, PE STA 106 may need to establish PASN protection individually with each scanned BSS.
[0135] Figure 20A A block diagram illustrating an example of a method for associating a wireless site with a Privacy Enhancement (PE) Basic Service Set (BSS) of a wireless network, according to some implementation schemes. Among other devices, Figure 20A The method shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the method elements shown may be executed concurrently in a different order than that shown, or may be omitted. Additional method elements may also be executed as needed. As shown in the figure, the method can operate as follows.
[0136] At 2002, a wireless station, such as wireless station 106, can communicate with the legacy BSS of the wireless network to switch to the PE BSS of the wireless network. In some cases, in order to communicate with the legacy BSS of the wireless network to switch to the PE BSS of the wireless network, the wireless station can receive a beacon from the legacy BSS of the wireless network indicating that the wireless network supports one or more PE BSSs, and can send a robust BSS switch query to the legacy BSS. The robust BSS switch query can request a PE BSS recommendation. Furthermore, the wireless station can receive a robust BSS switch request from the legacy BSS and can send a robust BSS switch response to the legacy BSS indicating a switch to a PE BSS. The BSS switch request may include a list of PE BSS candidates. PE BSSs may be included in the PE BSS candidate list.
[0137] At 2004, wireless sites can receive encrypted beacons from the PE BSS of the wireless network. The encrypted beacon can be decoded based on information received from the traditional BSS. Information received from the traditional BSS may include a PE BSS candidate list. The PE BSS candidate list may include neighbor reports and beacon reception parameters. In some cases, the encrypted beacon may be encrypted with a PE BSS-specific beacon key. In some cases, the encrypted beacon may include one or more of the following: Media Access Control (MAC) header fields, Timed Synchronization Function (TSF) fields, Multi-Link Device (MLD) / Authentication Address fields, Reduced Neighbor Report (RNR) fields, Traffic Indication Graph (TIM) fields, Change Sequence fields, Management Message Integrity Check (MIC) elements (MME) and / or optional fields. The MAC header may include the transmitter's MAC address. The MAC address may be randomized. The MLD / Authentication Address field may include the transmitter's authentication address. The RNR field may include a list of suitable access points located nearby and / or maintaining MLD links with other affiliated access points. The Change Sequence field signals to the PE BSS whether there are critical parameter updates. The MME field may include an integrity checksum of the encrypted beacon frame's content. The RNR field may include a Target Beacon Transmission Time (TBTT) information field. The TBTT information field may include at least a Short BSS Identifier (ID) field, a BSS parameter field, and / or a Multi-Link Device (MLD) parameter field. The Short BSS ID field may be a 4-byte hash of the Service Set Identifier (SSID) associated with the PE BSS. Additionally, the MLD parameter field may include at least a PE Access Point (AP) field. The PE AP field may be one bit long. Note that a value of one indicates that the reported access point is privacy-enhanced, and a value of zero indicates that the reported access point is not privacy-enhanced.
[0138] In some cases, to receive encrypted beacons from the PE BSS of a wireless network, a wireless station may determine that it understands the PE BSS based on the over-the-air BSS identifier (ID). The over-the-air BSS ID may be included in the information received from the traditional BSS. In some cases, to determine that a wireless station understands the PE BSS based on the over-the-air BSS identifier (ID), the wireless station may calculate the checksum of the encrypted beacon and determine that the checksum is equivalent to the Access Point Address Resolution Key (ARK). The ARK may be included in the information received from the traditional BSS.
[0139] In 2006, a wireless station could perform an encrypted handshake process (e.g., a multi-handshake, such as a four-way handshake, involving two or more exchanges between participating devices) with the PE BSS of the wireless network to authenticate and associate with it. In some cases, to perform the encrypted handshake process with the PE BSS of the wireless network to authenticate and associate with it, the wireless station could send an encrypted authentication request to the PE BSS and receive an encrypted authentication response from the PE BSS. Furthermore, the wireless station could send an encrypted association request to the PE BSS and receive an encrypted association response from the PE BSS.
[0140] In some cases, access points of a wireless network, such as access point 112, may host a traditional BSS and a PE BSS. Additionally, the access point may host one or more additional PE BSSs. It should be noted that each PE BSS and each of the additional PE BSSs may have a unique security domain. It should also be noted that each PE BSS and each of the additional PE BSSs may have a unique security key. In some cases, the one or more additional PE BSSs may include at least one of the following: a PE Guest BSS, a PE Internet of Things (IoT) BSS, a PE Backbone Mesh BSS, or a PE Service BSS. In some cases, the PE IoT BSS may operate as a hidden network. In some cases, the PE Backbone Mesh BSS may operate as a hidden network. In some cases, the PE Service BSS may be discoverable only by wireless sites having an application or configuration for operating within the PE Service BSS. Additionally, in some cases, the access point may host one or more additional traditional BSSs. The one or more additional traditional BSSs may include at least one of the following: a traditional Guest BSS, a traditional Internet of Things (IoT) BSS, a traditional Backbone Mesh BSS, or a traditional Service BSS.
[0141] Figure 20B A block diagram illustrating another example of a method for associating a wireless site with a privacy-enhanced (PE) Basic Service Set (BSS) of a wireless network, according to some implementation schemes, is shown. Among other devices, Figure 20BThe method shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the method elements shown may be executed concurrently in a different order than that shown, or may be omitted. Additional method elements may also be executed as needed. As shown in the figure, the method can operate as follows.
[0142] In 2012, access points hosting a PE BSS, such as access point 112, can transmit encrypted beacons to PE wireless sites. The encrypted beacons can be decoded based on information received from a traditional BSS. The encrypted beacons can be encrypted using a PE BSS-specific beacon key. Information received from a traditional BSS may include a PE BSS candidate list. The PE BSS candidate list may include neighbor reports and beacon reception parameters. In some cases, the encrypted beacons may be encrypted using a PE BSS-specific beacon key. In some cases, the encrypted beacon may include one or more of the following: Media Access Control (MAC) header fields, Timed Synchronization Function (TSF) fields, Multi-Link Device (MLD) / Authentication Address fields, Reduced Neighbor Report (RNR) fields, Traffic Indication Graph (TIM) fields, Change Sequence fields, Management Message Integrity Check (MIC) elements (MME) and / or optional fields. The MAC header may include the transmitter's MAC address. The MAC address may be randomized. The MLD / Authentication Address field may include the transmitter's authentication address. The RNR field may include a list of suitable access points located nearby and / or maintaining MLD links with other affiliated access points. The Change Sequence field signals whether the PE BSS has critical parameter updates. The MME field may include an integrity checksum of the encrypted beacon frame content. The RNR field may include a Target Beacon Transmission Time (TBTT) information field. The TBTT information field may include at least a Short BSS Identifier (ID) field, a BSS Parameter field, and / or a Multi-Link Device (MLD) Parameter field. The Short BSS ID field may be a 4-byte hash of the Service Set Identifier (SSID) associated with the PE BSS. Additionally, the MLD Parameter field may include at least a PE Access Point (AP) field. The PE AP field may be one bit long. Note that a value of one indicates that the reported access point is privacy-enhanced, and a value of zero indicates that the reported access point is not privacy-enhanced.
[0143] In 2014, an access point can perform an encrypted handshake process with a PE wireless site (e.g., a multi-handshake, such as a four-way handshake, involving two or more exchanges between participating devices) to authenticate the PE wireless site and associate it with the PE BSS. In some cases, to perform the encrypted handshake process with the PE wireless site to authenticate it and associate it with the PE BSS, the access point can receive an encrypted authentication request from the PE wireless site and send an encrypted authentication response to the PE wireless site. Furthermore, the access point can receive an encrypted association request from the PE wireless site and send an encrypted association response to the PE wireless site.
[0144] In some cases, an access point may host both a traditional BSS and a PE BSS. Additionally, an access point may host one or more additional PE BSSs. It should be noted that each PE BSS and each of the additional PE BSSs may have a unique security domain. It should also be noted that each PE BSS and each of the additional PE BSSs may have a unique security key. In some cases, the one or more additional PE BSSs may include at least one of the following: a PE Guest BSS, a PE Internet of Things (IoT) BSS, a PE Backbone Mesh BSS, or a PE Service BSS. In some cases, the PE IoT BSS may operate as a hidden network. In some cases, the PE Backbone Mesh BSS may operate as a hidden network. In some cases, the PE Service BSS may be discoverable only by wireless sites with an application or configuration for operating within the PE Service BSS. Additionally, in some cases, an access point may host one or more additional traditional BSSs. The one or more additional traditional BSSs may include at least one of the following: a traditional Guest BSS, a traditional Internet of Things (IoT) BSS, a traditional Backbone Mesh BSS, or a traditional Service BSS.
[0145] Figure 21A A block diagram illustrating an example of a method for associating an IoT site with a PE IoT BSS of a wireless network, according to some implementation schemes, is shown. Among other devices, Figure 21A The method shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the method elements shown may be executed concurrently in a different order than that shown, or may be omitted. Additional method elements may also be executed as needed. As shown in the figure, the method can operate as follows.
[0146] At 2102, IoT sites such as IoT site 107 can be configured to operate in PE BSS mode.
[0147] At 2104, the IoT site can communicate with a configuration wireless site of the wireless network, such as wireless site 106, to receive information associated with the PE IoT BSS. The information associated with the PE IoT BSS may include at least the channel on which the PE IoT BSS operates. In some cases, to communicate with the configuration wireless site of the wireless network to receive information associated with the PE IoT BSS, the IoT site may transmit an encrypted beacon to the configuration wireless site and perform an encrypted handshake process with the configuration wireless site (e.g., a multi-handshake such as a four-way handshake involving two or more exchanges between participating devices) to authenticate and associate with the configuration wireless site. Furthermore, the IoT site may receive encrypted data frames containing information associated with the PE IoT BSS from the configuration wireless site. In some cases, to perform an encrypted handshake process with the configuration wireless site to authenticate and associate with it, the IoT site may transmit an encrypted authentication request to the configuration wireless site and receive an encrypted authentication response from the configuration wireless site. Furthermore, the IoT site may transmit an encrypted association request to the configuration wireless site and receive an encrypted association response from the configuration wireless site.
[0148] At 2106, the IoT site can receive encrypted beacons from the PE IoT BSS. The encrypted beacons can be encrypted using a beacon key specific to the PE IoT BSS. In some cases, to receive encrypted beacons from the PE IoT BSS, the IoT site can determine that it understands the PE IoT BSS based on an over-the-air BSS identifier (ID). The over-the-air BSS ID can be included in the information associated with the PE IoT BSS received from the configuration radio site. In some cases, to determine that the IoT site understands the PE IoT BSS based on the over-the-air BSS ID, the IoT site can calculate a checksum of the encrypted beacon and determine that the checksum is equivalent to the Access Point Address Resolution Key (ARK). The ARK can be included in the information associated with the PE IoT BSS received from the configuration radio site.
[0149] In some cases, the encrypted beacon may include one or more of the following: Media Access Control (MAC) header fields, Timed Synchronization Function (TSF) fields, Multi-Link Device (MLD) / Authentication Address fields, Reduced Neighbor Report (RNR) fields, Traffic Indication Graph (TIM) fields, Change Sequence fields, Management Message Integrity Check (MIC) elements (MME) and / or optional fields. The MAC header may include the transmitter's MAC address. The MAC address may be randomized. The MLD / Authentication Address field may include the transmitter's authentication address. The RNR field may include a list of suitable access points located nearby or maintaining MLD links with other affiliated access points. The Change Sequence field may signal to the PE BSS whether there are critical parameter updates. The MME field may include an integrity checksum of the encrypted beacon frame's content. The RNR field may include a Target Beacon Transmission Time (TBTT) information field. The TBTT information field may include at least a Short BSS Identifier (ID) field, a BSS parameter field, and / or a Multi-Link Device (MLD) parameter field. The Short BSS ID field can be a 4-byte hash of the Service Set Identifier (SSID) associated with the PE BSS. The MLD parameter field may include at least the PE Access Point (AP) field. The PE AP field may be one bit long. A value of one indicates that the reported access point is privacy-enhanced, and a value of zero indicates that the reported access point is not privacy-enhanced.
[0150] At point 2108, an IoT site can perform an encrypted handshake process (e.g., a multi-handshake process involving two or more exchanges between participating devices, such as a four-way handshake) with the PE IoT BSS to authenticate and associate with it. In some cases, to perform the encrypted handshake process with the PE IoT BSS to authenticate and associate with it, the IoT site can send an encrypted authentication request to the PE IoT BSS and receive an encrypted authentication response from the PE IoT BSS. Furthermore, the IoT site can send an encrypted association request to the PE IoT BSS and receive an encrypted association response from the PE IoT BSS.
[0151] In some cases, the PE IoT BSS can operate as a hidden network. In some cases, an access point of a wireless network, such as access point 112, can host a PE IoT BSS and one or more additional PE BSSs. In such cases, the PE IoT BSS and one or more additional PE BSSs can each have a unique security domain. Additionally, the PE IoT BSS and one or more additional PE BSSs can each have a unique security key. In some cases, one or more additional PE BSSs can include at least one of the following: a PE resident BSS, a PE guest BSS, a PE backbone mesh BSS, and / or a PE service BSS. The PE backbone mesh BSS can operate as a hidden network. In some cases, the PE service BSS can be discovered only by wireless sites with applications or configurations for operating within the PE service BSS. In some cases, an access point can host one or more traditional BSSs. One or more traditional BSSs can include at least one of the following: a traditional resident BSS, a traditional guest BSS, a traditional Internet of Things (IoT) BSS, a traditional backbone mesh BSS, and / or a traditional service BSS.
[0152] Figure 21B A block diagram illustrating an example of a method for associating an IoT site with a PE IoT BSS of a wireless network, according to some implementation schemes, is shown. Among other devices, Figure 21B The method shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the method elements shown may be executed concurrently in a different order than that shown, or may be omitted. Additional method elements may also be executed as needed. As shown in the figure, the method can operate as follows.
[0153] At 2112, an access point such as access point 112 may transmit an encrypted beacon to an IoT site such as IoT site 107. The encrypted beacon may be decoded based on information received from a configured wireless site such as wireless site 106 associated with the IoT site. The encrypted beacon may be encrypted using a beacon key specific to the PE IoT BSS. Furthermore, the information associated with the PE IoT BSS may include at least the channel on which the PE IoT BSS operates. In some cases, the encrypted beacon may include one or more of the following: a Media Access Control (MAC) header field, a Timing Synchronization Function (TSF) field, a Multi-Link Device (MLD) / Authentication Address field, a Reduced Neighbor Report (RNR) field, a Traffic Indication Graph (TIM) field, a Change Sequence field, a Management Message Integrity Check (MIC) element (MME), and / or optional fields. The MAC header may include the transmitter's MAC address. The MAC address may be randomized. The MLD / Authentication Address field may include the transmitter's authentication address. The RNR field may include a list of suitable access points located nearby or maintaining MLD links with other affiliated access points. Changing the sequence field signals whether the PE BSS has critical parameter updates. The MME field may include an integrity checksum of the encrypted beacon frame content. The RNR field may include a Target Beacon Transmission Time (TBTT) information field. The TBTT information field may include at least a Short BSS Identifier (ID) field, a BSS parameter field, and / or a Multi-Link Device (MLD) parameter field. The Short BSS ID field may be a 4-byte hash of the Service Set Identifier (SSID) associated with the PE BSS. The MLD parameter field may include at least a PE Access Point (AP) field. The PE AP field may be one bit long. A value of one indicates that the reported access point is privacy-enhanced, and a value of zero indicates that the reported access point is not privacy-enhanced.
[0154] At point 2114, the access point can perform an encrypted handshake process with the IoT site (e.g., a multi-handshake such as a four-way handshake involving two or more exchanges between participating devices) to authenticate the IoT site and associate it with the PE IoT BSS. In some cases, to perform the encrypted handshake process with the IoT site to authenticate the IoT site and associate it with the PE IoT BSS, the access point can receive an encrypted authentication request from the IoT site and send an encrypted authentication response to the IoT site. Furthermore, the access point can receive an encrypted association request from the IoT site and send an encrypted association response to the IoT site.
[0155] In some cases, the PE IoT BSS can operate as a hidden network. In some cases, the access point can host one or more additional PE BSSs. In such cases, the PE IoT BSS and the one or more additional PE BSSs can each have a unique security domain. Furthermore, the PE IoT BSS and the one or more additional PE BSSs can each have a unique security key. In some cases, the one or more additional PE BSSs can include at least one of the following: PE Residential BSS, PE Guest BSS, PE Backbone Mesh BSS, or PE Service BSS. In some cases, the PE Backbone Mesh BSS can operate as a hidden network. The PE Service BSS can be discovered only by wireless sites with applications or configurations for operating within the PE Service BSS. In some cases, the access point can host one or more traditional BSSs. The one or more traditional BSSs can include at least one of the following: Traditional Residential BSS, Traditional Guest BSS, Traditional Internet of Things (IoT) BSS, Traditional Backbone Mesh BSS, and / or Traditional Service BSS.
[0156] Figure 22A A block diagram illustrating an example of a method for a wireless station to receive a PE BSS beacon according to some implementation schemes is shown. Among other devices, Figure 22A The method shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the method elements shown may be executed concurrently in a different order than that shown, or may be omitted. Additional method elements may also be executed as needed. As shown in the figure, the method can operate as follows.
[0157] At 2202, in order to receive the PE BSS beacon, a wireless station such as wireless station 106 can scan (or view) the BSSID in the PE BSS beacon.
[0158] At 2204, the wireless station can attempt to match the BSSID with the address key stored at the wireless station.
[0159] At 2206, if the BSSID matches the address key, the wireless station can use the BSS-specific key stored at the wireless station to decrypt the BSS-specific beacon.
[0160] As described above, a PE access point that transmits a discovery beacon may be discoverable only to PE radio stations. In some cases, PE radio stations may use PE query request and response signaling to query the PE BSS that transmits the discovery beacon. Furthermore, the PE BSS that transmits the discovery beacon may respond to probe requests with an unencrypted PE query response, allowing only the PE radio station to receive the response. In some cases, a PE BSS that only transmits encrypted beacons may not expect to be discoverable. Therefore, such a PE BSS may not respond to any active scans. In some cases, a PE BSS may establish a secure pre-association connection. For example, a PE BSS may establish pre-association security negotiation (PASN) protection and respond to PASN-protected active scans or queries. As another example, a PE BSS may use a public key to protect identifiers, such as an identifier protection key (IPK), to respond to protected active scans and queries. As yet another example, a PE BSS may perform an artificial (or dummy) association to establish a secure (e.g., encrypted) association before performing the actual protected (e.g., encrypted) association to respond to protected active scans and queries.
[0161] Figure 22B A block diagram illustrating an example of a method, according to some implementations, for a privacy-enhanced (PE) access point to advertise a hosted PE Basic Services Set (BSS) to unassociated PE radio sites. Among other devices, Figure 22B The method shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the method elements shown may be executed concurrently in a different order than that shown, or may be omitted. Additional method elements may also be executed as needed. As shown in the figure, the method can operate as follows.
[0162] At 2212, a wireless station, such as wireless station 106, which may be a non-associated PE wireless station, may receive one or more discovery beacons from a PE access point, such as access point 112, advertising a PE BSS hosted by the PE access point. Each of the one or more discovery beacons may include a Media Access Control (MAC) header field, a power envelope field, a Reduced Neighbor Report (RNR) field, and / or a Management Message Integrity Check (MIC) element (MME) field. The RNR field may include a Target Beacon Transmission Time (TBTT) information field. The TBTT information field may include at least a Short BSS Identifier (ID) field, a BSS parameter field, and / or a Multi-Link Device (MLD) parameter field. The Short BSS ID field may be a 4-byte hash of the Service Set Identifier (SSID) associated with the PE BSS. The MLD parameter field may include at least a PE Access Point (AP) field. The PE AP field may be one bit long. Note that a value of one indicates that the reported access point is privacy-enhanced, and a value of zero indicates that the reported access point is not privacy-enhanced.
[0163] At 2214, the wireless station can send a request to the PE access point to establish pre-association security protection.
[0164] At point 2216, a wireless station may transmit a protected request frame to the PE access point after establishing pre-association security protection. In some cases, to establish pre-association security protection, a wireless station may transmit a pre-association security negotiation (PASN) establishment request message to the PE access point and receive a PASN establishment response message from the PE access point. Additionally, a wireless station may transmit a PASN establishment confirmation message to the PE access point.
[0165] At 2218, the wireless station can receive a protected response from the PE access point, including PE access point parameters. PE access point parameters may include PE BSS information.
[0166] Figure 22C A block diagram illustrating an example of a method, according to some implementations, for a privacy-enhanced (PE) access point to advertise a hosted PE Basic Services Set (BSS) to unassociated PE radio sites. Among other devices, Figure 22C The method shown can also be used with any of the systems, methods, or devices shown in the figure. In various embodiments, some of the method elements shown may be executed concurrently in a different order than that shown, or may be omitted. Additional method elements may also be executed as needed. As shown in the figure, the method can operate as follows.
[0167] At 2222, an access point, such as access point 112, which can be a PE access point, can transmit one or more discovery beacons to non-associated PE radio sites, advertising a PE BSS hosted by the PE access point. Each of the one or more discovery beacons may include a Media Access Control (MAC) header field, a power envelope field, a Reduced Neighbor Report (RNR) field, and / or a Management Message Integrity Check (MIC) element (MME) field. The RNR field may include a Target Beacon Transmission Time (TBTT) information field. The TBTT information field may include at least a Short BSS Identifier (ID) field, a BSS parameter field, and / or a Multi-Link Device (MLD) parameter field. The Short BSS ID field may be a 4-byte hash of the Service Set Identifier (SSID) associated with the PE BSS. The MLD parameter field may include at least a PE Access Point (AP) field. The PE AP field may be one bit long. Note that a value of one indicates that the reported access point is privacy-enhanced, and a value of zero indicates that the reported access point is not privacy-enhanced.
[0168] At 2224, the access point can receive a request to establish pre-associated security protection from at least one non-associated PE wireless site.
[0169] At 2226, the access point may receive a protected request frame from at least one non-associated PE radio station after establishing pre-association security protection. In some cases, to establish pre-association security protection, the access point may receive a pre-association security negotiation (PASN) establishment request message from at least one non-association PE radio station and transmit a PASN establishment response message to at least one non-association PE radio station. Furthermore, the access point may receive a PASN establishment confirmation message from at least one non-association PE radio station.
[0170] At 2228, the access point can transmit a protected response, including PE access point parameters, to at least one unassociated PE radio station. PE access point parameters may include PE BSS information.
[0171] As is widely recognized, the use of personally identifiable information should comply with privacy policies and practices that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.
[0172] Embodiments of this disclosure may be implemented in any of a variety of forms. For example, some embodiments may be implemented as computer-implemented methods, computer-readable storage media, or computer systems. Other embodiments may be implemented using one or more custom-designed hardware devices such as ASICs. Other embodiments may be implemented using one or more programmable hardware elements such as FPGAs.
[0173] In some embodiments, a non-transitory computer-readable storage medium may be configured to store program instructions and / or data, wherein, if executed by a computer system, the program instructions cause the computer system to perform a method, such as any method embodiment of the method embodiments described herein, or any combination of method embodiments described herein, or any subset or combination of any such subset of any method embodiments described herein.
[0174] In some implementations, a wireless device (or wireless station) may be configured to include a processor (or a set of processors) and a memory medium, wherein the memory medium stores program instructions, and the processor is configured to read the program instructions from the memory medium and execute the program instructions, wherein the program instructions are executable to cause the wireless device to implement any of the various method implementations described herein (or any combination of the method implementations described herein, or any subset or any combination of such subsets of any method implementations described herein). The device may be implemented in any of a variety of forms.
[0175] Although the above embodiments have been described in considerable detail, many variations and modifications will become apparent to those skilled in the art once the disclosure is fully understood. This disclosure is intended to render the following claims as encompassing all such variations and modifications.
Claims
1. A method for associating a wireless site with a privacy-enhanced PE basic services set (BSS) of a wireless network, the method comprising: The wireless station, The wireless station communicates with the conventional BSS of the wireless network to transition to the PE BSS of the wireless network, wherein during communication with the conventional BSS, the wireless station receives information for decoding the encrypted beacon of the PE BSS; The encrypted beacon is received from the PE BSS of the wireless network, wherein the encrypted beacon is decodable using the information received from the conventional BSS and includes a Media Access Control (MAC) header field, the MAC header field including a randomized MAC address associated with the PE BSS; as well as An encrypted handshake process is performed with the PE BSS of the wireless network to authenticate the PE BSS of the wireless network and associate it with the PE BSS.
2. The method according to claim 1, The information received from the conventional BSS includes a PE BSS candidate list.
3. The method according to claim 2, The PE BSS candidate list includes neighbor reports and beacon reception parameters.
4. The method according to claim 1, The wireless station is included in the wireless network where the traditional BSS communicates with the wireless network to transition to the wireless network via the PE BSS. Receive a beacon from the conventional BSS of the wireless network indicating that the wireless network supports one or more PE BSSs; Send a request to the traditional BSS for a robust BSS transformation query recommended by the PE BSS; Receive a robust BSS conversion request from the conventional BSS, the robust BSS conversion request including a list of PE BSS candidate BSSs; and A robust BSS transition response is sent to the conventional BSS, indicating the transition to the PE BSS.
5. The method according to claim 1, The wireless station performs the cryptographic handshake process with the PE BSS of the wireless network to authenticate and associate with the PE BSS. Send an encrypted authentication request to the PE BSS; Receive an encrypted authentication response from the PE BSS; Send an encrypted association request to the PE BSS; and Receive an encrypted association response from the PE BSS.
6. The method according to claim 1, The access point of the wireless network hosts both the traditional BSS and the PE BSS.
7. The method according to claim 6, The access point hosts one or more additional PE BSSs, and each of the PE BSSs and the one or more additional PE BSSs has a unique security key.
8. The method according to claim 7, The one or more additional PE BSSs include at least one of the following: PE Guest BSS, PE IoT BSS as a hidden network operation, PE Backbone Mesh BSS as a hidden network operation, or PE Service BSS, which can only be discovered by wireless sites having an application or configuration for operating in the PE Service BSS.
9. The method according to claim 6, The access point therein hosts one or more additional traditional BSSs.
10. The method according to claim 9, The one or more additional traditional BSSs mentioned above include at least one of the following: traditional visitor BSS, traditional Internet of Things (IoT) BSS, traditional backbone grid BSS, or traditional service BSS.
11. The method according to claim 1, The encrypted beacon is encrypted using a beacon key specific to the PE BSS.
12. The method according to claim 1, The encrypted beacon also includes one or more of the following: a Timed Synchronization Function (TSF) field, a Multi-Link Device (MLD) / Authentication Address field, a Reduced Neighbor Report (RNR) field, a Traffic Indicator Graph (TIM) field, a Change Sequence field, a Management Message Integrity Verification (MIC) element, or an optional field.
13. The method according to claim 12, The MLD / authentication address field includes the authentication address associated with the transmitter; The RNR field includes a list of access points located nearby or maintaining MLD links with other affiliated access points, and a Target Beacon Transmission Time (TBTT) information field. The change in the sequence field signals the PE BSS whether there is a critical parameter update; and The MME field includes an integrity checksum of the contents of the encrypted beacon frame.
14. The method according to claim 13, The TBTT information fields include at least the Short BSS Identifier ID field, the BSS Parameter field, and the MLD Parameter field.
15. The method according to claim 1, The wireless station is among those receiving the encrypted beacon from the PE BSS of the wireless network. The wireless station is informed of the PE BSS based on the over-the-air BSS identifier ID, wherein the over-the-air BSS ID is included in the information received from the traditional BSS.
16. The method according to claim 15, The determination of the wireless station based on the over-the-air BSS ID includes the understanding that the PE BSS includes the wireless station: Calculate the checksum of the encrypted beacon; and The checksum is determined to be equivalent to the access point address resolution key ARK received from the conventional BSS.
17. The method according to claim 1, The access point of the wireless network hosts the traditional BSS, the PE BSS, and one or more additional PE BSSs, and each of the PE BSS and the one or more additional PE BSSs has a unique security domain.
18. A wireless station, the wireless station comprising: At least one antenna; At least one radio component, the at least one radio component being communicatively coupled to the at least one antenna; as well as At least one processor, which communicates with the at least one radio component and is configured to cause the wireless station to perform the method according to any one of claims 1 to 17.
19. A non-transitory computer-readable storage medium storing instructions executable by processing circuitry of a wireless station to perform the method according to any one of claims 1 to 17.