Status reporting frames for easy reconnection

By providing a protected management frame status reporting process in IEEE 802.11 wireless networks, the issues of non-AP STA identification and over-the-air traffic privacy are resolved, ensuring the security and accuracy of network management.

CN121909673APending Publication Date: 2026-04-21CISCO TECHNOLOGY INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CISCO TECHNOLOGY INC
Filing Date
2024-07-15
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In IEEE 802.11 wireless networks, issues related to the identification of non-AP STAs and the privacy and security of over-the-air traffic, including IRM selection conflicts, device ID recognition failures, and network authentication failures, lead to difficulties in network management.

Method used

A protected management frame status reporting process is provided, which sends status report frames from the AP to non-AP STAs to ensure fine-grained and secure information, prevent traffic analysis, and notify device status and policy errors.

Benefits of technology

It enables secure and fine-grained status notifications to non-AP STAs, preventing identity leakage and ensuring the accuracy and security of network policy enforcement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121909673A_ABST
    Figure CN121909673A_ABST
Patent Text Reader

Abstract

A status report frame may be provided. First, an access point (AP) may be associated with a client device. The AP may then send a status report to the client device in a status report frame that includes the protected management frame.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related applications This application was filed on July 15, 2024 as a PCT international patent application and claims the benefit and priority of U.S. Provisional Patent Application No. 63 / 513,545, filed on July 13, 2023, the disclosure of which is incorporated herein by reference in its entirety. Technical Field

[0002] This disclosure generally relates to providing a status report frame for easier reconnection. Background Technology

[0003] In computer networks, a wireless access point (AP) is a network hardware device that allows Wi-Fi-compatible client devices to connect to wired networks and other client devices. An AP typically connects to a router as a standalone device (directly or indirectly via a wired network); however, an AP can also be an integral part of the router itself. Multiple APs can also work together via direct wired or wireless connections, or through a central system (often called a Wireless Local Area Network (WLAN) controller). An AP differs from a hotspot, which is a physical location where Wi-Fi access to a WLAN is available.

[0004] Before the advent of wireless networks, establishing a computer network in a business, home, or school typically required laying numerous cables through walls and ceilings to provide network access for all network devices within the building. With the advent of wireless access points (APs), network users could add devices that could access the network using little or no cable. An AP connects to a wired network and then provides a radio frequency link to that wired network for other wireless devices. Most APs support multiple wireless devices connected at once. APs were built to support the use of these radio frequencies to send and receive data, which is the standard for APs. Attached Figure Description

[0005] The accompanying drawings, which are incorporated in and constitute a part of this disclosure, illustrate various embodiments of the present disclosure. In the drawings: Figure 1 This is a block diagram of the operating environment used to provide status report frames; Figure 2 This is a flowchart of a method for providing status report frames; and Figure 3 It is a block diagram of a computing device. Detailed Implementation

[0006] Overview A status report frame can be provided. First, the access point (AP) can be associated with a client device. Then, the AP can send a status report to the client device in a status report frame that includes a protected management frame.

[0007] The foregoing overview and the following example embodiments are merely exemplary and illustrative and should not be construed as limiting the scope of the described and claimed disclosure. Furthermore, additional features and / or variations may be provided in addition to the described features and / or variations. For example, embodiments of this disclosure may relate to various combinations and sub-combinations of features described in the example embodiments.

[0008] Example Implementation The following detailed description refers to the accompanying drawings. Wherever possible, the same reference numerals are used in the drawings and the following description to refer to the same or similar elements. While embodiments of this disclosure can be described, modifications, adaptations, and other implementations are possible. For example, elements illustrated in the drawings may be replaced, added, or modified, and the methods described herein may be modified by replacing, reordering, or adding stages to the disclosed methods. Therefore, the following detailed description does not limit this disclosure. Rather, the proper scope of this disclosure is defined by the appended claims.

[0009] For IEEE 802.11 wireless networks, privacy and security issues related to user identity and over-the-air traffic may arise. Over the years, different device implementations have developed processes to hide the Media Access Control (MAC) addresses used in the air, shifting from manufacturer-assigned Organizationally Unique Identifiers (OUIs) to locally managed addresses to reduce device tracking. These locally managed addresses can be randomly assigned from a 46-bit address space, indicating they are local by setting the second least significant bit (i.e., the generic / local bit) of the first octet of the address. This randomized address can be changed according to different policies and at different times, depending on the device implementation.

[0010] IEEE 802.11bh provides device identification for wireless stations that may use randomized MAC addresses, while still allowing for protection against third parties. Two concepts are introduced in IEEE 802.11bh: i) Identifiable Random MAC (IRM), which is a future MAC address selected by a non-AP station (STA) and sent to the AP during the device's network access process; and ii) Device ID, which can be an element sent by the AP to a non-AP STA and can be used to identify the non-AP STA when it moves within an Extended Service Set (ESS).

[0011] Different scenarios may exist where the handling of IRM or device IDs can lead to different problems due to their nature. First, a non-AP STA (e.g., a client device) might choose the same IRM value as another non-AP STA present in the ESS. This is a low-probability scenario, but it is still possible (e.g., when both STAs are from the same vendor and a simple algorithm is used to select the IRM), or it could be malicious activity intentionally carried out by an internal or external attacker. Second, the IRM selected by the AP-STA may not be recognizable as a possible identity of the AP. Third, the AP can provide a device ID to a non-AP STA, but the non-AP STA may not return that device ID to the AP during different protocol access scenarios as defined in IEEE 802.11bh. And fourth, the device ID returned by a non-AP STA may not be recognizable by the network.

[0012] Other potential issues may arise that can be signaled to non-AP STAs, either by allowing processing on the device itself or by notifying the user that the network may be taking administrative action because their device identity has not been recognized. This may differ from network authentication failures using any mechanism defined for an ESS. Therefore, embodiments of this disclosure may provide a process whereby the AP signals the status of a non-AP STA (e.g., a client device) via protected management frames. This status can indicate the success or failure of an element transmitted from the non-AP STA to the AP.

[0013] Figure 1 An operating environment 100 for providing status report frames is shown. For example... Figure 1As shown, the operating environment 100 may include a controller 105 and a coverage environment 110. The coverage environment 110 may include, but is not limited to, a Wireless Local Area Network (WLAN) comprising multiple Access Points (APs) that can provide wireless network access (e.g., for client devices to access the WLAN). The multiple APs may include a first AP 115, a second AP 120, and a third AP 125. The multiple APs can provide wireless network access to multiple client devices as these devices move within the coverage environment 110. The multiple client devices may include, but are not limited to, a first client device 130, a second client device 135, and a third client device 140. The client devices may include, but are not limited to, smartphones, personal computers, tablets, mobile devices, telephones, remote control devices, set-top boxes, digital video recorders, Internet of Things (IoT) devices, network computers, routers, virtual reality (VR) / augmented reality (AR) devices, or other similar microcomputer-based devices. Each of the multiple APs may conform to standards such as, but not limited to, the Institute of Electrical and Electronics Engineers (IEEE) 802.11ax standard.

[0014] Controller 105 may include a Wireless Local Area Network (WLC) controller and may configure and control coverage environment 110 (e.g., WLAN). Controller 105 may allow a first client device 130, a second client device 135, and a third client device 140 to join coverage environment 110. In some embodiments of this disclosure, controller 105 may be implemented by a Digital Network Architecture Center (DNAC) controller (i.e., a Software-Defined Networking (SDN) controller), which may configure information for coverage environment 110 to provide status report frames.

[0015] The aforementioned components of the operating environment 100 (e.g., controller 105, first AP 115, second AP 120, third AP 125, first client device 130, second client device 135, or third client device 140) may be implemented in hardware and / or software (including firmware, resident software, microcode, etc.) or in any other circuit or system. The components of the operating environment 100 may be implemented in circuits including discrete electronic components, packaged or integrated electronic chips containing logic gates, circuits utilizing microprocessors, or on a single chip containing electronic components or a microprocessor. Furthermore, the components of the operating environment 100 may also be implemented using other technologies capable of performing logical operations (e.g., AND, OR, and NOT), including but not limited to mechanical, optical, fluid, and quantum technologies. See below for reference. Figure 3In more detail, the components of the operating environment 100 can be implemented in the computing device 300.

[0016] Figure 2 This is a flowchart illustrating the general stages involved in a method 200 for providing a status report frame according to embodiments of the present disclosure. Method 200 may use the methods described below. Figure 3 The computing device 300 is implemented in more detail below. The computing device 300 can be embodied as the first AP 115. The manner in which each stage of the implementation method 200 is carried out will be described in more detail below.

[0017] Embodiments of this disclosure can provide a secure and fine-grained process for an AP to notify non-AP STAs of potential policy errors or STA status information (e.g., STA status set by the infrastructure) that the STA needs to know. This ensures that the information is fine-grained enough to ensure that different statuses or error scenarios can be shared with non-AP STAs. Furthermore, this ensures that the notification is secure (e.g., protected) against eavesdroppers. Additionally, this ensures that the notification will not be used to determine which identities (e.g., IRM or device ID) are valid on a given network. Moreover, this ensures that the notification frame does not have any specific dimensions or characteristics that could be used by a third party for traffic analysis to determine whether the identifier used is valid in the network.

[0018] Method 200 may begin at start box 205 and proceed to stage 210, where the first AP 115 may associate with the first client device 130. For example, the first client device 130 (e.g., a non-AP STA) may complete a selected authentication process with the first AP 115. This may be required by the ESS / network configuration. The association may be, for example, a full association or the establishment of a pre-association security negotiation (PASN) secure connection.

[0019] Starting at stage 210 (where the first AP 115 associates with the first client device 130), method 200 can proceed to stage 220, where the first AP 115 can send a status report to the first client device 130, the status report being contained in a status report frame that includes a protected management frame. For example, the first AP 115 can notify the first client device 130 of its status in the cell by using a robust action frame (i.e., a status report frame). In one embodiment, the status report frame may be sent to the first client device 130 unsolicited. This embodiment may be useful in scenarios where the first client device 130 may express elements it expects the first AP 115 to measure (e.g., the first client device 130 sends a device ID or uses an IRM). The status report frame may express whether the status is successful or unsuccessful for one or more elements transmitted by the first client device 130, or for one or more elements of a policy defined on the first AP 115 or the infrastructure.

[0020] In another embodiment, status report frames can be sent via exchange. In this example embodiment, the first client device 130 may decide (e.g., automatically after association, or under certain triggering conditions, such as when communication with a specific service expected to be reachable by the first client device 130's operating system (OS) is not possible) to send a status report query frame to the first AP 115. This query may be directed (e.g., "What is my IRM status?") or undirected (e.g., "Tell me what you know about my status"). The first AP 115 may respond accordingly with a status report frame.

[0021] As a result of verifying the provided identity (e.g., IRM, device ID, site type, or other parameters related to infrastructure policies), the status report frame may include information about which policies or actions might be applied to the network. Multiple policies may be returned as a result of such evaluation. Status report frames may be in, but are not limited to, the following two formats: i) fixed-length format; and ii) Type Length Value (TLV) format.

[0022] Fixed length In a fixed-length embodiment, the frame type may include an element ID / type / length, and a status report segment that may include zero or more status reports. A status report count field may indicate the number of reports provided, and for each report, there are a status type field and a status report field. The status type field may indicate which status was reported, and the status report field may indicate a numerical value representing a specific type of status. The frame can be scalable (because multiple reports can be sent), but its size may be limited because each report type and report value may include numerical values ​​for fields of a fixed size. Accordingly, this embodiment can achieve a relatively short frame size.

[0023] To provide resistance to traffic analysis attacks, padding subtypes can be defined, which can be used to add extra bytes to randomly change the overall frame size. The first client device 130 can ignore these sub-elements. The payload of a status report frame with a fixed-length format can be defined as shown in Table 1. Table 2 shows example status types.

[0024] Table 1 Table 2 Type Length Value (TLV) In another embodiment, the frame structure may include sub-elements. This structure provides additional flexibility and allows for sending more complex notifications to the first client device 130, including arbitrary strings defined by the network administrator. This embodiment can be useful because it allows infrastructure to transmit variable-length messages to the first client device 130, including potentially human-readable messages, which can then be displayed on the first client device 130 to the user of the first client device 130. Compared to the aforementioned fixed-length format, the TLV format can include a longer frame structure because each notification can include sub-elements (e.g., overhead for sub-element IDs and lengths in addition to the status type and status report). The payload of a status report frame with the TLV format can be defined as shown in Table 3. Table 4 shows example status sub-elements.

[0025] Table 3 Table 4 Once the first AP 115 sends a status report to the first client device 130 at stage 220 (the status report is located in a status report frame that includes a protected management frame), method 200 can then end at stage 230.

[0026] Figure 3 A computing device 300 is shown. (For example...) Figure 3 As shown, the computing device 300 may include a processing unit 310 and a memory unit 315. The memory unit 315 may include a software module 320 and a database 325. When executed on the processing unit 310, the software module 320 may perform, for example, the above-mentioned... Figure 2 The process described is for providing status report frames. For example, computing device 300 can provide an operating environment for controller 105, first AP 115, second AP 120, third AP 125, first client device 130, second client device 135, or third client device 140. Controller 105, first AP 115, second AP 120, third AP 125, first client device 130, second client device 135, or third client device 140 can operate in other environments and are not limited to computing device 300.

[0027] The computing device 300 can be implemented using Wi-Fi access points, tablets, mobile devices, smartphones, telephones, remote control devices, set-top boxes, digital video recorders, cable modems, personal computers, network computers, mainframes, routers, switches, server clusters, smart TV-like devices, network storage devices, network relay devices, or other similar microcomputer-based devices. The computing device 300 can include any computer operating environment, such as handheld devices, multiprocessor systems, microprocessor-based or programmable transmitter electronics, microcomputers, mainframes, etc. The computing device 300 can also be implemented in a distributed computing environment, where tasks are performed by remote processing devices. The systems and devices described above are examples; the computing device 300 can include other systems or devices.

[0028] Embodiments of this disclosure can be implemented, for example, as a computer process (method), a computing system, or as an article of manufacture such as a computer program product or a computer-readable medium. A computer program product can be a computer storage medium that is readable by a computer system and encodes instructions for performing a computer process. A computer program product can also be a propagated signal on a carrier of a computer program that is readable by a computing system and encodes instructions for performing a computer process. Therefore, this disclosure can be embodied in hardware and / or software (including firmware, resident software, microcode, etc.). In other words, embodiments of this disclosure can take the form of a computer program product on a computer-usable or computer-readable storage medium that embodies computer-usable or computer-readable program code for use by or in connection with an instruction execution system. A computer-usable or computer-readable medium can be any medium capable of containing, storing, communicating, propagating, or transmitting a program for use by or in connection with an instruction execution system, apparatus, or device.

[0029] Computer-usable or computer-readable media can be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, devices, or propagation media. More specific examples of computer-readable media (not an exhaustive list) include: electrical connections having one or more wires, portable computer disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, and compact discread-only memory (CD-ROM). Note that computer-usable or computer-readable media can even be paper or another suitable medium on which a program is printed, because the program can be electronically captured, for example, by optical scanning of the paper or other medium, and then, if necessary, compiled, interpreted, or otherwise processed in an appropriate manner, and subsequently stored in computer memory.

[0030] While some embodiments of this disclosure have been described, other embodiments are possible. Furthermore, although embodiments of this disclosure have been described as being associated with data stored in memory and other storage media, data may also be stored on or read from other types of computer-readable media, such as secondary storage devices like hard disks, floppy disks, or CD-ROMs, carrier waves from the Internet, or other forms of RAM or ROM. Additionally, the stages of the disclosed methods may be modified in any way, including through reordering stages and / or insertion or deletion stages, without departing from this disclosure.

[0031] Furthermore, embodiments of this disclosure can be implemented in circuits including discrete electronic components, packaged or integrated electronic chips containing logic gates, circuits utilizing microprocessors, or on a single chip containing electronic components or a microprocessor. Embodiments of this disclosure can also be implemented using other techniques capable of performing logical operations (e.g., AND, OR, and NOT), including but not limited to mechanical, optical, fluid, and quantum technologies. Additionally, embodiments of this disclosure can be implemented within a general-purpose computer or in any other circuit or system.

[0032] Embodiments of this disclosure can be implemented via a system-on-a-chip (SOC), wherein Figure 1 Each or many of the components shown can be integrated onto a single integrated circuit. Such a SoC device may include one or more processing units, graphics units, communication units, system virtualization units, and various application functions, all of which can be integrated (or “programmed”) onto a chip substrate as a single integrated circuit. When operating via the SoC, the functions described herein with respect to embodiments of this disclosure can be executed via dedicated logic integrated onto a single integrated circuit (chip) along with other components of the computing device 300.

[0033] For example, embodiments of the present disclosure have been described above with reference to block diagrams and / or operational illustrations of methods, systems, and computer program products according to embodiments of the present disclosure. The functions / behaviors described in the blocks may not occur in the order shown in any flowchart. For example, depending on the functions / actions involved, two blocks shown consecutively may actually be executed substantially simultaneously, or the blocks may sometimes be executed in reverse order.

[0034] While this specification includes examples, the scope of this disclosure is indicated by the appended claims. Furthermore, although this specification has been described in language specific to structural features and / or methodological actions, the claims are not limited to the features or actions described above. Rather, the specific features and actions described above are disclosed as examples of embodiments of this disclosure.

Claims

1. A method comprising: The access point (AP) is associated with the client device; as well as The AP sends a status report to the client device, and the status report is located in a status report frame that includes a protected management frame.

2. The method according to claim 1, wherein, The status report includes information about policies applied by the network.

3. The method according to claim 1 or 2, wherein, The status report frame has a fixed length format.

4. The method according to any of the preceding claims, wherein, The status report frame includes a Type Length Value (TLV) record format.

5. The method according to any of the preceding claims, wherein, Sending the status report includes sending the status report without request from the client device.

6. The method according to any of the preceding claims, wherein, Sending the status report includes sending the status report in response to an exchange between the client device and the AP.

7. The method according to any of the preceding claims, wherein, Associating with the client device includes establishing a pre-association security negotiation (PASN) secure connection.

8. The method according to any of the preceding claims, wherein, Associating with the client device includes: establishing a full association.

9. A system comprising: Memory storage device; as well as A processing unit, disposed in an access point (AP) and coupled to the memory storage device, wherein the processing unit is operable to: The AP is associated with the client device; as well as The AP sends a status report to the client device, and the status report is located in a status report frame that includes a protected management frame.

10. The system according to claim 9, wherein, The status report includes information about policies applied by the network.

11. The system according to claim 9 or 10, wherein, The status report frame has a fixed length format.

12. The system according to any one of claims 9 to 11, wherein, The status report frame includes a Type Length Value (TLV) record format.

13. The system according to any one of claims 9 to 12, wherein, The processing unit is operable to send the status report, including: the processing unit is operable to send the status report without request from the client device.

14. The system according to any one of claims 9 to 13, wherein, The processing unit is operable to send the status report, including: the processing unit is operable to send the status report in response to an exchange between the client device and the AP.

15. A non-transitory computer-readable medium storing a set of instructions, said set of instructions executing a method when executed, said method comprising: The access point (AP) is associated with the client device; as well as The AP sends a status report to the client device, and the status report is located in a status report frame that includes a protected management frame.

16. The non-transitory computer-readable medium according to claim 15, wherein, The status report includes information about policies applied by the network.

17. The non-transitory computer-readable medium according to claim 15 or 16, wherein, The status report frame has a fixed length format.

18. The non-transitory computer-readable medium according to any one of claims 15 to 17, wherein, The status report frame includes a Type Length Value (TLV) record format.

19. The non-transitory computer-readable medium according to any one of claims 15 to 18, wherein, Sending the status report includes sending the status report without request from the client device.

20. The non-transitory computer-readable medium according to any one of claims 15 to 19, wherein, Sending the status report includes sending the status report in response to an exchange between the client device and the AP.