Method and apparatus for privacy mechanism in wireless networks

By exchanging information between terminal devices and network nodes in a wireless network, the problem of inflexible use of privacy capabilities in existing technologies is solved, enabling flexible selection and adaptation of network node privacy capabilities and improving the efficiency of privacy protection.

CN121241589APending Publication Date: 2025-12-30ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380098922.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-05-31
Publication Date
2025-12-30

AI Technical Summary

Technical Problem

In wireless networks, existing technologies lack flexible privacy mechanisms to adapt to different types of terminal devices and network nodes, resulting in insufficient flexibility and uniformity in the use of privacy capabilities.

Method used

By exchanging information between terminal devices and network nodes, multiple privacy capabilities of network nodes can be acquired and selected. Privacy capabilities are discovered and selected using messages such as beacon frames, operation frames, probe responses, General Advertisement Service initial responses, authentication response frames, and four-way handshake response frames.

Benefits of technology

It enables flexible selection and adaptation of network node privacy capabilities, making it suitable for complex network scenarios and improving the flexibility and efficiency of privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121241589A_ABST
    Figure CN121241589A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a method and apparatus for a privacy mechanism in a wireless network. A method (900) performed by a terminal device comprises: obtaining (S902) information indicating multiple privacy capabilities of a network node; and selecting (S904) zero or at least one of the plurality of privacy capabilities. According to embodiments of the present disclosure, after obtaining (i.e., discovering) privacy capabilities of a network node, one of the privacy capabilities may be flexibly selected. The mechanism is more suitable for complex network scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various exemplary embodiments disclosed herein generally relate to communication technologies, and more particularly to methods and apparatus for privacy mechanisms in wireless networks. Background Technology

[0002] In wireless networks, it is necessary to provide the ability to protect the privacy information of communication devices (such as terminal devices and network nodes).

[0003] Network nodes (such as access points (APs) in a wireless local area network (WLAN)) can provide privacy capabilities to terminal devices (such as non-AP STAs). In ongoing research within the standard, terminal devices may be permitted to use only all privacy capabilities provided by the AP, or may be prohibited from using any privacy capabilities at all.

[0004] However, flexibility in privacy mechanisms is also needed because many different kinds of privacy capabilities may be developed and many different kinds of end devices may be deployed in the network. Summary of the Invention

[0005] This invention is provided to present, in a simplified form, some aspects further described below in the detailed description. This disclosure is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter.

[0006] Certain aspects of this disclosure and its embodiments can provide solutions to these or other challenges. Various embodiments are presented herein to address one or more problems disclosed herein. Specific methods and apparatus for privacy mechanisms in wireless networks can be provided.

[0007] A first aspect of this disclosure provides a method performed by a terminal device. The method includes: acquiring information indicating a plurality of privacy capabilities of a network node; and selecting zero or at least one of the plurality of privacy capabilities.

[0008] In an exemplary embodiment of this disclosure, obtaining information includes: receiving a first message from a network node indicating multiple privacy capabilities of the network node.

[0009] In an exemplary embodiment of this disclosure, the first message includes at least one of the following: a beacon frame, an operation frame, a probe response, a General Notification Service (GAS) initial response, an authentication response frame, an association response frame, or a four-way handshake response frame.

[0010] In an exemplary embodiment of this disclosure, the method further includes sending a second message to a network node to request the network node's privacy capabilities. The first message is a response to the second message.

[0011] In an exemplary embodiment of this disclosure, the second message includes at least one of the following: an operation frame, a probe request, a General Notification Service (GAS) initiation request, an authentication request frame, an association request frame, or a four-way handshake request frame.

[0012] In an exemplary embodiment of this disclosure, the first message and / or the second message includes at least one of the following related to the privacy capabilities of the network node: capability information field, robust secure network information element (RSNE), extended capability information element, robust secure network extended information element (RSNXE), privacy capability selection information element, access network query protocol (ANQP) element, or privacy capability selection key data encapsulation / four-way handshake field.

[0013] In exemplary embodiments of this disclosure, the first message and / or the second message may be encrypted or unencrypted.

[0014] In an exemplary embodiment of this disclosure, the terminal device makes the selection based at least on its local configuration. The method further includes sending a third message to the network node indicating the selection.

[0015] In an exemplary embodiment of this disclosure, the third message is sent during the association process between the terminal device and the network node and before the establishment of a secure connection between the terminal device and the network node. The third message includes at least one of the following: an authentication request frame, an association request frame, a four-way handshake request frame, or an operation frame.

[0016] In an exemplary embodiment of this disclosure, the third message is sent after the association between the terminal device and the network node and after the secure connection between the terminal device and the network node is established. The third message includes at least one of the following: a deassociation frame, a deauthentication frame, or an operation frame.

[0017] In an exemplary embodiment of this disclosure, the third message includes at least one of the following to indicate the selection: a capability information field, a robust secure network information element (RSNE), an extended capability information element, a robust secure network extended information element (RSNXE), a privacy capability selection information element, a privacy capability selection key data encapsulation / four-way handshake field, or a status code or reason code in the status information.

[0018] In an exemplary embodiment of this disclosure, the third message includes at least one of the following status information: selection was at least partially successful; capability was violated; capability is unknown; capability is not supported; capability needs to be resent; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is required due to privacy violation.

[0019] In exemplary embodiments of this disclosure, the third message may be encrypted or unencrypted.

[0020] In an exemplary embodiment of this disclosure, the method further includes: receiving a fourth message from a network node to instruct a terminal device to select zero or at least one of a plurality of privacy capabilities. The terminal device makes the selection based on the fourth message from the network node.

[0021] In an exemplary embodiment of this disclosure, the fourth message is received during the association process between the terminal device and the network node and before the establishment of a secure connection between the terminal device and the network node. The fourth message includes at least one of the following: an authentication response frame, an association response frame, a four-way handshake response frame, or an operation frame.

[0022] In an exemplary embodiment of this disclosure, the fourth message is received after the association between the terminal device and the network node and after the secure connection between the terminal device and the network node is established. The fourth message includes at least one of the following: a deassociation frame, a deauthentication frame, or an operation frame.

[0023] In an exemplary embodiment of this disclosure, the fourth message includes at least one of the following to indicate the selection: a capability information field, a robust secure network information element (RSNE), an extended capability information element, a robust secure network extended information element (RSNXE), a privacy capability selection information element, a privacy capability selection key data encapsulation / four-way handshake field, or a status code or reason code in the status information.

[0024] In an exemplary embodiment of this disclosure, the fourth message includes at least one of the following status information: selection was at least partially successful; capability was violated; capability is unknown; capability is not supported; capability needs to be resent; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is required due to privacy violation.

[0025] In an exemplary embodiment of this disclosure, the fourth message may be encrypted or unencrypted.

[0026] In an exemplary embodiment of this disclosure, the terminal device includes a non-AP STA; and the network node includes an AP.

[0027] A second aspect of this disclosure provides a method performed by a network node. The method includes sending information indicating multiple privacy capabilities of the network node to a terminal device. This information is used by the terminal device to select zero or at least one of the multiple privacy capabilities.

[0028] In an exemplary embodiment of this disclosure, sending information includes sending a first message to a terminal device that indicates multiple privacy capabilities of a network node.

[0029] In an exemplary embodiment of this disclosure, the first message includes at least one of the following: a beacon frame, an operation frame, a probe response, a General Notification Service (GAS) initial response, an authentication response frame, an association response frame, or a four-way handshake response frame.

[0030] In an exemplary embodiment of this disclosure, the method further includes: receiving a second message from a terminal device for requesting privacy capabilities of a network node. The first message is a response to the second message.

[0031] In an exemplary embodiment of this disclosure, the second message includes at least one of the following: an operation frame, a probe request, a General Notification Service (GAS) initiation request, an authentication request frame, an association request frame, or a four-way handshake request frame.

[0032] In an exemplary embodiment of this disclosure, the first message and / or the second message includes at least one of the following related to the privacy capabilities of the network node: capability information field, robust secure network information element (RSNE), extended capability information element, robust secure network extended information element (RSNXE), privacy capability selection information element, access network query protocol (ANQP) element, or privacy capability selection key data encapsulation / four-way handshake field.

[0033] In exemplary embodiments of this disclosure, the first message and / or the second message may be encrypted or unencrypted.

[0034] In an exemplary embodiment of this disclosure, the method further includes: receiving a third message from a terminal device to instruct the terminal device to select zero or at least one of a plurality of privacy capabilities.

[0035] In an exemplary embodiment of this disclosure, the third message is received during the association process between the terminal device and the network node and before the establishment of a secure connection between the terminal device and the network node. The third first message includes at least one of the following: an authentication request frame, an association request frame, a four-way handshake request frame, or an operation frame.

[0036] In an exemplary embodiment of this disclosure, the third message is received after the association between the terminal device and the network node and after the secure connection between the terminal device and the network node is established. The third message includes at least one of the following: a deassociation frame, a deauthentication frame, or an operation frame.

[0037] In an exemplary embodiment of this disclosure, the third message includes at least one of the following to indicate the selection: a capability information field, a robust secure network information element (RSNE), an extended capability information element, a robust secure network extended information element (RSNXE), a privacy capability selection information element, a privacy capability selection key data encapsulation / four-way handshake field, or a status code or reason code in the status information.

[0038] In an exemplary embodiment of this disclosure, the third message includes at least one of the following status information: selection was at least partially successful; capability was violated; capability is unknown; capability is not supported; capability needs to be resent; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is required due to privacy violation.

[0039] In exemplary embodiments of this disclosure, the third message may be encrypted or unencrypted.

[0040] In an exemplary embodiment of this disclosure, the method further includes sending a fourth message to a terminal device to instruct the terminal device to select zero or at least one of a plurality of privacy capabilities.

[0041] In an exemplary embodiment of this disclosure, the fourth message is sent during the association process between the terminal device and the network node and before the establishment of a secure connection between the terminal device and the network node. The fourth message includes at least one of the following: an authentication response frame, an association response frame, a four-way handshake response frame, or an operation frame.

[0042] In an exemplary embodiment of this disclosure, the fourth message is sent after the association between the terminal device and the network node and after the secure connection between the terminal device and the network node is established. The fourth message includes at least one of the following: a deassociation frame, a deauthentication frame, or an operation frame.

[0043] In an exemplary embodiment of this disclosure, the fourth message includes at least one of the following to indicate the selection: a capability information field, a robust secure network information element (RSNE), an extended capability information element, a robust secure network extended information element (RSNXE), a privacy capability selection information element, a privacy capability selection key data encapsulation / four-way handshake field, or a status code or reason code in the status information.

[0044] In an exemplary embodiment of this disclosure, the fourth message includes at least one of the following status information: selection was at least partially successful; capability was violated; capability is unknown; capability is not supported; capability needs to be resent; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is required due to privacy violation.

[0045] In an exemplary embodiment of this disclosure, the fourth message may be encrypted or unencrypted.

[0046] In an exemplary embodiment of this disclosure, the terminal device includes a non-access point station (non-AP STA). The network node includes an access point (AP).

[0047] A third aspect of this disclosure provides a terminal device including components configured to: acquire information indicating a plurality of privacy capabilities of a network node; and select zero or at least one of the plurality of privacy capabilities.

[0048] In exemplary embodiments of this disclosure, the component is also configured to perform a method according to any embodiment of the first aspect.

[0049] In an exemplary embodiment of this disclosure, the component includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the terminal device to perform an operation.

[0050] A fourth aspect of this disclosure provides a network node including a unit configured to perform the following operation: sending information indicating multiple privacy capabilities of the network node to a terminal device. This information is used by the terminal device to select zero or at least one of the multiple privacy capabilities.

[0051] In exemplary embodiments of this disclosure, the component is also configured to perform a method according to any embodiment of the second aspect.

[0052] In an exemplary embodiment of this disclosure, the component includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause a network node to perform an operation.

[0053] A fifth aspect of this disclosure provides a computer-readable storage medium storing instructions that, when executed by at least one processor of a terminal device, cause at least one processor of the terminal device to perform a method according to any embodiment of the first aspect; or, when executed by at least one processor of a network node, cause at least one processor of the network node to perform a method according to any embodiment of the second aspect.

[0054] The embodiments described herein offer numerous advantages. According to embodiments of this disclosure, improved approaches to privacy mechanisms can be provided, particularly privacy capabilities for discovering and / or selecting network nodes.

[0055] According to embodiments of this disclosure, after acquiring (i.e., discovering) the privacy capabilities of a network node, the capabilities among these privacy capabilities can be flexibly selected. This mechanism is more suitable for complex network scenarios. Attached Figure Description

[0056] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more apparent from the following detailed description with reference to the accompanying drawings, in which the same reference numerals or letters are used to denote the same or equivalent elements. The drawings are illustrated to facilitate a better understanding of embodiments of the present disclosure and are not necessarily drawn to scale, wherein: Figure 1 This is a diagram showing a GAS frame.

[0057] Figure 2 This is a diagram illustrating the format of the notification protocol elements.

[0058] Figure 3 This is a diagram illustrating GAS and ANQP: ANQP uses GAS frames (requests / responses) to obtain information from external networks.

[0059] Figure 4(a) is a diagram showing the ANQP element format; Figure 4(b) is a diagram showing the ANQP elements that can be defined by STA for requesting information from external networks.

[0060] Figure 5 This is a diagram showing beacon frames including those associated with Hotspot S2.0 / Passpoint IEs.

[0061] Figure 6A This is a diagram showing probe requests from IEs related to Hotspot S2.0 / Passpoint.

[0062] Figure 6B This is a graph showing the detection response of IEs related to Hotspot S2.0 / Passpoint.

[0063] Figure 7A This is a diagram illustrating the initial GAS request containing information for obtaining a list of NAI domains, 3GPP cellular network information, a list of domain names, and venue name information.

[0064] Figure 7B This is a diagram showing the initial GAS response containing information about the NAI domain list, 3GPP cellular network information, domain name list, and venue name information.

[0065] Figure 8 This diagram illustrates that when an AP announces its privacy capabilities, a non-AP STA cannot (and should not) choose to enable / disable a specific privacy capability.

[0066] Figure 9A This is a flowchart illustrating a method performed by a terminal device according to an exemplary embodiment of the present disclosure.

[0067] Figure 9BThis illustrates exemplary embodiments according to the present disclosure, such as Figure 9A A flowchart of the further steps of the method shown.

[0068] Figure 9C This illustrates exemplary embodiments according to the present disclosure, such as Figure 9A A flowchart of the further steps of the method shown.

[0069] Figure 9D This illustrates exemplary embodiments according to the present disclosure, such as Figure 9A A flowchart of the further steps of the method shown.

[0070] Figure 10A This is a flowchart illustrating a method performed by a network node according to an exemplary embodiment of the present disclosure.

[0071] Figure 10B This illustrates exemplary embodiments according to the present disclosure, such as Figure 10A A flowchart of the further steps of the method shown.

[0072] Figure 10C This illustrates exemplary embodiments according to the present disclosure, such as Figure 10A A flowchart of the further steps of the method shown.

[0073] Figure 10D This illustrates exemplary embodiments according to the present disclosure, such as Figure 10A A flowchart of the further steps of the method shown.

[0074] Figure 11 This is a diagram illustrating the discovery of the proposed privacy capabilities.

[0075] Figure 12.a This is a diagram showing the capability information field in a beacon frame.

[0076] Figure 12.b This is a diagram showing the format of the capability information fields.

[0077] Figure 12.c This is a diagram showing the privacy capabilities carried in bits 16 to n (B16-Bn) of the capability information field in the beacon.

[0078] Figure 12.d This is a diagram showing the privacy capabilities carried in one or more existing reserved bits in the capability information field of the beacon.

[0079] Figure 13.a This is a diagram showing the RSN information element (RSNE) in a beacon.

[0080] Figure 13.b This is a diagram illustrating the definition and format of RSN Information Elements (RSNE).

[0081] Figure 13.c This is a diagram illustrating the privacy capabilities carried in the privacy capability field of the RSN Message Element (RSNE) in the beacon.

[0082] Figure 13.d This is a diagram illustrating the privacy capabilities carried in the RSN Capabilities field of the RSN Message Element (RSNE) in a beacon.

[0083] Figure 14.a This is a diagram showing the extended capability information elements in a beacon.

[0084] Figure 14.b This is a diagram illustrating the definition and format of the extended capability information elements.

[0085] Figure 14.c This is a diagram showing the privacy capabilities carried in the privacy capability field of the extended capability information element in the beacon.

[0086] Figure 14.d This is a diagram illustrating the privacy capabilities carried in the extension capabilities field of the extension capabilities information element in the beacon.

[0087] Figure 15.a This is a diagram showing the RSN Extended Information Element (RSNXE) in a beacon.

[0088] Figure 15.b This is a diagram illustrating the definition and format of the RSN Extended Information Element (RSNXE).

[0089] Figure 15.c This is a diagram showing the privacy capabilities carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in the beacon.

[0090] Figure 15.d This is a diagram illustrating the privacy capabilities carried in the Extended RSN Capabilities field of the RSN Extended Information Element (RSNXE) in the beacon.

[0091] Figure 16.a This is a diagram illustrating the definition of privacy capability information elements in a beacon.

[0092] Figure 16.b This is a diagram illustrating the format of privacy capability information elements.

[0093] Figure 16.c This is a diagram showing the privacy capability information elements in the beacon.

[0094] Figure 17.a This is a diagram illustrating the definition of the capability information field in the probe request frame.

[0095] Figure 17.b This is a diagram showing the capability information field in the probe response frame.

[0096] Figure 17.c This is a diagram showing the format of the capability information fields.

[0097] Figure 17.d This is a diagram showing the privacy capability request carried in bits 16 to n (B16-Bn) of the capability information field in the probe request.

[0098] Figure 17.e This is a diagram illustrating a privacy capability request carried in one or more existing reserved bits in the capability information field of a probe request.

[0099] Figure 17.f This is a diagram showing the privacy capability response carried in bits 16 to n (B16-Bn) of the capability information field in the probe response.

[0100] Figure 17.g This is a diagram illustrating the privacy capabilities carried in one or more existing reserved bits in the capability information field of the probe response. Figure 18.a This is a diagram showing the RSN Information Element (RSNE) in the probe request frame.

[0101] Figure 18.b This is a diagram showing the RSN information element (RSNE) in the probe response frame.

[0102] Figure 18.c This is a diagram illustrating the definition and format of RSN Information Elements (RSNE).

[0103] Figure 18.d This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN information element (RSNE) in a probe request.

[0104] Figure 18.e This is a diagram illustrating a privacy capability request carried in the RSN Capability field of the RSN Information Element (RSNE) in a probe request.

[0105] Figure 18.f This is a diagram showing the privacy capability response carried in the privacy capability field of the RSN information element (RSNE) in the probe response.

[0106] Figure 18.g This is a diagram showing the privacy capabilities carried in the RSN Capabilities field of the RSN Information Element (RSNE) in the probe response.

[0107] Figure 19.a This is a diagram showing the extended capability information elements in the probe request frame.

[0108] Figure 19.bThis is a diagram showing the extended capability information elements in the probe response frame.

[0109] Figure 19.c This is a diagram illustrating the definition and format of the extended capability information elements.

[0110] Figure 19.d This is a diagram illustrating the privacy capability request carried in the privacy capability field of the extended capability information element in the probe request.

[0111] Figure 19.e This is a diagram illustrating a privacy capability request carried in the extension capability field of the extension capability information element in a probe request.

[0112] Figure 19.f This is a diagram showing the privacy capability response carried in the privacy capability field of the extended capability information element in the probe response.

[0113] Figure 19.g This is a diagram illustrating the privacy capabilities response carried in the extension capabilities field of the extension capabilities information element in the probe response.

[0114] Figure 20.a This is a diagram showing the RSN Extended Information Element (RSNXE) in the probe request frame.

[0115] Figure 20.b This is a diagram showing the RSN Extended Information Element (RSNXE) in the probe response frame.

[0116] Figure 20.c This is a diagram illustrating the definition and format of the RSN Extended Information Element (RSNXE).

[0117] Figure 20.d This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in a probe request.

[0118] Figure 20.e This is a diagram illustrating a privacy capability request carried in the Extended RSN Capability field of the RSN Extended Information Element (RSNXE) in a probe request.

[0119] Figure 20.f This is a diagram showing the privacy capability response carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in the probe response.

[0120] Figure 20.g This is a diagram showing the privacy capabilities carried in the extended RSN capabilities field of the RSN extended information element (RSNXE) in the probe response.

[0121] Figure 21.aThis is a diagram illustrating the definition and format of the privacy capability request information element in a probe request.

[0122] Figure 21.b This is a diagram illustrating the definition and format of privacy capability response information elements in the detection response.

[0123] Figure 21.c This is a diagram illustrating the privacy capability request information element in a probe request.

[0124] Figure 21.d This is a diagram illustrating the privacy capability response information elements in the detection response.

[0125] Figure 22.a This is a diagram illustrating the ANQP in the initial GAS request.

[0126] Figure 22.b This is a graph showing the ANQP in the initial response of GAS.

[0127] Figure 22.c This is a diagram illustrating a privacy-capable request with ANQP obtained from the query list in the initial GAS request.

[0128] Figure 22.d This is a diagram showing the privacy-capable response with ANQP in the initial GAS response.

[0129] Figure 23.a This is a diagram showing the RSN Information Element (RSNE) in the authentication frame.

[0130] Figure 23.b This is a diagram illustrating the definition and format of RSN Information Elements (RSNE).

[0131] Figure 23.c This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN Information Element (RSNE) in an authentication request.

[0132] Figure 23.d This is a diagram illustrating a privacy capability request carried in the RSN Capability field of the RSN Information Element (RSNE) in an authentication request.

[0133] Figure 23.e This is a diagram illustrating the privacy capability response or announcement carried in the privacy capability field of the RSN Information Element (RSNE) in the authentication response.

[0134] Figure 23.f This is a diagram illustrating the privacy capabilities response or announcement carried in the RSN Capabilities field of the RSN Information Element (RSNE) in the authentication response.

[0135] Figure 24.aThis is a diagram illustrating the definition and format of the privacy capability request information element in an authentication request.

[0136] Figure 24.b A diagram showing the definition and format of privacy capability response information elements in the authentication response is provided.

[0137] Figure 24.c This is a diagram illustrating the privacy capability request information element in an authentication request.

[0138] Figure 24.d This is a diagram showing the privacy capability response information elements in the authentication response.

[0139] Figure 25.a This is a diagram showing the capability information field in the associated request frame.

[0140] Figure 25.b This is a diagram showing the capability information field in the associated response frame.

[0141] Figure 25.c This is a diagram showing the format of the capability information fields.

[0142] Figure 25.d This is a diagram illustrating the privacy capability request carried in bits 16 to n (B16-Bn) of the capability information field in the association request.

[0143] Figure 25.e This is a diagram illustrating a privacy capability request carried in one or more existing reserved bits in the capability information field of an association request.

[0144] Figure 25.f This is a diagram showing the privacy capability response or announcement carried in bits 16 to n (B16-Bn) of the capability information field in the associated response.

[0145] Figure 25.g This is a diagram showing the privacy capabilities response or announcement carried in one or more existing reserved bits in the capability information field of the associated response.

[0146] Figure 26.a This is a diagram showing the RSN Information Element (RSNE) in the association request frame.

[0147] Figure 26.b This is a diagram showing the RSN Information Element (RSNE) in the associated response frame.

[0148] Figure 26.c This is a diagram illustrating the definition and format of RSN Information Elements (RSNE).

[0149] Figure 26.d This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN Information Element (RSNE) in an association request.

[0150] Figure 26.e This is a diagram illustrating a privacy capability request carried in the RSN Capability field of the RSN Information Element (RSNE) in an association request.

[0151] Figure 26.f This is a diagram illustrating the privacy capability response or announcement carried in the privacy capability field of the RSN Information Element (RSNE) in the associated response.

[0152] Figure 26.g This is a diagram illustrating the privacy capabilities response or announcement carried in the RSN Capabilities field of the RSN Information Element (RSNE) in the associated response.

[0153] Figure 27.a This is a diagram showing the extension capability information elements in the associated request frame.

[0154] Figure 27.b This is a diagram showing the extension capability information elements in the associated response frame.

[0155] Figure 27.c This is a diagram illustrating the definition and format of the extended capability information elements.

[0156] Figure 27.d This is a diagram illustrating the privacy capability request carried in the privacy capability field of the extended capability information element in the associated request.

[0157] Figure 27.e This is a diagram illustrating a privacy capability request carried in the extension capability field of the extension capability information element in an association request.

[0158] Figure 27.f This is a diagram illustrating the privacy capability response or announcement carried in the privacy capability field of the extended capability information element in the associated response.

[0159] Figure 27.g This is a diagram illustrating the privacy capabilities response or announcement carried in the extension capabilities field of the extension capabilities information element in the associated response.

[0160] Figure 28.a This is a diagram showing the RSN Extended Information Element (RSNXE) in the association request frame.

[0161] Figure 28.b This is a diagram showing the RSN Extended Information Element (RSNXE) in the associated response frame.

[0162] Figure 28.c This is a diagram illustrating the definition and format of the RSN Extended Information Element (RSNXE).

[0163] Figure 28.dThis is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in an association request.

[0164] Figure 28.e This is a diagram illustrating a privacy capability request carried in the Extended RSN Capability field of the RSN Extended Information Element (RSNXE) in an association request.

[0165] Figure 28.f This is a diagram illustrating a privacy capability response or announcement carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in an associated response.

[0166] Figure 28.g This is a diagram showing the privacy capabilities response or announcement carried in the Extended RSN Capabilities field of the RSN Extended Information Element (RSNXE) in the associated response.

[0167] Figure 29.a This is a diagram illustrating the definition and format of the privacy capability request information element in an association request.

[0168] Figure 29.b This is a diagram illustrating the definition and format of privacy capability response information elements in an associated response.

[0169] Figure 29.c This is a diagram illustrating the privacy capability request information element in the associated request.

[0170] Figure 29.d This is a diagram showing the privacy capability response information elements in the associated response.

[0171] Figure 30 This is a diagram illustrating the privacy capability requests and responses / announcements in the reserved bit fields of the four-way handshake frames.

[0172] Figure 31 This is a diagram illustrating the privacy capability requests and responses / announcements in the KDE field of the four-way handshake frame.

[0173] Figure 32 This is a diagram illustrating the privacy capability request and response / announcement in the newly defined privacy capability request / response fields of the four-way handshake frame.

[0174] Figure 33 This is a diagram illustrating the proposed privacy capability options.

[0175] Figure 34.a This is a diagram showing the privacy capability selection carried in bits 16 to n (B16-Bn) in the capability information field.

[0176] Figure 34.bThis is a diagram showing the selection of privacy capabilities carried in one or more existing reserved bits in the capability information field.

[0177] Figure 35.a This is a diagram showing the privacy capability selection carried in the privacy capability field of the RSN Information Element (RSNE).

[0178] Figure 35.b This is a diagram illustrating the privacy capability selection carried in the RSN Capabilities field of the RSN Message Element (RSNE).

[0179] Figure 36.a This is a diagram illustrating the privacy capability selection carried in the privacy capability field within the extended capability information element.

[0180] Figure 36.b A diagram showing the privacy capability selection carried in the extension capability field of the extension capability information element is presented.

[0181] Figure 37.a This is a diagram showing the privacy capability selection carried in the privacy capability field of the RSN Extended Information Element (RSNXE).

[0182] Figure 37.b This is a diagram illustrating the privacy capability selection carried in the Extended RSN Capabilities field of the RSN Extended Information Element (RSNXE).

[0183] Figure 38 This is a diagram illustrating the definition and format of privacy capability selection information elements.

[0184] Figure 39 This is a diagram showing the privacy capability selection in the reserved bit field (1), privacy selection field (2), or privacy selection KDE (3) in the four-way handshake frame.

[0185] Figure 40.a This is a diagram showing the status codes for privacy capability selection.

[0186] Figure 40.b A diagram showing the reason codes for privacy capability selection is provided.

[0187] Figure 41 This is a diagram illustrating the privacy capability selection operation frame.

[0188] Figure 42 This is a diagram illustrating exemplary scenario 1.

[0189] Figure 43 This is a diagram illustrating exemplary scenario 2.

[0190] Figure 44 This is a block diagram illustrating an exemplary structure of a terminal device according to an exemplary embodiment of the present disclosure.

[0191] Figure 45 This is a block diagram illustrating an exemplary structure of a network node according to an exemplary embodiment of the present disclosure.

[0192] Figure 46 This is a block diagram illustrating an apparatus / computer-readable storage medium according to embodiments of the present disclosure.

[0193] Figure 47 This is a block diagram illustrating exemplary device units suitable for performing methods according to embodiments of the present disclosure in a terminal device.

[0194] Figure 48 This is a block diagram illustrating exemplary device units suitable for performing methods according to embodiments of the present disclosure in a network node. Detailed Implementation

[0195] Embodiments of this disclosure have been described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed for better understanding only and not to limit the scope of this disclosure. The features, advantages, and characteristics described in this disclosure may be combined in any suitable manner in one or more embodiments.

[0196] Generally, all terms used herein will be interpreted according to their ordinary meaning in the relevant art, unless a different meaning is clearly given and / or implied from the context in which they are used. The steps of any method disclosed herein need not be performed in the exact order disclosed unless the context clearly gives and / or implies otherwise. Where appropriate, any feature of any embodiment disclosed herein may be applied to any other embodiment.

[0197] As used herein, the term "network" or "communication network" refers to a network that conforms to any suitable communication standard (such as the Internet or any wireless network). For example, wireless communication standards may include WLAN (Wireless Local Area Network), New Radio (NR), Long Term Evolution (LTE), LTE-Advanced, 5G NR, etc. In the following description, the terms "network" and "system" are used interchangeably.

[0198] The term "network node" refers to a network device, network entity, or network function in a communication network, or any other device (physical or virtual). For example, a network node in a network can include a base station (BS), access point (AP), or any other suitable device in a wireless communication network. A BS can be, for example, a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), a next-generation Node B (gNodeB or gNB), a remote radio unit (RRU), a radio head unit (RH), a remote radio head unit (RRH), a relay, or a low-power node (such as a femtosecond, picosecond, etc.).

[0199] The term "terminal device" refers to any terminal device that can access a communication network and receive services from it. By way of example and not limitation, a terminal device refers to a mobile terminal, user equipment (UE), non-AP device (such as a non-AP STA), or other suitable device. Terminal devices can include, but are not limited to, mobile phones, cellular phones, smartphones, wearable devices, in-vehicle wireless terminal equipment, vehicles, etc.

[0200] As an example, a terminal device can refer to a device configured to communicate according to one or more communication standards published by any standards organization (e.g., the 3rd Generation Partnership Project 3GPP).

[0201] As yet another example, in the Internet of Things (IoT) scenario, a terminal device can represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another terminal device and / or network device. Specific examples of such machines or devices are sensors, metering devices (such as power meters), industrial machinery, or household appliances or personal appliances (such as refrigerators, televisions, personal wearable devices (such as watches)). In other scenarios, a terminal device can represent a vehicle or other device capable of monitoring and / or reporting its operational status or other functions associated with its operation.

[0202] It should be understood that although the terms “first” and “second” may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.

[0203] As used herein, “at least one of the following: a list of two or more elements” and “at least one of the following: a list of two or more elements” and similar wording (where the list of two or more elements is connected by “and” or “or”) means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0204] Exemplary embodiments of this disclosure relate to privacy discovery and privacy selection in privacy-enhanced WLAN (Wireless Local Area Network) networks such as 802.11bi (a standard from the Institute of Electrical and Electronics Engineers, IEEE) and 802.11bh, and can be extended to WFA (Wireless Fidelity Alliance) and WBA (Wireless Broadband Alliance) solutions.

[0205] In the context of enhanced privacy, 802.11bh and 802.11bi were created to address at least several privacy-related issues in 802.11 networks (i.e., to provide enhanced privacy): IEEE P802.11bh addresses specific issues related to 802.11 MAC (Media Access Control) address randomization and aims to rapidly develop (i.e., within 18-24 months) modifications to IEEE 802.11 to address them. The goal is to maintain the efficiency of existing services that might otherwise be limited, such as network support, diagnostics, and troubleshooting, and to reliably detect device arrival in trusted network environments. IEEE P802.11bh will also incorporate mechanisms to optimize the user experience when a device's MAC address changes.

[0206] IEEE P802.11bi considers privacy issues beyond MAC address randomization from a broader and longer-term perspective. It will address and standardize privacy solutions to prevent the tracking of user location and movement. It will build upon the work already completed for IEEE 802.11aq-2018, which also addressed privacy issues as part of that work.

[0207] In short, to provide high privacy, 802.11bh only considers MAC address randomization (suitable for changing MAC addresses only in pre-association), while 802.11bi considers several factors (such as MAC address randomization - suitable for changing MAC addresses in pre / post-association, fingerprinting, identifier protection, etc.). Table 1 summarizes the issues / use cases related to privacy [22 / 332r 37, 22 / 1848r16].

[0208]

[0209] Table 1 - Issues / Use Cases in 802.11bh and 802.11bi 802.11bh and 802.11bi seek to find contributions and solutions to most (if not all) of the problems / use cases. For example, 802.11bh D0.2 employs a “network-generated device ID” solution [22 / 187r2], in which the AP (ESS) assigns an ID (identifier) ​​(i.e., device ID) to a non-AP STA, and the non-AP STA uses the assigned ID (i.e., device ID) in subsequent associations while changing its MAC address. As another example, [23 / 1975r4] proposes a solution to one of the requirements in [22 / 1848r16] (requirement number 26: 11bi should define an optional protected version of the following unicast management frames between the AP and the non-AP STA).

[0210] It also defines the General Notification Service (GAS).

[0211] According to the 802.11 standard, the Generic Advertisement Service (GAS) is an air transport service that allows frames for higher-level advertisements to be transported over the air between Stations (STAs) or between an advertising server and a non-access point (non-AP) STA. Protocols used to relay frames between APs, portals, and advertising servers are outside the scope of the standard. GAS supports higher-level protocols employing query / response mechanisms. GAS provides functionality that enables STAs to discover the availability of information related to desired network services, such as information about services offered in an IBSS (Independent Basic Services Set), local access services, available Subscription Service Providers (SSPs) and / or SSPNs (Subscription Service Provider Networks), or other external networks. GAS uses a generic container to advertise network service information over an IEEE 802.11 network. Public Action frames are used to transmit this information.

[0212] In other words, in order to communicate with external networks, the 802.11 standard (specifically 802.11u) defines GAS frame switching (request / response) for STAs. By doing so, GAS allows STAs to obtain pre-association information before associating with APs, enabling them to select the appropriate network.

[0213] Figure 1 This is a diagram showing a GAS frame.

[0214] It should be noted that GAS frames are common operation frames (recall that common operation frames are a special category of management frames). 802.11 Revme D2.1 defines four GAS frames, such as... Figure 1 As shown.

[0215] Figure 2 This is a diagram illustrating the format of the notification protocol elements.

[0216] In GAS frames, there exists a field called the "Announcement Protocol Element," such as... Figure 2 As shown. This field indicates which protocol is used, such as Access Network Query Protocol (ANQP), MIS (Media Independent Service) information service, etc.

[0217] like Figure 2As shown, the Access Query Protocol (ANQP) (Announcement Protocol ID=0) is a special protocol used in conjunction with GAS frames. GAS frames are used to transmit ANQP. ANQP uses GAS request / response frame exchange to obtain network information. ANQP is a very common protocol used with GAS in many technologies such as Hotspot 2.0 defined by the Wi-Fi Alliance.

[0218] Figure 3 This is a diagram illustrating GAS and ANQP: ANQP uses GAS frames (requests / responses) to obtain information from external networks.

[0219] Figure 3 The diagram illustrates the ANQP transmitted via a GAS frame. After a non-AP STA sends an initial GAS request to request external network information AP support, the AP sends an initial GAS response to notify the non-AP STA of external service AP support. Based on this external network information, the non-AP STA can decide (or decide not to) associate with the AP to use the advertised services.

[0220] Figure 4(a) is a diagram showing the ANQP element format; Figure 4(b) is a diagram showing the ANQP elements that can be defined by STA for requesting information from external networks.

[0221] To obtain external network information, 802.11 Revme D2.1 defines a GAS frame that includes ANQP elements as shown in Figures 4(a) and 4(b). As shown, the general ANQP element format (Figure 4(a)) can carry different ANQP elements for various external network information (such as 3GPP, TDLS (tunnel direct link establishment) capabilities, etc.).

[0222] To clarify the overall concept, how Hotspot 2.0 / Passpoint (defined by WFA) uses GAS frames for the ANQP protocol is examined below.

[0223] Figure 5 This is a diagram showing beacon frames including those associated with Hotspot S2.0 / Passpoint IEs.

[0224] 1) Passive Scanning: Beacon frames from the AP include an additional IE indicating its Hotspot 2.0 / Passpoint capability. For network discovery and selection, key fields indicating Hotspot 2.0 / Passpoint capability need to be examined, including ANQP and the access network type. Devices supporting Hotspot 2.0 / Passpoint will be able to understand these IEs.

[0225] Figure 6A This is a diagram showing probe requests from Internet Explorer (IE) related to Hotspot S2.0 / Passpoint.

[0226] 2.1) Active scanning: Broadcast probe requests sent from non-AP STAs contain Hotspot S2.0 / Passpoint related IEs.

[0227] Figure 6B This is a graph showing the detection response of IEs related to Hotspot S2.0 / Passpoint.

[0228] 2.2) Active Scanning: The probe responses sent from the AP contain Hotspot S2.0 / Passpoint related IEs. It should be noted that these IEs are the same as those sent in the beacon frame for Hotspot S2.0 / Passpoint.

[0229] Figure 7A This is a diagram illustrating the initial GAS request containing information for obtaining a list of NAI domains, 3GPP cellular network information, a list of domain names, and venue name information.

[0230] 3) Then, the non-AP STA sends a GAS initial request (common operation frame) containing the ANQP query list to obtain the NAI (Network Access Identifier) ​​domain list, 3GPP cellular network information, domain name list and venue name information.

[0231] Figure 7B This is a diagram showing the initial GAS response containing information about the NAI domain list, 3GPP cellular network information, domain name list, and venue name information.

[0232] 4) The AP responds with an initial GAS response containing a list of NAI domains, 3GPP cellular network information, a list of domain names, and venue name information.

[0233] 5) Finally, after the non-AP STA has obtained all the information, it decides (or decides not to) associate with the AP through the normal association process.

[0234] Figure 8 This diagram illustrates that when an AP announces its privacy capabilities, a non-AP STA cannot (and should not) choose to enable or disable a specific privacy capability. SAE refers to Simultaneous Authentication by Peers, and PMK refers to Paired Master Keys.

[0235] As an issue, even though the 802.11bh and 802.11bi solutions are optional (i.e., non-AP STAs choose to enable or disable those solutions), there is no clearing mechanism to select which solution to use. For example, such as Figure 8 As shown, after the AP notifies the non-AP STA of its privacy capabilities, non-AP STAs choose to use all solutions or choose not to use any solutions.

[0236] Non-AP STAs should obtain all privacy capability AP support / announcements and then choose which one to enable. Figure 8 For example, a non-AP STA chooses (2) MAC randomization (after association) and (4) element fingerprint evasion. Current 802.11bh and 802.11bi solutions do not specify which capability a non-AP STA wants to use / select and notify the AP of that capability. Current 802.11bh and 802.11bi solutions only allow non-AP STAs to use all privacy capabilities (select enabled) or not use any privacy capabilities (disabled). There should be a mechanism whereby a non-AP STA should tell the AP which privacy capability it wants to use. Otherwise, a non-AP STA cannot associate with its "wanted" privacy capabilities due to one or more "unwanted" privacy capabilities. In other words, a non-AP STA should enable or disable specific privacy capabilities, rather than enabling or disabling all privacy capabilities.

[0237] In this disclosure, exemplary embodiments propose a non-AP STA's ability to discover the privacy capabilities of different networks and to select (enable / disable) specific privacy capabilities during and / or after association with the network.

[0238] Figure 9A This is a flowchart illustrating a method performed by a terminal device according to an exemplary embodiment of the present disclosure.

[0239] like Figure 9A As shown, method 900 includes: step S902, obtaining information indicating multiple privacy capabilities of a network node; and step S904, selecting zero or at least one of the multiple privacy capabilities.

[0240] According to embodiments of this disclosure, after acquiring (i.e., discovering) the privacy capabilities of a network node, the capabilities among these privacy capabilities can be flexibly selected. This mechanism is more suitable for complex network scenarios.

[0241] Figure 9B This illustrates exemplary embodiments according to the present disclosure, such as Figure 9A A flowchart of the further steps of the method shown.

[0242] In an exemplary embodiment of this disclosure, obtaining information includes: step S9022, receiving a first message from the network node indicating multiple privacy capabilities of the network node.

[0243] In an exemplary embodiment of this disclosure, the first message includes at least one of the following: a beacon frame, an operation frame, a probe response, a General Notification Service (GAS) initial response, an authentication response frame, an association response frame, or a four-way handshake response frame.

[0244] In an exemplary embodiment of this disclosure, method 900 further includes: optional step S901, sending a second message to the network node to request the network node's privacy capabilities. The first message is a response to the second message.

[0245] In an exemplary embodiment of this disclosure, the second message includes at least one of the following: an operation frame, a probe request, a General Notification Service (GAS) initiation request, an authentication request frame, an association request frame, or a four-way handshake request frame.

[0246] In an exemplary embodiment of this disclosure, the first message and / or the second message includes at least one of the following related to the privacy capabilities of the network node: capability information field, robust secure network information element (RSNE), extended capability information element, robust secure network extended information element (RSNXE), privacy capability selection information element, access network query protocol (ANQP) element, or privacy capability selection key data encapsulation / four-way handshake field.

[0247] In exemplary embodiments of this disclosure, the first message and / or the second message may be encrypted or unencrypted.

[0248] According to embodiments of this disclosure, a terminal device may obtain information from a network node passively (without request) or actively (with request).

[0249] Figure 9C This illustrates exemplary embodiments according to the present disclosure, such as Figure 9A A flowchart of the further steps of the method shown.

[0250] In an exemplary embodiment of this disclosure, the terminal device makes the selection based at least on its local configuration. Method 900 further includes step S906, sending a third message to the network node to indicate the selection.

[0251] In an exemplary embodiment of this disclosure, the third message is sent during the association process between the terminal device and the network node and before the establishment of a secure connection between the terminal device and the network node. The third message includes at least one of the following: an authentication request frame, an association request frame, a four-way handshake request frame, or an operation frame.

[0252] In an exemplary embodiment of this disclosure, the third message is sent after the association between the terminal device and the network node and after the secure connection between the terminal device and the network node is established. The third message includes at least one of the following: a deassociation frame, a deauthentication frame, or an operation frame.

[0253] In an exemplary embodiment of this disclosure, the third message includes at least one of the following to indicate the selection: a capability information field, a robust secure network information element (RSNE), an extended capability information element, a robust secure network extended information element (RSNXE), a privacy capability selection information element, a privacy capability selection key data encapsulation / four-way handshake field, or a status code or reason code in the status information.

[0254] In an exemplary embodiment of this disclosure, the third message includes at least one of the following status information: selection was at least partially successful; capability was violated; capability is unknown; capability is not supported; capability needs to be resent; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is required due to privacy violation.

[0255] In exemplary embodiments of this disclosure, the third message may be encrypted or unencrypted.

[0256] According to embodiments of this disclosure, the terminal device itself can make this selection.

[0257] Figure 9D This illustrates exemplary embodiments according to the present disclosure, such as Figure 9A A flowchart of the further steps of the method shown.

[0258] In an exemplary embodiment of this disclosure, method 900 further includes step S903, receiving a fourth message from a network node to instruct a terminal device to select zero or at least one of a plurality of privacy capabilities. The terminal device makes this selection based on the fourth message from the network node.

[0259] In an exemplary embodiment of this disclosure, the fourth message is received during the association process between the terminal device and the network node and before the establishment of a secure connection between the terminal device and the network node. The fourth message includes at least one of the following: an authentication response frame, an association response frame, a four-way handshake response frame, or an operation frame.

[0260] In an exemplary embodiment of this disclosure, the fourth message is received after the association between the terminal device and the network node and after the secure connection between the terminal device and the network node is established. The fourth message includes at least one of the following: a deassociation frame, a deauthentication frame, or an operation frame.

[0261] In an exemplary embodiment of this disclosure, the fourth message includes at least one of the following to indicate the selection: a capability information field, a robust secure network information element (RSNE), an extended capability information element, a robust secure network extended information element (RSNXE), a privacy capability selection information element, a privacy capability selection key data encapsulation / four-way handshake field, or a status code or reason code in the status information.

[0262] In an exemplary embodiment of this disclosure, the fourth message includes at least one of the following status information: selection was at least partially successful; capability was violated; capability is unknown; capability is not supported; capability needs to be resent; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is required due to privacy violation.

[0263] In an exemplary embodiment of this disclosure, the fourth message may be encrypted or unencrypted.

[0264] According to embodiments of this disclosure, the terminal device can make the selection by following instructions from a network node.

[0265] In an exemplary embodiment of this disclosure, the terminal device includes a non-AP STA; and the network node includes an AP.

[0266] Figure 10A This is a flowchart illustrating a method performed by a network node according to an exemplary embodiment of the present disclosure.

[0267] like Figure 10A As shown, method 1000 includes: step S1002, sending information indicating multiple privacy capabilities of a network node to a terminal device. This information is used for the terminal device to select zero or at least one of the multiple privacy capabilities.

[0268] Figure 10B This illustrates exemplary embodiments according to the present disclosure, such as Figure 10A A flowchart of the further steps of the method shown.

[0269] In an exemplary embodiment of this disclosure, sending information includes: step S10022, sending a first message to the terminal device indicating multiple privacy capabilities of the network node.

[0270] In an exemplary embodiment of this disclosure, the first message includes at least one of the following: a beacon frame, an operation frame, a probe response, a General Notification Service (GAS) initial response, an authentication response frame, an association response frame, or a four-way handshake response frame.

[0271] In an exemplary embodiment of this disclosure, method 1000 includes: optional step S1001, receiving a second message from a terminal device for requesting privacy capabilities of a network node. A first message is a response to the second message.

[0272] In an exemplary embodiment of this disclosure, the second message includes at least one of the following: an operation frame, a probe request, a General Notification Service (GAS) initiation request, an authentication request frame, an association request frame, or a four-way handshake request frame.

[0273] In an exemplary embodiment of this disclosure, the first message and / or the second message includes at least one of the following related to the privacy capabilities of the network node: capability information field, robust secure network information element (RSNE), extended capability information element, robust secure network extended information element (RSNXE), privacy capability selection information element, access network query protocol (ANQP) element, or privacy capability selection key data encapsulation / four-way handshake field.

[0274] In exemplary embodiments of this disclosure, the first message and / or the second message may be encrypted or unencrypted.

[0275] Figure 10C This illustrates exemplary embodiments according to the present disclosure, such as Figure 10A A flowchart of the further steps of the method shown.

[0276] In an exemplary embodiment of this disclosure, method 1000 further includes: step S1006, receiving a third message from a terminal device to instruct the terminal device to select zero or at least one of a plurality of privacy capabilities.

[0277] In an exemplary embodiment of this disclosure, the third message is received during the association process between the terminal device and the network node and before the establishment of a secure connection between the terminal device and the network node. The third first message includes at least one of the following: an authentication request frame, an association request frame, a four-way handshake request frame, or an operation frame.

[0278] In an exemplary embodiment of this disclosure, the third message is received after the association between the terminal device and the network node and after the secure connection between the terminal device and the network node is established. The third message includes at least one of the following: a deassociation frame, a deauthentication frame, or an operation frame.

[0279] In an exemplary embodiment of this disclosure, the third message includes at least one of the following to indicate the selection: a capability information field, a robust secure network information element (RSNE), an extended capability information element, a robust secure network extended information element (RSNXE), a privacy capability selection information element, a privacy capability selection key data encapsulation / four-way handshake field, or a status code or reason code in the status information.

[0280] In an exemplary embodiment of this disclosure, the third message includes at least one of the following status information: selection was at least partially successful; capability was violated; capability is unknown; capability is not supported; capability needs to be resent; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is required due to privacy violation.

[0281] In exemplary embodiments of this disclosure, the third message may be encrypted or unencrypted.

[0282] Figure 10D This illustrates exemplary embodiments according to the present disclosure, such as Figure 10A A flowchart of the further steps of the method shown.

[0283] In an exemplary embodiment of this disclosure, method 1000 further includes: step S1003, sending a fourth message to the terminal device to instruct the terminal device to select zero or at least one of a plurality of privacy capabilities.

[0284] In an exemplary embodiment of this disclosure, the fourth message is sent during the association process between the terminal device and the network node and before the establishment of a secure connection between the terminal device and the network node. The fourth message includes at least one of the following: an authentication response frame, an association response frame, a four-way handshake response frame, or an operation frame.

[0285] In an exemplary embodiment of this disclosure, the fourth message is sent after the association between the terminal device and the network node and after the secure connection between the terminal device and the network node is established. The fourth message includes at least one of the following: a deassociation frame, a deauthentication frame, or an operation frame.

[0286] In an exemplary embodiment of this disclosure, the fourth message includes at least one of the following to indicate the selection: a capability information field, a robust secure network information element (RSNE), an extended capability information element, a robust secure network extended information element (RSNXE), a privacy capability selection information element, a privacy capability selection key data encapsulation / four-way handshake field, or a status code or reason code in the status information.

[0287] In an exemplary embodiment of this disclosure, the fourth message includes at least one of the following status information: selection was at least partially successful; capability was violated; capability is unknown; capability is not supported; capability needs to be resent; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is required due to privacy violation.

[0288] In an exemplary embodiment of this disclosure, the fourth message may be encrypted or unencrypted.

[0289] In an exemplary embodiment of this disclosure, the terminal device includes a non-access point station (non-AP STA). The network node includes an access point (AP).

[0290] As mentioned above, the current 802.11bh and 802.11bi solutions do not specify specific privacy capabilities for non-AP STAs to discover when they want to associate with an AP (ESS).

[0291] Figure 11 This is a diagram illustrating the proposed Privacy Capability Discovery.

[0292] like Figure 11 As shown, some embodiments of this disclosure are proposed for non-AP STA: 1- Discover the privacy capabilities of different networks: a) Passive scanning to obtain AP privacy capabilities: The AP can advertise its privacy capabilities in the beacon frame, allowing non-AP STAs to discover which privacy capabilities the AP supports.

[0293] The AP can announce its privacy capabilities in the operation frame, allowing non-AP STAs to discover which privacy capabilities the AP supports.

[0294] b) Proactive scanning to obtain AP privacy capabilities: A non-AP STA can request the AP's privacy capabilities by sending a probe request, a GAS initialization request, and / or an operation frame. The AP sends the privacy capabilities in the probe response, GAS initialization response, and / or operation frame, respectively.

[0295] c) During connection establishment: A non-AP STA can request the AP's privacy capabilities during connection establishment via an authentication request, an association request, or a four-way handshake request. The AP sends the privacy capabilities in the authentication response, association response, or four-way handshake response, respectively.

[0296] Alternatively, the AP may notify its privacy capability authentication response, association response, or four-way handshake response in the absence of a privacy capability request from a non-AP STA.

[0297] To achieve privacy capability discovery, embodiments of this disclosure propose using one of the following (but are not limited to): 1) Capability Information Field 2) RSN Information Element (RSNE) 3) Extended capability information elements 4) RSN Extended Information Element (RSNXE) 5) Privacy capabilities in Internet Explorer (the newly defined IE) 6) ANQP elements 7) Privacy Capability KDE (Newly Defined KDE) / Four-Way Handshake Field In the relevant frames, it depends on the detection mechanism.

[0298] Exemplary embodiments of this disclosure propose a mechanism for discovering privacy capabilities in Wi-Fi networks. Figure 11 This illustrates the general concept of privacy capability discovery.

[0299] The following exemplary embodiments provide further details on the proposed discovery of privacy capabilities.

[0300] Regarding the discovery of privacy capabilities, as mentioned earlier, a non-AP STA needs to discover the AP's privacy capabilities before associating with the AP. This discovery can be achieved using the following methods: A) Passive scanning: I. The AP announces its privacy capabilities in the beacon frame, and the non-AP STA discovers the AP's privacy capabilities by receiving the beacon frame.

[0301] II. The AP announces its privacy capabilities in the operation frame, and the non-AP STA discovers the AP's privacy capabilities by receiving the operation frame.

[0302] B) Active scanning: I. Non-AP STA requests the AP's privacy capabilities by sending a probe request and receives the AP's privacy capabilities in the probe response.

[0303] II. Non-AP STAs request the privacy capabilities of the AP by sending a GAS Initial Request and receive the privacy capabilities of the AP in the GAS Initial Response.

[0304] III. Non-AP STAs request the AP's privacy capabilities by sending an operation frame and receive the AP's privacy capabilities in the operation frame.

[0305] C) During connection establishment: I. Non-AP STA requests the AP's privacy capabilities in the authentication request and receives the AP's privacy capabilities in the authentication response.

[0306] II. Non-AP STAs request the AP's privacy capabilities in the association request and receive the AP's privacy capabilities in the association response.

[0307] III. The non-AP STA requests the AP's privacy capabilities via a four-way handshake and receives the AP's privacy capabilities via a four-way handshake.

[0308] For passive scanning, the AP announces its privacy capabilities in beacon frames and / or operation frames, and the non-AP STA discovers the AP's privacy capabilities by receiving beacon frames and / or operation frames.

[0309] For AI beacons, the AP can announce its privacy capabilities in the beacon frame, and non-AP STAs can discover the AP's privacy capabilities by receiving the beacon frame.

[0310] Privacy capabilities can be announced in beacon frames through, but are not limited to, one of the following: 1) Capability Information Field 2) RSN Information Element (RSNE) 3) Extended capability information elements 4) RSN Extended Information Element (RSNXE) 5) Privacy capabilities in Internet Explorer It should be noted that privacy capabilities announced in one of the aforementioned four ways can be sent encrypted or unencrypted.

[0311] Figure 12.a This is a diagram showing the capability information field in a beacon frame.

[0312] Figure 12.b This is a diagram showing the format of the capability information fields.

[0313] Figure 12.c This is a diagram showing the privacy capabilities carried in bits 16 to n (B16-Bn) of the capability information field in the beacon.

[0314] Figure 12.d This is a diagram showing the privacy capabilities carried in one or more existing reserved bits in the capability information field of the beacon.

[0315] 1) In one embodiment, the AP may insert its privacy capabilities into the capability information field of the beacon frame, such as... Figure 12.a , Figure 12.b , Figure 12.c and Figure 12.d As shown.

[0316] Subsection 9.3.3.2 of 802.11REVme_D2.1 defines the RSN capability information field in the beacon frame with order = 3, such as... Figure 12.a As shown.

[0317] The 802.11REVme_D2.1 subsection 9.4.1.4 defines, for example,... Figure 12.b The capability information field shown.

[0318] In order to announce privacy capabilities, embodiments of this disclosure propose the use of AP: -bit 16 to bit n (B16-Bn), as shown in Figure 12.3, or -One or more of the currently reserved bits (B2, B3, B6, B7, B14, B15), such as Figure 12.d As shown.

[0319] To avoid confusion, the privacy bit in B4 can be defined for data confidentiality, and its purpose differs from the proposed privacy capabilities.

[0320] Figure 13.a This is a diagram showing the RSN information element (RSNE) in a beacon.

[0321] Figure 13.b This is a diagram illustrating the definition and format of RSN Information Elements (RSNE).

[0322] Figure 13c is a diagram showing the privacy capabilities carried in the privacy capability field of the RSN information element (RSNE) in the beacon.

[0323] Figure 13.d This is a diagram illustrating the privacy capabilities carried in the RSN Capabilities field of the RSN Message Element (RSNE) in a beacon.

[0324] 2) In another embodiment, the AP can insert its privacy capabilities into the RSN Information Element (RSNE) in the beacon frame, such as... Figure 13.a , Figure 13.b , Figure 13.c and Figure 13.d As shown.

[0325] Subsection 9.3.3.2 of 802.11REVme_D2.1 defines the RSN information element (RSNE) with order=17 in the beacon frame, such as... Figure 13.a As shown.

[0326] Subsection 9.4.2.24 of 802.11REVme_D2.1 defines the RSN Message Element (RSNE) with element ID=48, such as... Figure 13.b As shown.

[0327] In order to announce privacy capabilities, embodiments of this disclosure propose the use of AP: - The privacy capability field (k bits) in the RSN Information Element (RSNE), such as Figure 13.c As shown, or - The RSN capability field in the RSN Information Element (RSNE), such as Figure 13.d As shown Figure 14.a This is a diagram showing the extended capability information elements in a beacon.

[0328] Figure 14.b This is a diagram illustrating the definition and format of the extended capability information elements.

[0329] Figure 14.c This is a diagram showing the privacy capabilities carried in the privacy capability field of the extended capability information element in the beacon.

[0330] Figure 14.d This is a diagram illustrating the privacy capabilities carried in the extension capabilities field of the extension capabilities information element in the beacon.

[0331] 3) In another embodiment, the AP can insert its privacy capabilities into the extended capability information element in the beacon frame, such as... Figure 14.a , Figure 14.b , Figure 14.c and Figure 14.d As shown.

[0332] Subsection 9.3.3.2 of 802.11REVme_D2.1 defines the extended capability information element with order=37 in the beacon frame, such as... Figure 14.a As shown.

[0333] Subsection 9.4.2.26 of 802.11REVme_D2.1 defines the extended capability information element with element ID=127, such as... Figure 14.a and Figure 14.b As shown.

[0334] In order to announce privacy capabilities, embodiments of this disclosure propose the use of AP: - The privacy capability field (n bits) in the extended capability information element, such as Figure 14.c As shown, or - The expansion capability field (n bits) in the expansion capability information element, such as Figure 14.d As shown.

[0335] Figure 15.a This is a diagram showing the RSN Extended Information Element (RSNXE) in a beacon.

[0336] Figure 15.b This is a diagram illustrating the definition and format of the RSN Extended Information Element (RSNXE).

[0337] Figure 15.c This is a diagram showing the privacy capabilities carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in the beacon.

[0338] Figure 15.d This is a diagram illustrating the privacy capabilities carried in the Extended RSN Capabilities field of the RSN Extended Information Element (RSNXE) in the beacon.

[0339] 4) In another embodiment, the AP can insert its privacy capabilities into the RSN Extended Information Element (RSNXE) in the beacon frame, such as... Figure 15.a , Figure 15.b , Figure 15.c and Figure 15.d As shown.

[0340] Subsection 9.3.3.2 of 802.11REVme_D2.1 defines the RSN extension information element (RSNXE) with order=75 in the beacon frame, such as... Figure 15.a As shown.

[0341] The 802.11REVme_D2.1 subsection 9.4.2.241 defines the RSN Extended Information Element (RSNXE) with element ID=244, such as... Figure 15.b As shown.

[0342] In order to announce privacy capabilities, embodiments of this disclosure propose the use of AP: - The privacy capability field (k bits) in the RSN Extended Information Element (RSNXE), such as Figure 15.c As shown; or - The Extended RSN Capabilities field in the RSN Extended Information Element (RSNXE), such as Figure 15.d As shown.

[0343] Figure 16.a This is a diagram illustrating the definition of privacy capability information elements in a beacon.

[0344] Figure 16.b This is a diagram illustrating the format of privacy capability information elements.

[0345] Figure 16.c This is a diagram showing the privacy capability information elements in the beacon.

[0346] 5) In another embodiment, the AP can insert its privacy capabilities into a newly defined information element called the Privacy Capability Information Element, and this IE can be sent in a beacon frame, such as... Figure 16.a , Figure 16.b and Figure 16.c As shown.

[0347] Subsection 9.4.2 of 802.11REVme_D2.1 defines numerous information elements. For example, the newly defined information element utilizes a reserved field and is defined with element ID=255 and element ID extension=117. The definition and format of privacy capabilities in IE are... Figure 16.a and Figure 16.b As shown in the figure. An exemplary embodiment of this disclosure proposes defining a privacy capability information element with order=92 in a beacon frame to announce the privacy capabilities of the AP, such as... Figure 16.c As shown.

[0348] For A.II) operation frames, the AP can announce its privacy capabilities in the operation frame, and non-AP STAs can discover the AP's privacy capabilities by receiving the operation frame.

[0349] These types of operational frames include those used to announce the capabilities of the AP (including the AP's privacy capabilities); in other words, operational frames can behave like beacon frames. An example of such operational frames is the FILS (Fast Initial Link Establishment) discovery frame.

[0350] For B. Active scanning, a non-AP STA can request the AP's privacy capabilities, and in response to the AP discovering the AP's privacy capabilities, as follows (as explained in the embodiments): I. Non-AP STA requests the AP's privacy capabilities by sending a directed or broadcast probe request and receives the AP's privacy capabilities in the probe response.

[0351] To request / respond to the AP's privacy capabilities, a non-AP STA may send one of the following (but not limited to) in a probe request, and the AP may respond with one of the following (but not limited to) in a probe response: 1) Capability Information Field 2) RSN Information Element (RSNE) 3) Extended capability information elements 4) RSN Extended Information Element (RSNXE) 5) Privacy Capabilities Information Elements II. Non-AP STAs request the privacy capabilities of the AP by sending a GAS Initial Request and receive the privacy capabilities of the AP in the GAS Initial Response.

[0352] To request / respond to the AP's privacy capabilities, a non-AP STA may send one of the following (but not limited to) in a probe request, and the AP may respond with one of the following (but not limited to) in a probe response: 1) GAS initial request / GAS initial response with ANQP element 2) GAS initial request / GAS initial response containing elements other than ANQP elements III. Non-AP STAs request the AP's privacy capabilities by sending an operation frame and receive the AP's privacy capabilities in the operation frame.

[0353] It should be noted that privacy capability requests and responses in one of the aforementioned methods can be sent encrypted or unencrypted.

[0354] For BI probe requests / responses, further details can be provided as follows.

[0355] Figure 17.a This is a diagram illustrating the definition of the capability information field in the probe request frame.

[0356] Figure 17.b This is a diagram showing the capability information field in the probe response frame.

[0357] Figure 17c is a diagram showing the format of the capability information field.

[0358] Figure 17.d This is a diagram showing the privacy capability request carried in bits 16 to n (B16-Bn) of the capability information field in the probe request.

[0359] Figure 17.e This is a diagram illustrating a privacy capability request carried in one or more existing reserved bits in the capability information field of a probe request.

[0360] Figure 17.f This is a diagram showing the privacy capability response carried in bits 16 to n (B16-Bn) of the capability information field in the probe response.

[0361] Figure 17.g This is a diagram illustrating the privacy capabilities carried in one or more existing reserved bits in the capability information field of the probe response. 1) In one embodiment, a non-AP STA can request the privacy capabilities of an AP by using the capability information field in a probe request frame, and the AP can respond to its privacy capabilities by using the capability information field in a probe response frame, as shown in Figures 17a to 17g: Subsection 9.3.3.9 of 802.11REVme_D2.1 does not define a capability information field in a probe request frame. In this context, for example, embodiments of this disclosure propose defining a capability information field with order=42 for a probe request, such as... Figure 17.a As shown.

[0362] Subsection 9.3.3.10 of 802.11REVme_D2.1 defines the capability information field with order=3 in the probe response frame, such as... Figure 17.b As shown.

[0363] Subsection 9.4.1.4 of 802.11REVme_D2.1 defines the capability information field as shown in Figure 17c.

[0364] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: -bit 16 to bit n (B16-Bn), such as Figure 17.d As shown, or -One or more of the currently reserved bits (B2, B3, B6, B7, B14, B15), such as Figure 17.e As shown.

[0365] In response to privacy requirements, for example, embodiments of this disclosure propose the use of the AP: -bit 16 to bit n (B16-Bn), such as Figure 17.f As shown, or -One or more of the currently reserved bits (B2, B3, B6, B7, B14, B15), such as Figure 17.g As shown.

[0366] Figure 18.a This is a diagram showing the RSN Information Element (RSNE) in the probe request frame.

[0367] Figure 18.b This is a diagram showing the RSN information element (RSNE) in the probe response frame.

[0368] Figure 18.c This is a diagram illustrating the definition and format of RSN Information Elements (RSNE).

[0369] Figure 18.d This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN information element (RSNE) in a probe request.

[0370] Figure 18.e This is a diagram illustrating a privacy capability request carried in the RSN Capability field of the RSN Information Element (RSNE) in a probe request.

[0371] Figure 18.f This is a diagram showing the privacy capability response carried in the privacy capability field of the RSN information element (RSNE) in the probe response.

[0372] Figure 18.g This is a diagram showing the privacy capabilities carried in the RSN Capabilities field of the RSN Information Element (RSNE) in the probe response.

[0373] 2) In another embodiment, a non-AP STA can request the AP's privacy capabilities by using an RSN Information Element (RSNE) in a probe request frame, and the AP can respond to its privacy capabilities by using an RSN Information Element (RSNE) in a probe response frame, such as... Figures 18.a to 18.g As shown.

[0374] Subsection 9.3.3.9 of 802.11REVme_D2.1 does not define an RSN Information Element (RSNE) in a probe request frame. In this context, for example, embodiments of this disclosure propose defining an RSN Information Element (RSNE) with order=42 for a probe request, such as... Figure 18.a As shown.

[0375] Subsection 9.3.3.10 of 802.11REVme_D2.1 defines the RSN information element (RSNE) with order=16 in the probe response frame, such as... Figure 18.b As shown.

[0376] Subsection 9.4.2.24 of 802.11REVme_D2.1 defines the RSN Message Element (RSNE) with element ID=48, such as... Figure 18.c As shown.

[0377] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - The privacy capability field (k bits) in the RSN Information Element (RSNE), such as Figure 18.d As shown, or - The RSN capability field in the RSN Information Element (RSNE), such as Figure 18.e As shown.

[0378] In response to privacy capabilities from the AP, for example, embodiments of this disclosure propose that the AP use: - The privacy capability field (k bits) in the RSN Information Element (RSNE), such as Figure 18.f As shown, or - The RSN capability field in the RSN Information Element (RSNE), such as Figure 18.g As shown.

[0379] Figure 19.a This is a diagram showing the extended capability information elements in the probe request frame.

[0380] Figure 19.b This is a diagram showing the extended capability information elements in the probe response frame.

[0381] Figure 19.c This is a diagram illustrating the definition and format of the extended capability information elements.

[0382] Figure 19.d This is a diagram illustrating the privacy capability request carried in the privacy capability field of the extended capability information element in the probe request.

[0383] Figure 19.e This is a diagram illustrating a privacy capability request carried in the extension capability field of the extension capability information element in a probe request.

[0384] Figure 19.f This is a diagram showing the privacy capability response carried in the privacy capability field of the extended capability information element in the probe response.

[0385] Figure 19.g This is a diagram illustrating the privacy capabilities response carried in the extension capabilities field of the extension capabilities information element in the probe response.

[0386] 3) In another embodiment, a non-AP STA can request the AP's privacy capabilities by using the extended capability information element in the probe request frame, and the AP can respond to its privacy capabilities by using the extended capability information element in the probe response frame, such as... Figures 19.a to 19.g As shown.

[0387] Subsection 9.3.3.9 of 802.11REVme_D2.1 defines the extended capability information element with order=9 in the probe request frame, such as... Figure 19.a As shown.

[0388] Subsection 9.3.3.10 of 802.11REVme_D2.1 defines the extended capability information element with order=35 in the probe response frame, such as... Figure 19.b As shown.

[0389] Subsection 9.4.2.26 of 802.11REVme_D2.1 defines the extended capability information element with element ID=127, such as... Figure 19.c As shown.

[0390] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - The privacy capability field (n bits) in the extended capability information element, such as Figure 19.d As shown, or - The extension capability field in the extension capability information element, such as Figure 19.e As shown.

[0391] In response to privacy capabilities from the AP, for example, embodiments of this disclosure propose that the AP use: - The privacy capability field (n bits) in the extended capability information element, such as Figure 19.f As shown, or - The extension capability field in the extension capability information element, such as Figure 19.g As shown.

[0392] Figure 20.a This is a diagram showing the RSN Extended Information Element (RSNXE) in the probe request frame.

[0393] Figure 20.bThis is a diagram showing the RSN Extended Information Element (RSNXE) in the probe response frame.

[0394] Figure 20.c This is a diagram illustrating the definition and format of the RSN Extended Information Element (RSNXE).

[0395] Figure 20.d This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in a probe request.

[0396] Figure 20.e This is a diagram illustrating a privacy capability request carried in the Extended RSN Capability field of the RSN Extended Information Element (RSNXE) in a probe request.

[0397] Figure 20f is a diagram showing the privacy capability response carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in the probe response.

[0398] Figure 20.g This is a diagram showing the privacy capabilities carried in the extended RSN capabilities field of the RSN extended information element (RSNXE) in the probe response.

[0399] 4) In another embodiment, a non-AP STA can request the AP's privacy capabilities by using the RSN Extended Information Element (RSNXE) in a probe request frame, and the AP can respond to its privacy capabilities by using the RSN Extended Information Element (RSNXE) in a probe response frame, such as... Figures 20.a to 20.g As shown: Subsection 9.3.3.9 of 802.11REVme_D2.1 does not define an RSN Extended Information Element (RSNXE) in a probe request frame. In this context, exemplary embodiments of this disclosure propose defining an RSN Extended Information Element (RSNXE) with order=43 for a probe request, such as... Figure 20.a As shown.

[0400] Subsection 9.3.3.10 of 802.11REVme_D2.1 defines the RSN extension information element (RSNXE) with order=92 in the probe response frame, such as... Figure 20.b As shown.

[0401] The 802.11REVme_D2.1 subsection 9.4.2.241 defines the RSN Extended Information Element (RSNXE) with element ID=244, such as... Figure 20.c As shown.

[0402] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - The privacy capability field (k bits) in the RSN Extended Information Element (RSNXE), such as Figure 20.d As shown, or - The Extended RSN Capabilities field in the RSN Extended Information Element (RSNXE), such as Figure 20.e As shown.

[0403] In response to privacy capabilities from the AP, for example, embodiments of this disclosure propose that the AP use: - The privacy capability field (k bits) in the RSN Extended Information Element (RSNXE), such as Figure 20.f As shown, or - The Extended RSN Capabilities field in the RSN Extended Information Element (RSNXE), such as Figure 20.g As shown.

[0404] Figure 21.a This is a diagram illustrating the definition and format of the privacy capability request information element in a probe request.

[0405] Figure 21.b This is a diagram illustrating the definition and format of privacy capability response information elements in the detection response.

[0406] Figure 21.c This is a diagram illustrating the privacy capability request information element in a probe request.

[0407] Figure 21.d This is a diagram illustrating the privacy capability response information elements in the detection response.

[0408] 5) In another embodiment, a non-AP STA can request the privacy capabilities of an AP using a newly defined information element called a "privacy capability request information element" in a probe request frame, and the AP can respond to its privacy capabilities using a newly defined information element called a "privacy capability response information element" in a probe response frame, such as... Figures 21.a to 21.d As shown.

[0409] Subsection 9.4.2 of 802.11REVme_D2.1 defines many informational elements.

[0410] The proposed new definition of the privacy capability request information element utilizes reserved fields and is defined as having element ID=255 and element ID extension=118, such as Figure 21.a As shown in the image.

[0411] The proposed new definition of the privacy-capable response information element utilizes reserved fields and is defined as having element ID=255 and element ID extension=119, such as Figure 21.b As shown in the image.

[0412] For example, embodiments of this disclosure propose a privacy capability request information element with order=42 in a probe request defined for STA, to request, as Figure 21.c The privacy capabilities of the AP are shown, and a privacy capability response information element with order=112 is defined in the probe response for the AP to respond to its privacy capabilities, such as... Figure 21.d As shown in the image.

[0413] In another embodiment, a single newly defined information element (e.g., a privacy capability information element) can be used for both privacy capability requests and privacy capability responses.

[0414] For B.II) GAS initial request / GAS initial response, further details can be provided as follows.

[0415] Figure 22.a This is a diagram illustrating the ANQP in the initial GAS request.

[0416] Figure 22.b This is a graph showing the ANQP in the initial response of GAS.

[0417] Figure 22.c This is a diagram illustrating a privacy-capable request with ANQP obtained from the query list in the initial GAS request.

[0418] Figure 22.d This is a diagram showing the privacy-capable response with ANQP in the initial GAS response.

[0419] 1) In one embodiment, a non-AP STA can request the privacy capabilities of an AP by using an ANQP element in the GAS initial request, and the AP can respond to its privacy capabilities by using an ANQP element in the GAS initial response frame, such as... Figures 22.a to 22.d As shown.

[0420] Subsection 9.4.5 of 802.11REVme_D2.1 defines the ANQP element (defined in subsection 9.6.7.12) for the GAS initial request, whose advertisement protocol element is ANQP (advertisement protocol ID=0). Figure 22.a As shown, ANQP elements are defined for the initial GAS response (defined in subsection 9.6.7.13), as follows. Figure 22.b As shown.

[0421] A non-AP STA can request the AP's privacy capabilities using a newly defined ANQP element named "Privacy Capabilities" with ANQP query ID=287, through the query list (Information ID=256) in the initial GAS request. Figure 22.cAs shown, the AP can respond to its privacy capabilities by using a newly defined ANQP element named "Privacy Capabilities" with information ID=287 in the initial GAS response, such as... Figure 22.d As shown.

[0422] 2) In another embodiment, a non-AP STA can request the AP's privacy capabilities using any protocol other than ANQP in the GAS initial request, and the AP can respond to its privacy capabilities using any protocol other than ANQP in the GAS initial response. If the GAS initial request selects any announcement protocol ID other than 0 (e.g., announcement protocol ID = 1, 2, 3, 4) or is reserved (e.g.) Figure 22.a (as shown in the image), or if the initial GAS response selects any announcement protocol ID other than 0 (e.g., announcement protocol ID = 1, 2, 3, 4) or is reserved (as shown in the image). Figure 22.b As shown in the diagram, this scenario is possible.

[0423] For B.III) Operation frames, non-AP STAs can request the privacy capabilities of the AP in the operation frame, and non-AP STAs can discover the privacy capabilities of the AP by receiving the operation frame.

[0424] These types of operation frames include those used to exchange AP capabilities, including AP privacy capabilities. An example of such an operation frame is the FILS operation frame.

[0425] Regarding discovery during connection establishment (C.), the non-AP STA and AP can also exchange AP privacy capabilities during connection establishment, as described below. Here, connection establishment means that the non-AP STA attempts to associate with the AP by sending authentication frames, association frames, or four-way handshake frames. It should be noted that these frames must occur after passive (beacon) or active (probe, GAS, operation) scanning and before connection establishment (data frames).

[0426] The non-AP STA requests the AP's privacy capabilities by sending an authentication request and receives the AP's privacy capabilities in the authentication response.

[0427] Alternatively, the AP (in the absence of a privacy capability request from a non-AP STA) announces its privacy capabilities in the authentication response.

[0428] It should be noted that the authentication request corresponds to the authentication frame sent from the non-AP STA to the AP. The authentication response corresponds to the authentication frame sent from the AP to the non-AP STA.

[0429] To request / respond to the AP's privacy capabilities, a non-AP STA may send one of the following (but not limited to) in the authentication request, and the AP may respond with one of the following (but not limited to) in the authentication response. Alternatively, the AP (in the absence of a privacy capability request from a non-AP STA) may announce its privacy capabilities in its authentication response in one of the following (but not limited to): 1) RSN Information Element (RSNE); 2) Privacy-enabled information elements.

[0430] A non-AP STA requests the AP's privacy capabilities by sending an association request and receives the AP's privacy capabilities in the association response.

[0431] Alternatively, the AP (in the absence of a privacy capability request from a non-AP STA) may announce its privacy capabilities in an associated response.

[0432] It should be noted that an association request corresponds to an association frame sent from a non-AP STA to the AP. An association response corresponds to an association frame sent from the AP to a non-AP STA.

[0433] In order to request / respond to the privacy capabilities of an AP, a non-AP STA may send one of the following (but not limited to) in an association request, and the AP may respond with one of the following (but not limited to) in an association response.

[0434] Alternatively, the AP (in the absence of a privacy capability request from a non-AP STA) may announce its privacy capabilities in an associated response in one of the following (but not limited to): 1) Capability information field; 2) RSN Information Element (RSNE); 3) Extended capability information elements; 4) RSN Extended Information Element (RSNXE); 5) Privacy-enabled information elements.

[0435] A non-AP STA requests the AP's privacy capabilities by sending a four-way handshake request and receives the AP's privacy capabilities by responding with a four-way handshake.

[0436] Alternatively, the AP (in the absence of a privacy capability request from a non-AP STA) announces its privacy capabilities in a four-way handshake response.

[0437] It should be noted that the four-way handshake request corresponds to the four-way handshake frame sent from the non-AP STA to the AP. The four-way handshake response corresponds to the four-way handshake frame sent from the AP to the non-AP STA.

[0438] In order to request / respond to the privacy capabilities of an AP, a non-AP STA may send one of the following (but not limited to) four-way handshake requests, and the AP may respond with one of the following (but not limited to) four-way handshake responses.

[0439] Alternatively, the AP may (in the absence of a privacy capability request from a non-AP STA) announce its privacy capabilities in a four-way handshake response in one of the following (but not limited to): 1) Reserved bit fields; 2) Key Data Encapsulation (KDE) field; 3) Privacy capability field (n bits).

[0440] It should be noted that the exchange of privacy capabilities during connection establishment in one of the aforementioned methods can be sent encrypted or unencrypted.

[0441] For CI certification requests / responses, further details can be provided as follows.

[0442] Figure 23.a This is a diagram showing the RSN Information Element (RSNE) in the authentication frame.

[0443] Figure 23.b This is a diagram illustrating the definition and format of RSN Information Elements (RSNE).

[0444] Figure 23.c This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN Information Element (RSNE) in an authentication request.

[0445] Figure 23.d This is a diagram illustrating a privacy capability request carried in the RSN Capability field of the RSN Information Element (RSNE) in an authentication request.

[0446] Figure 23.e This is a diagram illustrating the privacy capability response or announcement carried in the privacy capability field of the RSN Information Element (RSNE) in the authentication response.

[0447] Figure 23.f This is a diagram illustrating the privacy capabilities response or announcement carried in the RSN Capabilities field of the RSN Information Element (RSNE) in the authentication response.

[0448] 1) In one embodiment, a non-AP STA can request the privacy capabilities of an AP by using an RSN Information Element (RSNE) in an authentication request frame, and the AP can respond to its privacy capabilities by using an RSN Information Element (RSNE) in an authentication response frame.

[0449] Alternatively, the AP can advertise its privacy capabilities by using the RSN Information Element (RSNE) in the authentication response frame without a privacy capability request from a non-AP STA, such as... Figures 23a to 23f As shown.

[0450] Subsection 9.3.3.11 of 802.11REVme_D2.1 defines the RSN information element (RSNE) with order=11 in the authentication frame, such as... Figure 23.a As shown.

[0451] Subsection 9.4.2.24 of 802.11REVme_D2.1 defines the RSN Message Element (RSNE) with element ID=48, such as... Figure 23.b As shown.

[0452] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - The privacy capability field (k bits) in the RSN Information Element (RSNE), such as Figure 23.c As shown, or - The RSN capability field in the RSN Information Element (RSNE), such as Figure 23.d As shown.

[0453] In response to privacy capabilities or by announcement of privacy capabilities by the AP, for example, embodiments of this disclosure propose that the AP use: - The privacy capability field (k bits) in the RSN Information Element (RSNE), such as Figure 23.e As shown, or - The RSN capability field in the RSN Information Element (RSNE), such as Figure 23.f As shown.

[0454] Figure 24.a This is a diagram illustrating the definition and format of the privacy capability request information element in an authentication request.

[0455] Figure 24.b A diagram showing the definition and format of privacy capability response information elements in the authentication response is provided.

[0456] Figure 24.c This is a diagram illustrating the privacy capability request information element in an authentication request.

[0457] Figure 24.d This is a diagram showing the privacy capability response information elements in the authentication response.

[0458] 2) In another embodiment, a non-AP STA can request the privacy capabilities of an AP by using a newly defined information element called a "Privacy Capability Request Information Element" in the authentication request frame, and the AP can respond to its privacy capabilities by using a newly defined information element called a "Privacy Capability Response Information Element" in the authentication response. Alternatively, the AP can announce its privacy capabilities by using the privacy capability response information element in the authentication response frame, without requiring a privacy capability request from a non-AP STA, such as... Figures 24a to 24d As shown.

[0459] Subsection 9.4.2 of 802.11REVme_D2.1 defines many informational elements.

[0460] The proposed new definition of the privacy capability request information element utilizes reserved fields and is defined as having element ID=255 and element ID extension=118, such as Figure 24.a As shown.

[0461] The proposed new definition of the privacy-capable response information element utilizes reserved fields and is defined as having element ID=255 and element ID extension=119, such as Figure 24.b As shown.

[0462] For example, embodiments of this disclosure propose defining a privacy capability request information element with order=26 in the authentication request, so that the STA can request the privacy capabilities of the AP, such as... Figure 24.c As shown, and the privacy capability response information element with order=27 is defined in the authentication response for the AP to respond to or announce its privacy capabilities, such as... Figure 24.d As shown.

[0463] In another embodiment, a single newly defined information element (e.g., a privacy capability information element) can be used for both privacy capability requests and privacy capability responses.

[0464] For C.II) related requests / responses, further details can be provided as follows.

[0465] Figure 25.a This is a diagram showing the capability information field in the associated request frame.

[0466] Figure 25.b This is a diagram showing the capability information field in the associated response frame.

[0467] Figure 25.c This is a diagram showing the format of the capability information fields.

[0468] Figure 25.d This is a diagram illustrating the privacy capability request carried in bits 16 to n (B16-Bn) of the capability information field in the association request.

[0469] Figure 25.e This is a diagram illustrating a privacy capability request carried in one or more existing reserved bits in the capability information field of an association request.

[0470] Figure 25.f This is a diagram showing the privacy capability response or announcement carried in bits 16 to n (B16-Bn) of the capability information field in the associated response.

[0471] Figure 25.g This is a diagram showing the privacy capabilities response or announcement carried in one or more existing reserved bits in the capability information field of the associated response.

[0472] 1) In one embodiment, a non-AP STA can request the privacy capabilities of an AP by using the capability information field in an associated request frame, and the AP can respond to its privacy capabilities by using the capability information field in an associated response frame.

[0473] Alternatively, the AP can advertise its privacy capabilities by using the capability information field in the associated response frame, without requiring a privacy capability request from a non-AP STA, such as... Figures 25.a to 25.g As shown.

[0474] Subsection 9.3.3.5 of 802.11REVme_D2.1 defines the capability information field with order=1 in the associated request frame, such as... Figure 25.a As shown.

[0475] Subsection 9.3.3.6 of 802.11REVme_D2.1 defines the capability information field with order=1 in the associated response frame, such as... Figure 25.b As shown.

[0476] The 802.11REVme_D2.1 subsection 9.4.1.4 defines, for example,... Figure 25.c The capability information field shown.

[0477] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: -bit 16 to bit n (B16-Bn), such as Figure 25.d As shown, or -One or more of the currently reserved bits (B2, B3, B6, B7, B14, B15), such as Figure 25.e As shown in the image.

[0478] In response to privacy capabilities or by announcement of privacy capabilities by the AP, for example, embodiments of this disclosure propose that the AP use: -bit 16 to bit n (B16-Bn), such as Figure 25.f As shown, or -One or more of the currently reserved bits (B2, B3, B6, B7, B14, B15), such as Figure 25.g As shown.

[0479] Figure 26.a This is a diagram showing the RSN Information Element (RSNE) in the association request frame.

[0480] Figure 26.b This is a diagram showing the RSN Information Element (RSNE) in the associated response frame.

[0481] Figure 26.c This is a diagram illustrating the definition and format of RSN Information Elements (RSNE).

[0482] Figure 26.d This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN Information Element (RSNE) in an association request.

[0483] Figure 26.e This is a diagram illustrating a privacy capability request carried in the RSN Capability field of the RSN Information Element (RSNE) in an association request.

[0484] Figure 26.f This is a diagram illustrating the privacy capability response or announcement carried in the privacy capability field of the RSN Information Element (RSNE) in the associated response.

[0485] Figure 26.g This is a diagram illustrating the privacy capabilities response or announcement carried in the RSN Capabilities field of the RSN Information Element (RSNE) in the associated response.

[0486] 2) In one embodiment, a non-AP STA can request the AP's privacy capabilities by using an RSN Information Element (RSNE) in an association request frame, and the AP can respond to its privacy capabilities by using an RSN Information Element (RSNE) in an association response frame. Alternatively, the AP can advertise its privacy capabilities by using the RSN Information Element (RSNE) in the associated response frame without a privacy capability request from a non-AP STA, such as... Figures 26.a to 26.g As shown.

[0487] like Figure 26.a As shown, subsection 9.3.3.5 of 802.11REVme_D2.1 defines the RSN information element (RSNE) with order=8 in the association request frame.

[0488] Subsection 9.3.3.6 of 802.11REVme_D2.1 defines the RSN information element (RSNE) with order=10 in the associated response frame, such as... Figure 26.b As shown.

[0489] Subsection 9.4.2.24 of 802.11REVme_D2.1 defines the RSN Message Element (RSNE) with element ID=48, such as... Figure 26.c As shown.

[0490] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - The privacy capability field (k bits) in the RSN Information Element (RSNE), such as Figure 26.d As shown, or - The RSN capability field in the RSN Information Element (RSNE), such as Figure 26.e As shown.

[0491] In response to privacy capabilities or by announcement of privacy capabilities by the AP, for example, embodiments of this disclosure propose that the AP use: - The privacy capability field (k bits) in the RSN Information Element (RSNE), such as Figure 26.f As shown, or - The RSN capability field in the RSN Information Element (RSNE), such as Figure 26.g As shown.

[0492] Figure 27.a This is a diagram showing the extension capability information elements in the associated request frame.

[0493] Figure 27.b This is a diagram showing the extension capability information elements in the associated response frame.

[0494] Figure 27.c This is a diagram illustrating the definition and format of the extended capability information elements.

[0495] Figure 27.d This is a diagram illustrating the privacy capability request carried in the privacy capability field of the extended capability information element in the associated request.

[0496] Figure 27.e This is a diagram illustrating a privacy capability request carried in the extension capability field of the extension capability information element in an association request.

[0497] Figure 27.f This is a diagram illustrating the privacy capability response or announcement carried in the privacy capability field of the extended capability information element in the associated response.

[0498] Figure 27.gThis is a diagram illustrating the privacy capabilities response or announcement carried in the extension capabilities field of the extension capabilities information element in the associated response.

[0499] 3) In another embodiment, a non-AP STA can request the privacy capabilities of an AP by using the extended capability information element in an association request frame, and the AP can respond to its privacy capabilities by using the extended capability information element in an association response frame. Alternatively, the AP can advertise its privacy capabilities by using the extended capability information element in the associated response frame, without requiring a privacy capability request from a non-AP STA, such as... Figures 27.a to 27.g As shown.

[0500] Subsection 9.3.3.5 of 802.11REVme_D2.1 defines the extended capability information element with order=15 in the associated request frame, such as... Figure 27.a As shown.

[0501] Subsection 9.3.3.6 of 802.11REVme_D2.1 defines the extended capability information element with order=19 in the associated response frame, such as... Figure 27.b As shown.

[0502] Subsection 9.4.2.26 of 802.11REVme_D2.1 defines the extended capability information element with element ID=127, such as... Figure 27.c As shown.

[0503] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - The privacy capability field (n bits) in the extended capability information element, such as Figure 27.d As shown, or - The extension capability field in the extension capability information element, such as Figure 27.e As shown.

[0504] In response to privacy capabilities or by announcement of privacy capabilities by the AP, for example, embodiments of this disclosure propose that the AP use: - The privacy capability field (n bits) in the extended capability information element, such as Figure 27.f As shown, or - The extension capability field in the extension capability information element, such as Figure 27.g As shown.

[0505] Figure 28.a This is a diagram showing the RSN Extended Information Element (RSNXE) in the association request frame.

[0506] Figure 28.b This is a diagram showing the RSN Extended Information Element (RSNXE) in the associated response frame.

[0507] Figure 28.c This is a diagram illustrating the definition and format of the RSN Extended Information Element (RSNXE).

[0508] Figure 28.d This is a diagram illustrating a privacy capability request carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in an association request.

[0509] Figure 28.e This is a diagram illustrating a privacy capability request carried in the Extended RSN Capability field of the RSN Extended Information Element (RSNXE) in an association request.

[0510] Figure 28.f This is a diagram illustrating a privacy capability response or announcement carried in the privacy capability field of the RSN Extended Information Element (RSNXE) in an associated response.

[0511] Figure 28.g This is a diagram showing the privacy capabilities response or announcement carried in the Extended RSN Capabilities field of the RSN Extended Information Element (RSNXE) in the associated response.

[0512] 4) In another embodiment, a non-AP STA can request the AP's privacy capabilities by using the RSN Extended Information Element (RSNXE) in the association request frame, and the AP can respond to its privacy capabilities by using the RSN Extended Information Element (RSNXE) in the association response frame. Alternatively, the AP can advertise its privacy capabilities without a privacy capability request from a non-AP STA by using the RSN Extended Information Element (RSNXE) in the associated response frame, such as... Figures 28.a to 28.g As shown.

[0513] Subsection 9.3.3.5 of 802.11REVme_D2.1 defines the RSN Extended Information Element (RSNXE) with order=43 in the associated response frame, such as... Figure 28.a As shown.

[0514] Subsection 9.3.3.6 of 802.11REVme_D2.1 defines the RSN Extended Information Element (RSNXE) with order=55 in the associated response frame, such as... Figure 28.b As shown.

[0515] The 802.11REVme_D2.1 subsection 9.4.2.241 defines the RSN Extended Information Element (RSNXE) with element ID=244, such as... Figure 28.c As shown.

[0516] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - The privacy capability field (k bits) in the RSN Extended Information Element (RSNXE), such as Figure 28.d As shown, or - The Extended RSN Capabilities field in the RSN Extended Information Element (RSNXE), such as Figure 28.e As shown.

[0517] In response to privacy capabilities or privacy capabilities announced by the AP, exemplary embodiments of this disclosure propose that the AP use: - The privacy capability field (k bits) in the RSN Extended Information Element (RSNXE), such as Figure 28.f As shown, or - The Extended RSN Capabilities field in the RSN Extended Information Element (RSNXE), such as Figure 28.g As shown.

[0518] Figure 29.a This is a diagram illustrating the definition and format of the privacy capability request information element in an association request.

[0519] Figure 29.b This is a diagram illustrating the definition and format of privacy capability response information elements in an associated response.

[0520] Figure 29.c This is a diagram illustrating the privacy capability request information element in the associated request.

[0521] Figure 29.d This is a diagram showing the privacy capability response information elements in the associated response.

[0522] 5) In another embodiment, a non-AP STA can request the privacy capabilities of an AP by using a newly defined information element called a "Privacy Capability Request Information Element" in the association request frame, and the AP can respond to its privacy capabilities by using a newly defined information element called a "Privacy Capability Response Information Element" in the association response. Alternatively, an AP can announce its privacy capabilities by using a privacy capability response information element in the associated response frame without a privacy capability request from a non-AP STA, such as... Figures 29.a to 29.d As shown.

[0523] Subsection 9.4.2 of 802.11REVme_D2.1 defines many informational elements.

[0524] The proposed new definition of the privacy capability request information element utilizes reserved fields and is defined as having element ID=255 and element ID extension=118, such as Figure 29.a As shown.

[0525] The proposed new definition of the privacy-capable response information element utilizes reserved fields and is defined as having element ID=255 and element ID extension=119, such as Figure 29.b As shown.

[0526] For example, embodiments of this disclosure propose defining a privacy capability request information element with order=59 in an association request, so that the STA can request the privacy capabilities of the AP, such as... Figure 29.c As shown, and defines the privacy capability response information element with order=78 in the associated response for AP to respond to or announce its privacy capabilities, such as Figure 29.d As shown.

[0527] In another embodiment, a single newly defined information element (e.g., a privacy capability information element) can be used for both privacy capability requests and privacy capability responses.

[0528] For the C.III) four-way handshake, further details can be provided as follows.

[0529] Figure 30 This is a diagram illustrating the privacy capability requests and responses / announcements in the reserved bit fields of the four-way handshake frames.

[0530] 1) In one embodiment, a non-AP STA can request the AP's privacy capabilities by using the reserved bit field in the four-way handshake request frame, and the AP can respond to its privacy capabilities by using the reserved bit field in the four-way handshake response frame. Or, such as Figure 30 As shown, an AP can announce its privacy capabilities by using a reserved bit field in a four-way handshake response frame without a privacy capability request from a non-AP STA: The 802.11REVme_D2.1 subsection 12.7.4 defines, for example,... Figure 30 The reserved bit field of the four-way handshake frame shown.

[0531] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - Reserved bit field (n bits).

[0532] In response to privacy capabilities or by announcement of privacy capabilities by the AP, for example, embodiments of this disclosure propose that the AP use: - Reserved bit field (n bits).

[0533] Figure 31 This is a diagram illustrating the privacy capability requests and responses / announcements in the KDE field of the four-way handshake frame.

[0534] 2) In another embodiment, a non-AP STA can request the AP's privacy capabilities by using the Key Data Encapsulation (KDE) field in the four-way handshake request frame, and the AP can respond to its privacy capabilities by using the Key Data Encapsulation (KDE) field in the four-way handshake response frame. Alternatively, the AP can announce its privacy capabilities in the four-way handshake response frame by using the Key Data Encapsulation (KDE) field without a privacy capability request from a non-AP STA, such as... Figure 31 As shown.

[0535] Subsection 12.7.4 of 802.11REVme_D2.1 defines the Key Data Encapsulation (KDE) field for the four-way handshake frame, such as... Figure 31 As shown.

[0536] Subsection 12.7.4 of 802.11REVme_D2.1 also defines different key data encapsulation (KDE) for four-way handshake frames (such as RSNE KDE, RSNXEKDE, etc.), such as Figure 31 As shown.

[0537] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - One of the existing KDEs in the KDE field (such as RSNE KDE, RSNXE KDE), or - A new definition of KDE called "Privacy Capability Request KDE".

[0538] In response to privacy capabilities or by announcement of privacy capabilities by the AP, for example, embodiments of this disclosure propose that the AP use: - One of the existing KDEs in the KDE field (such as RSNE KDE, RSNXE KDE), or - A new definition of KDE called "Privacy Capability Response KDE".

[0539] Figure 32 This is a diagram illustrating the privacy capability request and response / announcement in the newly defined privacy capability request / response fields of the four-way handshake frame.

[0540] 3) In another embodiment, a non-AP STA can request the AP's privacy capabilities by using a newly defined field called "Privacy Capability Request Field" in the four-way handshake request frame, and the AP can respond to its privacy capabilities by using a newly defined field called "Privacy Capability Response Field" in the four-way handshake response frame. Or, such as Figure 32As shown, an AP can announce its privacy capabilities without a privacy capability request from a non-AP STA by using a newly defined field called the "Privacy Capability Field" in the four-way handshake response frame: The 802.11REVme_D2.1 subsection 12.7.4 defines, for example,... Figure 32 The four handshake frames shown.

[0541] In order to request privacy capabilities from an AP, for example, embodiments of this disclosure propose the use of a non-AP STA: - Privacy capability request field (n bits).

[0542] In response to privacy capabilities or by announcement of privacy capabilities by the AP, for example, embodiments of this disclosure propose that the AP use: - Privacy capability response field (n bits).

[0543] Figure 33 This is a diagram illustrating the proposed privacy capability options.

[0544] As mentioned above, current 802.11bh and 802.11bi solutions do not specify which privacy capabilities a non-AP STA should select / use (enable / disable) when it wants to associate with an AP (ESS). In an exemplary embodiment, enabling means "selecting specific privacy capabilities to use, including all of them." (For example, out of 5 privacy capabilities, the STA selects to [enable] 4 privacy capabilities). Disabling means "not selecting specific privacy capabilities, including zero." (For example, out of 5 privacy capabilities, the STA does not select to [disable] 2 privacy capabilities). The STA should be able to dynamically change its preferences [enable or disable] (for example, out of 5 privacy capabilities, the STA selects to [enable] 3 privacy capabilities, but after a period of time abandons [disabling] one of them, resulting in the use of 2 privacy capabilities).

[0545] like Figure 33 As shown, an exemplary embodiment proposes that a non-AP STA selects (enables / disables) specific privacy capabilities during and / or after being associated with the network.

[0546] During the association process (before a secure connection is established between the non-AP STA and the AP); -non-AP STA can enable / disable one / zero / all of the AP's privacy capabilities via (but not limited to) authentication, association, four-way handshake, or operation frames.

[0547] - The AP can enable / disable one / zero / all of the AP's privacy capabilities from a non-AP STA via (but not limited to) authentication, association, four-way handshake, or operation frames.

[0548] After association (after a secure connection is established between the non-AP STA and the AP); - When a non-AP STA enables (or disables) one / zero / all of the AP's privacy capabilities, it can disable / enable specific privacy capabilities at any time as needed via (but not limited to) unassociation, deauthentication, or operation frames.

[0549] When a non-AP STA enables (or disables) one / zero / all of the AP's privacy capabilities, the AP can enable / disable specific privacy capabilities for the non-AP STA at any time as needed via (but not limited to) unassociation, deauthentication, or operation frames.

[0550] To enable privacy capability discovery, exemplary embodiments of this disclosure propose the use of one of the following (but are not limited to): 1) Capability Information Field 2) RSN Information Element (RSNE) 3) Extended capability information elements 4) RSN Extended Information Element (RSNXE) 5) Privacy capabilities in Internet Explorer (the newly defined IE) 6) ANQP elements 7) Privacy Capability KDE (Newly Defined KDE) / Four-Way Handshake Field 8) Status Information In the relevant frames, it depends on the detection mechanism.

[0551] Exemplary embodiments of this disclosure propose a mechanism for selecting privacy capabilities in Wi-Fi networks. Figure 33 This illustrates the general concept of privacy capability selection.

[0552] The following will further describe the details of the proposed privacy capability selection, the definition of privacy capabilities, and some examples of privacy capability selection.

[0553] The following describes the details of choosing privacy capabilities.

[0554] As previously mentioned, a non-AP STA can enable / disable specific privacy capabilities of the AP during and / or after its association with the AP. Similarly, the AP can enable / disable specific privacy capabilities of the AP for non-AP STAs during and / or after its association with the AP, as described below.

[0555] During the association period: non-AP STAs enable / disable specific privacy capabilities of the AP in the authentication request frame, or In the authentication response frame, the AP enables / disables specific privacy capabilities of the AP for the STA.

[0556] non-AP STAs enable / disable specific privacy capabilities of the AP in the request frame, or In the associated response frame, the AP enables / disables specific privacy capabilities of the AP for the STA.

[0557] non-AP STAs enable / disable specific privacy capabilities of the AP using a four-way handshake request frame, or The AP uses a four-way handshake response frame to enable / disable specific privacy capabilities of the AP from the STA, or non-AP STAs enable / disable specific privacy capabilities of the AP in the operation frame.

[0558] In the operation frame, the AP enables / disables specific privacy capabilities of the AP for the STA.

[0559] During connection establishment: non-AP STAs enable / disable specific privacy capabilities of the AP in the deauthentication frame, or The AP enables / disables specific privacy capabilities of the AP in the deauthentication frame.

[0560] non-AP STAs enable / disable specific privacy capabilities of the AP in the deassociation frame, or In the disassociation frame, the AP enables / disables specific privacy capabilities of the AP from the STA.

[0561] non-AP STAs enable / disable specific privacy capabilities of the AP in the operation frame, or The AP enables / disables specific privacy capabilities of the AP in the operation frame for the STA. "During association" means that the non-AP STA and AP exchange authentication, association, four-way handshake, and operation frames (if any). In other words, the secure connection has not yet been established, but is about to be established.

[0562] "After association" means that the non-AP STA and AP have completed authentication, association, four-way handshake, and operation frames (if any), and a secure connection has been established, for example, obtaining and preparing to use the encryption key. At this point, the non-AP STA and AP can begin securely transmitting data frames.

[0563] It should be noted that the privacy capability selection in one of the aforementioned methods can be sent encrypted or unencrypted.

[0564] To enable privacy capability selection, exemplary embodiments of this disclosure propose the use of one of the following (but are not limited to): Figure 34.a This is a diagram showing the privacy capability selection carried in bits 16 to n (B16-Bn) of the capability information field.

[0565] Figure 34.b This is a diagram showing the selection of privacy capabilities carried in one or more existing reserved bits in the capability information field.

[0566] 1) Capability Information Field: This field is already defined in 802.11REVme_D2.1. Additional bits in the Capability Information Field (such as...) Figure 34.a (as shown) or an existing reserved bit (such as Figure 34.b (As shown) can be used for privacy capability selection, such as Figure 34.a and Figure 34.b As shown.

[0567] Figure 35.a This is a diagram showing the privacy capability selection carried in the privacy capability field of the RSN Information Element (RSNE).

[0568] Figure 35.b This is a diagram illustrating the privacy capability selection carried in the RSN Capabilities field of the RSN Message Element (RSNE).

[0569] 2) RSN Information Element (RSNE): This IE element is already defined in 802.11REVme_D2.1 with element ID=48. Newly defined privacy capability selection fields (such as...) Figure 35.a (as shown) or an existing RSN capability field in the RSNE (such as...) Figure 35.b (As shown) can be used for privacy capability selection.

[0570] Figure 36.a This is a diagram illustrating the privacy capability selection carried in the privacy capability field within the extended capability information element.

[0571] Figure 36.b A diagram showing the privacy capability selection carried in the extension capability field of the extension capability information element is presented.

[0572] 3) Extended Capability Information Element: This IE element is already defined in 802.11REVme_D2.1 as having element ID=127. Newly defined privacy capability selection fields (such as...) Figure 36.a (as shown) or an existing extension capability field in the extension capability information element (such as...) Figure 36.b (As shown) can be used for privacy capability selection.

[0573] Figure 37.a This is a diagram showing the privacy capability selection carried in the privacy capability field of the RSN Extended Information Element (RSNXE).

[0574] Figure 37.b This is a diagram illustrating the privacy capability selection carried in the Extended RSN Capabilities field of the RSN Extended Information Element (RSNXE).

[0575] 4) RSN Extended Information Element (RSNXE): This element is already defined in 802.11REVme_D2.1 with element ID=244. Newly defined privacy capability selection fields (such as...) Figure 37.a (as shown) or the extended RSN capability already existing in the extended capability information element (such as...) Figure 37.b (As shown) can be used for privacy capability selection.

[0576] Figure 38 This is a diagram illustrating the definition and format of privacy capability selection information elements.

[0577] 5) Privacy Capability Selection IE: This is a newly defined IE. As an example, this IE can be defined in 802.11REVme_D2.1 with element ID=255 and element ID extension=118. This IE can be used for privacy capability selection, such as... Figure 38 As shown.

[0578] Figure 39 This is a diagram showing the privacy capability selection in the reserved bit field (1), privacy selection field (2), or privacy selection KDE (3) in the four-way handshake frame.

[0579] 6) Privacy Capability Selection KDE / Four-Way Handshake Field: Privacy Capability Selection KDE is a newly defined KDE used for privacy selection in the four-way handshake frame (in... Figure 39 As shown in (3)). Alternatively, reserve bit fields (in Figure 39 The field shown in (1) is a newly defined reserved bit field (in Figure 39 The text shows that (2) can be used for privacy selection, such as... Figure 39 As shown.

[0580] Figure 40.a This is a diagram showing the status codes for privacy capability selection.

[0581] Figure 40.b A diagram showing the reason codes for privacy capability selection is provided.

[0582] 7) Status Information (Status Code / Reason Code): Status information can be sent in the management frame to indicate the privacy capability selection (enabled / disabled). As an example, status information can be included in the relevant frame of the IE.

[0583] Similarly, status codes or reason codes can be used to enable / disable specific privacy capabilities. In this context, we propose a definition as follows: Figure 40.aThe privacy capability selection status code shown (status code = 130) and as follows Figure 40.b The privacy capability selection reason code shown is (reason code = 72).

[0584] The privacy capability selection status code or privacy capability selection reason code includes at least one of those in Table 2.

[0585]

[0586] [Note 1] In Table 2, _x represents a specific privacy capability.

[0587] [Note 2] In Table 2, STA can be non-AP STA or AP, depending on the use.

[0588] Table 2 - Examples of Privacy Capability Status Information To make a selection during the association process, further details can be provided as follows.

[0589] For authentication requests / responses, in one embodiment, the non-AP STA enables / disables AP-specific privacy capabilities in the authentication request frame, or the AP enables / disables AP-specific privacy capabilities in the authentication response frame by at least using the following methods: RSN Information Element (RSNE) Privacy Capabilities Information Elements Status information.

[0590] It should be noted that the authentication request corresponds to the authentication frame sent from the non-AP STA to the AP. The authentication response corresponds to the authentication frame sent from the AP to the non-AP STA.

[0591] In another embodiment, for association requests / responses, the non-AP STA enables / disables specific privacy capabilities of the AP in the association request frame, or the AP enables / disables specific privacy capabilities of the AP in the association response frame by at least using the following methods: Capability Information Field RSN Information Element (RSNE) Extended capability information elements RSN Extended Information Element (RSNXE) Privacy Capabilities Information Elements Status information.

[0592] It should be noted that the authentication request corresponds to the authentication frame sent from the non-AP STA to the AP. The authentication response corresponds to the authentication frame sent from the AP to the non-AP STA.

[0593] In another embodiment, for the four-way handshake request / response, the non-AP STA enables / disables specific privacy capabilities of the AP in the four-way handshake request frame, or the AP enables / disables specific privacy capabilities of the AP in the four-way handshake response frame by at least using the following methods: Privacy capabilities choose KDE Reserved bit field Privacy capability selection field.

[0594] It should be noted that the four-way handshake request corresponds to the four-way handshake frame sent from the non-AP STA to the AP. The four-way handshake response corresponds to the four-way handshake frame sent from the AP to the non-AP STA.

[0595] For the operation frame, in another embodiment, the non-AP STA enables / disables specific privacy capabilities of the AP in the operation request frame, or the AP enables / disables specific privacy capabilities of the AP in the operation response frame by using at least the following methods: Privacy options for Internet Explorer Status information.

[0596] Figure 41 This is a diagram illustrating the privacy capability selection operation frame.

[0597] As an example, this operation frame can be defined in 802.11REVme_D2.1 with its category value = 33. This operation frame can be used for privacy capability selection, such as... Figure 41 As shown.

[0598] It should be noted that the operation request corresponds to the operation frame sent from the non-AP STA to the AP. The operation response corresponds to the four-way handshake frame sent from the AP to the non-AP STA.

[0599] To allow for selection during connection establishment, further details can be provided as follows.

[0600] For a deauthentication frame, in one embodiment, the non-AP STA enables / disables specific privacy capabilities of the AP in the deauthentication frame, or the AP enables / disables specific privacy capabilities of the AP in the deauthentication frame by at least the following methods: Privacy options for Internet Explorer Status information.

[0601] It should be noted that deauthentication frames can be sent from either a non-AP STA or an AP.

[0602] In another embodiment, for the deassociation frame, the non-AP STA enables / disables specific privacy capabilities of the AP in the deassociation frame, or the AP enables / disables specific privacy capabilities of the AP in the deassociation frame by at least using the following methods: Privacy options for Internet Explorer Status information.

[0603] It should be noted that unassociation frames can be sent from either a non-AP STA or an AP.

[0604] For the operation frame, in another embodiment, similarly, during association, the non-AP STA enables / disables specific privacy capabilities of the AP in a newly defined operation request frame, or the AP selects specific privacy capabilities of the AP in a newly defined operation response frame by at least using the following methods: Privacy options for Internet Explorer Status information.

[0605] The definition of privacy capabilities can be further proposed as follows.

[0606] Different networks are more likely to support different privacy capabilities. The following shows some examples of privacy capabilities to choose from.

[0607] The range of privacy capabilities on the internet can be from advanced privacy to truly detailed privacy capabilities.

[0608] As an example, network privacy capabilities may include one of the privacy capabilities listed in Table 3:

[0609] Table 3 - Examples of Privacy Capability Definitions When a non-AP STA selects a privacy capability, it can use MLME-SAP primitives when signaling a specific privacy capability from the upper layer.

[0610] Subsection 6.5 of 802.11REVme_D2.1 defines many MLME-SAP primitives. Within this context, primitives can be applied to any relevant frame ( Figure 33 (As shown) Defines the privacy capability MLME-SAP primitive.

[0611] As an example, if privacy capability selection is used in associated requests / responses, the MLME-SAP primitives used for privacy capabilities can be defined as follows:

[0612] In addition, some examples of privacy capability choices can be proposed as follows.

[0613] Figure 42 This is a diagram illustrating exemplary scenario 1.

[0614] The process in Example 1 may include the following steps.

[0615] Step 1: The non-AP STA discovers the AP's privacy capabilities, namely, whether the AP supports 1) Network Diagnostics, 2) Troubleshooting, and 3) Pre-Association Client Steering. Step 2: Non-AP STAs only want to select troubleshooting and send the privacy capability selection in the association request.

[0616] Step 3: The non-AP STA and AP establish a connection using the selected troubleshooting.

[0617] Figure 43 This is a diagram illustrating exemplary scenario 2.

[0618] The process in Example 2 may include the following steps.

[0619] Step 1: The non-AP STA discovers the AP's privacy capabilities, namely, the AP supports 1) Post-Association Changing MAC and 2) Customer Support.

[0620] Step 2: The non-AP STA only wants to change the MAC address after selecting association and sends this privacy capability selection in the four-way handshake request.

[0621] Step 3: Non-AP STA and AP establish a connection by changing the MAC address after the selected association.

[0622] Step 4: AP decides to change its privacy policy and no longer supports changing the MAC address after association.

[0623] Step 5: Due to the reason mentioned in Step 4, the AP sends a deauthentication frame with reason_code=CHANGE_PRIVACY to the non-AP STA.

[0624] Step 6: The non-AP STA re-associates with the AP after changing the MAC address without selecting association.

[0625] Figure 44 This is a block diagram illustrating an exemplary structure of a terminal device according to an exemplary embodiment of the present disclosure.

[0626] like Figure 44 As shown, terminal device 440 includes component 4400 configured to: acquire information indicating multiple privacy capabilities of a network node; and select zero or at least one of the multiple privacy capabilities.

[0627] In exemplary embodiments of this disclosure, component 4400 is also configured to perform the methods of any of the above embodiments, such as Figure 9A , Figure 9B , Figure 9C , Figure 9D As shown.

[0628] In an exemplary embodiment of this disclosure, component 4400 includes: at least one processor 4402; and at least one memory 4404 storing instructions that, when executed by at least one processor 4402, cause terminal device 440 to perform operations.

[0629] Figure 45 This is a block diagram illustrating an exemplary structure of a network node according to an exemplary embodiment of the present disclosure.

[0630] like Figure 45 As shown, network node 450 includes component 4500 configured to send information indicating multiple privacy capabilities of the network node to a terminal device. This information is used by the terminal device to select zero or at least one of the multiple privacy capabilities.

[0631] In exemplary embodiments of this disclosure, component 4500 is also configured to perform the methods of any of the above embodiments, such as Figure 10A , Figure 10B , Figure 10C , Figure 10D As shown.

[0632] In an exemplary embodiment of this disclosure, component 4500 includes: at least one processor 4502; and at least one memory 4504 storing instructions that, when executed by at least one processor 4502, cause network node 450 to perform operations.

[0633] Processors 4402 and 4502 can be any type of processing unit, such as one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), application-specific digital logic, etc. Memory 4404 and 4504 can be any type of storage component, such as read-only memory (ROM), random access memory, cache memory, flash memory, optical storage devices, etc.

[0634] Figure 46 This is a block diagram illustrating an apparatus / computer-readable storage medium according to embodiments of the present disclosure.

[0635] like Figure 46 As shown, a computer-readable storage medium 460 is illustrated, which stores instructions 461, which, when executed by at least one processor of a terminal device, cause at least one processor of the terminal device to perform a method according to any of the above embodiments, such as Figure 9A , Figure 9B , Figure 9C , Figure 9D The embodiments shown; or, when executed by at least one processor of the network node, causing at least one processor of the network node to execute the method according to any of the above embodiments, such as Figure 10A , Figure 10B , Figure 10C , Figure 10D As shown.

[0636] Additionally, this disclosure may also provide a carrier containing the computer program / instructions described above. The carrier is one of electronic signals, optical signals, radio signals, or the above computer-readable storage media. Computer-readable storage media may be, for example, optical discs or electronic storage devices such as RAM (Random Access Memory), ROM (Read-Only Memory), flash memory, magnetic tape, CD-ROM, DVD, Blu-ray disc, etc.

[0637] Figure 47 This is a block diagram illustrating exemplary device units suitable for performing methods according to embodiments of the present disclosure in a terminal device.

[0638] like Figure 47 As shown, the terminal device 470 may include: an acquisition unit 4702, for acquiring information indicating multiple privacy capabilities of a network node; and a selection unit 4704, for selecting zero or at least one of the multiple privacy capabilities.

[0639] In exemplary embodiments of this disclosure, terminal device 470 is also configured to perform the methods of any of the above embodiments, such as Figure 9A , Figure 9B , Figure 9C , Figure 9D As shown.

[0640] Figure 48 This is a block diagram illustrating exemplary device units suitable for performing methods according to embodiments of the present disclosure in a network node.

[0641] like Figure 48 As shown, network node 480 may include: a transmitter 4802, configured to send information indicating multiple privacy capabilities of the network node to a terminal device. This information is used by the terminal device to select zero or at least one of the multiple privacy capabilities.

[0642] In exemplary embodiments of this disclosure, network node 480 is also configured to perform the methods of any of the above embodiments, such as Figure 10A , Figure 10B , Figure 10C , Figure 10D As shown.

[0643] The term “unit” can have a conventional meaning in the field of electronic, electrical and / or electronic equipment, and can include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, outputs and / or display functions, such as those described herein.

[0644] As used in this disclosure, the term "circuit system" may refer to one or more or all of the following: (a) Hardware circuit implementation only (such as implementation in analog and / or digital circuits only), and (b) A combination of hardware circuitry and software, such as (if applicable): (i) A combination of analog and / or digital hardware circuitry with software / firmware, and (ii) Any part of a hardware processor (including a digital signal processor), software, and memory that works together to enable a device (such as a mobile phone or server) to perform various functions, and (c) One or more hardware circuits and / or one or more processors, such as one or more microprocessors or a portion thereof, that require software (e.g., firmware) to operate, but the software may not be present when operation is not required.

[0645] This definition of circuit system applies to all uses of the term in this disclosure, including in any claim. As another example, as used in this disclosure, the term circuit system also covers implementations of hardware circuitry or processors (or processors in general) or a portion thereof and their accompanying software and / or firmware. For example, if applicable to a particular claim element, the term circuit system also covers baseband integrated circuits or processor integrated circuits for use in mobile devices or servers, cellular network devices, or other computing or networking devices.

[0646] Using these units, the device can be configured with any type of computing and storage resources from at least one network node / device / entity / device associated with the communication system, without requiring a fixed processor or memory. Virtualization and network computing technologies (e.g., cloud computing) can be further introduced to improve the efficiency of network resource utilization and network flexibility.

[0647] The techniques described herein can be implemented by various components, such that the means for implementing one or more functions of the corresponding apparatus described in the embodiments includes not only prior art means but also components for implementing one or more functions of the corresponding apparatus described in the embodiments, and it can include separate components for each individual function, or components that can be configured to perform two or more functions. For example, these techniques can be implemented in hardware (one or more means), firmware (one or more means), software (one or more modules / units), or a combination thereof. For firmware or software, it can be implemented by modules (e.g., procedures, functions, etc.) that perform the functions described herein.

[0648] In some embodiments, some or all of the functions described herein may be provided by a processing circuitry system that executes instructions stored in memory, which in some embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functions may be provided by the processing circuitry system, such as in a hard-wired manner, without executing instructions stored on a separate or discrete device-readable storage medium. In any of those particular embodiments, the processing circuitry system may be configured to perform the described functions, whether or not instructions stored on a non-transitory computer-readable storage medium are executed. The benefits provided by such functions are not limited to the individual processing circuitry system or other components of the computing device, but are enjoyed generally by the computing device and / or by the end user and wireless network.

[0649] As used herein, the term “non-transient” refers to the limitation of the medium itself (i.e., tangible, not signal-based), rather than a limitation on the persistence of data storage (e.g., RAM versus ROM).

[0650] As described in the exemplary embodiments of this disclosure above, the embodiments herein offer numerous advantages. According to embodiments of this disclosure, improved methods for privacy mechanisms can be provided, particularly privacy capabilities for discovering and / or selecting network nodes.

[0651] According to embodiments of this disclosure, after acquiring (i.e., discovering) the privacy capabilities of a network node, the capabilities among these privacy capabilities can be flexibly selected. This mechanism is more suitable for complex network scenarios.

[0652] It should be understood that the above embodiments are for illustrative purposes only and not for limitation. This disclosure may be practiced in ways different from those specifically set forth herein without departing from its essential characteristics. All changes to these embodiments without departing from the meaning and equivalents of the appended claims are intended to be included herein.

[0653] The following are references incorporated in their entirety into this paper: [22 / 332r37]: IEEE 802.11-21 / 0332r37, IEEE P802.11, Wireless LAN Issues Tracking (Wireless LANs, Issues Tracking) Date: 2022-06-11, Authors: Mark Hamilton (Ruckus / Comm) and Jay Yang (Nokia).

[0654] [22 / 187r2]: IEEE 802.11-22 / 0187r2, IEEE P802.11, IEEE P802.11, Wireless LAN, Wireless Local Area Network Generated Device ID (Network generated Device ID) Date: 2022-03-10, Author: Jouni Malinen (Qualcomm).

[0655] [23 / 1975r4]: IEEE 802.11-22 / 1975r4, 802.11bi draft specification, technical specification proposal for the unicast management frame protected version. (Proposed spec texts for protected version of unicast management frames) Date: 2022-11-07, Authors: Po-Kai Huang, Danny Alexander, IdoOuzieli, Johannes Berg, Ilan Peer (Intel).

[0656] [22 / 1848r16]: IEEE 802.11-21 / 1848r16, IEEE P802.11, Wireless LAN Task Group TGbi Requirements Trace (Wireless LANs, TGbi Requirements Tracking)Date: 2022-09-14, Author: Carol Ansley (Cox Communications).

[0657] 802.11Revme D2.1 (802.11REVme_D2.1): IEEE P802.11-REVme / D2.1, January 2023, Draft Standard for Information Exchange between Local Area Networks and Metropolitan Area Networks - Specific Requirements Part 11: Specification for Wireless LAN Media Access Control (MAC) and Physical Layer (PHY), prepared by the 802.11 Working Group of the LAN / MAN Standards Committee of the IEEE Computer Society.

[0658] Abbreviation Explanation ANQP Access Network Query Protocol AP access point DA Destination Address ESS Extended Services GAS General Announcement Service IE Information Elements KDE key data encapsulation PHY physical layer RCM Random and Variable MAC Addresses RF radio frequency RMA random MAC address SA source address STA Station TA Sending Address WFA Wireless Fidelity Alliance OTA (Over-the-Air) Download SSPN Subscription Service Provider Network TDLS tunnel direct link establishment FILS Fast Initial Link Establishment

Claims

1. A method (900) performed by a terminal device, comprising: obtaining (S902) information indicating a plurality of privacy capabilities of a network node; and selecting (S904) zero or at least one of the plurality of privacy capabilities.

2. The method (900) of claim 1, wherein obtaining the information comprises: receiving (S9022), from the network node, a first message indicating the plurality of privacy capabilities of the network node.

3. The method (900) of claim 2, wherein the first message comprises at least one of: a beacon frame, an operation frame, a probe response, a generic advertisement service (GAS) initial response, an authentication response frame, an association response frame, or a four-way handshake response frame.

4. The method (900) of claim 2 or 3, further comprising: sending (S901), to the network node, a second message requesting privacy capabilities of the network node; wherein the first message is a response to the second message.

5. The method (900) of claim 4, wherein the second message comprises at least one of: an operation frame, a probe request, a generic advertisement service (GAS) initial request, an authentication request frame, an association request frame, or a four-way handshake request frame.

6. The method (900) of claim 4 or 5, wherein the first message and / or the second message comprises at least one of: a capabilities information field, a robust security network information element (RSNE), an extended capabilities information element, a robust security network extension information element (RSNXE), a privacy capability selection information element, an access network query protocol (ANQP) element, or a privacy capability selection key data encapsulation / four-way handshake field related to privacy capabilities of the network node.

7. The method (900) of any of claims 4 to 6, wherein the first message and / or the second message is encrypted or unencrypted.

8. The method (900) of any of claims 1 to 7, wherein the terminal device makes the selection based on at least a local configuration; and sending (S906), to the network node, a third message to indicate the selection. wherein the method further comprises:

9. The method (900) of claim 8, wherein the third message is sent during association between the terminal device and the network node and before a secure connection is established between the terminal device and the network node; and wherein the third message comprises at least one of: an authentication request frame, an association request frame, a four-way handshake request frame, or an operation frame.

10. The method (900) of claim 8, wherein the third message is sent after association between the terminal device and the network node and after a secure connection is established between the terminal device and the network node; and wherein the third message comprises at least one of: a disassociation frame, a deauthentication frame, or an operation frame.

11. The method (900) of any of claims 8 to 10, wherein the third message is sent during association between the terminal device and the network node and before a secure connection is established between the terminal device and the network node; and wherein the third message comprises at least one of: an authentication request frame, an association request frame, a four-way handshake request frame, or an operation frame. wherein the third message comprises at least one of the following to indicate the selection: a capability information field, a robust security network information element RSNE, an extended capability information element, a robust security network extended information element RSNXE, a privacy capability selection information element, a privacy capability selection key data wrap / four-way handshake field, or a status code or reason code in status information.

12. The method (900) of any of claims 8-11, wherein the third message comprises at least one of the following status information: the selection is at least partially successful; a capability is violated; a capability is unknown; a capability is not supported; a capability needs to be retransmitted; a capability needs to be changed; a capability needs to be changed to; a capability needs to be selected; or a re-association or re-authentication is needed due to privacy violation.

13. The method (900) of any of claims 8-12, wherein the third message is encrypted or unencrypted.

14. The method (900) of any of claims 1-13, further comprising: receiving (S903) a fourth message from the network node to indicate the terminal device to select zero or at least one of the plurality of privacy capabilities, wherein the terminal device makes the selection based on the fourth message from the network node.

15. The method (900) of claim 14, wherein the fourth message is received during an association between the terminal device and the network node and before a secure connection is established between the terminal device and the network node; and wherein the fourth message comprises at least one of the following: an authentication response frame, an association response frame, a four-way handshake response frame, or an operation frame.

16. The method (900) of claim 14, wherein the fourth message is received after an association between the terminal device and the network node and after a secure connection is established between the terminal device and the network node; and wherein the fourth message comprises at least one of the following: a disassociation frame, a deauthentication frame, or an operation frame.

17. The method (900) of any of claims 14-16, wherein the fourth message comprises at least one of the following to indicate the selection: a capability information field, a robust security network information element RSNE, an extended capability information element, a robust security network extended information element RSNXE, a privacy capability selection information element, a privacy capability selection key data wrap / four-way handshake field, or a status code or reason code in status information.

18. The method (900) of any of claims 14-17, wherein the fourth message comprises at least one of the following status information: the selection is at least partially successful; a capability is violated; a capability is unknown; a capability is not supported; a capability needs to be retransmitted; a capability needs to be changed; a capability needs to be changed to; a capability needs to be selected; or a re-association or re-authentication is needed due to privacy violation.

19. The method (900) of any of claims 14-18, wherein the fourth message is encrypted or unencrypted.

20. The method (900) of any one of claims 1-19, wherein the terminal device comprises a non-AP station (non-AP STA); and wherein the network node comprises an AP.

21. A method (1000) performed by a network node, comprising: sending (SI 002), to a terminal device, information indicating a plurality of privacy capabilities of the network node, wherein the information is for the terminal device to select zero or at least one of the plurality of privacy capabilities.

22. The method (1000) of claim 21, wherein sending the information comprises: sending (SI 0022), to a terminal device, a first message indicating the plurality of privacy capabilities of the network node.

23. The method (1000) of claim 22, wherein the first message comprises at least one of: a beacon frame, an operation frame, a probe response, a generic advertisement service (GAS) initial response, an authentication response frame, an association response frame, or a four-way handshake response frame.

24. The method (1000) of claim 22 or 23, further comprising: receiving (SI 001), from the terminal device, a second message for requesting privacy capabilities of the network node; wherein the first message is in response to the second message.

25. The method (1000) of claim 24, wherein the second message comprises at least one of: an operation frame, a probe request, a generic advertisement service (GAS) initial request, an authentication request frame, an association request frame, or a four-way handshake request frame.

26. The method (1000) of any one of claims 24-25, wherein the first message and / or the second message comprises at least one of: a capabilities information field, a robust security network information element (RSNE), an extended capabilities information element, a robust security network extended information element (RSNXE), a privacy capability selection information element, an access network query protocol (ANQP) element, or a privacy capability selection key data encapsulation / four-way handshake field related to privacy capabilities of the network node.

27. The method (1000) of any one of claims 24-26, wherein the first message and / or the second message is encrypted or unencrypted.

28. The method (1000) of any one of claims 21-27, further comprising: receiving (SI 006), from the terminal device, a third message to indicate a selection of zero or at least one of the plurality of privacy capabilities by the terminal device.

29. The method (1000) of claim 28, wherein the third message is received during an association between the terminal device and the network node and prior to a secure connection establishment between the terminal device and the network node; and wherein the third message comprises at least one of: an authentication request frame, an association request frame, a four-way handshake request frame, or an operation frame.

30. The method (1000) of claim 28, wherein the third message is received after association between the terminal device and the network node and after establishment of a secure connection between the terminal device and the network node; and wherein the third message comprises at least one of: a disassociation frame, a deauthentication frame, or an action frame.

31. The method (1000) of any of claims 28-30, wherein the third message comprises at least one of: a capabilities information field, a robust security network information element, RSNE, an extended capabilities information element, a robust security network extended information element, RSNXE, a privacy capabilities selection information element, a privacy capabilities selection key data wrap / 4-way handshake field, or a status code or reason code in status information to indicate the selection.

32. The method (1000) of any of claims 28-31, wherein the third message comprises at least one of the following status information: selection at least partially successful; capability violated; capability unknown; capability not supported; capability needs to be retransmitted; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication needed due to privacy violation.

33. The method (1000) of any of claims 28-32, wherein the third message is encrypted or unencrypted.

34. The method (1000) of any of claims 21-33, further comprising: sending (S1003) a fourth message to the terminal device to indicate that the terminal device selects zero or at least one of the plurality of privacy capabilities.

35. The method (1000) of claim 34, wherein the fourth message is sent during association between the terminal device and the network node and before establishment of a secure connection between the terminal device and the network node; and wherein the fourth message comprises at least one of: an authentication response frame, an association response frame, a 4-way handshake response frame, or an action frame.

36. The method (1000) of claim 34, wherein the fourth message is sent after association between the terminal device and the network node and after establishment of a secure connection between the terminal device and the network node; and wherein the fourth message comprises at least one of: a disassociation frame, a deauthentication frame, or an action frame.

37. The method (1000) of any of claims 34-36, wherein the fourth message comprises at least one of: a capabilities information field, a robust security network information element, RSNE, an extended capabilities information element, a robust security network extended information element, RSNXE, a privacy capabilities selection information element, a privacy capabilities selection key data wrap / 4-way handshake field, or a status code or reason code in status information to indicate the selection.

38. The method (1000) of any of claims 34-37, wherein the fourth message comprises at least one of the following status information: selection at least partially successful; capability violated; capability unknown; capability not supported; capability needs to be retransmitted; capability needs to be changed; capability needs to be changed; capability needs to be selected; or re-association or re-authentication is needed due to privacy violation.

39. The method (1000) of any of claims 34-37, wherein the fourth message is encrypted or unencrypted.

40. The method (1000) of any of claims 21-39, wherein the terminal device comprises a non-AP station, non-AP STA; and wherein the network node comprises an AP.

41. A terminal device (440) comprising means (4400) configured to: obtain information indicating a plurality of privacy capabilities of a network node; and select zero or at least one of the plurality of privacy capabilities.

42. The terminal device (440) of claim 41, wherein the means (4400) are further configured to perform the method of any of claims 2-20.

43. The terminal device (440) of claim 41 or 42, wherein the means (4400) comprise: at least one processor (4402); and at least one memory (4402) storing instructions that, when executed by the at least one processor (4402), cause performance of the terminal device (440).

44. A network node (450) comprising means (4500) configured to: send, to a terminal device, information indicating a plurality of privacy capabilities of the network node; wherein the information is for the terminal device to select zero or at least one of the plurality of privacy capabilities.

45. The network node (450) of claim 44, wherein the means (4500) are further configured to perform the method of any of claims 22-40.

46. The network node (450) of claim 44 or 45, wherein the means (4500) comprise: at least one processor (4502); and at least one memory (4504) storing instructions that, when executed by the at least one processor (4502), cause performance of the network node (450).

47. A computer-readable storage medium (460) storing instructions (461) that, when executed by at least one processor of a terminal device, cause the at least one processor of the terminal device to perform the method of any of claims 1-20; or that, when executed by at least one processor of a network node, cause the at least one processor of the network node to perform the method of any of claims 21-40.