Apparatus and method for device identification in wireless local area network
By performing the authentication process in the wireless LAN and assigning identification information, the problem that unassociated STA cannot be identified is solved, and identification and network connection to the STA are realized.
Patent Information
- Application Number
- CN202280101660.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-10
- Publication Date
- 2025-06-27
AI Technical Summary
In a wireless LAN, an unassociated STA will never enter the 4 handshake, so it cannot participate in the device identification process, resulting in the inability to be identified by the network.
By performing the authentication process in the wireless local area network, the first identification information is assigned, including the identification information element IE, which indicates the first identifier ID of the STA or the first random media access control address RMA.
The identification of unassociated STAs in the wireless local area network is realized, and the unidentified device is avoided, and identification information can be allocated during the authentication process.
Smart Images

Figure CN120226393A_ABST
Abstract
Description
Technical Field
[0001] Various example embodiments generally relate to communication technologies, and particularly to methods and apparatuses for device identification in a wireless local area network. Background Art
[0002] This section introduces aspects that may facilitate a better understanding of the present disclosure. Accordingly, the statements in this section should be read in this regard and should not be construed as an admission of what is in the prior art or what is not in the prior art.
[0003] In a wireless communication network (such as in a wireless local area network), a communication device (such as a non-AP station STA) may access the network via another communication device (such as an access point AP) to obtain various services.
[0004] In some scenarios, identification of a communication device is required. For example, the 4-way handshake may be utilized to identify the STA. However, in some procedures (such as the FTM procedure), some STAs (such as unassociated STAs) never enter the 4-way handshake and thus never participate in the identification process. Therefore, such unassociated STAs are never identified by the network. Summary of the Invention
[0005] This Summary of the Invention is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary of the Invention is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0006] Certain aspects of the present disclosure and their embodiments may provide solutions to these challenges or other challenges. Various embodiments for solving one or more of the problems disclosed herein are presented herein. Specific apparatuses and methods for device identification in a wireless local area network may be provided to identify STAs in a wireless network.
[0007] A first apparatus includes components configured to: perform a first authentication process between the first apparatus and a second apparatus in a wireless local area network. First identification information of the first apparatus is assigned during the first authentication process.
[0008] In an exemplary embodiment of the present disclosure, the first identification information includes an identification information element IE that indicates: a first identifier ID of the first apparatus, or a first random media access control address RMA of the first apparatus.
[0009] In an exemplary embodiment of the present disclosure, the first authentication process performed by the first apparatus includes: sending a first message of the first authentication process to the second apparatus; receiving a second message of the first authentication process from the second apparatus; and sending a third message of the first authentication process to the second apparatus.
[0010] In an exemplary embodiment of the present disclosure, the first identification information of the first device is assigned by the second device; and the first device receives from the second device the following: the first identification information of the first device in the second message of the first authentication process, or at least one parameter for generating the first identification information based on a predefined equation.
[0011] In an exemplary embodiment of the present disclosure, the first identification information of the first device is assigned by the first device.
[0012] In an exemplary embodiment of the present disclosure, the first device sends the first identification information of the first device to the second device in the first message or the third message of the first authentication process; or, the first device sends to the second device the following: one or more parameters for the first device and the second device to generate the same first identification information based on a predefined equation.
[0013] In an exemplary embodiment of the present disclosure, the first device further performs a second authentication process between the first device and the second device.
[0014] In an exemplary embodiment of the present disclosure, the first device sends the first message of the second authentication process to the second device, and the first message includes: the first identification information of the first device; and / or the first device sends the third message of the second authentication process to the second device, and the third message includes: the first identification information of the first device.
[0015] In an exemplary embodiment of the present disclosure, the first device receives the second message of the second authentication process from the second device, and the second message includes: the second identification information, or at least one parameter for generating the second identification information based on a predefined equation; or, the first device sends the first message or the third message of the second authentication process to the second device, and the first message or the third message includes the second identification information.
[0016] In an exemplary embodiment of the present disclosure, the second message of the second authentication process further includes: a status code for indicating the success or failure of the identification of the first device.
[0017] In an exemplary embodiment of the present disclosure, the wireless local area network operates according to the 802.11 standard; the first device includes a non-AP station STA; the second device includes an access point AP; and the first device and the second device are not associated.
[0018] In an exemplary embodiment of the present disclosure, the second device is the first AP in an extended service set ESS; and the ESS further includes: a second AP and a third AP.
[0019] In an exemplary embodiment of the present disclosure, during a third authentication process between the first device and the second AP, the first device uses the first identification information or the second identification information; and during a fourth authentication process between the first device and the third AP, the first device uses the first identification information or the second identification information.
[0020] In an exemplary embodiment of the present disclosure, during a third authentication process between the first device and the second AP, the first device uses the first identification information or the second identification information; and during the third authentication process between the first device and the second AP, the first device obtains third identification information; and during a fourth authentication process between the first device and the third AP, the first device uses the third identification information.
[0021] In an exemplary embodiment of the present disclosure, the first identification information and the fourth identification information of the first device are assigned during a first authentication process; during a third authentication process between the first device and the second AP, the first device uses the first identification information; and during a fourth authentication process between the first device and the third AP, the first device uses the fourth identification information.
[0022] In an exemplary embodiment of the present disclosure, the component includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first device to execute.
[0023] A second aspect of the present disclosure provides a method executed by a first device, the method including: performing a first authentication process between the first device and a second device in a wireless local area network. The first identification information of the first device is assigned during the first authentication process.
[0024] In an exemplary embodiment of the present disclosure, the method is executed by the first device according to any exemplary embodiment in the exemplary embodiments of the first aspect of the present disclosure.
[0025] A third aspect of the present invention provides a second device, the second device including components for: performing a first authentication process between a first device and a second device in a wireless local area network. The first identification information of the first device is assigned during the first authentication process.
[0026] In an exemplary embodiment of the present disclosure, the first identification information includes an identification information element IE that indicates: the first identifier ID of the first device, or the first random media access control address RMA of the first device.
[0027] In an exemplary embodiment of the present disclosure, the first authentication process performed by the second device includes: receiving a first message of the first authentication process from the first device; sending a second message of the first authentication process to the first device; and receiving a third message of the first authentication process from the first device.
[0028] In an exemplary embodiment of the present disclosure, the first identification information of the first device is assigned by the second device; and the second device sends the following items to the first device: the first identification information of the first device in the second message of the first authentication process, or at least one parameter for generating the first identification information based on a predefined equation.
[0029] In an exemplary embodiment of the present disclosure, the first identification information of the first device is assigned by the first device.
[0030] In an exemplary embodiment of the present disclosure, the second device receives, from the first device, the first identification information of the first device in the first message or the third message of the first authentication process; or, the second device receives, from the first device, the following items: one or more parameters for the first device and the second device to generate the same first identification information based on a predefined equation.
[0031] In an exemplary embodiment of the present disclosure, the second device further performs a second authentication process between the first device and the second device.
[0032] In an exemplary embodiment of the present disclosure, the second device receives, from the first device, the first message of the second authentication process, where the first message includes: the first identification information of the first device; and / or the second device receives, from the first device, the third message of the second authentication process, where the third message includes: the first identification information of the first device.
[0033] In an exemplary embodiment, the first identification information may include a first RMA and / or a first ID. The first RMA should be the same in the first message and the third message. The first ID may be carried in the first message or the third message for identification.
[0034] In an exemplary embodiment of the present disclosure, the second device sends, to the first device, the second message of the second authentication process, where the second message includes: the second identification information, or at least one parameter for generating the second identification information based on a predefined equation; or, the second device receives, from the first device, the first message or the third message of the second authentication process, where the first message or the third message includes the second identification information.
[0035] In an exemplary embodiment of the present disclosure, the second message of the second authentication process further includes: a status code for indicating the success or failure of the identification of the first device.
[0036] In an exemplary embodiment of the present disclosure, the wireless local area network operates according to the 802.11 standard; the first device includes a non-AP station STA; the second device includes an access point AP; and the first device and the second device are not associated.
[0037] In an exemplary embodiment of the present disclosure, the second device is the first AP in an Extended Service Set (ESS); and the ESS further includes: a second AP and a third AP.
[0038] In an exemplary embodiment of the present disclosure, during a third authentication process between the first device and the second AP, the first device uses the first identification information or the second identification information; and during a fourth authentication process between the first device and the third AP, the first device uses the first identification information or the second identification information.
[0039] In an exemplary embodiment of the present disclosure, during a third authentication process between the first device and the second AP, the first device uses the first identification information or the second identification information; and during the third authentication process between the first device and the second AP, the first device obtains third identification information; and during a fourth authentication process between the first device and the third AP, the first device uses the third identification information.
[0040] In an exemplary embodiment of the present disclosure, the first identification information and the fourth identification information of the first device are assigned during a first authentication process; during a third authentication process between the first device and the second AP, the first device uses the first identification information; and during a fourth authentication process between the first device and the third AP, the first device uses the fourth identification information.
[0041] In an exemplary embodiment of the present disclosure, the component includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second device to execute.
[0042] A fourth aspect of the present disclosure provides a method executed by a second device, the method including: performing a first authentication process between a first device and the second device in a wireless local area network; and the first identification information of the first device is assigned during the first authentication process.
[0043] In an exemplary embodiment of the present disclosure, the method is executed by the second device according to any exemplary embodiment in the exemplary embodiments of the third aspect of the present disclosure.
[0044] A fifth aspect of the present disclosure provides a computer-readable storage medium storing instructions that, when executed by at least one processor of the first device, cause the at least one processor of the first device to perform a first authentication process between the first device and the second device in a wireless local area network; or, when executed by at least one processor of the second device, cause the at least one processor of the second device to perform a first authentication process between the first device and the second device in a wireless local area network. The first identification information of the first device is assigned during the first authentication process.
[0045] In an exemplary embodiment of the present disclosure, the instruction is executed by at least one processor of the first device mentioned above; or the instruction is executed by at least one processor of the second device mentioned above.
[0046] The embodiments herein provide many advantages. According to the embodiments of the present disclosure, an improved way for device identification in a wireless local area network can be provided. The identification information of the device can be assigned during the authentication process. Therefore, in some scenarios, unidentifiable devices can be further avoided.
[0047] For example, unassociated STAs without a four-way handshake can also be identified. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more apparent by way of example from the following detailed description with reference to the accompanying drawings, in which like reference numerals or letters are used to refer to the same or equivalent elements. The drawings are illustrated to facilitate a better understanding of the embodiments of the present disclosure and are not necessarily drawn to scale. In the drawings:
[0049] Figure 1 is a diagram showing the current frame exchange for key generation (PMK and PTK) in the 802.11 standard.
[0050] Figure 2 is a diagram showing the overall signaling flow of the 802.11bh proposal.
[0051] Figure 3a is a diagram showing the FTM and PASN processes for an associated STA.
[0052] Figure 3b is a diagram showing the FTM and PASN processes for an unassociated STA.
[0053] Figure 4 is a diagram showing the following identification problem for an unassociated STA during the FTM process: the lack of a four-way handshake results in a failed identification exchange.
[0054] Figure 5 is a block diagram showing an exemplary structure for a first device according to an exemplary embodiment of the present disclosure.
[0055] Figure 6a is a flowchart illustrating a method executed by a first device according to some embodiments of the present disclosure.
[0056] Figure 6b is a flowchart illustrating sub-steps of a method executed by a first device according to some embodiments of the present disclosure.
[0057] Figure 7is a block diagram showing an exemplary structure for a second device according to an exemplary embodiment of the present disclosure.
[0058] Figure 8a is a flowchart illustrating a method performed by a second device according to some embodiments of the present disclosure.
[0059] Figure 8b is a flowchart illustrating sub-steps of a method performed by a second device according to some embodiments of the present disclosure.
[0060] Figure 9 is a block diagram showing a device / computer-readable storage medium according to an embodiment of the present disclosure.
[0061] Figure 10a is a block diagram showing an exemplary device unit of a first device suitable for performing a method according to an embodiment of the present disclosure.
[0062] Figure 10b is a block diagram showing an exemplary device unit of a second device suitable for performing a method according to an embodiment of the present disclosure.
[0063] Figure 11a is a diagram illustrating the general idea of how to implement an identification process (using RMA) for an unassociated STA in an FTM process for network-initiated identification (category 1).
[0064] Figure 11b is a diagram illustrating the general idea of how to implement an identification process (using RMA) for an unassociated STA in an FTM process for STA-initiated identification (category 2).
[0065] Figure 12 is a diagram summarizing identification process categories and authentication frames at which an unassociated STA is identified.
[0066] Figure 13 is a diagram showing a proposed exchange sequence between an AP and an STA according to an exemplary embodiment, the exchange sequence being for identifying an unassociated STA in FTM for a network-allocated ID.
[0067] Figure 14 is a diagram showing a proposed exchange sequence between an AP and an STA according to an exemplary embodiment, the exchange sequence being for identifying an unassociated STA in FTM for a network-allocated RMA.
[0068] Figure 15 is a diagram showing a proposed exchange sequence between an AP and an STA according to an exemplary embodiment, the exchange sequence being for identifying an unassociated STA in FTM for a STA-allocated ID.
[0069] Figure 16 FIG. Figure 16 is a diagram showing a proposed exchange sequence between an AP and an STA according to an exemplary embodiment, the exchange sequence being for identifying an unassociated STA in FTM for an RMA assigned to the STA.
[0070] Figure 17a FIG. is a diagram showing a proposed information element order in an authentication frame according to an embodiment of the present disclosure.
[0071] Figure 17b FIG. is a diagram showing a proposed information element definition according to an embodiment of the present disclosure.
[0072] Figure 17c FIG. is a diagram showing a proposed identification information element format according to an embodiment of the present disclosure.
[0073] Figure 18 FIG. Figure 17c is a diagram showing a proposed status information in a status code field in an authentication frame according to an embodiment of the present disclosure.
[0074] Figure 19 FIG. Figure 19 is a diagram showing a proposed status information in identification information incorporated into an authentication frame according to an embodiment of the present disclosure.
[0075] Figure 20 FIG. is a diagram showing multiple FTM sessions, where an STA establishes multiple FTM sessions with APs in the same ESS.
[0076] Figure 21 FIG. Figure 21 is a diagram showing an example of single identifier usage for multi-session FTM according to an embodiment of the present disclosure.
[0077] Figure 22 FIG. Figure 22 is a diagram showing an example of multi-identifier usage for multi-session FTM according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0078] Embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that the discussion of these embodiments is only for better understanding, and is not intended to limit the scope of the present disclosure. The described features, advantages, and characteristics of the present disclosure may be combined in any suitable manner in one or more embodiments.
[0079] In general, all terms used herein should be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or implied in the context in which the term is used. Unless clearly given and / or implied in the context, the steps of any method disclosed herein do not have to be performed in the exact order disclosed. As appropriate, any feature of any embodiment disclosed herein can be applied to any other embodiment.
[0080] As used herein, the term "network" or "communication network" refers to a network (such as the Internet network or any wireless network) that follows any suitable communication standard. For example, wireless communication standards may include WLAN, New Radio (NR), Long-Term Evolution (LTE), LTE Advanced, etc. In the following description, the terms "network" and "system" may be used interchangeably.
[0081] The term "communication device" refers to any end device that can access a communication network and receive services therefrom. By way of example and not limitation, a communication device refers to a mobile terminal, a user equipment (UE), or other suitable devices. A communication device may include, but is not limited to, a mobile phone, a cellular phone, a smart phone, a wearable device, an in-vehicle wireless terminal device, a vehicle, etc.
[0082] As an example, a communication device may represent a device configured for communication according to one or more communication standards promulgated by the Institute of Electrical and Electronics Engineers (IEEE), such as any 802.11 standard, or communication standards promulgated by any other organization, such as the Third Generation Partnership Project (3GPP).
[0083] As another example, in the Internet of Things (IoT) scenario, a communication device may represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another terminal device and / or network device. Specific examples of such machines or devices are sensors, metering devices (such as power meters), industrial machinery, or household or personal appliances (e.g., refrigerators, televisions), personal wearable devices (such as watches), etc. In other scenarios, a communication device may represent a vehicle or other device capable of monitoring and / or reporting its operating state or other functions associated with its operation.
[0084] It should be understood that although the terms "first" and "second" etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, the first element may be referred to as the second element, and similarly, the second element may be referred to as the first element. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.
[0085] As used herein, "at least one of the following: <list of two or more elements>" and "at least one of <list of two or more elements>" and similar phrases (where the list of two or more elements is joined by "and" or "or") mean at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.
[0086] The following will illustrate an application scenario in an 802.11 network only as an example and not by way of limitation.
[0087] Figure 1 It is a diagram showing the current frame exchanges for key generation (PMK and PTK) in the 802.11 standard.
[0088] As Figure 1 shown, the PMK (Pairwise Master Key) is generated in the authentication exchange, and the PTK (Pairwise Temporary Key) is generated in the 4 - way handshake.
[0089] The STA can communicate with the AP via probe requests and responses (Req / Resp).
[0090] Then, the STA can communicate with the AP via authentication requests and responses, and the PMK is generated.
[0091] The STA can communicate with the AP via association requests and responses.
[0092] The STA can communicate with the AP via the 4 - way handshake, and the PTK is generated.
[0093] Finally, a data connection between the STA and the AP will be established.
[0094] The current 802.11 standard requires the generation of security keys (such as PMK and PTK) in specific frame exchanges. Strictly speaking, the PMK is generated in the authentication frame exchange, and the PTK is generated in the 4 - way handshake as Figure 1 shown. Recall that the PTK is derived from the PMK (and other parameters). If the key generation is successful (i.e., the keys are verified at both the STA (Station) and the AP (Access Point)), then the STA and the AP can start data communication with each other.
[0095] The 802.11bh and 802.11az working groups are relevant within the context of the embodiments of the present disclosure and mainly include the following.
[0096] First, the 802.11bh working group focuses on STAs that use randomized and changing MAC (Media Access Control) (RCM) and are still identified by the network. [22 / 0296r8] and [22 / 888r2] introduce several proposals for RCM. The vast majority of these proposals take advantage of the assignment of ID (identifier) / random MAC addresses in the 4 - way handshake. Specifically, there are four strong candidate solutions, namely:
[0097] a. Network-Generated Device ID (NGID) [22 / 187r2], where the AP generates and assigns a unique ID (referred to as the device ID) to the STA during the 4-way handshake, and the STA uses this device ID in subsequent associations. Note that this solution is already in the 802.11bh document, such as the 802.11bh draft (D0.2).
[0098] b. MAAD (MAC Address Assignment) [22 / 925r2], where the AP generates and assigns a unique random MAC address (RMA) to the STA during the 4-way handshake, and the STA uses this RMA in subsequent associations.
[0099] c. IRMA (Identifiable Random MAC Address) [22 / 895r1], where the STA generates and assigns a unique random MAC address (RMA) to itself during the 4-way handshake, and the STA uses this RMA in subsequent associations.
[0100] d. RRCM (Rule-Based Random and Changing MAC Address) [22 / 888r2], where the STA and the AP share some parameters so that both parties (the STA and the AP) generate the same RMA, which will be used in subsequent associations.
[0101] Figure 2 is a diagram showing the overall signaling flow of the 802.11bh proposal.
[0102] As Figure 2 shown, during the first association, in addition to Figure 1 the illustration, an identifier (ID) or RMA is also generated and assigned during the 4-way handshake.
[0103] The data connection between the STA and the AP can be established and then disconnected.
[0104] In the second association, the previously generated identifier (ID) or RMA can be further used. In each association, the PMK generation should be in the authentication request / response frame exchange, and the PTK generation should be in the 4-way handshake.
[0105] Secondly, 802.11az focuses on determining the absolute and relative positions of STAs. To achieve this, 802.11az utilizes the Fine Timing Measurement (FTM) process, in which an STA uses Time-of-Flight (TOF), Time Difference of Arrival, and phase measurements to determine the round-trip distance, relative distance, and direction of that STA to another STA. The FTM process is implemented through FTM frames (action frames). In addition, 802.11az also defines a mechanism called Pre-Association Security Negotiation (PASN). Different from traditional 802.11 standards where PMK is generated in the authentication frame exchange and PTK is generated in the 4-way handshake, PASN generates both PMK and PTK in the authentication frame exchange. In addition, the FTM process is defined for both associated STAs and unassociated STAs.
[0106] Figure 3a FIG. is a diagram showing the FTM and PASN processes for an associated STA. Figure 3b FIG. is a diagram showing the FTM and PASN processes for an unassociated STA.
[0107] It should be noted that an STA can establish multiple FTM sessions with different APs in the same ESS (Extended Service Set).
[0108] As Figure 3a shown, PASN generates PMK in the authentication frame exchange. Then, the STA can communicate with the AP via the 4-way handshake, and PTK can be generated. Then, a data connection can be established. Finally, the FTM process can be executed.
[0109] If an STA intends to associate with an AP for data frame exchange and FTM frame exchange, the STA can establish a wireless connection after the frame exchange shown in Figure 1 .
[0110] As Figure 3b shown, PASN generates both PMK and PTK in the authentication frame exchange. Then, the FTM process can be executed without the need for an association and the 4-way handshake process.
[0111] In traditional PMK generation and PTK generation, PMK is generated in the authentication frame exchange, and PTK is generated in the 4-way handshake.
[0112] In the overall concept of the 802.11bh RCM solution, an identifier or RMA is generated / assigned in the 4-way handshake, and the generated ID or RMA will be used by the STA in subsequent associations.
[0113] In PASN, both PMK and PTK are generated in the authentication frame exchange (contrary to traditional PMK generation and PTM generation).
[0114] During the FTM process, FTM frame exchanges (to determine the STA location) can occur for associated STAs (STAs that have completed association with the AP) and / or unassociated STAs (STAs that are not associated with the AP).
[0115] All current 802.11bh proposals follow a similar logic: The STA should first send authentication and association frames, and then enter the 4-way handshake for ID / RMA generation and allocation. In subsequent associations, the generated / allocated ID / RMA will be used again by the STA. This process requires the STA to associate with the AP each time. If the STA is not associated with the AP, the process is interrupted. As a related scenario, the FTM process for unassociated STAs (see Figure 3b ) can be taken as an example. In this scenario, the STA never associates with the AP (note that the STA only sends authentication frames and FTM frames). Since the STA never associates with the AP, the STA will never get an ID or RMA (because the STA never enters the 4-way handshake as proposed by the 802.11bh solution). Because the STA never gets an ID / RMA, the identification process cannot occur. In other words, since unassociated STAs in the FTM process will never enter the 4-way handshake, the STA cannot utilize the related identification process proposed by the 802.11bh solution, and the STA will never be identified when using the RMA.
[0116] Figure 4 is a diagram showing the following identification problem for unassociated STAs in the FTM process: The lack of the 4-way handshake results in identification failure.
[0117] In Figure 4 , the STA uses RMA1 in the authentication frame and then starts the FTM process using RMA1. After some time, the STA changes its random MAC (i.e., RMA2) and wishes to restart the FTM process using RMA2. Since the identification process never occurs (because unassociated STAs never enter the 4-way handshake, while the current 802.11bh solution implements the identification process), the STA is never identified.
[0118] Figure 4 The missing processes for association and the 4-way handshake are shown as dashed lines in
[0119] As discussed above, the proposed identification process (generating and allocating an ID or RMA) for 802.11bh (STA using a random MAC and identified by the network) occurs during the 4-way handshake. However, in the FTM process, an unassociated STA never enters the 4-way handshake and thus never participates in the identification process. Therefore, an unassociated STA in the FTM process is never identified by the network.
[0120] To overcome this problem, embodiments of the present disclosure propose to utilize the advantages of authentication frame exchanges (such as in the PASN) to generate and allocate an ID / RMA. By implementing the identification process in the authentication frame exchange, an unassociated STA can be identified by the network.
[0121] In addition, an unassociated STA can establish multiple FTM processes (referred to as multi-session FTM) with different APs in the same ESS (Extended Service Set). Embodiments of the present disclosure also address this scenario.
[0122] Figure 5 is a block diagram showing an exemplary structure for a first device according to an exemplary embodiment of the present disclosure.
[0123] As Figure 5 shown, the first device 50 includes components 510 configured to: perform a first authentication process between the first device 50 and a second device in a wireless local area network. First identification information of the first device 50 is allocated during the first authentication process.
[0124] According to an embodiment of the present disclosure, an improved way for device identification in a wireless local area network can be provided. Identification information of a device can be allocated during an authentication process. Thus, in some scenarios, un-identified devices can be further avoided. For example, an unassociated STA without a 4-way handshake can also be identified.
[0125] In an exemplary embodiment of the present disclosure, the first identification information includes an identification information element IE that indicates: a first identifier ID of the first device 50, or a first random media access control address RMA of the first device 50.
[0126] In an exemplary embodiment of the present disclosure, the first authentication process performed by the first device 50 includes: sending a first message of the first authentication process to the second device; receiving a second message of the first authentication process from the second device; and sending a third message of the first authentication process to the second device.
[0127] In an exemplary embodiment of the present disclosure, the first identification information of the first device 50 is assigned by the second device; and the first device 50 receives from the second device: the first identification information of the first device 50 in the second message of the first authentication process, or at least one parameter for generating the first identification information based on a predefined equation.
[0128] In an exemplary embodiment of the present disclosure, the first identification information of the first device 50 is assigned by the first device 50.
[0129] In an exemplary embodiment of the present disclosure, the first device 50 sends the first identification information of the first device 50 to the second device in the first message or the third message of the first authentication process; or the first device 50 sends to the second device: one or more parameters for the first device 50 and the second device to generate the same first identification information based on a predefined equation.
[0130] In an exemplary embodiment of the present disclosure, the first device 50 further performs a second authentication process between the first device 50 and the second device.
[0131] In an exemplary embodiment of the present disclosure, the first device 50 sends the first message of the second authentication process to the second device, and the first message includes: the first identification information of the first device 50; and / or the first device 50 sends the third message of the second authentication process to the second device, and the third message includes: the first identification information of the first device 50.
[0132] In an exemplary embodiment of the present disclosure, the first device 50 receives the second message of the second authentication process from the second device, and the second message includes: the second identification information, or at least one parameter for generating the second identification information based on a predefined equation; or the first device 50 sends the first message or the third message of the second authentication process to the second device, and the first message or the third message includes the second identification information.
[0133] In an exemplary embodiment of the present disclosure, the second message of the second authentication process further includes: a status code for indicating the success or failure of the identification of the first device 50.
[0134] In an exemplary embodiment of the present disclosure, the wireless local area network operates according to the 802.11 standard; the first device 50 includes a non-AP station STA; the second device includes an access point AP; and the first device 50 and the second device are not associated.
[0135] In an exemplary embodiment of the present disclosure, the second device is the first AP in an extended service set ESS; and the ESS further includes: a second AP and a third AP.
[0136] In an exemplary embodiment of the present disclosure, during a third authentication process between the first device 50 and the second AP, the first device 50 uses the first identification information or the second identification information; and during a fourth authentication process between the first device 50 and the third AP, the first device 50 uses the first identification information or the second identification information.
[0137] In an exemplary embodiment of the present disclosure, during a third authentication process between the first device 50 and the second AP, the first device 50 uses the first identification information or the second identification information; and during the third authentication process between the first device 50 and the second AP, the first device 50 obtains the third identification information; and during a fourth authentication process between the first device 50 and the third AP, the first device 50 uses the third identification information.
[0138] In an exemplary embodiment of the present disclosure, the first identification information and the fourth identification information of the first device 50 are assigned during a first authentication process; during a third authentication process between the first device 50 and the second AP, the first device 50 uses the first identification information; and during a fourth authentication process between the first device 50 and the third AP, the first device 50 uses the fourth identification information.
[0139] According to an exemplary embodiment of the present disclosure, when multiple authentication processes occur for an unassociated STA, the identification of the STA can still be executed.
[0140] In an exemplary embodiment of the present disclosure, the component 510 includes: at least one processor 512; and at least one memory 514 that stores instructions, which when executed by the at least one processor 512, cause the first device 50 to execute.
[0141] The processor 512 can be any type of processing component, such as one or more microprocessors or microcontrollers, and other digital hardware, which can include a digital signal processor (DSP), dedicated digital logic, etc. The memory 514 can be any type of storage component, such as a read-only memory (ROM), random access memory, cache memory, flash memory device, optical storage device, etc.
[0142] Figure 6a is a flowchart illustrating a method executed by a first device according to some embodiments of the present disclosure.
[0143] As Figure 6a shown, the method 60 executed by the first device 50 may include: step S600, performing a first authentication process between the first device 50 and the second device in a wireless local area network. The first identification information of the first device 50 is assigned during the first authentication process.
[0144] In an exemplary embodiment of the present disclosure, the method is performed by a first device 50 as described above, such as shown in Figure 5 the above.
[0145] Figure 6b FIG. is a flowchart showing sub-steps of a method performed by a first device according to some embodiments of the present disclosure.
[0146] As shown in Figure 6b the first authentication process may include: sub-step S602, sending a first message of the first authentication process to a second device; sub-step S604, receiving a second message of the first authentication process from the second device; and sub-step S606, sending a third message of the first authentication process to the second device.
[0147] Figure 7 FIG. is a block diagram showing an exemplary structure for a second device according to an exemplary embodiment of the present disclosure.
[0148] As shown in Figure 7 the second device 70 includes components 710 configured to perform a first authentication process between the first device 50 and the second device 70 in a wireless local area network. First identification information of the first device 50 is assigned during the first authentication process.
[0149] In an exemplary embodiment of the present disclosure, the first identification information includes an identification information element IE that indicates: a first identifier ID of the first device 50, or a first random media access control address RMA of the first device 50.
[0150] In an exemplary embodiment of the present disclosure, the first authentication process performed by the second device 70 includes: receiving a first message of the first authentication process from the first device 50; sending a second message of the first authentication process to the first device 50; and receiving a third message of the first authentication process from the first device 50.
[0151] In an exemplary embodiment of the present disclosure, the first identification information of the first device 50 is assigned by the second device 70; and the second device 70 sends to the first device 50: the first identification information of the first device 50 in the second message of the first authentication process, or at least one parameter for generating the first identification information based on a predefined equation.
[0152] In an exemplary embodiment of the present disclosure, the first identification information of the first device 50 is assigned by the first device 50.
[0153] In an exemplary embodiment of the present disclosure, the second device 70 receives, in a first message or a third message of a first authentication process, first identification information of the first device 50 from the first device 50; or the second device 70 receives from the first device 50 the following: one or more parameters for the first device 50 and the second device 70 to generate the same first identification information based on a predefined equation.
[0154] In an exemplary embodiment of the present disclosure, the second device 70 further performs a second authentication process between the first device 50 and the second device 70.
[0155] In an exemplary embodiment of the present disclosure, the second device 70 receives a first message of a second authentication process from the first device 50, the first message including: first identification information of the first device 50; and / or the second device 70 receives a third message of the second authentication process from the first device 50, the third message including: first identification information of the first device 50.
[0156] In an exemplary embodiment of the present disclosure, the second device 70 sends a second message of the second authentication process to the first device 50, the second message including: second identification information, or at least one parameter for generating the second identification information based on a predefined equation; or the second device 70 receives a first message or a third message of the second authentication process from the first device 50, the first message or the third message including the second identification information.
[0157] In an exemplary embodiment of the present disclosure, the second message of the second authentication process further includes: a status code for indicating success or failure of the identification of the first device 50.
[0158] In an exemplary embodiment of the present disclosure, the wireless local area network operates according to the 802.11 standard; the first device 50 includes a non-AP station STA; the second device 70 includes an access point AP; and the first device 50 and the second device 70 are not associated.
[0159] In an exemplary embodiment of the present disclosure, the second device 70 is the first AP in an extended service set ESS; and the ESS further includes: a second AP and a third AP.
[0160] In an exemplary embodiment of the present disclosure, the first device 50 uses the first identification information or the second identification information in a third authentication process between the first device 50 and the second AP; and the first device 50 uses the first identification information or the second identification information in a fourth authentication process between the first device 50 and the third AP.
[0161] In an exemplary embodiment of the present disclosure, the first device 50 uses first identification information during a third authentication process between the first device 50 and the second AP; and the first device 50 obtains third identification information during the third authentication process between the first device 50 and the second AP; and the first device 50 uses the third identification information during a fourth authentication process between the first device 50 and the third AP.
[0162] In an exemplary embodiment of the present disclosure, the first identification information and the fourth identification information of the first device 50 are assigned during a first authentication process; the first device 50 uses the first identification information during a third authentication process between the first device 50 and the second AP; and the first device 50 uses the fourth identification information during a fourth authentication process between the first device 50 and the third AP.
[0163] In an exemplary embodiment of the present disclosure, the component includes: at least one processor 712; and at least one memory 714 storing instructions that, when executed by the at least one processor 712, cause the second device 70 to execute.
[0164] Figure 8a is a flowchart illustrating a method executed by a second device according to some embodiments of the present disclosure.
[0165] As Figure 8a shown, the method 80 executed by the second device 70 includes: step S800, performing a first authentication process between the first device and the second device 70 in a wireless local area network. The first identification information of the first device is assigned during the first authentication process.
[0166] In an exemplary embodiment of the present disclosure, the method is executed by the second device 70 described above as Figure 7 shown.
[0167] Figure 8b is a flowchart illustrating sub-steps of a method executed by a second device according to some embodiments of the present disclosure.
[0168] As Figure 8b shown, the first authentication process may include: sub-step S802, receiving a first message of the first authentication process from the first device 50; sub-step S804, sending a second message of the first authentication process to the first device 50; and sub-step S806, receiving a third message of the first authentication process from the first device 50.
[0169] Figure 9 is a block diagram showing a device / computer-readable storage medium according to an embodiment of the present disclosure.
[0170] As Figure 9As shown, the computer-readable storage medium 90 stores instructions 91 which, when executed by at least one processor of the first device, cause at least one processor of the first device 50 to perform a first authentication process between the first device 50 and the second device 70 in a wireless local area network; or the instructions 91, when executed by at least one processor of the second device 70, cause at least one processor of the second device 70 to perform a first authentication process between the first device and the second device 70 in a wireless local area network. The first identification information of the first device 50 is assigned during the first authentication process.
[0171] In an exemplary embodiment of the present disclosure, the first device 50 is as described above (such as Figure 5 as shown), and the second device 70 is as described above (such as Figure 7 as shown).
[0172] In addition, the present disclosure may also provide a carrier containing the computer program / instructions mentioned above. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. The computer-readable storage medium may be, for example, an optical disc or an electronic memory device such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, magnetic tape, CD-ROM, DVD, Blu-ray disc, etc.
[0173] Figure 10a is a block diagram showing an exemplary device unit of a first device suitable for executing the method according to an embodiment of the present disclosure.
[0174] As Figure 10a shown, the first device 50 may include an execution unit 1001 for performing a first authentication process between the first device 50 and the second device 70 in a wireless local area network. The first identification information of the first device is assigned during the first authentication process.
[0175] Figure 10b is a block diagram showing an exemplary device unit of a second device suitable for executing the method according to an embodiment of the present disclosure.
[0176] As Figure 10b shown, the second device 70 may include an execution unit 1011 for performing a first authentication process between the first device 50 and the second device 70 in a wireless local area network. The first identification information of the first device 50 is assigned during the first authentication process.
[0177] The term "unit" can have its conventional meaning in the field of electronic devices, electrical equipment, and / or electronic equipment, and can include, for example, electrical and / or electronic circuitry systems, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, outputs, and / or display functions, such as those described herein.
[0178] As used in this disclosure, the term "circuitry" can refer to one or more or all of the following:
[0179] (a) Only hardware circuit implementations (such as implementations in only analog and / or digital circuitry), and
[0180] (b) Combinations of hardware circuits and software, such as (where applicable):
[0181] (i) Combinations of (multiple) analog and / or digital hardware circuits and software / firmware, and
[0182] (ii) Any portion of (multiple) hardware processors (including (multiple) digital signal processors), software, and (multiple) memories, which work together to cause a device (such as a mobile phone or a server) to perform various functions, and
[0183] (c) (Multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or a part of (multiple) microprocessors, which require software (e.g., firmware) for operation, but the software may be absent when not needed for operation.
[0184] This definition of circuitry applies to all uses of the term in this disclosure, including in any claims. As another example, as used in this disclosure, the term circuitry also covers implementations of only hardware circuits or processors (or multiple processors), or a part of a hardware circuit or processor and its (or their) attendant software and / or firmware. For example and if applicable to a particular claim element, the term circuitry also covers a baseband integrated circuit or a processor integrated circuit for a mobile device, or a similar integrated circuit in a server, a cellular network device, or other computing or network devices.
[0185] Using these units, the device may not require a fixed processor or memory, and any kind of computing resources and storage resources can be arranged from at least one network node / device / entity / device associated with the communication system. Virtualization technologies and network computing technologies (e.g., cloud computing) can be further introduced to improve the usage efficiency of network resources and the flexibility of the network.
[0186] The techniques described herein can be implemented by various components such that an apparatus that implements one or more functions of the corresponding apparatus described using the embodiments includes not only components of the prior art but also components for implementing one or more functions of the corresponding apparatus described using the embodiments, and the apparatus can include separate components for each individual function or can be configured to perform two or more functions. For example, these techniques can be implemented in hardware (one or more apparatuses), firmware (one or more apparatuses), software (one or more modules / units), or a combination thereof. For firmware or software, the implementation can be carried out by modules (e.g., procedures, functions, etc.) that execute the functions described herein.
[0187] In some embodiments, some or all of the functions described herein can be provided by a processing circuitry that executes instructions stored in a memory, which in some embodiments can be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functions can be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of these particular embodiments, whether or not instructions stored on a non-transitory computer-readable storage medium are executed, the processing circuitry can be configured to perform the described functions. The benefits provided by such functions are not limited to the separate processing circuitry or other components of a computing device but are generally shared by the entire computing device and / or by the end user and the wireless network.
[0188] The term "non-transitory" as used herein is a limitation on the medium itself (i.e., tangible, rather than a signal), rather than a limitation on the persistence of data storage (e.g., RAM versus ROM).
[0189] In summary, within this context, the ideas of the embodiments of the present disclosure can include the following.
[0190] Embodiments of the present disclosure propose to use authentication frame exchange in PASN to generate and distribute ID / RMA. By doing so, unassociated STAs with RMA can be identified by the network during the FTM process.
[0191] Embodiments of the present disclosure define a feedback mechanism (i.e., status information) to indicate the success / failure of the proposed identification method.
[0192] Embodiments of the present disclosure also address multi-session FTM processes.
[0193] For the sake of simplicity in illustrating the implementation scenarios, the 802.11bh identification process can be divided into two categories:
[0194] 1 - Network-initiated identification: This covers the cases where the network (AP) generates an ID and assigns it to the STA, and the cases where the network (AP) generates an RMA and assigns it to the STA.
[0195] 2 - STA-initiated identification: This covers the cases where the STA generates an RMA and assigns it to itself, the cases where the STA shares relevant parameters with the AP so that both can generate the same RMA, and the cases where the STA generates an ID and assigns it to itself.
[0196] Specifically, in network-initiated identification (category 1): The STA is assigned identification information (e.g., RMA or ID) in the authentication Msg2 in the first association (authentication) (through the AP). The STA uses the identification information (e.g., RMA or ID) in the authentication Msg1 (e.g., RMA or ID) or authentication Msg3 (e.g., ID) in the second association (authentication).
[0197] In addition, the STA can be assigned identification information (e.g., a new RMA or ID) in the authentication Msg2 in the second association (authentication) (through the AP).
[0198] In STA-initiated identification (category 2): The STA is assigned identification information (e.g., RMA or ID) in the authentication Msg1 or authentication Msg3 in the first association (authentication) (through itself). The STA uses the identification information (e.g., RMA or ID) in the authentication Msg1 (e.g., RMA or ID) or authentication Msg3 (e.g., ID) in the second association.
[0199] In addition, the STA can be assigned identification information (e.g., a new RMA or ID) in the authentication Msg1 or authentication Msg3 in the second association (authentication) (through itself).
[0200] Figure 11a is a diagram showing the general idea of how to implement the identification process (using RMA) for an unassociated STA in the FTM process for network-initiated identification (category 1).
[0201] Figure 11b is a diagram showing the general idea of how to implement the identification process (using RMA) for an unassociated STA in the FTM process for STA-initiated identification (category 2).
[0202] More specifically, the key steps of the embodiment can be summarized as follows. The STA and the AP first negotiate which identification scheme they will use (A. Network-initiated identification - category 1; or B. STA-initiated identification - category 2).
[0203] AsFigure 11a As shown in Figure 11a , for a network-initiated identity (category 1), the first association process may include the following steps.
[0204] 1) The unassociated STA first sends an authentication Msg1 to the AP. This message consists of the initialization of the FTM process and the relevant information for key generation.
[0205] 2) After the AP receives the authentication Msg1, the AP derives its security keys (PMK and PTK), generates identity information (ID or RMA, depending on the identity scheme), encrypts this information as an information element (IE) in the authentication Msg2 payload, and sends the IE to the STA. This identity information will be used by the STA in a later association.
[0206] 3) After the STA receives the authentication Msg2, the STA derives its security keys (the same PMK and PTK), decrypts and obtains the identity information (ID or RMA) for future use.
[0207] 4) After obtaining the identity information, the STA sends an authentication Msg3 to complete the authentication process and enters the FTM process.
[0208] Then, any later association may include the following steps.
[0209] 1) The STA wishes to restart the FTM process with another MAC address; thus, it first starts an authentication frame exchange with a random MAC (RMA). Since the previous association assigned identity information (ID or RMA) to the STA, the STA uses this identity information (ID and / or RMA) in the authentication Msg1 and / or Msg3, as follows.
[0210] 1.1) If the STA uses the RMA identity, the STA uses the RMA information (assigned from the previous association) in the authentication Msg1. Thus, in the authentication Msg1, the STA is always identified.
[0211] 1.2) If the STA uses the ID identity, the STA uses the ID information (assigned from the previous association) in the authentication Msg1 or Msg3. Thus, in the authentication Msg1 or Msg3, the STA is always identified.
[0212] 1.3) If the STA uses both the RMA identity and the ID identity, the STA uses the RMA information (assigned from the previous association) in the authentication Msg1 and Msg3, and the ID information (assigned from the previous association) in the authentication Msg1 or Msg3. Thus, in the authentication Msg1 and / or the authentication Msg3, the STA is always identified.
[0213] 2) The STA always obtains new identification information (ID or RMA generated and assigned by the AP) in the authentication Msg2. In addition, the authentication Msg2 may also include status information indicating identification success / failure.
[0214] The identification information may be optionally encrypted in the authentication Msg1, Msg2, and Msg3 whenever possible.
[0215] As Figure 11b shown, for the identification initiated by the STA (category 2), the first association process may include the following steps.
[0216] 1) The unassociated STA first sends the authentication Msg1 to the AP. This message consists of the initialization of the FTM process and the relevant information for key generation.
[0217] 2) After the AP receives the authentication Msg1, the AP accordingly derives its security keys (PMK and PTK). The AP replies with the authentication Msg2.
[0218] 3) After the STA receives the authentication Msg2, the STA derives the security keys (the same PMK and PTK), generates the identification information (ID or RMA, depending on the identification scheme), encrypts this information as an information element (IE) in the authentication Msg3 payload, and sends the IE to the AP. This identification information will be used by the STA in a later association.
[0219] 4) The AP receives the authentication Msg3, decrypts it and obtains the identification information (ID or RMA). The authentication process ends with the authentication Msg3.
[0220] Then, any later association may include the following steps.
[0221] 1) The STA wishes to restart the FTM process with another MAC address; therefore, it first starts the authentication frame exchange with a random MAC (RMA). Since the previous association assigned identification information (ID or RMA) to the AP, the STA uses this identification information (ID / RMA) in the authentication Msg1 and / or Msg3 as follows.
[0222] 1.1) If the STA uses the RMA identification, the STA uses the RMA information (assigned in the previous association) in the authentication Msg1. Thus, in the authentication Msg1, the STA is always identified.
[0223] 1.2) If the STA uses the ID identification, the STA uses the ID information (assigned in the previous association) in the authentication Msg3. Thus, in the authentication Msg3, the STA is always identified.
[0224] 1.3) If the STA uses both the RMA identifier and the ID identifier, the STA uses the RMA information (generated in the previous association) in the authentication Msg1 and the ID information (assigned in the previous association) in the authentication Msg3. Thus, in the authentication Msg1 and / or authentication Msg3, the STA is always identified.
[0225] 2) The authentication Msg2 may include status information for indicating identification success / failure.
[0226] 3) The STA always assigns new identification information (ID or RMA generated and assigned by the STA) in the authentication Msg3.
[0227] It should be noted that in each scenario, the identification information (including such RMA, ID) can be carried in both MSG1 and MSG3.
[0228] Figure 12 is a diagram summarizing the identification process categories and the authentication frames at which unassociated STAs are identified.
[0229] As Figure 12 shown, for identification, whether network-initiated identification (category 1) or STA-initiated identification (category 2), the STA can be identified. For the assigned ID, the STA can be identified in Msg1 or Msg3. Alternatively, for the assigned RMA, the STA can be identified in Msg1 or Msg3.
[0230] In addition, for example, in some scenarios, the identification process can be referred to as the random MAC (RMA) identification process as Figure 12 shown, and thus the identification information can also be referred to as RMA identification information.
[0231] Additional detailed embodiments for category 1 (network-initiated identification) and category 2 (STA-initiated identification) will be described below.
[0232] Furthermore, the detailed embodiments will further provide details for implementing the proposed process, such as: creating information elements (IEs) to carry relevant identification information (ID and RMA) in the authentication frame; adding status information to the feedback regarding identification; resolving the situation of multiple FTM sessions from unassociated STAs.
[0233] The current identification solution for 802.11bh utilizes the 4-way handshake. However, during the FTM process, an unassociated STA never enters the 4-way handshake and thus never participates in the identification process. Therefore, an unassociated STA during the FTM process is never identified by the network. Accordingly, an exemplary embodiment can provide an identification process in the authentication frame exchange in the PASN. Note that the PASN utilizes 3 authentication message exchanges. It should also be noted that the PASN generates the necessary security keys for encryption in the authentication frame (specifically, the AP can encrypt for authentication Msg2, and the STA can encrypt for authentication Msg3. In some scenarios, authentication Msg1 cannot be encrypted).
[0234] By leveraging the advantages of the authentication frame exchange for identification, when the STA uses a random MAC (RMA), the network (AP) can identify the unassociated STA.
[0235] In this context, as explained according to Figure 11a , Figure 11b , and Figure 12 , the 802.11bh identification process can be divided into two categories: 1 - network-initiated RMA identification; 2 - STA-initiated RMA identification
[0236] It can be recalled that Figure 11a , Figure 11b , and Figure 12 to give an overall view of the identification schemes for these two categories.
[0237] The detailed signaling flows for Category 1 identification and Category 2 identification will be described. The necessary information elements (IEs) for carrying the identification information (ID and RMA) will be described. The status information regarding the feedback on identification will be introduced. Multiple FTM sessions of unassociated STAs will also be described.
[0238] The following embodiment demonstrates the detailed signaling flows for: Category 1 - network-assigned ID and network-assigned RMA, and Category 2 - STA-assigned ID and STA-assigned RMA and the parameters assigned by the STA to generate the same RMA.
[0239] Figure 13 is a diagram showing the proposed exchange sequence between the AP and the STA according to an exemplary embodiment, which is used to identify an unassociated STA in FTM for a network-assigned ID.
[0240] As Figure 13 shown, this embodiment covers the solution where the network (AP) generates the ID and assigns the ID to the STA.
[0241] The first association includes the following steps.
[0242] 1) The unassociated STA first sends an authentication Msg1 to the AP. This message consists of the initialization of the FTM process and the relevant information for key generation.
[0243] 2) After the AP receives the authentication Msg1, the AP accordingly derives the security keys (PMK and PTK). At this time, since the AP has the security keys, the AP can now encrypt the authentication Msg2 payload. Therefore, the AP generates identification information (ID), encrypts this information as an information element (IE) in the authentication Msg2 payload, and sends the IE to the STA. This identification information will be used by the STA in a later association.
[0244] 3) After the STA receives the authentication Msg2, the STA derives its security keys (the same PMK and PTK). Here, since the STA also has the security keys, the STA can decrypt the payload of the authentication Msg2. Therefore, the STA decrypts and obtains the identification information (such as ID) for future use. Note that since only the STA and the AP have the relevant security keys, only they can decrypt the identification information (no third party can access this information).
[0245] 4) After obtaining the ID information, the STA sends an authentication Msg3 to complete the authentication process and enters the FTM process.
[0246] Any later association may include the following steps.
[0247] 1) The STA wishes to restart the FTM process with another MAC address; therefore, the STA first starts an authentication frame exchange with a random MAC (RMA). Here, the STA uses an unidentifiable RMA in its MAC header. Since the previous association assigned identification information (ID) to the STA, the STA uses this identification information (ID) in the authentication Msg1 or Msg3. Therefore, in the authentication Msg1 or Msg3, the STA is always identifiable.
[0248] 2) The STA always obtains new identification information (ID generated and assigned by the AP) in the authentication Msg2.
[0249] Figure 14 FIG. is a diagram showing the proposed exchange sequence between an AP and a STA according to an exemplary embodiment, the exchange sequence being used to identify an unassociated STA in FTM for a network - assigned RMA.
[0250] As Figure 14 shown, this embodiment covers a solution in which the network (AP) generates an RMA and assigns the RMA to the STA.
[0251] The first association may include the following steps.
[0252] 1) The unassociated STA first sends an authentication Msg1 to the AP. This message consists of the initialization of the FTM process and the relevant information for key generation.
[0253] 2) After the AP receives the authentication Msg1, the AP accordingly derives the security keys (PMK and PTK). At this time, since the AP has the security keys, the AP can now encrypt the authentication Msg2 payload. Therefore, the AP generates identification information (such as RMA), encrypts this information as an information element (IE) in the authentication Msg2 payload, and sends this IE to the STA. This RMA information will be used by the STA in a later association.
[0254] 3) After the STA receives the authentication Msg2, the STA derives its security keys (the same PMK and PTK). Here, since the STA also has the security keys, it can decrypt the payload of the authentication Msg2. Therefore, the STA decrypts and obtains the identification information (RMA) for future use. Note that since only the STA and the AP have the relevant security keys, only they can decrypt the identification information (no third party can access this information).
[0255] 4) After obtaining the RMA information, the STA sends an authentication Msg3 to complete the authentication process and enters the FTM process.
[0256] Any later association may include the following steps.
[0257] 1) The STA wishes to restart the FTM process with another MAC address; therefore, the STA first starts an authentication frame exchange using a random MAC (RMA). Since the previous association assigned identification information (RMA) to the STA, the STA uses this identification information (RMA) in the authentication Msg1. Note that this identification information (RMA) is an identifiable RMA used in the MAC header. Therefore, in the authentication Msg1, the STA is always identifiable. This identification information (RMA) can also be used in Msg3.
[0258] 2) The STA always obtains new identification information (RMA generated and assigned by the AP) in the authentication Msg2. In addition, the authentication Msg2 may also include status information indicating the success / failure of identification.
[0259] Figure 15FIG. is a diagram showing a proposed exchange sequence between an AP and an STA according to an exemplary embodiment, the exchange sequence being for identifying an unassociated STA in FTM with an ID assigned to the STA.
[0260] As Figure 15 shown, this embodiment covers solutions in which the STA generates an ID and an ID is assigned to the STA.
[0261] The first association may include the following steps.
[0262] 1) The unassociated STA first sends an authentication Msg1 to the AP. This message consists of the initialization of the FTM process and relevant information for key generation.
[0263] 2) After the AP receives the authentication Msg1, the AP accordingly derives its security keys (PMK and PTK). At this time, since the AP has the security keys, the AP replies with the authentication Msg2.
[0264] 3) After the STA receives the authentication Msg2, the STA derives its security keys (the same PMK and PTK). Here, since the STA also has the security keys, the STA can encrypt the authentication Msg3. Therefore, the STA generates identification information (ID), encrypts this information as an information element (IE) in the authentication Msg3 payload, and sends the IE to the AP. This identification information will be used by the STA in a later association.
[0265] 4) The AP receives the authentication Msg3, decrypts it and obtains the identification information (ID). The authentication process ends with the authentication Msg3.
[0266] In addition, as Figure 15 shown, identification information (such as ID) may also be included in Msg1.
[0267] Any later association may include the following steps.
[0268] 1) The STA wishes to restart the FTM process with another MAC address; therefore, the STA first starts an authentication frame exchange with a random MAC (RMA). Here, the STA uses an unidentifiable RMA in its MAC header. Since the previous association assigned identification information (ID) to the AP, the STA can use this identification information (ID) in the authentication Msg1 or Msg3. Therefore, in the authentication Msg1 or Msg3, the STA is always identified.
[0269] 2) The STA always assigns new identification information (ID or RMA generated and assigned by the STA) in the authentication Msg1 or Msg3.
[0270] Figure 16 FIG. Figure 16 is a diagram showing a proposed exchange sequence between an AP and an STA according to an exemplary embodiment, the exchange sequence being for identifying an unassociated STA in FTM for an RMA assigned to the STA.
[0271] As Figure 16 shown, this embodiment covers a solution in which a network STA generates an RMA and assigns the RMA to the AP. Note that when the IRMA generates an RMA and sends the RMA to the AP, the RRCM sends relevant parameters to the AP, such as a seed, an RMA number, a timer, a predefined equation, a private key, a public key, a private ID, a public ID, a public MAC address, time information, any additional private / public data, so that the AP and the STA can generate the same RMA.
[0272] The first association may include the following steps.
[0273] 1) The unassociated STA first sends an authentication Msg1 to the AP. This message consists of an initialization for the FTM process and relevant information for key generation.
[0274] 2) After the AP receives the authentication Msg1, the AP accordingly derives its security keys (PMK and PTK). At this time, since the AP has the security keys, the AP replies with an authentication Msg2.
[0275] 3) After the STA receives the authentication Msg2, the STA derives its security keys (the same PMK and PTK). Here, since the STA also has the security keys, it can encrypt the authentication Msg3. Therefore, the STA generates identification information (RMA), encrypts this information as an information element (IE) in the authentication Msg3 payload, and sends the IE to the AP. This identification information will be used by the STA in a later association.
[0276] 4) The AP receives the authentication Msg3, decrypts it and obtains the identification information (RMA). The authentication process ends with the authentication Msg3.
[0277] In addition, as Figure 16 shown, the identification information (RMA) may also be included in Msg1.
[0278] Any later association may include the following steps.
[0279] 1) The STA wishes to restart the FTM process using another MAC address; thus, the STA first starts the authentication frame exchange using a Random MAC (RMA). Since the previous association assigned identification information (RMA) to the AP, the STA uses this identification information (RMA) in the authentication Msg1. Note that this identification information (RMA) is an identifiable RMA used in the MAC header. Thus, in the authentication Msg1, the STA is always identifiable. This identification information (RMA) can also be used in Msg3.
[0280] 2) The authentication Msg2 may include status information indicating authentication success / failure.
[0281] 3) The STA always allocates new identification information (ID or RMA generated and allocated by the STA) in the authentication Msg1 or Msg3.
[0282] The proposed information element (RMA identification information) for the authentication frame carrying the identification (ID or RMA) information will be further described below.
[0283] Figure 17a is a diagram showing the proposed information element order in the authentication frame according to an embodiment of the present disclosure.
[0284] Figure 17b is a diagram showing the proposed information element definition according to an embodiment of the present disclosure.
[0285] Figure 17c is a diagram showing the proposed RMA identification information element format according to an embodiment of the present disclosure.
[0286] As Figure 17a shown, the proposed identification scheme utilizes the authentication frame exchange. That is, the identification information (ID or RMA) should be placed in the authentication frame. To achieve this, this embodiment proposes an information element (IE) in the authentication frame body. This IE can be called the RMA identification information IE.
[0287] Current 802.11 REVme_D1.3 defines 24 items in the authentication frame body (see Table 9.68 in 802.11 REVme-D1.3). As Figure 17a shown, the proposed information element order is: order = 25 or other values. This field carries the identification information (ID or RMA) for the unassociated STA in the FTM process.
[0288] Current 802.11 REVme_D1.3 also defines many information elements (Table 9-128 - Element ID in 802.11 REVme-D1.3). As Figure 17bAs shown, the proposed information element is: Element ID = 255, Element ID Extension = 94, Extensible = No, Segmentable = No. If some new element IDs are inserted in the 802.11 specification according to the actual implementation, the IDs can be changed accordingly.
[0289] An exemplary format for the proposed RMA identification information element can be: Element, Length, Element ID Extension, RMA Identification Information, as Figure 17c shown. Specifically, the information element can be used to include: 1) Random MAC Address (RMA); and / or 2) ID; and / or 3) Parameters for generating the RMA or ID (such as a key, MAC, time information, seed, or any other parameter described above).
[0290] Figure 18 is a diagram showing the proposed status information in the status code field in the authentication frame according to an embodiment of the present disclosure.
[0291] Figure 19 is a diagram showing the proposed status information in the RMA identification information incorporated into the authentication frame according to an embodiment of the present disclosure.
[0292] This embodiment defines a feedback mechanism for the identification process. More specifically, the proposed identification mechanism generates identification information (ID or RMA) from the STA in the authentication frame exchange and assigns the identification information (ID or RMA) to the STA. However, there is no feedback mechanism to specify the success or failure of the identification process. In this regard, it is proposed to add "status information" to the identification process in one of the following two ways: extending the status code already existing in the authentication frame (as Figure 18 shown), extending the "RMA Identification Information" field defined in the authentication frame body (as Figure 19 shown).
[0293] Status codes have been defined for management frames, which include authentication frames (see Figure 17a - Sequence: 3).
[0294] The current 802.11 REVme_D1.3 defines 129 status codes (see Table 9.78 in 802.11 REVme-D1.3). There are many reserved status code fields, which are used for the proposed identification process. As Figure 18 shown, it is proposed to add relevant status information to this field.
[0295] This field can include several relevant status information for the identification scheme of unassociated STAs. As an example, some of these fields can at least include the values shown in the following table.
[0296] Status Code Name Meaning 130 UNKNOWN_ID The assigned identification information (ID) is unknown. 131 UNKNOWN_RMA The assigned identification information (RMA) is unknown. 132 KNOWN_ID The assigned identification information (ID) is known. 133 KNOWN_RMA The assigned identification information (RMA) is known.
[0297] If status code 130 or status code 131 is sent, it indicates that the identification fails; if status code 132 or status code 133 is sent, the identification is successful.
[0298] As Figure 19 shown, an example of the status information bits incorporated into the identification information can be illustrated.
[0299] The status information can be incorporated into the RMA identification information field. Some control bits can be added to the identification information to indicate the status information regarding the process.
[0300] If 000 or 001 is sent in the status information, the identification fails. If 002 or 003 is sent in the status information, the identification is successful.
[0301] It should be noted that other codes, names, and meanings can also be configured according to the actual implementation.
[0302] Figure 20 is a diagram showing multiple FTM sessions, where the STA establishes multiple FTM sessions with APs in the same ESS.
[0303] As Figure 20 shown, an example where the STA establishes multiple FTM sessions with the same ESS via using different RMAs can be illustrated.
[0304] This embodiment solves the identification for the multi-session FTM process. The multi-session FTM process occurs when STAs with different RMAs simultaneously establish more than one FTM session with multiple APs in the same ESS. AP1, AP2, and AP3 can belong to the same ESS.
[0305] The STA can establish Session 1 with AP1, Session 2 with AP2, and Session 3 with AP3.
[0306] When establishing multiple FTM sessions, the STA or the AP can generate multiple identification information to be used in each session. A single identification information can be used between the STA and the AP, or multiple identification information can be used between the STA and the AP.
[0307] Figure 21 is a diagram showing an example of the use of a single identification for multi-session FTM according to an embodiment of the present disclosure.
[0308] As Figure 21 shown, a method in which the STA and the AP establish a single identification information can be shown.
[0309] To establish a first FTM session, the STA first sends an authentication request to a specific AP (such as AP1) in the ESS. In the authentication frame exchange, the STA establishes a single identification information (single ID or single RMA) (the ESS grants the single identification information to the STA, or the STA grants the single identification information to the ESS), and starts the FTM process.
[0310] Then, the STA starts to establish a second FTM session by sending an authentication request to another AP (such as AP2) in the ESS. During this authentication frame exchange, the STA uses the identification information granted in the previous authentication frame exchange from the first session.
[0311] When the STA wants to start another FTM session (for example, the third FTM session with AP3), if the ESS does not grant new identification information to the STA in the second session, or the STA does not grant new identification information in the second session, the STA must use the same identification (granted in the first session) in the third session. If the ESS grants new identification information to the STA in the second session, or the STA grants new identification information in the second session, the STA uses the identification granted in the second session.
[0312] As Figure 21 shown, in the first FTM session, the STA is granted ID1. In the second FTM session, the STA uses ID1 (granted from the first session). In the second session, if new identification information (ID2) is not granted, the STA uses ID1 for the third session. If new identification information (ID2) is granted, the STA uses ID2 for the third session.
[0313] Figure 22 is a diagram showing an example of multi-identification usage for multi-session FTM according to an embodiment of the present disclosure.
[0314] As Figure 22 shown, the method by which the STA and the AP establish multiple identification information can be illustrated.
[0315] To establish a first FTM session, the STA first sends an authentication request to a specific AP (such as AP1) in the ESS. In the authentication frame exchange, the STA establishes multiple identification information (multiple IDs or multiple RMAs) (the ESS grants the multiple identification information to the STA, or the STA grants the multiple identification information to the ESS), and starts the FTM process.
[0316] Then, the STA starts to establish a second FTM session by sending an authentication request to another AP (such as AP2) in the ESS. During this authentication frame exchange, the STA uses one of the multiple identification information granted in the first session.
[0317] When the STA wants to start another FTM session (e.g., the third FTM session with AP3), the STA uses another multi-identity information granted in the first session.
[0318] As Figure 22 shown, in the first FTM session, the STA is granted ID1 and ID2. In the second FTM session, the STA uses ID1 (granted from the first session). In the third session, the STA uses ID2 (granted from the first session).
[0319] It should be understood that the above embodiments are for illustration only and not for limitation. Without departing from the basic characteristics of the present disclosure, the present disclosure can be implemented in other ways than those specifically described herein. All changes to these embodiments are intended to be included herein without departing from the meaning and equivalence of the appended claims.
[0320] References
[0321] 802.11bh Draft (D0.2), Reference: IEEE P802.11bh TM D0.2, May 2022, Draft Standard for Information technology - Telecommunications and information exchange between systems Local and metropolitan area networks - Specific requirements, Part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications, Amendment 7: Randomized and Changing MAC Addresses (Draft Standard for Information technology - Telecommunications and information exchange between systems Local and metropolitan area networks - Specific requirements, Part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications, Amendment 7: Randomized and Changing MAC Addresses), Prepared by the IEEE Computer Society LAN / MAN Standards Committee, 802.11 Working Group.
[0322] 802.11az, Reference: IEEE P802.11az TM / D7.0, September 2022, Draft Standard for Information technology - Telecommunications and information exchange between systems Local and metropolitan area networks - Specific requirements, Part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications, Amendment 4: Enhancements for positioning (Draft Standard for Information Technology - Telecommunications and Information Exchange between Systems - Local and Metropolitan Area Networks - Specific Requirements, Part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications, Amendment 4: Enhancements for Positioning), prepared by the IEEE LAN / MAN Standards Committee, 802.11 Working Group.
[0323] 802.11REVme_D1.3, Reference: IEEE P802.11 - REVme TM / D1.3, June 2022, Draft Standard for Information technology - Telecommunications and information exchange between systems Local and metropolitan area networks - Specific requirements / D1.3, June 2022, Part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications (Draft Standard for Information Technology - Telecommunications and Information Exchange between Systems - Local and Metropolitan Area Networks - Specific Requirements, Part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications), prepared by the IEEE Computer Society LAN / MAN Standards Committee, 802.11 Working Group.
[0324] [22 / 0296r8], Reference: IEEE 802.11 - 22 / 296r8, TGbh Proposal, Date: 2022 - 02 - 22, Jouni Malinen, Qualcomm, etc.
[0325] [22 / 187r2], Reference: IEEE 802.11-22 / 0187r2, Network generated Device ID, Date: 2022-03-10, Jouni Malinen, Qualcomm.
[0326] [22 / 925r2], Reference: IEEE 802.11-22 / 0925r2, Proposed Text for MAAD for TGbh Draft 0.2, Date: 2022-07, Graham SMITH (SRTWireless).
[0327] [22 / 895r1], Reference: IEEE 802.11-22 / 0895r1, Proposed Text for Identifiable Random MAC, IRM-3, Date: 2022-06, Graham SMITH (SRT Wireless).
[0328] [22 / 888r2], Reference: IEEE 802.11-22 / 0888r2, Rule-based random MAC STA identification (RRCM), Date: 2022-06-12, Orhan Okan Mutgan, Nokia, etc.
[0329] Abbreviation Explanation
[0330] AP: Access Point
[0331] FTM: Fine Timing Measurement
[0332] IE: Information Element
[0333] PASN: Pre-Association Security Negotiation
[0334] PMK: Pairwise Master Key
[0335] PTK: Pairwise Temporary Key
[0336] RCM: Random and Changing MAC
[0337] RMA: Random MAC Address
[0338] STA: Station
[0339] ESS: Extended Service Set
[0340] MAAD: MAC Address Assignment
[0341] IRMA: Identifiable Random MAC Address
[0342] RRCM: Rule-based Random and Changing MAC Address
Claims
1. A first device (50), comprising components (510) configured for: Performing a first authentication process between the first device (50) and a second device (70) in a wireless local area network; Wherein first identification information of the first device (50) is assigned during the first authentication process.
2. The first device (50) according to claim 1, Wherein the first identification information includes an identification information element IE, and the identification IE indicates: a first identifier ID of the first device (50), or a first random media access control address RMA of the first device (50).
3. The first device (50) according to claim 1 or 2, wherein the first authentication process performed by the first device (50) includes: Sending a first message of the first authentication process to the second device (70); Receiving a second message of the first authentication process from the second device (70); And Sending a third message of the first authentication process to the second device (70).
4. The first device (50) according to claim 3, Wherein the first identification information of the first device (50) is assigned by the second device (70); and Wherein the first device (50) receives from the second device (70): the first identification information of the first device (50) in the second message of the first authentication process, or at least one parameter for generating the first identification information based on a predefined equation.
5. The first device (50) according to claim 3, Wherein the first identification information of the first device (50) is assigned by the first device (50).
6. The first device (50) according to claim 5, Wherein the first device (50) sends the first identification information of the first device (50) to the second device (70) in the first message or the third message of the first authentication process; or Wherein the first device (50) sends to the second device (70): one or more parameters for the first device (50) and the second device (70) to generate the same first identification information based on a predefined equation.
7. The first device (50) according to any one of claims 1 to 6, Wherein the first device (50) further performs a second authentication process between the first device (50) and the second device (70).
8. The first device (50) according to claim 7, Wherein the first device (50) sends a first message of the second authentication process to the second device (70), and the first message includes: The first identification information of the first device (50); And / or Wherein the first device (50) sends a third message of the second authentication process to the second device (70), and the third message includes: the first identification information of the first device (50).
9. The first device (50) according to claim 8, wherein the first device (50) receives a second message of the second authentication process from the second device (70), the second message including: Second identification information, or at least one parameter for generating the second identification information based on a predefined equation; Or Wherein the first device (50) sends the third message of the second authentication process to the second device (70), and the third message includes second identification information.
10. The first device (50) according to claim 8 or 9, The second message of the second authentication process further includes: A status code used to indicate the success or failure of the identification of the first device (50).
11. The first device (50) according to any one of claims 1 to 10, Wherein the wireless local area network operates according to the 802.11 standard; Wherein the first device (50) includes a non-access point station STA; Wherein the second device (70) includes an access point AP; and Wherein the first device (50) is not associated with the second device (70).
12. The first device (50) according to any one of claims 2 to 11, Wherein the second device (70) is the first AP in an extended service set ESS; and Wherein, the ESS further includes: A second AP and a third AP.
13. The first device (50) according to claim 12, Wherein the first device (50) uses the first identification information or the second identification information during a third authentication process between the first device (50) and the second AP; and Wherein the first device (50) uses the first identification information or the second identification information during a fourth authentication process between the first device (50) and the third AP.
14. The first device (50) according to claim 12, Wherein the first device (50) uses the first identification information or the second identification information during a third authentication process between the first device (50) and the second AP; and Wherein the first device (50) obtains third identification information during the third authentication process between the first device (50) and the second AP; and Wherein the first device (50) uses the third identification information during a fourth authentication process between the first device (50) and the third AP.
15. The first device (50) according to claim 12, Wherein the first identification information and the fourth identification information of the first device (50) are assigned during the first authentication process; Wherein the first device (50) uses the first identification information during a third authentication process between the first device (50) and the second AP; and Wherein the first device (50) uses the fourth identification information during a fourth authentication process between the first device (50) and the third AP.
16. The first device (50) according to any one of claims 1 to 15, wherein the component (510) includes: At least one processor (512); And At least one memory (514), and the at least one memory (514) stores instructions, and when the instructions are executed by the at least one processor (512), the execution of the first device (50) is caused.
17. A method executed by a first device (50), including: Perform a first authentication process between the first device (50) and the second device (70) in a wireless local area network; Wherein first identification information of the first device (50) is assigned during the first authentication process.
18. The method according to claim 17, Wherein the method is performed by the first device (50) according to any one of claims 1 to 16.
19. A second device (70), comprising components (710) configured for: Perform a first authentication process between the first device (50) and the second device (70) in a wireless local area network; Wherein first identification information of the first device (50) is assigned during the first authentication process.
20. The second device (70) according to claim 19, Wherein the first identification information includes an identification information element IE, and the identification IE indicates: the first identifier ID of the first device (50), or the first random media access control address RMA of the first device (50).
21. The second device (70) according to claim 19 or 20, wherein the first authentication process performed by the second device (70) includes: Receiving a first message of the first authentication process from the first device (50); Sending a second message of the first authentication process to the first device (50); And Receiving a third message of the first authentication process from the first device (50).
22. The second device (70) according to claim 21, Wherein the first identification information of the first device (50) is assigned by the second device (70); and Wherein the second device (70) sends to the first device (50): the first identification information of the first device (50) in the second message of the first authentication process, or at least one parameter for generating the first identification information based on a predefined equation.
23. The second device (70) according to claim 21, Wherein the first identification information of the first device (50) is assigned by the first device (50).
24. The second device (70) according to claim 23, Wherein the second device (70) receives the first identification information of the first device (50) from the first device (50) in the first message or the third message of the first authentication process; or Wherein the second device (70) receives from the first device (50): one or more parameters for the first device (50) and the second device (70) to generate the same first identification information based on a predefined equation.
25. The second device (70) according to any one of claims 19 to 24, Wherein the second device (70) further performs a second authentication process between the first device (50) and the second device (70).
26. The second device (70) according to claim 25, wherein the second device (70) receives a first message of the second authentication process from the first device (50), the first message comprising: The first identification information of the first device (50); And / or Wherein the second device (70) receives a third message of the second authentication process from the first device (50), and the third message includes: the first identification information of the first device (50).
27. The second device (70) according to claim 26, wherein the second device (70) sends a second message of the second authentication process to the first device (50), and the second message includes: second identification information, or at least one parameter for generating the second identification information based on a predefined equation; Or Wherein the second device (70) receives the first message or the third message of the second authentication process from the first device (50), and the first message or the third message includes the second identification information.
28. The second device (70) according to claim 26 or 27, The second message of the second authentication process further includes: A status code for indicating success or failure of the identification of the first device (50).
29. The second device (70) according to any one of claims 26 to 28, Wherein the wireless local area network operates according to the 802.11 standard; Wherein the first device (50) includes a non-access point station STA; Wherein the second device (70) includes an access point AP; and Wherein the first device (50) is not associated with the second device (70).
30. The second device (70) according to any one of claims 20 to 29, Wherein the second device (70) is the first AP in an extended service set ESS; and Wherein the ESS further includes: A second AP and a third AP.
31. The second device (70) according to claim 30, Wherein the first device (50) uses the first identification information or the second identification information during a third authentication process between the first device (50) and the second AP; and Wherein the first device (50) uses the first identification information or the second identification information during a fourth authentication process between the first device (50) and the third AP.
32. The second device (70) according to claim 30, Wherein the first device (50) uses the first identification information or the second identification information during a third authentication process between the first device (50) and the second AP; and Wherein the first device (50) obtains third identification information during the third authentication process between the first device (50) and the second AP; and Wherein the first device uses the third identification information during a fourth authentication process between the first device (50) and the third AP.
33. The second device (70) according to claim 30, Wherein the first identification information and the fourth identification information of the first device (50) are assigned during the first authentication process; Wherein the first device (50) uses the first identification information during a third authentication process between the first device (50) and the second AP; and Wherein the first device (50) uses the fourth identification information during a fourth authentication process between the first device (50) and the third AP.
34. The second device (70) according to any one of claims 19 to 33, wherein the component (710) comprises: at least one processor (712); and at least one memory (714), the at least one memory (714) storing instructions which, when executed by the at least one processor (712), cause the second device (70) to perform.
35. A method performed by a second device (70), comprising: performing a first authentication process between a first device (50) and the second device (70) in a wireless local area network; wherein first identification information of the first device (50) is assigned during the first authentication process.
36. The method according to claim 35, wherein the method is performed by the second device (70) according to any one of claims 19 to 34.
37. A computer-readable storage medium (90) storing instructions (91) which, when executed by at least one processor of a first device (50), cause the at least one processor of the first device (50) to perform a first authentication process between the first device (50) and a second device (70) in a wireless local area network; or the instructions, when executed by at least one processor of the second device (70), cause the at least one processor of the second device (70) to perform a first authentication process between the first device (50) and the second device (70) in a wireless local area network; wherein first identification information of the first device (50) is assigned during the first authentication process.
38. The computer-readable storage medium according to claim 37, wherein the instructions are executed by at least one processor of the first device (50) according to any one of claims 2 to 16; or wherein the instructions are executed by at least one processor of the second device (70) according to any one of claims 20 to 34.