IDENTITY CONCEALMENT FOR A WIRELESS STATION
By using a short-term identity that changes periodically and encrypting it with cryptographic keys, the system addresses the issue of exposing long-term identities in wireless networks, preventing tracking and maintaining secure association.
Patent Information
- Application Number
- DE102020118054
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-05-29
- Filing Date
- 2020-07-08
- Publication Date
- 2025-07-03
- Estimated Expiration
- 2040-07-08
AI Technical Summary
Wireless communication standards like IEEE 802.11 often expose the long-term identity of electronic devices, such as MAC addresses, unencrypted and immutable after connection, leading to privacy concerns and easy tracking via network sniffers.
Implement a system where a station (STA) establishes a security association with an access point (AP) to obtain a short-term identity (AID) and periodically changes it, while maintaining a constant long-term identity (MAC address) that remains unexposed, using cryptographic keys for encryption.
Prevents tracking of the STA by periodically changing the short-term identity and masking fingerprint fields, maintaining association with the AP using the constant long-term identity without exposing it over the wireless network.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
STATE OF THE ARTTechnical area
[0001] This disclosure relates to the field of wireless communications including identity concealment of a station (STA) connected to a wireless network to prevent tracking of the STA. State of the art
[0002] Wireless networking has fundamentally changed where users use their electronic devices. Instead of using their electronic devices only in their homes or offices, users now use their electronic devices to connect to wireless networks in various other locations, such as coffee shops, stores, and airports. Users connect to these wireless networks using various wireless communication standards. For example, users often connect to wireless networks using the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard (current guidelines and / or future versions). To manage the association of an electronic device to a wireless network, wireless communication standards such as IEEE 802.11 often use the electronic device's long-term identity (e.g., the Media Access Control (MAC) address).This often requires the electronic device to include its long-term identity in the frames it transmits.
[0003] However, these wireless communication standards often include the long-term identity of the electronic device, which is unencrypted in transmitted frames. Furthermore, these wireless communication standards often prevent the electronic device from changing its long-term identity after the electronic device has already established a connection to the wireless network. This can raise privacy concerns in certain environments. For example, the electronic device can be easily tracked via its long-term identity using a network sniffer that intercepts traffic traveling over the wireless network.
[0004] US 2016 / 0 316 362 A1 relates to a method for protecting location privacy, comprising generating an identification update notification message to be sent to at least one access point, wherein the identification update notification message includes a first identifier of a wireless terminal to indicate that the identification update notification message is to be sent from the wireless terminal. The identification update notification message also includes second identification information of the wireless terminal.The method further includes sending the identification update notification message so that the access point acquires a second identifier according to the second identifier information and uses the second identifier as an identifier of the wireless terminal; and sending a subsequent message containing the second identifier to the access point to indicate that the subsequent message is sent from the wireless terminal.
[0005] US 2017 / 0013449 A1 relates to systems, devices, techniques, and products for managing the dynamic assignment of Media Access Control (MAC) addresses to wireless network devices, e.g., by identifying a dynamically assigned MAC address before, after, or during a wireless mapping process and communicating the dynamically assigned MAC address to a wireless network device. Also disclosed are systems, devices, techniques, and products for preventing a denial-of-service attack on the mapping table of a wireless access point, e.g., by requiring devices connecting to a wireless access point to respond to a query from the wireless access point shortly after connecting. SUMMARY
[0006] According to some embodiments, a mapping between a short-term identity for a station (STA) and a long-term identity for the STA may be used to enable identity concealment of the STA to prevent tracking of the STA while connected to a wireless network. In some embodiments, the wireless network may use the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard (current guidelines and / or future versions) or various other wireless communication protocols.
[0007] In some embodiments, an STA may establish a security association with an access point (AP) to obtain a short-term identity from the AP. The short-term identity may be an association identifier (AID) assigned to the STA by the AP when the STA established the security association with the AP. The STA may generate a new long-term identity for itself and then transmit the new long-term identity to the AP. The new long-term identity may be a media access control (MAC) address. The STA may transmit the new long-term identity by leveraging the security association with the AP. For example, the STA may encrypt the new long-term identity using a set of cryptographic keys installed through the security association.Both the AP and the STA can map the STA's new long-term identity to its short-term identity assigned by the AP; to do so, the STA only needs to include its short-term identity in the frames sent to the AP. At a later time, the STA can send a request frame to the AP to change the short-term identity assigned to it by the AP. The STA can then receive a reply frame from the AP. The reply frame can include a new short-term identity assigned to the STA by the AP. The new short-term identity can be a new AID assigned to the STA by the AP. The request and reply frames can be encrypted to avoid being tracked by other devices. Both the AP and the STA can then map their new long-term identity to their new short-term identity assigned by the AP, and the STA can include its new short-term identity in the frame sent to the AP.Thereafter, the STA can periodically change its short-term identity to prevent tracking. The STA can further maintain its association with the AP using the new long-term identity without being tracked, provided the new long-term identity is never transmitted unprotected over the wireless network.
[0008] In some embodiments, an STA may periodically change or mask various "fingerprint" fields stored in the frame sent over a wireless network to prevent tracking of the STA while connected to the wireless network. For example, the STA may reset a flow control (SC) field in a frame to a random value whenever the STA has changed its short-term identity. The STA may reset a packet number (PN) of a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field in a frame to a random value whenever the STA has changed its short-term identity. The STA may mask a High Throughput Control (HTC) and / or a CCMP field in a frame. The STA may also encrypt one or more MAC header fields of a frame along with MAC payload.
[0009] In some embodiments, an AP may establish a security association with an STA and assign a short-term identity to the STA. The short-term identity may be an AID assigned to the STA by the AP when the STA first established the security association with the AP. The AP may then receive a new long-term identity from the STA. The new long-term identity may be a MAC address. The AP may receive the new long-term identity based on the security association. For example, the STA may send the new long-term identity to the AP in encrypted form using a set of cryptographic keys installed by the security association. Both the AP and the STA may map the STA's new long-term identity to its AP-assigned short-term identity; to do so, the AP only needs to include its short-term identity in the frames sent to the STA.The AP may then receive a request frame from the STA to change the short-term identity assigned to the STA by the AP. The AP may then send a response frame to the STA. The response frame may include a new short-term identity assigned to the station. The request and response frames may be encrypted to avoid being tracked by other devices. The new short-term identity may be a new AID assigned to the STA by the AP. The AP may randomly select the new AID within a data block of AIDs that is randomly selected when a new AID change period begins. Both the AP and the STA may map the new long-term identity for the STA to the new short-term identity assigned to the STA, and the AP may include the STA's new short-term identity in the frames sent to the STA.The AP can then periodically change the STA's short-term identity to prevent STA tracking. The AP can also maintain an association with the STA using the STA's new long-term identity without transmitting the new long-term identity unprotected over the wireless network.
[0010] Further features of the present invention will become apparent from the accompanying drawings and the detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The attached drawings are incorporated herein and form part of the specification. Fig. 1 illustrates an example system for identity concealment of a station (STA) connected to a wireless network, according to some embodiments. Fig. 2 is a block diagram of an example STA that transmits and receives frames over a wireless network, according to some embodiments. Fig. 3 illustrates a block diagram of an example access point (AP) that transmits and receives frames over a wireless network, according to some embodiments. Fig. 4 is a block diagram of an exemplary IEEE (Institute of Electrical and Electronics Engineers) 802.11 compliant frame, according to some embodiments. Fig. 5 is a flowchart of an example method for identity concealment of a STA connected to a wireless network, according to some embodiments. Fig. 6 is a swimlane diagram illustrating identity concealment of a STA connected to an IEEE 802.11 wireless network, according to some embodiments. Fig. 7 is a block diagram of an example traffic indication map bitmap of a TIM field represented using a partial virtual bitmap, according to some embodiments. Fig. 8 is a block diagram of an example standards-compliant frame in which a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field has been moved along with MAC payload as part of the encryption of one or more MAC header fields, according to some embodiments. Fig. 9 is an exemplary computer system for implementing various embodiments.
[0012] In the drawings, like reference numbers generally indicate identical or similar elements. Furthermore, the leftmost digit(s) of a reference number generally identify the drawing in which the reference number first appears. DETAILED DESCRIPTION
[0013] Provided herein are system, device, apparatus, method, and / or computer program product embodiments, and / or combinations and subcombinations thereof, for identity concealment of a station (STA) connected to a wireless network to prevent tracking of the STA. Some embodiments operate by having an STA establish a mapping between a short-term identity for the STA (e.g., an AID) that is broadcast "unprotected" over a wireless network and changed periodically, and a long-term identity for the STA (e.g., a Media Access Control (MAC) address) that remains constant while the STA is associated with an access point (AP) and is never broadcast "unprotected" over the wireless network.Additionally, some embodiments operate by having an STA periodically change or mask various "fingerprint" fields stored in frames transmitted over a wireless network.
[0014] Users often use their electronic devices (e.g., mobile phones, laptops, smartwatches, and various other electronic devices, as would be appreciated by one of ordinary skill in the art) to connect to wireless networks provided in public spaces, such as coffee shops, stores, and airports. Users connect to these wireless networks using various wireless communication standards. For example, users often connect to wireless networks using the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard (current guidelines and / or future versions). To manage the association of an electronic device to a wireless network, wireless communication standards such as IEEE 802.11 often use the electronic device's long-term identity (e.g., the Media Access Control (MAC) address).This often requires the electronic device to include its long-term identity in the frames it transmits.
[0015] However, these wireless communication standards often store the long-term identity of the electronic device unencrypted in transmitted frames. Furthermore, these wireless communication standards often prevent the electronic device from changing its long-term identity after the electronic device has already established a connection to a wireless network. This can raise privacy concerns in certain environments. In particular, the electronic device can be easily tracked using a network sniffer that intercepts traffic passing over the wireless network. This is because the long-term identity of the electronic device is stored in an unencrypted format and remains relatively constant. This is especially true in public spaces, such as coffee shops, stores, and airports.
[0016] For example, a customer may visit a store and connect their mobile device to the store's wireless network. However, once the customer connects to the store's wireless network, any network sniffers in the store can track where in the store the customer spends their time, how often they visit the store, and even what they browse on their mobile device.
[0017] Some wireless communication standards allow an electronic device to dynamically change its long-term identity before connecting to a wireless network. This can reduce the likelihood that the electronic device can be tracked before joining the wireless network. However, this still raises privacy concerns. This is because the electronic device often cannot change its long-term identity once it joins a wireless network. Therefore, once the electronic device has joined the wireless network, it can still be easily tracked as long as it is connected to the network. Thus, conventional approaches are unable to simultaneously manage the association of an electronic device with a wireless network and conceal the identity of the electronic device.
[0018] Systems and methods for solving this technological problem are provided herein. In particular, embodiments herein include mapping between a short-term identity for an STA (e.g., an AID) that is transmitted unprotected over a wireless network and changes periodically, and a long-term identity for the STA (e.g., a MAC address) that remains constant while the STA is assigned to an AP and that is never transmitted "unprotected" over the wireless network; herein, "unprotected" means transmitted unencrypted over the wireless network.
[0019] Fig. 1 illustrates an exemplary system 100 for identity concealment of a STA connected to a wireless network, according to some embodiments. System 100 includes AP 102 and STAs 104, 106, and 108. Together with AP 102, STAs 104, 106, and 108 form a BSS (Basic Service Set) or an ESS (Extended Service Set). It is understood that system 100 may include other STAs in addition to or instead of the STAs described in Fig. 1 without departing from the scope and spirit of this disclosure. These other STAs include, but are not limited to, desktop computers, laptops, smartphones, tablets, touchpads, wearable electronic devices, smartwatches, or other electronic devices.
[0020] STAs 104, 106, and 108 may transmit and receive frames via AP 102. For example, AP 102 and STAs 104, 106, and 108 may transmit and receive MAC Protocol Data Unit (MPDU) frames in accordance with the IEEE 802.11 standard (current guidelines and / or future versions). As will be appreciated by one of ordinary skill in the art, STAs 104, 106, and 108 may transmit and receive frames via AP 102 using various other wireless communication protocols.
[0021] Fig. 2 illustrates a block diagram of an example STA 200 that transmits and receives frames over a wireless network, according to some embodiments. STA 200 may be any STA (e.g., 104, 106, or 108) of system 100. STA 200 includes processor 210, transceiver 220, communication infrastructure 230, memory 240, and antenna 250. Memory 240 may include random access memory (RAM) and / or cache, and may include control logic (e.g., computer software) and / or data. Processor 210, along with instructions stored in memory 240 (or hardwired into processor 210), performs operations that protect an identity of STA 200 while generating various data exchange frames (data and / or control) that are transmitted over a wireless network using transceiver 220. Transceiver 220 sends and receives communication signals (e.g.wireless signals) via antenna 250, including data exchange frames that support protecting an identity of STA 200 while connected to a wireless network, according to some embodiments. Communication infrastructure 230 may be a bus. Antenna 250 may include one or more antennas, which may be of the same or different types.
[0022] Fig. 3 illustrates a block diagram of an example AP 300 that transmits and receives frames over a wireless network, according to some embodiments. AP 300 may be AP 102 of system 100. AP 300 includes processor 310, transceiver 320, communication infrastructure 330, memory 340, antenna 350, and a wireless interface 360. Memory 340 may include random access memory (RAM) and / or cache, and may include control logic (e.g., computer software) and / or data. Processor 310, in conjunction with instructions stored in memory 640, performs operations that protect an identity of an STA (e.g., any STA 104, 106, or 108) while connected to a wireless network.Transceiver 320 may transmit and receive communication signals, including data exchange frames that support protecting an identity of an STA 200, over wireless interface 360 and may be coupled to antenna 350. Communication infrastructure 330 may be a bus. Antenna 350 may include one or more antennas, which may be of the same or different types.
[0023] Fig. 4 is a block diagram of an exemplary standards-compliant frame 400 according to the IEEE 802.11 standard (current guidelines and / or future versions), according to some embodiments. Fig. 4 is with reference to Fig. 1, where STAs 104, 106 and 108 can send and receive frame 400 with AP 102.
[0024] Frame 400 may include a physical (PHY) header 402, a MAC header 404, and MAC payload 406. Frame 400 may include various other fields, as would be appreciated by one of ordinary skill in the art. Frame 400 may be a data frame, a management frame, a control frame, or any other type of frame, as would be appreciated by one of ordinary skill in the art.
[0025] Frame 400 may include one or more identities for STAs (e.g., STAs 104, 106, and 108) and an AP (e.g., AP 102). For example, PHY header 402 may include an association identifier (AID) for an STA. An AID may also be referred to as a short-term identity for an STA. A short-term identity for an STA is an identity that can be easily changed while the STA is associated with an AP.
[0026] An AID can be assigned to an STA by an AP. The AID can be assigned to the STA after the STA has been associated with the AP. An AP can use an AID to indicate various information to an STA. For example, the AP can include an AID in a traffic indicator map (TIM) field of frame 400. In this case, frame 400 can be a beacon frame. The presence of the AID in the TIM field can indicate that downlink frames are available at the AP for downloading by the associated station. The AP can also include an AID in frame 400 to indicate a resource block allocation for the corresponding STA. In this case, frame 400 can be a trigger frame. The AP can also include an AID in a signaling information (SIG) field in frame 400 to indicate a resource block allocation for the corresponding STA.
[0027] Frame 400 may include a MAC header 404. MAC header 404 may include one or more identities for STAs. For example, MAC header 404 may include one or more MAC addresses for STAs. A MAC address may also be referred to as a long-term identity for an STA. A long-term identity for an STA is an identity that cannot be easily changed while the STA is connected to an AP or an ESS network to which the AP belongs. A MAC address can be a globally unique MAC address or a locally administered MAC address.
[0028] A network interface of an STA (e.g., transceiver 220 of STA 200) is assigned a globally unique MAC address by the network interface manufacturer. The STA's network interface can also be assigned a locally administered MAC address, which overrides the globally unique MAC address. For example, a network administrator can assign a locally administered MAC address to the STA. A locally administered MAC address of the STA can be changed.
[0029] An AP may use a MAC address of an STA to manage the STA. For example, the AP may use the STA's MAC address to manage the STA's association with the AP. The AP may use the STA's MAC address to manage the assignment of logical network addresses (e.g., an Internet Protocol (IP) address) to the STA. The AP may use the STA's MAC address to perform Address Resolution Protocol (ARP) caching for the STA. The AP may use the STA's MAC address to manage roaming across the STA. The AP may use the STA's MAC address to manage various other features associated with the STA, as would be apparent to one of ordinary skill in the art.
[0030] In conventional approaches, Frame 400 may store an STA's MAC address in an unencrypted (i.e., "unprotected") format. As a result, a network sniffer can intercept Frame 400 and determine the STA's MAC address. This means the STA is easily traced. To avoid tracking, an STA may periodically change its MAC address to a random value. However, this still does not protect the STA from tracking. This is because the STA may not be able to change its MAC address once it joins a wireless network, as changing it can prevent the AP from managing the STA's association with the AP. Therefore, once the STA joins the wireless network, the STA can often be easily traced until the STA disconnects from the network.
[0031] Additionally, frame 400 can include various other fields ("fingerprint fields") that can be used to identify an STA. In conventional approaches, frame 400 can store these fields "unprotected," or unencrypted. Accordingly, a network sniffer can intercept frame 400 and monitor the values of these fields. This means the STA can also be easily tracked using these fields.
[0032] For example, MAC header 404 may include various fields that can carry unique fingerprints for an STA. MAC header 404 may include receiver address (RA) 408, sender address (TA) 410, BSS identifier (BSSID) 412, flow control (SC) 414, high-throughput screening (HTC) 416, and counter mode cipher block chaining message authentication code protocol (CCMP) 418. SC 414 may carry a frame sequence number 400. The sequence number may be sequentially incremented in subsequent frames. HTC 416 may store various control settings. CCMP 418 may store a packet number (PN). The PN may be sequentially incremented in subsequent frames.
[0033] To address these technical problems, the embodiments described herein map between a short-term identity for an STA (e.g., an AID) that is sent "unprotected" over a wireless network and changes periodically, and a long-term identity for the STA (e.g., a MAC address) that remains constant while the STA is associated with an AP (or an ESS network to which the AP belongs) and is never sent "unprotected" over the wireless network. Furthermore, embodiments herein periodically change and / or mask various "fingerprint" fields stored in frames sent over a wireless network.
[0034] The term "long-term" in long-term identity may refer to the fact that a long-term identity of an STA is often changed less frequently than a short-term identity of the STA. For example, a long-term identity of an STA often cannot be changed after an association with an AP has been established.
[0035] Fig. 5 is a flowchart of an exemplary method 500 for identity concealment of a STA connected to a wireless network, according to some embodiments. Method 500 may be performed by processing logic including hardware (e.g., circuitry, dedicated logic, programmable logic, microcode, etc.), software (e.g., instructions executing on a processing device), or a combination thereof. Method 500 may be used with various wireless communication protocols. It should be understood that not all steps are required to practice the disclosure provided herein. Further, some of the steps may be performed concurrently or in a different order than that presented in Fig. 5, as will be understood by one of ordinary skill in the art. Fig. 5 is made with reference to Fig. 1, Fig. 2 and Fig. 4 described.
[0036] At 501, a STA (e.g., STA 104) sends a discovery request frame (e.g., a query request frame) to discover available networks (e.g., an IEEE 802.11 network) in its vicinity. Before sending the discovery request frame, the STA acquires an initial long-term identity (e.g., a locally administered MAC address). The station may include its initial long-term identity in the discovery request frame.
[0037] The term "long-term" in long-term identity may refer to the fact that a long-term identity of an STA is often changed less frequently than a short-term identity of the STA. For example, a long-term identity of an STA often cannot be changed after an association with an AP has been established.
[0038] The STA may generate its own initial long-term identity, or its initial long-term identity may be assigned by a user, network administrator, manufacturer, or other entity, as would be understood by one of ordinary skill in the art. The initial long-term identity may also be referred to as an initial long-term identity. The initial long-term identity may also be referred to as a pre-association long-term identity. This is because the STA may be configured with the pre-association long-term identity before joining a wireless network. The STA may change its initial long-term identity before 502. For example, the STA may change its initial long-term identity to a random value to prevent it from being tracked.
[0039] In 502, the STA receives a discovery response frame from an AP (e.g., AP 102) in response to the transmission of the discovery request frame.
[0040] At 503, the STA authenticates itself to the AP. This authentication process determines whether the STA can join the AP's wireless network. As will be appreciated by one of ordinary skill in the art, the STA may authenticate the AP using various types of authentication techniques. The STA may include its initial long-term identity in the one or more authentication frames used during the authentication process. However, once the authentication process begins, the STA cannot change its initial long-term identity until a security association is completed or aborted.
[0041] At 504, the STA sends an association request frame to join the AP's wireless network. The STA includes its first long-term identity in the association request frame.
[0042] At 505, the STA receives an association response frame from the AP in response to the transmission of the association request frame. The association response frame may indicate whether the AP has allowed the STA to join its wireless network. If the AP has allowed the STA to join its wireless network, the association response frame may include a first short-term identity for the STA (e.g., an AID). The AP may assign the first short-term identity to the STA based on a random value. The STA's short-term identity may identify the STA in the AP's wireless network. The STA then maps its first short-term identity to its first long-term identity and stores the mapping in memory, such as memory 240.
[0043] At 506, the STA establishes a first security association with the AP. The STA may use the first security association to encrypt frames to and from the AP. For example, the first security association may include a set of cryptographic keys that the STA uses to encrypt subsequent frames exchanged with the AP. The STA may establish a first security association based on the STA's first long-term identity and the AP's identity (e.g., the AP's MAC address).
[0044] In 507, the STA creates a second long-term identity (“a new long-term identity”) for itself. The STA may create its second long-term identity based on a random value.
[0045] At 508, the STA transmits its second long-term identity to the AP using the first security association. Transmitting the STA's second long-term identity to the AP using the first security association prevents the second long-term identity from being intercepted by a network sniffer.
[0046] At 509, the STA uses its second long-term identity and the AP's identity to establish a second security association with the AP. The STA may use the second security association to encrypt frames to and from the AP after the first and second security associations have been successfully established. For example, the second security association may include a set of cryptographic keys that the STA may use to encrypt frames to and from the AP.
[0047] At 510, the STA sends a request to the AP to change its first short-term identity. The STA may send the request to the AP to change its first short-term identity using the second security association.
[0048] At 511, the STA receives an acknowledgment from the AP indicating that the STA's first short-term identity has been changed to a second short-term identity. The STA may receive the acknowledgment using the second security association. The STA then maps its assigned second short-term identity to its second long-term identity. The STA and AP may include the STA's second short-term identity and the AP's identity (e.g., BSSID) in frames to avoid exposing the STA's second long-term identity to other devices. The STA may have changed its short-term identity periodically but kept its second long-term identity unchanged, allowing it to maintain the second security association with the AP without changing cryptographic keys.
[0049] For example, the STA and AP may include the STA's second short-term identity and the AP's identity (e.g., BSSID) in frame 400 to avoid exposing the STA's second long-term identity to other devices. If frame 400 is a data downlink or management frame, PHY header 402 may include the AP's identity (e.g., BSSID), the STA's second short-term identity, a hash value of the STA's second short-term identity, a hash value of the AP's identity, and / or a hash value of the STA's second short-term identity. RA 408 may include the AP's identity, the STA's second short-term identity, and / or a hash value of the STA's second short-term identity and the AP's identity. TA 410 may include the AP's identity, a zero short-term identity of the STA, and / or a hash value of the zero short-term identity of the STA and the AP's identity. BSSID 412 can include the identity of the AP.
[0050] If frame 400 is an uplink acknowledgment or frame acknowledgment frame, RA 408 may include the AP identity, a zero short-term identity of the STA, and / or a hash of the zero short-term identity of the STA and the AP identity. TA 410 may include the AP identity, the second short-term identity of the STA, and / or a hash of the second short-term identity of the STA and the AP identity.
[0051] If frame 400 is a data uplink or management frame, PHY header 402 may include the AP identity, a zero short-term identity of the STA, and / or a hash of the zero short-term identity of the STA and the AP identity. RA 408 may include the AP identity, a zero short-term identity of the STA, and / or a hash of the zero short-term identity of the STA and the AP identity. TA 410 may include the AP identity, the second short-term identity of the STA, and / or a hash of the second short-term identity of the STA and the AP identity. BSSID 412 may include the AP identity.
[0052] If frame 400 is a downlink acknowledgment or frame acknowledgment frame, RA 408 may include the AP identity, the STA's second short-term identity, and / or a hash of the STA's second short-term identity and the AP's identity. TA 410 may include the AP identity, a zero short-term identity of the STA, and / or a hash of the zero short-term identity of the STA and the AP's identity.
[0053] Fig. 6 is a swimlane diagram illustrating identity concealment of a STA connected to an IEEE 802.11 wireless network according to some embodiments. Fig. 6 is made with reference to Fig. 1 discussed.
[0054] At 601, a STA (e.g., STA 104) may send a request-query frame to an AP (e.g., AP 102) to discover wireless networks (e.g., BSSs) in its vicinity. The request-query frame may advertise the data rates and capabilities supported by the STAs (e.g., IEEE 802.11ax capable). Before transmitting the request-query frame to the AP, the STA acquires a first MAC address and includes the first MAC address in the request-query frame. The STA may generate its first MAC address itself, or its first MAC address may be assigned by a user, network administrator, manufacturer, or other entity, as would be understood by one of ordinary skill in the art. The first MAC address may also be referred to as a pre-association MAC address. This is because the STA may acquire a pre-association MAC address before joining a wireless network. The STA can change its first MAC address up to 602.For example, the STA can change its first MAC address to a random value.
[0055] At 602, the AP may send the STA a request-response frame in response to receiving the request-query frame. The AP may send the request-response frame to the STA if the STA is network compatible with the AP. The request-response frame may include a Service Set Identifier (SSID) of a BSS for the AP. The request-response frame may include one or more supported data rates, one or more supported encryption types, and various other capabilities of the AP, as would be appreciated by one of ordinary skill in the art.
[0056] In 603, the STA can authenticate itself with the AP. For example, the STA can perform IEEE 802.11 authentication, such as Open System Authentication or Shared Key Authentication. In Open System Authentication, the STA can authenticate itself with the AP using its first MAC address. For example, the STA can send an IEEE 802.11 authentication management frame containing its first MAC address to the AP. The AP can then check the STA's first MAC address and return an authentication verification frame. After completing 603, the STA is authenticated with the AP but not yet associated with the AP. Once the authentication process begins, the STA cannot change its first MAC address until a security association is completed or aborted.
[0057] At 604, the STA may send an association request frame to the AP. The STA may send the association request frame to the AP if it determines that it wishes to associate with the AP. The STA may include its first MAC address in the association request frame. The association request frame may include the data rates supported by the STA, the encryption types supported, and various other capabilities of the STA, as would be apparent to one of ordinary skill in the art.
[0058] At 605, the AP may send the STA an association response frame in response to receiving the association request frame. The AP may indicate in the association response frame whether the AP has allowed the STA to join its BSS. The AP may allow the STA to join its BSS if the capabilities specified in the association request frame match the capabilities of the AP. If the AP accepts the association request from the STA, the AP may assign an arbitrary association identifier (AID) to the STA. The AP may include the assigned AID in the association response frame. This AID may be referred to as a first short-term identifier or an initial short-term identifier.
[0059] At 606, the STA may derive a first set of cryptographic keys based on its first MAC address and the MAC address of the AP. Similarly, the AP may derive the same or more cryptographic keys based on the STA's first MAC address and the AP's MAC address. The first set of cryptographic keys may include an Extensible Authentication Protocol over LAN Key Confirmation Key (EAPOL-KCK) and an EAPOL Key Encryption Key (EAPOL-KEK). The first set of cryptographic keys may be part of a first security association between the STA and the AP. The STA may use the first security association to encrypt frames to and from the AP. For example, the STA may encrypt the frames of a 4-way handshake between the STA and the AP. The 4-way handshake may be based on the IEEE 802.11i standard.
[0060] At 607, the AP may send the STA a first frame in the four-way handshake. The first frame may include a nonce value (e.g., an ANonce) and a key replay counter. The key replay counter may be a digit used to associate each pair of transmitted frames.
[0061] At 608, the STA may generate an arbitrary second MAC address in response to receiving the first frame of the 4-way handshake from the AP. The second MAC address may also be referred to as a post-association MAC address. This is because the STA may use the post-association MAC address after joining the wireless network. The STA may begin using the second MAC address after the 4-way handshake is complete.
[0062] The STA may further derive a second set of cryptographic keys based on the second MAC address and the MAC address of the AP. The second set of cryptographic keys may be part of a second security association between the STA and the AP. The STA may use the second security association to encrypt frames to and from the AP after the four-way handshake is complete and the STA is associated with the AP.
[0063] At 609, the STA may securely transmit a second frame in the four-way handshake to the AP using the first set of cryptographic keys. The second frame may include the second MAC address. The second frame may include the second MAC address in its key data field, which is encrypted based on the first set of cryptographic keys. In other words, the AP may send the second frame to the AP in encrypted form.
[0064] In 610, the AP may derive the second set of cryptographic keys 608 based on the second MAC address stored in the second frame in the 4-way handshake and the MAC address of the AP.
[0065] At 611, the AP may securely transmit a third frame in the 4-way handshake to the STA using the first set of cryptographic keys. The AP may indicate in the third frame whether the AP has allowed the STA to elect to assign the second MAC address to itself. If the AP determines that the second MAC address is already in use by another STA, the AP may terminate the 4-way handshake by including an error code in the third frame (e.g., "Duplicate MAC Address"). On the other hand, if the AP determines that the MAC address does not conflict with a MAC address of another STA, the AP may confirm that there is no conflict by including the second MAC address in the third frame. The third frame may include the second MAC address in its key data field, which is encrypted based on the first set of cryptographic keys.
[0066] At 612, the STA may securely transmit a fourth frame in the 4-way handshake to the AP using the first set of cryptographic keys. The STA may indicate in the fourth frame whether the STA has confirmed that the third frame in the 4-way handshake is valid and therefore complete the 4-way handshake.
[0067] At 613, the STA may assign itself (or switch to) the second MAC address in response to the completion of the four-way handshake. The AP and STA may further map the AID assigned to the STA at 605 to the STA's second MAC address. The STA may further use the second set of cryptographic keys to securely exchange frames with the AP in the future. The STA and AP may include the STA's AID and the AP's identity (e.g., BSSID) in the frames to avoid revealing the STA's second MAC address to other devices. The STA may have changed its AID periodically but kept its second MAC address unchanged, allowing it to maintain the second security association with the AP without changing any cryptographic keys.
[0068] For example, the STA and AP may include the STA's AID and the AP's identity in frame 400 to avoid disclosing the STA's second MAC address to other devices. If frame 400 is a data downlink or management frame, PHY header 402 may include the AP's identity (e.g., BSSID), the STA's AID, a hash of the STA's AID, a hash of the AP's identity, and / or a hash of the STA's AID and the AP's identity. RA 408 may include the AP's identity, the STA's AID, and / or a hash of the STA's AID and the AP's identity. TA 410 may include the AP's identity, a zero STA AID, and / or a zero STA AID hash and the AP's identity. BSSID 412 may include the APs.
[0069] For example, if frame 400 is an uplink acknowledgement or frame acknowledgement, RA 408 may include the AP identity, a zero STA AID, and / or a hash of the zero STA AID and the AP identity. TA 410 may include the AP identity, the STA AID, and / or a hash of the STA AID and the AP identity.
[0070] If frame 400 is an uplink data or management frame, PHY header 402 may include the AP identity, a zero STA AID, and / or a hash of the zero STA AID and the AP identity. RA 408 may include the AP identity, a zero STA AID, and / or a hash of the zero STA AID and the AP identity. TA 410 may include the AP identity, the STA AID, and / or a hash of the STA AID and the AP identity. BSSID 412 may include the AP identity.
[0071] If frame 400 is a downlink acknowledgment or frame acknowledgment frame, RA 408 may include the AP identity, the STA AID, and / or a hash of the STA AID and the AP identity. TA 410 may include the AP identity, a zero STA AID, and / or a hash of the zero STA AID and the AP identity.
[0072] After the STA assigns itself the second MAC address (e.g., a new long-term identifier) and associates itself with the AP, the STA can request the AP to change its assigned AID (e.g., its original short-term identifier). Regularly changing the AID assigned to the STA can reduce the likelihood that a network sniffer can track the STA based on its assigned AID. This is because the assigned AID can be transmitted "unprotected."
[0073] The STA can change its assigned AID using AID change requests, AID change responses, and / or AID update frames. AID change requests, AID change responses, and AID update frames can be robust management frames encrypted by the second set of cryptographic keys. AID change requests, AID change responses, and AID update frames can also be Extensible Authentication Protocol (EAP) frames encrypted by the second set of cryptographic keys.
[0074] In some embodiments, after the STA assigns itself the second MAC address and associates with the AP, the STA may send the AP an AID change request frame with a desired AID change period. An AID change period indicates how often the AP will assign a new AID (e.g., a new short-term identifier) to the STA via an AID update frame. The AID change period may also be referred to as the short-term identity change period.
[0075] In response to receiving the AID change request frame, the AP may return an AID change response frame with an acknowledged AID change period.
[0076] The confirmed AID change period may differ from the desired AID change period. The AP can then send the STA an AID update frame with the STA's new AID. The STA can then use the new AID in the future. Both the AP and the STA can also map the STA's new AID to their second MAC address.
[0077] In some other embodiments, after the STA assigns itself the second MAC address and associates with the AP, the STA may send the AP an on-demand AID change request frame. The AP may send an AID update frame with its new AID back to the STA. The STA may then use the new AID in the future. Both the AP and the STA may also map the STA's new AID to its second MAC address.
[0078] After a new AID is assigned, the STA can retain its second MAC address and continue using the second set of cryptographic keys to securely exchange frames with the AP. Both the AP and the STA can include the STA's new AID and the AP's identity in the transmitted frames.
[0079] Whether the STA is assigned its new AID periodically or upon request, it is preferable for the AP to assign an unpredictable new AID to the STA to prevent a network sniffer from tracking the STA due to changes in its AID. However, it is also preferable for the AP to continuously assign AID to multiple STAs. This is because continuously assigning AID to STAs reduces the size of a traffic indicator map (TIM) field in a beacon frame transmission by the AP.
[0080] The TIM field in a beacon frame can specify cached frames available at the AP for downloading by STAs. The TIM field can use a bitmap to specify cached frames available at the AP for downloading by associated STAs. Each bit in the bitmap can represent an AID potentially assigned to an STA. The bitmap can contain 2008 bits.
[0081] Due to the large size of the bitmap, the entire bitmap is often never transmitted in its entirety in a beacon frame. Rather, the TIM field may use a portion of the virtual bitmap. The partial virtual bitmap may represent a continuous section of bitmap space containing AIDs pointing to all STAs that have cached frames at the AP. The TIM field includes an address offset indicating where the partial virtual bitmap begins within the larger bitmaps. This can reduce the size of the TIM field, which can reduce decoding time, disk contention, and power consumption at the associated STAs.
[0082] Fig. 7 is a block diagram of an exemplary TIM bitmap 702 of a TIM field represented using a virtual bitmap 706, according to some embodiments. The TIM bitmap 702 may represent a range of AIDs 704 available for association with STAs by an AP. This range of AIDs 704 may also be referred to as an AID space or a short-term identity space.
[0083] In Fig. 7, the TIM bitmap 702 includes 2008 bits. Each bit in the TIM bitmap 702 may correspond to an AID 704. A 1 bit may indicate that cached frames are available for downloading at the AP by the associated STA. A 0 bit may indicate that no frames are available for downloading at the AP by the associated STA. Thus, because the TIM bitmap 702 includes 2008 bits, the TIM bitmap 702 may specify whether the cached frames are available at the AP for downloading by up to 2008 STAs (e.g., AID 0 to AID 2007).
[0084] However, often the AP has a small number of STAs connected to it. To reduce the size of the TIM bitmap 702, the AP may assign AIDs to the STAs from a continuous portion of the range of AIDs 704 in the TIM bitmap 702. Since AIDs outside this continuous portion are not assigned to STAs, they need not be represented in the TIM field. Rather, the continuous portion may be represented as a partial virtual bitmap 706 along with an address offset (e.g., n). The address offset may indicate where the partial virtual bitmap 706 begins in the TIM bitmap 702. The AP may include a partial virtual bitmap 706 and its assigned address offset in the TIM field in a beacon frame.
[0085] However, in some embodiments, it is also preferable for an AP to assign an unpredictable new AID to an STA to prevent a network sniffer from tracking the STA based on changes in its AID. To allow the AP to select an unpredictable new AID for an STA while maintaining a reduction in the size of the TIM bitmap 702, the AP may select a new AID for an STA using a data block-based strategy.
[0086] In some embodiments incorporating this data block-based strategy, the AP may estimate the maximum number of STAs associated with the AP (e.g., m STAs). For example, the AP may estimate the maximum number of STAs associated with the AP based on the number of STAs that joined the AP in a period of time. The AP may then divide the entire AID space (e.g., AID 0 to AID 2007) into a number of AID data blocks (e.g., s data blocks). Each data block may contain m AIDs.
[0087] When a new AID change period begins, the AP can select any AID data block from s AID data blocks. The AP can then arbitrarily assign and / or reassign AIDs within the selected AID data block until the end of the AID change period. In other words, the AP can assign and / or reassign AIDs within the selected AID data block based on any value. This approach can ensure that AIDs assigned to STAs cannot be predicted while still allowing the TIM bitmap 702 to be represented at a reduced size using a partial virtual bitmap 706.
[0088] During AID assignment and / or reassignment, the AP can verify that old AIDs do not conflict with new AIDs between two adjacent AID change periods. The AP can also simultaneously serve STAs that support the AID change and STAs that do not. The AP can achieve this by maintaining an original TIM bitmap for STAs that do not support the AID change and one or more new TIM bitmaps for STAs that do support the AID change.
[0089] In addition to including one or more identities for an STA in a frame, the frame can often include various other fields (“fingerprint” fields) that can be used to identify the STA. For example, frame 400 of Fig. 4 include various fields that can be used to identify an STA, such as, but not limited to, SC 414, HTC 416, and CCMP 418. In conventional approaches, frame 400 may store these fields "unprotected," or unencrypted. As a result, a network sniffer can intercept frame 400 and determine the values of these fields. This means that the STA can often be easily traced using these fields.
[0090] To address this technical problem, in some embodiments, an STA may periodically change or mask various "fingerprint" fields stored in frames over a wireless network so that a network sniffer cannot track the STA using these fields. For example, the STA may reset the SC field (e.g., SC 414) in a frame to a random value whenever the STA has changed its AID (e.g., short-term identity).
[0091] The STA can also reset the packet number (PN) of a CCMP field (e.g., CCMP 418) in a frame to a random value whenever the STA has changed its AID (e.g., short-term identity). To prevent the PN from rapidly expiring, the STA can reset the PN to a random value within a first subspace of its entire sequence space. In this case, the first m most significant bits (MSBs) are set to zero. To reset the PN, the STA can also establish a new set of cryptographic keys (e.g., a PTK) with the AP.
[0092] The STA may also mask an HTC field (e.g., HTC 416) and / or a CCMP field (e.g., CCMP 418) in a frame. This may allow the STA to avoid having to change the actual values of these fields. To mask these fields, the STA may calculate a mask and apply the mask to the fields. The STA may apply the mask to the fields using a bitwise XOR operation. As will be appreciated by one of ordinary skill in the art, the STA may also apply the mask to the fields using various other techniques.
[0093] The STA may use a set of cryptographic keys to calculate the mask. The set of cryptographic keys may be generated as part of establishing a security association between the STA and the AP. For example, the STA may generate the second set of cryptographic keys in step 607 of Fig. 6. In other words, the STA can use the set of cryptographic keys created for use by the STA after associating with the AP.
[0094] The STA may calculate the mask by applying a cryptographic hash function to a key_mask from the set of cryptographic keys, the AP's BSS identifier, and the STA's AID. The STA may change the mask whenever a new AID is assigned to the STA. As will be appreciated by one of ordinary skill in the art, the STA may calculate the mask using various types of cryptographic hash functions, such as, but not limited to, SipHash, Secure Hash Algorithm (SHA)-1, SHA-2, or SHA-3.
[0095] The STA can also determine the mask by applying a cryptographic hash function to a key-mask consisting of the set of cryptographic keys, the BSS identifier of the AP, the AID of the STA and the value of an SC field (e.g. SC 414 in Fig. 4). In this case, the STA can change the mask for each transmitted frame. The STA can also reset the SC field to a random value when the STA is assigned a new AID.
[0096] The STA may also encrypt one or more MAC header fields of a frame along with the MAC payload. For example, the STA may encrypt MAC header fields 408-416 along with the MAC payload 406 of frame 400.
[0097] The STA may encrypt this data using a set of cryptographic keys. The set of cryptographic keys may be generated as part of establishing a security association between the STA and the AP. For example, the STA may generate the second set of cryptographic keys in step 607 of Fig. 6. In other words, the STA can use the set of cryptographic keys created for use by the STA after associating with the AP.
[0098] However, to encrypt this data, the STA may need to move one or more MAC header fields before the encrypted data. For example, the STA may need to move the CCMP field before the encrypted data (e.g., CCMP 418 in frame 400).
[0099] Fig. 8 is a block diagram of an exemplary standards-compliant frame 800 in which a CCMP field has been moved along with MAC payload data as part of the encryption of one or more MAC header fields, according to some embodiments.
[0100] Fig. 8 encrypts the STA RA 408, TA 410, BSSID 412, SC 414, and HTC 416 together with MAC payload 406 of frame 400 to generate encrypted data 802. The STA then moves CCMP 418 of frame 400 in front of encrypted data 802. The result is frame 800.
[0101] The STA may encrypt RA 408, TA 410, BSSID 412, SC 414, and HTC 416 along with the MAC payload 406 using a set of cryptographic keys. The set of cryptographic keys may be generated as part of establishing a security association between the STA and the AP. For example, the STA may generate the second set of cryptographic keys in step 607 of Fig. 6. In other words, the STA can use the set of cryptographic keys created for use by the STA after associating with the AP.
[0102] The STA can also reset the PN of CCMP 418 to a random value in frame 800 whenever the STA has changed its AID (or short-term identity). The STA can also mask the CCMP 418 in frame 800.
[0103] For example, various embodiments may be implemented using systems such as STA 200 and AP 300. For example, STA 200 may be used to implement method 500 and the swimlane of Fig. 6. AP 300 can be used, for example, to implement the swimlane of Fig. 6 to be implemented.
[0104] Various embodiments may be implemented, for example, using one or more computer systems such as the one described in Fig. 9. Computer system 900 may be used, for example, to implement method 500 and the swimlane of Fig. 6. Computer system 900 may be any computer capable of performing the functions described herein.
[0105] Computer system 900 includes one or more processors (also called central processing units or CPUs), such as a processor 904. Processor 904 is connected to a communications infrastructure or bus 906.
[0106] One or more processors 904 may each be a graphics processing unit (GPU). In embodiments, a GPU is a processor that is a specialized electronic circuit designed to process mathematically intensive applications. The GPU may have a parallel structure that is efficient for parallel processing of large blocks of data, such as mathematically intensive data common to computer graphics applications, images, videos, etc.
[0107] Computer system 900 also includes user input / output device(s) 903, such as monitors, keyboards, pointing devices, etc., that communicate with communication infrastructure 906 via user input / output interface(s) 902.
[0108] Computer system 900 also includes a main memory or primary storage 908, such as random access memory (RAM). Main memory 908 may include one or more cache levels. Main memory 908 stores control logic (e.g., computer software) and / or data.
[0109] Computer system 900 may also include one or more secondary storage devices or memories 910. Secondary storage 910 may include, for example, a hard disk drive 912 and / or a removable storage device or drive 914. Removable storage drive 914 may be a floppy disk drive, a magnetic tape drive, a CD drive, an optical storage device, a tape backup device, and / or any other storage device / drive.
[0110] The removable storage drive 914 can interact with a removable storage unit 918. The removable storage unit 918 includes a computer-usable or computer-readable storage device on which computer software (control logic) and / or data are stored. The removable storage unit 918 can be a floppy disk, a magnetic tape, a compact disk, a DVD, an optical disk, and / or another computer data storage device. The removable storage drive 914 reads from and / or writes to the removable storage unit 918 in a well-known manner.
[0111] According to embodiments, secondary storage 910 may include other means, instrumentalities, or other approaches to allow computer programs and / or other instructions and / or data to be accessed by computer system 900. Such means, instrumentalities, or other approaches may include, for example, a removable storage device 922 and an interface 920. Examples of removable storage device 922 and interface 920 may include a program cartridge and cartridge interface (such as those found in video game devices), a removable memory chip (such as an EPROM or PROM) and associated socket, a memory stick and USB port, a memory card and associated memory card slot, and / or any other removable storage device and associated interface.
[0112] Computer system 900 may further include a communications or network interface 924. Communications interface 924 enables computer system 900 to communicate and interact with any combination of remote devices, remote networks, remote entities, etc. (individually and collectively designated by reference numeral 928). For example, communications interface 924 may enable computer system 900 to communicate with remote devices 928 via communications path 926, which may be wired and / or wireless and may include any combination of LANs, WANs, the Internet, etc. Communications interface 924 may also be referred to as a transceiver. Control logic and / or data may be transmitted to and from computer system 900 via communications path 926.
[0113] In embodiments, a tangible device or article of manufacture including a tangible computer-usable or computer-readable medium having control logic (software) stored thereon is also referred to herein as a computer program product or program storage device. This includes, but is not limited to, computer system 900, main memory 908, secondary storage 910, and removable storage units 918 and 922, as well as tangible articles of manufacture embodying any combination of the preceding embodiments. Such control logic, when executed by one or more computing devices (such as computer system 900), causes such computing devices to operate as described herein.
[0114] Based on the teachings contained in this disclosure, it will be apparent to one skilled in the art to which it pertains how embodiments of the disclosure may be implemented using data processing apparatus, computer systems, and / or computer architectures other than those disclosed in Fig. 9 shown are to be distinguished, manufactured and used.
[0115] In particular, embodiments may operate with software, hardware, and / or operating system implementations that differ from those described herein.
[0116] It should be understood that the Detailed Description section, and not the Summary and Abstract sections, are intended to interpret the claims. The Summary and Abstract sections (if present) may set forth one or more, but not all, embodiments of the disclosure as contemplated by the inventor(s) and are therefore not intended to limit the disclosure or the appended claims in any way.
[0117] Although the disclosure has been described herein with reference to exemplary embodiments for exemplary fields and applications, it should be understood that the disclosure is not limited thereto. Other embodiments and modifications thereto are possible and are within the scope and spirit of the disclosure. For example, and without limiting the generality of this paragraph, embodiments are not limited to the software, hardware, firmware, and / or entities illustrated in the figures and / or described herein. Furthermore, embodiments (whether explicitly described herein or not) have significant utility in fields and applications beyond the examples described herein.
[0118] Embodiments have been described herein using functional blocks that illustrate the implementation of predetermined functions and relationships thereof. The boundaries of these functional blocks have been defined arbitrarily herein for descriptive purposes. Alternative boundaries may be defined as long as the predetermined functions and relationships (or their equivalents) are performed in a suitable manner. Furthermore, alternative embodiments may perform functional blocks, steps, operations, methods, etc., in orders different from those described herein.
[0119] Reference to "one embodiment," "an exemplary embodiment," or similar language indicates that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes that particular feature, structure, or characteristic. Furthermore, such language does not necessarily refer to the same embodiment. Furthermore, where a particular feature, structure, or characteristic is described in connection with one embodiment, it would be within the knowledge of one of ordinary skill in the art(s) in question to incorporate such a feature, structure, or characteristic into other embodiments, whether explicitly mentioned or described herein.
[0120] The breadth and scope of the disclosure should not be limited by the embodiments described above, but should be defined only in accordance with the claims and their equivalents.
[0121] As described above, one aspect of the present technology may include collecting and using data available from various sources, for example, to improve or deepen modes of action. The present disclosure contemplates that, in some cases, this collected data may include personal data that uniquely identifies a particular individual or that can be used to contact or locate that individual. This personal data may include demographic data, location-based data, phone numbers, email addresses, Twitter IDs, home addresses, data or records about a user's health or fitness level (e.g., vital sign measurements, medication information, exercise information), date of birth, or other identifying or personal information.This disclosure recognizes that the use of this personal information in the present technology can be used to the benefit of users.
[0122] This disclosure contemplates that entities responsible for the collection, analysis, disclosure, transmission, storage, or other use of such personal data will adhere to generally established privacy policies and / or practices. In particular, such entities should implement and consistently use privacy policies and practices that are generally recognized as meeting or exceeding industry or regulatory requirements for maintaining and protecting the confidentiality of personal data. Such policies should be readily accessible to users and should be updated as the collection and / or use of data changes.
[0123] Personal information from users should be collected for legitimate and meaningful uses by entities and should not be shared or sold outside of those legitimate uses. Furthermore, such collection / sharing should occur after obtaining the users' informed consent. Furthermore, such entities should consider taking all necessary steps to protect and secure access to such personal information and ensure that others who have access to the personal information adhere to their data protection policies and procedures. Furthermore, such entities may submit to third-party evaluation to confirm that they adhere to generally accepted data protection policies and practices.Furthermore, policies and practices should be tailored to the specific types of personal data being collected and / or accessed and should be aligned with applicable laws and standards, including jurisdiction-specific considerations. For example, in the United States, the collection of or access to certain health information may be regulated by federal and / or state laws, such as the Health Insurance Portability and Accountability Act (HIPAA); whereas, health information in other countries may be subject to different regulations and policies and should be treated accordingly. Therefore, different data protection practices should be followed for different types of personal information in each country.
[0124] Notwithstanding the foregoing, the present disclosure also contemplates embodiments in which users selectively block the use of or access to personal data. That is, the present disclosure contemplates that hardware and / or software elements may be provided to prevent or block access to such personal data. For example, the present technology may be configurable to provide the user with the opportunity to "opt in" or "opt out" of participation in the collection of personal data, e.g., during registration for services or at any time thereafter. In addition to the "opt in" and "opt out" options, the present disclosure contemplates providing notifications regarding access to or use of personal data.For example, a user can be notified when downloading an app that their personal data is being accessed and then reminded again shortly before the app accesses the personal data.
[0125] Furthermore, it is the intent of this disclosure that personal data be managed and handled in a manner that minimizes the risk of accidental or unauthorized access or use. This risk can be minimized by limiting the collection of data and deleting data once it is no longer needed. In addition, and where necessary, including in certain health-related applications, data de-identification can be used to protect a user's privacy. De-identification can be facilitated, where appropriate, by removing specific identifiers (e.g., date of birth, etc.), controlling the amount or specificity of the data stored (e.g., collecting location data at the city level rather than the address level), controlling how data is stored (e.g., aggregating data across users), and / or by using other methods.
[0126] Therefore, although the present disclosure broadly covers the use of personal data to implement one or more of the various disclosed embodiments, the present disclosure also contemplates that the various embodiments may be implemented without the need for access to such personal data. That is, the various embodiments of the present technology will not be rendered inoperable due to the absence of all or any portion of such personal data.
Claims
[1] Station, including: a transceiver; and at least one processor communicatively connected to the transceiver, the at least one processor configured to: Establishing, using the transceiver, a first security association with an access point (AP) based at least in part on an original long-term identity for the station; Creating a new long-term identity for the station; Establishing, using the first security association, a second security association with the AP based at least in part on the new long-term identity for the station and an identity of the AP; Sending, using the second security association, a request frame to the AP to change an original short-term identity assigned to the station; Receiving, using the second security association, a response frame from the AP that includes a new short-term identity assigned to the station by the AP; and Mapping the new short-term identity for the station to the new long-term identity assigned to the station by the AP. [2] The station of claim 1, wherein the station operates according to an IEEE (Institute of Electrical and Electronics Engineers) standard 802.11, the new short-term identity comprises an association identifier (AID) assigned by the AP, and the new long-term identity comprises a media access control (MAC) address. [3] The station of claim 1, wherein the at least one processor is further configured to: Receiving, using the transceiver, a link response frame from the AP that includes the original short-term identity assigned to the station. [4] The station of claim 1, wherein to generate the new long-term identity for the station, the at least one processor is further configured to: Generating the new long-term identity for the station based at least in part on a random value. [5] The station of claim 1, wherein the at least one processor is further configured to: Encrypting the new long-term identity using an encryption key associated with the first security association; and Send, using the transceiver, the encrypted new long-term identity to the AP. [6] The station of claim 1, wherein the at least one processor is further configured to: Setting at least one of a flow control (FG) field or a packet number (PN) field in a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field in a frame to a random value in response to the station being assigned the new short-term identity. [7] The station of claim 1, wherein the at least one processor is further configured to: Masking at least one of a High Throughput Control (HTC) field or a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field in a frame in response to the station being assigned the new short-term identity. [8] The station of claim 1, wherein to receive the response frame from the AP, the at least one processor is further configured to: Receiving, using the second security association, the response frame from the AP based at least in part on a short-term identity change period. [9] A method for concealing an identity of a station in a wireless network, comprising: Establishing, using a transceiver, a first security association with an access point (AP) based at least in part on an initial long-term identity for the station; Creating, by at least one processor, a new long-term identity for the station; Establishing, using the first security association, a second security association with the AP based at least in part on the new long-term identity for the station and an identity of the AP; Sending, using the second security association, a request frame to the AP to change an original short-term identity assigned to the station; Receiving, using the second security association, a response frame from the AP that includes a new short-term identity assigned to the station by the AP; and Mapping, by the at least one processor, the new short-term identity for the station to the new long-term identity assigned to the station by the AP. [10] The method of claim 9, wherein the station operates according to an IEEE (Institute of Electrical and Electronics Engineers) standard 802.11, the new short-term identity comprises an association identifier (AID) assigned by the AP, and the new long-term identity comprises a media access control (MAC) address. [11] The method of claim 9, wherein generating the new long-term identity for the station further comprises: Generating, by the at least one processor, the new long-term identity for the station based at least in part on a random value. [12] The method of claim 9, further comprising: Encrypting, by the at least one processor, the new long-term identity using an encryption key associated with the first security association; and Send, using the transceiver, the encrypted new long-term identity to the AP. [13] The method of claim 9, further comprising: Setting, by the at least one processor, at least one of a control flow (SC) field or a packet number (PN) field in a CCMP (Counter Mode Cipher Block Chaining Message Authentication Code Protocol) field in a frame to a random value in response to the station being assigned the new short-term identity. [14] The method of claim 9, further comprising: Masking, by the at least one processor, at least one of a High Throughput Control (HTC) field or a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field in a frame in response to the station being assigned the new short-term identity. [15] Access Point (AP), comprising: a transceiver; and at least one processor communicatively connected to the transceiver, wherein the at least one processor is configured to: Establishing, using the transceiver, a first security association with a station based at least in part on an original long-term identity for the station; Receiving, using the first security association, a new long-term identity for the station from the station; Establishing, using the first security association, a second security association with the station based at least in part on the new long-term identity for the station and an identity of the AP; Receiving, using the second security association, a request frame from the station to change an original short-term identity assigned to the station by the AP; Sending, using the second security association, a response frame to the station that includes a new short-term identity assigned to the station by the AP; and Mapping the new short-term identity for the station to the new long-term identity assigned to the station by the AP. [16] The AP of claim 15, wherein the AP operates according to an IEEE (Institute of Electrical and Electronics Engineers) standard 802.11, the new short-term identity comprises an association identifier (AID) assigned to the station by the AP, and the new long-term identity comprises a media access control (MAC) address. [17] The AP of claim 15, wherein the at least one processor is further configured to: Send, using the transceiver, a link response frame to the station that includes the original short-term identity assigned to the station by the AP. [18] The AP of claim 15, wherein the at least one processor is further configured to: Decrypt the new long-term identity for the station using a decryption key associated with the first security association. [19] The AP of claim 15, wherein to send the response frame to the station, the at least one processor is further configured to: Sending, using the second security association, the response frame to the station based at least in part on a short-term identity change period. [20] The AP of claim 15, wherein the at least one processor is further configured to: Determining a maximum number of stations associated with the AP; Separating a short-term identity space into a set of data blocks; Selecting a data block in the set of data blocks based at least in part on a random value; and Selecting the new short-term identity for the station from the selected data block in response to receiving the request frame from the station to change an original short-term identity assigned to the station.
Citation Information
Patent Citations
Location Privacy Protection Method, Apparatus, and System
US20160316362A1
Infrastructure coordinated media access control address assignment
US20170013449A1