Methods and apparatus for protecting information elements

EP4740525A1Pending Publication Date: 2026-05-13NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2023-07-07
Publication Date
2026-05-13

AI Technical Summary

Technical Problem

Current 802.11 standards face security concerns due to the use of fixed, unencrypted MAC addresses in frame headers, allowing third parties to track wireless devices and access points, and existing solutions like MAC address randomization do not adequately protect personal identifiable information in information elements (IEs) sent before robust security network association (RSNA) establishment.

Method used

The proposed solution involves using an identifiable random medium access control (IRM) address as an identifier for wireless devices, obtaining an encryption key associated with this identifier, and communicating frames between the wireless device and the access point that include the identifier and information elements encrypted with the encryption key, even before security establishment.

Benefits of technology

This approach effectively protects personal identifiable information in information elements by encrypting them with a key associated with the IRM address, preventing unauthorized tracking and ensuring privacy even before a robust security network association is established.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2023106406_16012025_PF_FP_ABST
    Figure CN2023106406_16012025_PF_FP_ABST
Patent Text Reader

Abstract

Methods, apparatus and computer-readable medium are disclosed for protecting information element. In an embodiment, there is provided a method performed at a wireless device. The method comprises obtaining an identifier of the wireless device; obtaining an encryption key, wherein the encryption key is associated to the identifier; and communicating a frame between the wireless device and the first access point. The frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND APPARATUS FOR PROTECTING INFORMATION ELEMENTSTECHNICAL FIELD

[0001] Embodiments of the disclosure generally relate to wireless communication technology, and more particularly, to methods and apparatus for protecting information elements (IEs) by using an identifier of a wireless device, e.g., an identifiable random medium access control (IRM) address.BACKGROUND

[0002] In conventional 802.11 standards, a non-access point (non-AP) station (STA) , which may be simply referred to as an STA in the present disclosure, and an access point (AP) use a fixed unencrypted medium access control (MAC) address in a frame header. This causes a security concern by allowing others to track the STA and the AP based on their MAC addresses. To prevent an STA and an AP from being tracked and improve the privacy of 802.11 standards, a MAC address randomization became a common technique. Within this regard, institute of electrical and electronics engineers (IEEE) 802.11bh and 802.11bi groups focus on identification of an STA using a random MAC address (RMA) without decreasing user privacy.

[0003] The 802.11bh draft 1.0 (D1.0) defines two identification mechanisms, namely, network generated identifier (such as a device ID (identifier) ) and STA generated identifier (such as an identifiable random MAC (IRM) ) . An AP may generate an identifier (e.g., a unique number, called device ID) for an STA, and send it to the STA. Then, the STA can use that unique identifier again when it returns to the same AP or a same extended service set (ESS) of the AP. By using the device ID, the STA may be identified by the AP or other AP (s) in the ESS. An STA may generate an identifier (e.g., a unique MAC address, called IRM) for itself, and send it to an AP. Then, the STA can use that unique MAC address again when it returns to the same AP or a same ESS of the AP. By using the IRM, the STA may be identified by the AP or other AP (s) in the ESS.

[0004] When an STA returns to a same AP or another AP of a same ESS, information element (s) (IEs) included in management frames may be sent in the air without protection from the STA before robust security network association (RSNA) establishment between the STA and the AP. It becomes critical if those IEs consist of personal identifiable information, such as information of a device ID. In this case, any third party can track the STA based on those unprotected IEs.SUMMARY

[0005] This summary is provided to introduce simplified concepts of the present disclosure. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0006] According to a first aspect of the disclosure, there is provided an apparatus at a wireless device. The apparatus comprises at least one processor, and at least one memory storing instructions that, when executed on the at least one processor, cause the apparatus at least to obtain an identifier of the wireless device; obtain an encryption key, wherein the encryption key is associated with the identifier; and communicate a frame between the wireless device and the first access point. The frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.

[0007] According to some embodiments, the frame may be communicated before a security establishment between the wireless device and the first access point is completed.

[0008] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to obtain the identifier by determining the identifier of the wireless device. The apparatus may be further caused to transmit the determined identifier to the first access point, or to a second access point which belongs to a same network as the first access point.

[0009] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to configure the encryption key by generating the encryption key. The apparatus may be further caused to transmit the encryption key to the first access point or to a second access point which belongs to a same network as the first access point. The encryption key may be transmitted together with the identifier.

[0010] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to obtain the encryption key by receiving the encryption key from the first access point or from a second access point which belongs to a same network as the first access point. The encryption key may be received together with the identifier.

[0011] According to some embodiments, the identifier and the encryption key may be obtained during an initial connection to the first access point or a network of the first access point.

[0012] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may further cause the apparatus at least to communicate the frame by transmitting a first frame to the first access point. The identifier may be carried in in a header field of  the first frame, and a first information element encrypted with the encryption key may be carried in a payload field of the first frame.

[0013] According to some embodiments, the first frame is transmitted as a first pre-association security negotiation frame for a next connection to the first access point. The first pre-association security negotiation frame may be one of: a probe request frame, an authentication frame, an association request frame, an action frame, or a 4-way Handshake frame. the first information element comprises at least one of: a device identifier of the wireless device in the first pre-association security negotiation frame for the next connection; an identifier of simultaneous authentication of equals password in the authentication frame for the next connection; or an identifier of pairwise master key in the association request for the next connection.

[0014] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to communicate the frame by: receiving a second frame from the first access point or the second access point. The identifier may be carried in a head field of the second frame, and a second information element encrypted with the encryption key may be carried in a payload field of the second frame. The apparatus is further caused to retrieve the encryption key according to the identifier carried in the second frame, and decrypt the second information element using the encryption key.

[0015] According to some embodiments, the second frame may be received as a second pre-association security negotiation frame for a next connection from the first access point. The second authentication pre-association security negotiation frame may be one of a probe response frame, an authentication frame, an association response frame, an action frame, and a 4-way Handshake frame. The second information element may comprise at least one of a device identifier of the wireless device in the second pre-association security negotiation frame for the next connection, or an identifier of simultaneous authentication of equals password in the second authentication frame for the next connection.

[0016] According to some embodiments, the identifier is an identifiable random medium access control (IRM) address of the wireless device.

[0017] According to some embodiments, the network is an extended service set.

[0018] According to a second aspect of the disclosure, there is provided an apparatus at a first access point. The apparatus comprises at least one processor, and at least one memory storing instructions that, when executed on the at least one processor, cause the apparatus at least to obtain an identifier of a wireless device; obtain an encryption key, wherein the encryption key is associated with the identifier; and communicate a frame between the wireless device and the first access point. The frame  comprises the identifier of the wireless device and an information element encrypted with the encryption key.

[0019] According to some embodiments, the frame is communicated before a security establishment between the wireless device and the first access point is completed.

[0020] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to obtain the identifier by: receiving the identifier from the wireless device or from a second access point which belongs to a same network as the first access point.

[0021] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to obtain the encryption key by: receiving the encryption key from the wireless device or from a second access point which belongs to a same network as the first access point. The encryption key may be received from the wireless device together with the identifier.

[0022] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to obtain the encryption key by: generating the encryption key.

[0023] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to transmit the encryption key to the wireless device; and / or transmit the encryption key to a second access point which belongs to a same network as the access point.

[0024] According to some embodiments, the identifier and the encryption key may be obtained during an initial connection of the wireless device to the first access point or a network of the first access point.

[0025] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to communicate the frame by: receiving a first frame from the wireless device. The identifier may be carried in a header field of the first frame, and a first information element encrypted with the encryption key may be carried in a payload field of the first frame. The apparatus may be further caused to retrieve the encryption key according to the identifier carried in the first frame; and decrypt the first information element using the encryption key.

[0026] According to some embodiments, when the instructions are executed by the at least one processor, the instructions may cause the apparatus at least to communicate the frame by: transmitting a second frame to the wireless device. The identifier may be carried in in a header field of the second  frame and a second information element encrypted with the encryption key may be carried in a payload field of the second frame.

[0027] According to a third aspect of the disclosure, there is provided a method performed at a wireless device. The method comprises obtaining an identifier of the wireless device; obtaining an encryption key, wherein the encryption key is associated with the identifier; and communicating a frame between the wireless device and a first access point. The frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.

[0028] According to some embodiments, communicating the frame may comprises transmitting a first frame to a first access point. The identifier may be carried in in a header field of the first frame and a first information element encrypted with the encryption key may be carried in a payload field of the first frame.

[0029] According to some embodiments, communicating the frame may comprises receiving a second frame from the first access point, wherein the identifier is carried in a head field of the second frame, and a second information element encrypted with the encryption key is carried in a payload field of the second frame; retrieving the encryption key according to the identifier carried in the second frame; and decrypting the second information element using the encryption key.

[0030] According to a fourth aspect of the disclosure, there is provided a method performed at a first access point. The method comprises obtaining an identifier of a wireless device; obtaining a encryption key, wherein the encryption key is associated with the identifier; and communicating a frame between the wireless device and the first access point. The frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.

[0031] According to some embodiments, communicating the frame may comprise receiving a first frame from the wireless device. The identifier may be carried in in a header field of the first frame and a first information element encrypted with the encryption key may be carried in a payload field of the first frame. Communicating the frame may further comprise retrieving the encryption key according to the identifier carried in the first frame; and decrypting the first information element using the encryption key.

[0032] According to some embodiments, communicating the frame may comprise transmitting a second frame to the wireless device. The identifier may be carried in in a header field of the second frame and a second information element encrypted with the encryption key may be carried in a payload field of the second frame.

[0033] According to a fifth aspect of the disclosure, there is provided a computer readable storage medium, on which instructions are stored. When executed by at least one processor, the instructions cause the at least one processor to perform any method according to the third or fourth aspect.

[0034] According to sixth aspect of the disclosure, there is provided computer program product comprising instructions which when executed by at least one processor, cause the at least one processor to perform any method according to the third or fourth aspect.

[0035] According to a seventh aspect of the disclosure, there is provided an apparatus implemented at a wireless device, comprising: means for obtaining an identifier of the wireless device; means for obtaining an encryption key, wherein the encryption key is associated with the identifier; and means for communicating a frame between the wireless device and a first access point. The frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.

[0036] According to some embodiments, the means for communicating the frame may comprise means for transmitting a first frame to a first access point. The identifier may be carried in in a header field of the first frame and a first information element encrypted with the encryption key may be carried in a payload field of the first frame.

[0037] According to some embodiments, the means for communicating the frame may comprises means for receiving a second frame from the first access point, wherein the identifier is carried in a head field of the second frame, and a second information element encrypted with the encryption key is carried in a payload field of the second frame; means for retrieving the encryption key according to the identifier carried in the second frame; and means for decrypting the second information element using the encryption key.

[0038] According to an eighth aspect of the disclosure, there is provided an apparatus implemented at a first access point, comprising: means for obtaining an identifier of a wireless device; means for obtaining an encryption key, wherein the encryption key is associated with the identifier; and means for communicating a frame between the wireless device and the first access point. The frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.

[0039] According to some embodiments, the means for communicating the frame may comprise means for receiving a first frame from the wireless device. The identifier may be carried in in a header field of the first frame and a first information element encrypted with the encryption key may be carried in a payload field of the first frame; means for retrieving the encryption key according to the identifier carried in the first frame; and means for decrypting the first information element using the encryption key.

[0040] According to some embodiments, the means for communicating the frame may comprise means for transmitting a second frame to the wireless device. The identifier may be carried in in a header field of the second frame and a second information element encrypted with the encryption key may be carried in a payload field of the second frame.

[0041] It is to be understood that the summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Some example embodiments will now be described with reference to the accompanying drawings in which:

[0043] FIG. 1 illustrate an exemplary procedure of using a device ID for identification;

[0044] FIG. 2 illustrates an exemplary procedure of using IRM for identification;

[0045] FIGs. 3a, 3b and 3c illustrates exemplary procedures using a device ID for different authentication algorithms;

[0046] FIGs. 4a, 4b, and 4c illustrates exemplary procedures using an IRM for different authentication algorithms;

[0047] FIG. 5 is a flow chart depicting a method performed at a wireless device according to an embodiment of the present disclosure;

[0048] FIG. 6 is a flow chart depicting a method performed at an access point according to an embodiment of the present disclosure;

[0049] FIG. 7 is a flow chart depicting an exemplary process according to an embodiment of the present disclosure;

[0050] FIGs. 8a, 8b and 8c are flow charts depicting exemplary processes for configuring a secret key according to an embodiment of the present disclosure;

[0051] FIG. 9 is a flow chart depicting an exemplary encryption process for IE according to an embodiment of the present disclosure;

[0052] FIG. 10 is a flow chart depicting an exemplary process according to an embodiment of the present disclosure;

[0053] FIG. 11 is a flow chart depicting an exemplary process according to an embodiment of the present disclosure;

[0054] FIG. 12 is a flow chart depicting an exemplary process according to an embodiment of the present disclosure; and

[0055] FIG. 13 shows a simplified block diagram of an apparatus according to an embodiment of the present disclosure.DETAILED DESCRIPTION

[0056] Some example embodiments will now be described in more detail hereinafter with reference to the accompanying drawings, in which some, but not all embodiments are shown. Indeed, the example embodiments may take many different forms and should not be construed as fixed to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will satisfy applicable legal requirements. Like reference numerals refer to like elements throughout.

[0057] References in the present disclosure to “one embodiment” , “an embodiment” , “an example embodiment” , and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an example embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.

[0058] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.

[0059] As used herein, the terms “data, ” “content, ” “information, ” and similar terms may be used interchangeably to refer to data capable of being transmitted, received and / or stored in accordance with embodiments of the present invention. Thus, use of any such terms should not be taken to limit the spirit and scope of embodiments of the present invention.

[0060] As used in this application, the term “circuitry” may refer to one or more or all of the following:

[0061] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and

[0062] (b) combinations of hardware circuits and software, such as (as applicable) :

[0063] (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and

[0064] (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and

[0065] (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0066] This definition of “circuitry” applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term “circuitry” also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term “circuitry” also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0067] As defined herein, a “computer-readable storage medium, ” which refers to a non-transitory physical storage medium (e.g., volatile or non-volatile memory device) , can be differentiated from a “computer-readable transmission medium, ” which refers to an electromagnetic signal. Such a medium may take many forms, including, but not limited to a non-transitory computer-readable storage medium (e.g., non-volatile media, volatile media) , and transmission media. Transmission media include, for example, coaxial cables, copper wire, fiber optic cables, and carrier waves that travel through space without wires or cables, such as acoustic waves and electromagnetic waves, including radio, optical and infrared waves. Signals include man-made transient variations in amplitude, frequency, phase, polarization or other physical properties transmitted through the transmission media. Examples of non-transitory computer-readable media include a magnetic computer readable medium (e.g., a floppy disk, hard disk, magnetic tape, any other magnetic medium) , an optical computer readable medium (e.g., a compact disc read only memory (CD-ROM) , a digital versatile disc (DVD) , a Blu-Ray disc, or the like) , a random access memory (RAM) , a programmable read only memory (PROM) , an erasable programmable read only memory (EPROM) , a FLASH-EPROM, or any other non-transitory medium from which a computer can read. The term computer-readable storage medium is used herein to refer to any computer-readable medium except transmission media. However, it will be appreciated that where embodiments are described to use a computer-readable storage medium, other types of  computer-readable mediums may be substituted for or used in addition to the computer-readable storage medium in alternative embodiments.

[0068] In the following, certain embodiments are explained with reference to a wireless device (or a station, or a terminal device) capable of wireless communication on a wireless access, via an access point or similar network node in a wireless local area network (LAN) or any other similar wireless communication system. The wireless device may comprise any suitable device capable of at least receiving wireless communication of data. For example, the wireless device can be handheld data processing device equipped with wireless receiver, data processing and user interface apparatus. Non-limiting examples include a mobile station (MS) such as a mobile phone or what is known as a “smart phone” , a portable computer such as a laptop or a tablet computer provided with a wireless interface card or other wireless interface facility, personal data assistant (PDA) provided with wireless communication capabilities, or any combinations of these or the like. Further examples include wearable wireless devices such as those integrated with watches or smart watches, eyewear, helmets, hats, clothing, ear pieces with wireless connectivity, jewelry and so on, universal serial bus (USB) sticks with wireless capabilities, modem data cards, machine type devices or any combinations of these or the like.

[0069] For communication in a wireless local area network (LAN) , two identification mechanisms are defined in 802.11bh standards, namely, network generated identifier (such as a device ID) and STA generated identifier (such as IRM) . Simply saying, the identification mechanism of device ID is that, “an AP tells an STA to use a device ID later when the STA comes back so that the AP identifies the STA” . Afterwards (once a device ID is used for the STA) , the AP can generate and send another device ID (such as another unique number) to the STA, so that the STA can use said another device ID again in the future. Note that generating and sending a device ID every time is optional. An STA can use a same device ID for a while (or even all the time) .

[0070] FIG. 1 illustrate an exemplary procedure using a device ID for identification. As shown at block 110, in an initial connection procedure of an STA (such as STA 101) which is to be attached to an ESS, the STA 101 does not have a device ID. In this procedure, it may use a completely random and unidentifiable MAC address, (denoted as MAC1) , to initiate a connection in a wireless local area network (LAN) , e.g., an ESS. Then, an AP (such as AP1 102) generates a device ID (denoted as devID1) for the STA 101 and sends (tells) the STA 101 in a message, e.g., Auth Msg2, about it. For example, the message Auth Msg2 may contain an encrypted device ID (denoted as enc (devID1) , =aa) . This device ID (devID1) would be shared among all APs in a same ESS, which comprises one or more access points, such as AP1, and other APs (such as AP2 103) . When the STA 101 establishes another connection with another AP (such as AP2 103) in the same ESS as shown at block 120, the STA 101  may use another MAC address (denoted as MAC2) , but it also signals devID1 in Auth Msg1. With the help of devID1, AP2 is able to identify the STA 101 (not based on MAC2) . During the procedure 120, the AP2 103 may generate and send another device ID (denoted as devID2) to the STA 101 so that the STA 101 can use devID2 in the future, e.g., in the later connection procedure shown at block 130. This new device ID (devID2) would be shared among all APs in a same ESS. Similarly, APs in the ESS may identify the STA 101 based on the device ID in later connection procedures of the STA 101 in this ESS, as shown at blocks 130 and 140.

[0071] The identification mechanism of IRM is that, “an STA tells an AP which MAC address the STA will use later when the STA comes back so that the AP identifies the STA” . Afterwards (once an IRM is used) , the STA can generate and send another unique MAC to the STA itself so that the STA can use said another MAC in the future. Note that generating and sending an IRM every time is optional. An STA can use a same IRM for a while (or even all the time) .

[0072] FIG. 2 illustrate an exemplary procedure of using IRM for identification. As shown at block 210, in an initial connection procedure of an STA (such as STA 101) which is to be attached to an ESS, the STA does not have an IRM. In this procedure, it may use a completely random and unidentifiable MAC address, (denoted as MAC1) , to initiate a connection in a wireless local area network (LAN) , e.g., an ESS. Then, the STA generates an IRM (denoted as IRM1) for itself and sends (tells) an AP (denoted as AP1 102) in a message, such as Auth Msg3, about it. This IRM (IRM1) would be shared among all APs in a same ESS, which comprises one or more access points, such as AP1, and other APs (such as AP2 103) . When the STA 101 establishes another connection with another AP (such as AP2 103) in the same ESS as shown at block 220, it uses IRM1 as MAC address. With the help of IRM1, AP2 is able to identify the STA 101. During the procedure 220, the STA 101 may generate and send another IRM (denoted asIRM2) to the AP2 103. This new IRM (IRM2) would be shared among all APs in a same ESS. Then, APs in the ESS may identify the STA 101 based on the new IRM in later connection procedures of the STA 101 in this ESS, as shown at blocks 230 and 240.

[0073] The two identification mechanisms are defined for three kinds of authentication algorithms, namely, a) fast initial network link setup (FILS) , b) pre-association security negotiation (PASN) c) Other Authentication (i.e., any authentication algorithm other than FILS or PASN, for example, SAE, PSK etc. ) .

[0074] FIG. 3a illustrates exemplary procedure using a device ID for FILS. As shown at step 310a, in an initial connection procedure, when an STA (such as STA 101) associates with an AP (such as AP 102) or an ESS, the AP or ESS assigns a device ID encrypted to the STA in a 4-way Handshake message 3. When the STA returns to the same AP or the same ESS for a next connection procedure, the STA sends the assigned device ID in a (Re) Association Request, as shown at step 320a. Hence, the  STA can be identified by the same AP or the same ESS. Note that an AP in the present disclosure refers to a single AP in basic service set (BSS) or in ESS, and an ESS in the present disclosure refers to one or more APs in an ESS.

[0075] FIG. 3b illustrates exemplary procedure using a device ID for PASN. As shown at step 310b, in an initial connection procedure, when an STA (such as STA 101) performs PASN with an AP (such as AP 102) or an ESS, the AP or ESS assigns a device ID encrypted to the STA in a second PASN frame. When the STA returns to the same AP or the same ESS or performs another PASN with another AP in the same ESS for a next connection procedure, the STA sends the assigned device ID in a first PASN frame, as shown at step 320b. Hence, the STA can be identified by the same AP or the same ESS.

[0076] FIG. 3c illustrates exemplary procedure using a device ID for other authentication algorithm. As shown at step 310c, in an initial connection procedure, when an STA (such as STA 101) associates with an AP (such as AP 102) or an ESS, the AP or ESS assigns a device ID encrypted to the STA in a 4-way Handshake message 3. When the STA returns to the same AP or the same ESS for a next connection procedure, the STA sends the assigned device ID in an encrypted in 4-way Handshake message 2, as shown at step 320c. Hence, the STA can be identified by the same AP or the same ESS.

[0077] FIG. 4a illustrates exemplary procedure using an IRM for FILS. As shown at step 410a, in an initial connection procedure, when an STA (such as STA 101) associates with an AP (such as AP 102) or an ESS, the STA assigns an IRM to itself and informs the AP or the ESS about the IRM encrypted in a frame body of a 4-way Handshake message 4. When the STA returns to the same AP or the same ESS for a next connection procedure, the STA sends the assigned IRM in an MAC header of a (Re) Association Request and / or in other frames, as shown at step 420a. Hence, the STA can be identified by the same AP or the same ESS.

[0078] FIG. 4b illustrates exemplary procedure using an IRM for PASN. As shown at step 410b, in an initial connection procedure, when an STA (such as STA 101) performs PASN with an AP (such as AP 102) or an ESS, the STA assigns an IRM to itself and informs the AP or the ESS about the IRM encrypted in a frame body of a third PASN frame. When the STA returns to the same AP or the same ESS or performs another PASN with another AP in the same ESS for a next connection procedure, the STA sends the assigned IRM in an MAC header of a first PASN frame, as shown at step 420b. The STA may keep using the same IRM for the other future frames (such as second PASN frame, third PASN frame etc. ) . Hence, the STA can be identified by the same AP or the same ESS.

[0079] FIG. 4c illustrates exemplary procedure using an IRM for other authentication algorithm. As shown at step 410c, in an initial connection procedure, when an STA (such as STA 101) associates with an AP (such as AP 102) or an ESS, the STA assigns an IRM to itself and informs the AP or the ESS about the IRM encrypted in a frame body of a 4-way Handshake message 4. When the STA  returns to the same AP or the same ESS for a next connection procedure, the STA sends the assigned IRM in an MAC header of an authentication frame, reassociation frame and / or in other frames, as shown at step 420c. Hence, the STA can be identified by the same AP or the same ESS.

[0080] In the communication in a wireless local area network (LAN) , some frames are susceptible to protect their Information Element (s) (IEs) . These frames are mostly management frames before a security establishment between a STA and an AP, such as Robust Security Network Association (RSNA) establishment between a STA and an AP. Such examples are IEs that are included in management frames sent from an STA, for example, probe request, authentication request, (re) association request, some action frames (e.g., public action frames) , and the like. Because these frames are sent before a security establishment between a STA and an AP, and consequently the STA and the AP do not have any security key to protect their IEs, those IEs contained in a frame body of these frames are sent in the air without protection. It becomes critical if those IEs comprise important privacy information, such as personal identifiable information (PII) , e.g., information of a device ID. In this case, any third party can track the STA based on those unprotected IEs.

[0081] An example of such scenario is that defined in the current 802.11bh draft, as shown in FIGs. 1, 3a, 3b, and 3c. For example, an STA may send its device ID unencrypted in a first PASN frame when using PASN, as shown in step 320b. According to the 802.11bh draft, a new device ID is assigned to the STA in each PASN frame exchange, e.g., in a second PASN frame as shown in step 310b. This would prevent trackability of the STA based on the device ID in a first PASN frame. However, in bad implementations, third parties might still track the STA based on a device ID even though a new device ID is assigned to the STA in each PASN frame exchange. As an example, when a device ID includes PII (such as an employee number, an employee e-mail, etc. ) , third parties can still track the STA based on the device ID. For instance, assume that the generated and assigned device IDs would be Alice1, Alice2, Alice3 etc. Even though a new device ID (Alice1, Alice2, Alice3 etc. ) is generated and assigned to an STA in each PASN exchange, the new device ID is sent unencrypted / unprotected in the first PASN frame (as shown at step 320b) , and the third party would track the STA. In other words, it is easy for the third party to figure out that a real identity of the STA is “Alice” , even though a new device ID (Alice1, Alice2, Alice3 etc. ) is generated and assigned to the STA in each PASN frame exchange.

[0082] Furthermore, the same device ID should be shared among all APs in the same ESS. For example, if an AP in an ESS assigns a device ID, “Alice1” , to an STA, another AP (e.g., AP2) should have the same device ID = “Alice1” . This means that all APs in the same ESS (AP1 and AP2) should somehow exchange the device ID between each other, so that each AP would assign a unique and unused device ID to the STA (for example, while AP1 assigns Alice1 to the STA, AP2 would assign  Alice2, not Alice1 again, to the STA) and the STA would use the device ID with any AP in the same ESS without any problem. In other words, synchronizing the device ID for all APs in the same ESS would cause some burden on the network.

[0083] To sum up, the current 802.11 specification does not address the following problems. Bad implementations (e.g., generating device ID that include PII) of device ID that is sent unencrypted in some scenarios (such as sending the device ID unencrypted in the first PASN frame) might cause trackability issue in the network. Also, synchronizing the device ID among all APs in the same ESS would put too much burden on the network.

[0084] The present disclosure proposes an improved solution for protecting IEs using IRM. The solution may be applicable to a wireless LAN (or any other similar wireless communication system) including an access point (or a network node) and a wireless device (or a station or a terminal device) . Hereinafter, the solution of the present disclosure will be described in detail with reference to FIGs. 5-13.

[0085] In general, according to embodiments of the present disclosure, a secret key is defined, and an identifier (such as IRM) of an STA which is to identify the STA uniquely in a wireless LAN (such as an ESS) is used as a key index for the secret key. By using the identifier as a key index, the STA and AP(s) in the ESS are able to find the secret key, and use the secret key to protect (e.g., encrypt / decrypt) IEs communicated between the STA and the AP (s) ) .

[0086] FIG. 5 is a flow chart depicting a method performed at a wireless device (such as an STA) according to an embodiment of the present disclosure. At block 510, the wireless device obtains an identifier of the wireless device. In an embodiment, the identifier may be an IRM of the wireless device. The identifier may be determined by the wireless device independently. For example, the wireless device may choose (e.g., configure an IRM to itself) or generate its IRM. In an example, an IRM may be assigned to the wireless device, as defined in 802.11bh. Then, the wireless device may use the identifier as an index a security key for protecting IEs transmitted from or to the wireless device. In case the identifier is an IRM, the IRM may be used as a transmitter address or receiver address in a frame transmitted from or to the wireless device.

[0087] In some embodiment, the wireless device may further transmit the determined identifier (such as IRM) to a first access point or other access points in a network (such as an ESS) . The identifier of the wireless device may be transmitted to the access point in any suitable frame. For example, an IRM of an STA may be transmitted to an AP in an initial connection to the AP or to other APs in a same ESS as the AP, or other network nodes of the ESS. The initial connection means a procedure when an STA comes to a network (such as an ESS) for the first time, such as the procedure shown by 110, 210,  310a, 310b, 310c, 410a, 410b, and 410c. This is where an STA obtains the identifier (such as IRM and / or device ID assignment) . The future connections of the STA within the network would depend on this initial connection. If the STA does not obtain any identifier (such as IRM and / or device ID assignment) in the initial connection, it can’t use an IRM and / or a device ID in future connections, and hence cannot be identified by the AP (s) of the network. If the STA obtains an identifier (such as IRM and / or device ID assignment) in the initial connection, it can use the IRM and / or device ID in future connections, and hence can be identified by the AP (s) of the network) .

[0088] At block 520, the wireless device obtains an encryption key. The encryption key is associated with the identifier of the wireless device. The encryption key may be obtained during an initial connection of the wireless device to the first access point or to the network (such as ESS) of the first access point.

[0089] In an embodiment, the wireless device may generate the encryption key, and then transmit it to the first access point. The encryption key is transmitted together with the identifier.

[0090] In another embodiment, the wireless device may receive the encryption key from the first access point. In this case, the secret key may be generated by the first access point. The encryption key is received together with the identifier.

[0091] In another embodiment, the wireless device may receive the encryption key from a second access point. The second access point belongs to a same network (e.g., ESS) as the first access point. For example, the encryption key may be received during an initial connection of the wireless device to the second access point. The encryption key is received together with the identifier.

[0092] In yet another embodiment, the wireless device may generate the secret key, without a necessity to transmit the secret key to the first access point. In this case, the secret key may be generated at a wireless device side and an access point side, respectively, based on another paired keys, such as pairwise master key (PMK) or pairwise transient key (PTK) .

[0093] At block 530, the wireless device communicates a frame between the wireless device and the first access point. The frame may be communicated before a security establishment between the wireless device and the first access point is completed. In this regard, the wireless device transmits a frame to the first access point, and / or receives a frame from the first access point. The frame comprises the identifier of the wireless device and an information element (IE) encrypted with the encryption key.

[0094] In an embodiment, the wireless device may transmit a first frame to the first access point, as show at block 532. The identifier (e.g., IRM) of the wireless device may be carried in in a header field of the first frame, and a first information element encrypted with the encryption key may be carried in  a payload field of the first frame. The first frame may be transmitted as a first pre-association security negotiation frame for a next connection to the first access point or the second access point. The next connection means a future connection (s) after the initial connection, such as the procedures. As mentioned above, an STA obtains an identifier (such as IRM and / or device ID assignment) in the initial connection, and can use the identifier (such as IRM and / or device ID) in a next (future) connection (s) .

[0095] In this context, the first pre-association security negotiation frame refers to any frame transmitted before a security establishment between the wireless device and the first access point or the second access point. Some examples of the first pre-association security negotiation frame comprise: a probe request frame, an authentication frame (which is also called as authentication request frame) , association request frame, some action frames (such as public action frames) , 4-way Handshake frame, or the like. All these frames can carry IE (s) , so IEs in these frames may be protected with the security key when the identifier is also contained in these frames. The IE (s) can carry many things. As the current Wi-Fi standard defines more than 300 IEs, some / many of which can be sent as IEs in the so-called first pre-association security negotiation frame. For example, the IE (s) may comprise at least one of a device identifier of the wireless device in the first pre-association security negotiation frame for the next connection; an identifier of simultaneous authentication of equals (SAE) password in the authentication frame for the next connection; and an identifier of pairwise master key (PMK) in the association request for the next connection, and any other IE that is defined in pre-association security negotiation frame.

[0096] In an embodiment, the wireless device may receive a second frame from the first access point, as shown at block 534. The identifier of the wireless device (e.g., an IRM) may be carried in a head field of the second frame, and a second information element encrypted with the encryption key may be carried in a payload field of the second frame. Then, the wireless device may retrieve the encryption key according to the identifier (e.g., IRM) carried in the second frame as shown at block 536 and decrypt the second information element using the encryption key as shown at block 538. The encryption key associated with the identifier may be stored in a memory in the wireless device by using the identifier as a key index, and then may be searched and retrieved based on the identifier.

[0097] The second frame may be received as a second pre-association security negotiation frame for a next connection from the first access point or the network. In this context, the second pre-association security negotiation frame can be any frame received from an access point to the wireless device before a security establishment. Some examples of the second pre-association security negotiation frame comprise: a probe response frame, an authentication frame (also called as authentication response frame) , an association response frame, some action frames (such as public action frames) , a 4-way Handshake frame, or the like. There may be many IEs that can carry different information in the second  frame. The second information element may comprise at least one of a device identifier of the wireless device in the second pre-association security negotiation frame for the next connection; or an identifier of simultaneous authentication of equals password in a second authentication frame for the next connection. In an example, the second information element may comprise any other information element that is defined in a pre-association security negotiation frame.

[0098] FIG. 6 is a flow chart depicting an exemplary method performed at a first access point according to an embodiment of the present disclosure.

[0099] At block 610, the first access point obtains an identifier of a wireless device (such as an STA) . The identifier may be an IRM of the wireless device. In an embodiment, the identifier may be received from the wireless device. In another embodiment, the identifier may be received from a second access point which belongs to a same network (such as a same ESS) as the first access point. In this case, the identifier of the wireless device is distributed within the network. APs of the network would exchange the identifier among each other.

[0100] The identifier of the wireless device may be received in any suitable frame. For example, an IRM of an STA may be received in an initial connection from the STA to the access point, or from other access point in a same ESS as the access point of the ESS.

[0101] At block 620, the first access point obtains an encryption key that is mapped to the identifier of the wireless device. The encryption key may be obtained during an initial connection of the wireless device to the first access point or a network (such as an ESS) of the first access node. The first access point may further transmit or exchange the encryption key and the identifier of the wireless device among access points in the network (such as the ESS) .

[0102] In an embodiment, the first access point may receive the encryption key from the wireless device. In this case, the encryption key may be generated by the wireless device. The encryption key is received together with the identifier of the wireless device, so as to indicate the association therebetween.

[0103] In another embodiment, the first access point may generate the encryption key, and then transmit it to the wireless device. The encryption key is transmitted together with the identifier, so as to indicate the association therebetween.

[0104] In yet another embodiment, the first access point may generate the encryption key, without a necessity to transmit the encryption key to the wireless device. In this case, the encryption key may be generated at a wireless device side and the first access point side, respectively, based on another paired keys, such as pairwise master key (PMK) or pairwise transient key (PTK) .

[0105] In yet another embodiment, the first access point may receive the encryption key from a second access point which belongs to a same network (such as a same ESS) as the first access point. The second access point has got the encryption key that is mapped to the identifier, and then share the encryption key among APs of the network, e.g., through a distribution mechanism within the network.

[0106] At block 630, the first access point communicates a frame between the wireless device and the first access point. The frame may be communicated before a security establishment between the wireless device and the first access point is completed. In this regard, the first access point may receive a frame from the wireless device and / or transmit a frame from the wireless device. The frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.

[0107] In an embodiment, the first access point may receive a first frame from the wireless device, as shown at block 642. The identifier (e.g., IRM) of the wireless device may be carried in in a header field of the first frame, and a first information element encrypted with the encryption key may be carried in a payload field of the first frame. Then, the first access point may retrieve the encryption key according to the identifier (e.g., IRM) carried in the first frame as shown at block 634, and decryption the first information element using the encryption key as shown at block 636.

[0108] The first frame may be received as a first pre-association security negotiation frame for a next connection to the access point. In this context, the first pre-association security negotiation frame refers to any frame received before the security establishment between the wireless device and the access point. Some examples of the first pre-association security negotiation frame comprise: a probe request frame, an authentication frame (which is also called as authentication request frame) , association request frame, some action frames (such as public action frames) , 4-way Handshake frame, or the like. All these frames can carry IE (s) , so IEs in these frames may be protected with the security key when the identifier is also contained in these frames. For example, the IE (s) may comprise at least one of a device identifier of the wireless device in the first pre-association security negotiation frame for the next connection; an identifier of simultaneous authentication of equals (SAE) password in the authentication frame for the next connection; and an identifier of pairwise master key (PMK) in the association request for the next connection, and any other IE that is defined in pre-association security negotiation frame.

[0109] In an embodiment, the first access point may transmit a second frame to the wireless device. The identifier of the wireless device may be carried in in a header field of the second frame and a second information element encrypted with the encryption element is carried in the payload field of the second frame. The second frame may be received as a second pre-association security negotiation frame for a next connection from the first access point or the network of the first access point.

[0110] In this context, the second pre-association security negotiation frame can be any frame received from an access point to the wireless device before a security establishment. Some examples of the second pre-association security negotiation frame comprise: a probe response frame, an authentication frame (also called as authentication response frame) , an association response frame, some action frames (such as public action frames) , a 4-way Handshake frame, or the like. There may be many IEs that can carry different information in the second frame. In an example, the second information element may comprise at least one of a device identifier of the wireless device in the second pre-association security negotiation frame for the next connection, or an identifier of simultaneous authentication of equals password in the second authentication frame for the next connection. In an example, the second information element may comprise any other information element that is defined in a pre-association security negotiation frame.

[0111] With the methods of FIGs. 5 and 6, the real information in an information element communicated between a wireless device and an access point before a security establishment therebetween is never exposed. As long as the encryption of the information element happens along with an identifier (e.g., an IRM) of the wireless device IRM, the wireless device and the access point can encrypt and decrypt any information quickly and smoothly because of the encryption key is mapped to identifier (e.g., IRM) . In addition, any information can be encrypted with this mechanism without a security establishment between a wireless device and an access point (e.g., RSNA establishment) . Furthermore, the network (e.g., BSS or ESS comprising one or more access points) doesn’t need to assign a different device ID in each association of a wireless device to the network, as the device ID communicated between the wireless device and any access point in the network before a security establishment therebetween can be protected. Accordingly, efforts for synchronizing the device ID among access points within the network can mitigated on network side.

[0112] FIG. 7 is a flow chart depicting an exemplary process according to an embodiment of the present disclosure. The process provides a method to protect IE (s) in frames communicated between an STA and an AP or an ESS, where those IE (s) are sent unprotected under current wireless LAN protocols.

[0113] As shown in FIG. 7, at step 1, an STA 701 uses an IRM as its identifier, e.g., a transmitter address for a transmission from the STA 701 to an AP 702. In this regard, The STA determine or assign the IRM to itself independently. Then, the STA may use the IRM as a transmitter address when desired, e.g., as defined in the current 802.11bh protocols. For example. The STA may transmit the IRM to the access point in any suitable frames, such as a 4-way Handshake Msg4, a third PASN frame, Authentication Msg3 or other authentication messages, as shown in FIGs. 2 and 4.

[0114] At step 2, the STA and the AP configure a secret key that is mapped to the IRM. The secret key would be used as an encryption key to protect IE (s) communicated between the STA and the AP. Configuring the secret key means that the secret key should be stored and used at the STA side and the AP side until a further action is needed (e.g., changing the secret key) . The secret key may be mapped to the IRM along with assigning the IRM to the STA. Note that the secret key is unique between each STA and AP / ESS. Also note that the secret key would be distributed among all APs in the same ESS.

[0115] Configuring the secret key may be implemented though any suitable manner. In an embodiment illustrated in FIG. 8a, the STA may generate the secret key as shown at step 802. Then, the STA may transmit the secret key to the AP together with the STA’s IRM (e.g., as TA) , indicating that the secret key is mapped to the IRM, as shown at step 804. In some examples, the secret key may be encrypted (if possible) , so that an encrypted secret key is carried and sent to the AP, e.g., in one of the frames below: a Probe Request frame, an Authentication Request frame, an Association Request frame, a 4-way Handshake frame, or an Action frame. In an example, when the STA generates and assigns the IRM to itself, the secret key may be also generated and mapped to the IRM. For example, when the STA initiates a connection to the AP, it may generate its IRM. At this point, a secret key is also generated. Then, the STA send its IRM and the secret key to the AP in 4-way Handshake Msg4. The AP receives the secret key together with the STA’s IRM, and maps the secret key to the IRM of the STA on the AP side, as shown at step 806.

[0116] In another embodiment illustrated in FIG. 8b, an AP may generate the secret key as shown at step 812. Then the AP may transmit the secret key to the STA, as shown at step 814. In some examples, the secret key may be encrypted (if possible) , so that an encrypted secret key is carried and sent to the STA, e.g., in one of the frames below: a beacon frame, a probe response frame, an authentication response frame, an association response frame, 4-way handshake frame, or an action frame. Then, the STA receives the secret key and configures the secret key to be mapped to its IRM, as shown at step 816. When the IRM is generated or assigned to the STA, the STA may send its STA to the AP as shown at 818. Then, the AP can map the secret key to the IRM of the STA on the AP side, as shown at step 820.

[0117] In another embodiment illustrated in FIG. 8c, an STA and an AP can generate the secret key locally based on another key, such as pairwise master key (PMK) or pairwise transient key (PTK) , as shown at steps 822 and 822’. Then, the STA and the AP may store the secret key. When the IRM of the STA is generated or assigned to the STA, the STA may send its STA to the AP as shown at 824. The STA may configure the secret key to be mapped to the IRM of the STA, as shown at step 826.  The AP may receive the IRM of the STA and then map the secret key to the IRM of the STA on the AP side, as shown at step 828.

[0118] Now return to FIG. 7, at step 3, if the STA intends to protect a first IE, the STA may encrypt the first IE with the secret key and a cryptographic function. After that, the STA may send the encrypted first IE in the air along with the IRM. For example, a first frame carrying both the IRM in the MAC header (as Transmitter Address [TA] ) and the encrypted first IE in the frame body (i.e., a payload field) is sent to the AP over the air.

[0119] The encryption of IE is based on the secret key and a cryptographic function. The encryption might also include additional input such as a string. The cryptographic function can be any strong encryption function, for example, allegedRC4 (ARC4) , RC5, triple data encryption algorithm (3DES) , advanced encryption standard (AES) , strong hash functions (such as SHA-256) , or any encryption function defined in 802.11, such as counter CBC-MAC protocol (CCMP) , Galois counter mode protocol (GCMP) .

[0120] FIG. 9 illustrates an example of IE encryption. In this example, the real IE is “abc” . The configured secret key between the STA and the AP / ESS is “111” . To encrypt the IE, a cryptographic function, AES, may be adopted, which takes the real IE= “abc” and uses the secret key = “111” to generate the encrypted IE = “xyz” . That encrypted IE= “xyz” will be sent in the first frame in the air instead of the real IE= “abc” . Noted that besides the real IE and the secret key, the encrypted IE may be generated based on other suitable parameters, which may be dependent on the adopted cryptographic function.

[0121] At step 4, after receiving the first frame in step3, the AP can recognize the STA via the IRM in the MAC header, and then it can use the secret key mapped to the IRM to decrypt the encrypted first IE and obtain the real information in the first IE. FIG. 10 illustrate an exemplary procedure which extends the example shown in FIG. 9. In this figure, After the STA and the AP configures the secret key ( “111” ) , the STA starts encrypting the real IE ( “abc” ) locally. Afterwards, when the STA constructs a frame (such as the first frame shown in step 3 of FIG. 7) and includes the encrypted IE in the frame, it uses the IRM as TA to send the frame containing encrypted IE ( “xyz” ) . When the AP receives the frame, because it knows the IRM and the corresponding secret key, it can immediately find the relevant secret key ( “111” ) and decrypt the encrypted IE ( “xyz” ) to obtain the real IE ( “abc” ) .

[0122] At step 5, if the AP also intends to protect a second IE, the AP may encrypt the second IE with the same secret key and the cryptographic function. After that, a second frame carrying both the IRM in the MAC header (as Receiver Address [RA] ) and the encrypted second IE in the frame body (i.e., payload field) is sent to the STA over the air. The second IE may be encrypted in a similar manner as  shown in FIG. 9. It should be noted that with the proposed mechanism, encryption of multiple IEs in a frame is also possible.

[0123] At step 6, after receiving the frame in step 5, the STA can use the secret key mapped to the IRM to decrypt the encrypted second IE and obtain the real information in the second IE. The encrypted second IE may be decrypted in a similar manner as shown in FIG. 10.

[0124] FIG. 11 illustrate an example scenario using a protected IE according to embodiments of the present disclosure. In this example, the STA uses an IRM and a device ID for two PASN procedures with a same ESS. The details of a procedure in this scenario are as follows.

[0125] At step 1, an STA 1101 wants to perform a PASN procedure with an ESS using both an IRM and a device ID. Therefore, during a first PASN. The ESS comprises more than one APs, including AP1 1102 and AP2 1103. The AP1 1102 may assign a device ID (e.g., “alice123” ) encrypted to the STA 1101 in the second PASN frame as shown at 1112, e.g., in response to a request (e.g., the first PASN frame) from the STA 1101 as shown at 1110. The STA assigns itself an IRM (e.g., “aa: bb: cc: dd: ee: ff” ) and sends it to the AP1 1102 encrypted in the third PASN frame, as show at 1114. The encryption for the device ID and the IRM may be executed as defined specifically in 802.11bh draft.

[0126] According to embodiments of the present disclosure, the STA 1101 further generates the secret key (e.g., “111” ) , and sends it to the AP1 1102 encrypted also in the third PASN frame, as show at 1114. This is a mapping (denoted as aa: bb: cc: dd: ee: ff <-> 111) . So, whenever the STA uses the IRM, it actually “points” to the secret key as well. The IRM works as a “key index” in this context. This secret key may be exchanged in the ESS. As shown at 1116, AP1 may distribute the secret key and the associated IRM (i.e., the mapping of IRM to encryption key) to other APs (e.g., AP2 1103) in the same ESS. In this example, the distributed secret key ( “111” ) is mapped to the IRM ( “aa: bb: cc: dd: ee: ff” ) .

[0127] At step 2, the STA wants to perform a second PASN with another AP (e.g., AP2 1103) in the same ESS. According to the current 802.11bh draft, the device ID of the STA 1101 is sent unencrypted in the first PASN frame. However, using the mechanism proposed in the present disclosure, the STA 1101 encrypts the device ID with the secret key ( “111” ) , resulting in “alice123” being transformed to “a1b1c1” .

[0128] At step 3, after constructing the encrypted device ID, the STA 1101 puts the encrypted device ID in the first PASN frame. Note that the STA 1101 uses IRM= “aa: bb: cc: dd: ee: ff” as TA in the first PASN frame. The STA 1101 may send the encrypted device ID to AP2 1102 in the first PASN frame along with the IRM.

[0129] At step 4, after AP2 1103 receives the first PASN frame, it checks the IRM. Since AP2 1103 recognizes the IRM, it could find the corresponding (mapped) secret key ( “111” ) . Therefore, AP2 1103 can decrypt the encrypted device ID, and obtains the real device ID ( “alice123” ) .

[0130] FIG. 12 illustrate another example scenario using a protected IE according to embodiments of the present disclosure. In this example, an STA 1201 uses an IRM in simultaneous authentication of equals (SAE) authentication. The details of a procedure in this scenario are as follows.

[0131] At step 1, the STA 1201 performs an initial connection to an AP 1202. During an initial connection, the STA 1201 assigns a SAE Password ID (SAE PW ID) (e.g., “001” ) encrypted to the AP 1202 in the first Authentication frame, as shown at 1210. The AP confirms the SAE PW ID ( “001” ) with the second Authentication frame, as shown at 1212. The STA 1201 and the AP 1202 also generate pairwise master key identifier (PMKID) (e.g., “999” ) locally at their sides, as shown at 1214 and 1216, respectively. The STA 1201 assigns itself an IRM (e.g., “aa: bb: cc: dd: ee: ff” ) along with a secret key (e.g., “111” ) , and sends them encrypted in the 4-way Handshake Message 4, as shown at 1218.

[0132] At step 2, the STA 1201 returns to the same AP 1202 or the same ESS to which the AP 1202 belongs, for a next connection. The STA 1201 encrypts the SAE PW ID with the secret key ( “111” ) , resulting in “001” being transformed to “123” , as shown at 1220. Then the STA 1201 puts the encrypted SAE PW ID in the first Authentication frame. Note that the STA uses IRM=“aa: bb: cc: dd: ee: ff” as TA in the MAC header of the first Authentication frame. The STA 1201 sends the encrypted SAE PW ID to the AP 1202 in the first Authentication frame along with the IRM, as shown at 1222. The AP 1202 receives the first Authentication frame, it checks the IRM contain in the head field. Since the AP 1202 can recognize the IRM, it finds the corresponding (mapped) secret key (“111” ) . Therefore, the AP 1202 can decrypt the encrypted SAE PW ID, and obtains the real SAE PW ID ( “001” ) , as shown at 1224.

[0133] At step 3, the AP 1202 wants to protect the SAE PW ID ( “001” ) to be sent in Authentication frame 2. The AP encrypts the SAE PW ID with the secret key ( “111” ) , resulting in “001” being transformed to “456” , as shown at 1230. It should be appreciated that, encryption for the SAE PW ID may use the secret key along with other parameters. The other parameters may be anything depending on the encryption algorithm, e.g., time information, which may be a public information known the STA 1201 and the AP 1202. Therefore, even if the same secret key, the encryption output at 1230 may be different from the encryption output at 1220. The AP 1202 puts the encrypted SAE PW ID in the second Authentication frame. Note that the AP uses IRM= “aa: bb: cc: dd: ee: ff” as RA in the MAC header of second Authentication frame. The AP 1202 may send the encrypted SAE PW ID to the STA 1201 in the second Authentication frame along with the IRM, as shown at 1232. The STA 1201 receives the second Authentication frame, it checks the IRM contain in the head field. Since the STA  1201 can recognize the IRM, it finds the corresponding (mapped) secret key ( “111” ) . Therefore, the STA 1201 can decrypt the encrypted SAE PW ID, and obtains the real SAE PW ID ( “001” ) , as shown at 1234.

[0134] At step 4, the STA 1201 wants to protect the PMKID ( “999” ) to be sent in Association request. The STA 1201 encrypts the PMKID with the secret key ( “111” ) , resulting in “999” being transformed to “987” , as shown at 1240. Then, the STA 1201 puts the encrypted PMKID in the Association Request frame. Note that the STA uses IRM= “aa: bb: cc: dd: ee: ff” as TA in the MAC header of the Association Request frame. The STA 1201 may send the encrypted PMKID to the AP 1202 in the Association Request frame along with the IRM, as shown at 1242. The AP 1202 receives the Association Request frame, it checks the IRM contain in the head field. Since the AP 1202 can recognize the IRM, it finds the corresponding (mapped) secret key ( “111” ) . Therefore, the AP 1202 can decrypt the encrypted PMKID, and obtains the real PMKID ( “999” ) , as shown at 1244.

[0135] Now reference is made to FIG. 13 illustrating a simplified block diagram of an apparatus 1300 that may be embodied in / as the access point, or the first wireless device. The apparatus 1300 may comprise at least one processor 1301, such as a data processor (DP) and at least one memory 1302 coupled to the at least one processor 1301. The apparatus 1300 may further comprise one or more transmitters TX, one or more receivers RX 1303, or one or more transceivers coupled to the one or more processors 1301 to communicate wirelessly and / or through wireline.

[0136] Although not shown, the apparatus 1300 may have at least one communication interface, for example, the communicate interface can be at least one antenna, or transceiver as shown in the FIG. 13.The communication interface may represent any interface that is necessary for communication with other network entities.

[0137] The processors 1301 may be of any type suitable to the local technical environment, and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples.

[0138] The memory 1302 may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory, as non-limiting examples.

[0139] The memory 1302 stores a program 1304. The program 1304 may include instructions that, when executed on the associated processor 1301, enable the apparatus 1300 to operate in accordance with the embodiments of the present disclosure. A combination of the at least one processor 1701 and  the at least one memory 1302 may form processing circuitry or means 1305 adapted to implement various embodiments of the present disclosure.

[0140] Various embodiments of the present disclosure may be implemented by computer program executable by one or more of the processors 1301, software, firmware, hardware or in a combination thereof.

[0141] In general, the various exemplary embodiments may be implemented in hardware or special purpose circuits, software, logic, module, means or any combination thereof. For example, some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the invention is not limited thereto. While various aspects of the exemplary embodiments of this disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, means, module, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0142] As such, it should be appreciated that at least some aspects of the exemplary embodiments of the disclosures may be practiced in various components such as integrated circuit chips and modules. It should thus be appreciated that the exemplary embodiments of this disclosure may be realized in an apparatus that is embodied as an integrated circuit, where the integrated circuit may comprise circuitry (as well as possibly firmware) for embodying at least one or more of a data processor, a digital signal processor, baseband circuitry and radio frequency circuitry that are configurable so as to operate in accordance with the exemplary embodiments of this disclosure.

[0143] It should be appreciated that at least some aspects of the exemplary embodiments of the disclosures may be embodied in computer-executable instructions, such as in one or more program modules, executed by one or more computers or other devices. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types when executed by a processor in a computer or other device. The computer executable instructions may be stored on a computer readable medium, for example, non-transitory computer readable medium, such as a hard disk, optical disk, removable storage media, solid state memory, RAM, etc. As will be appreciated by one of skills in the art, the function of the program modules may be combined or distributed as desired in various embodiments. In addition, the function may be embodied in whole or in part in firmware or hardware equivalents such as integrated circuits, field programmable gate arrays (FPGA) , and the like.

[0144] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.

[0145] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0146] As used herein, the phrase “at least one of A and B” or “at least one of A or B” should be understood to mean “only A, only B, or both A and B. ” The phrase “A and / or B” should be understood to mean “only A, only B, or both A and B” .

[0147] The present disclosure includes any novel feature or combination of features disclosed herein either explicitly or any generalization thereof. Various modifications and adaptations to the foregoing exemplary embodiments of this disclosure may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings. However, any and all modifications will still fall within the scope of the non-limiting and exemplary embodiments of this disclosure.

Claims

1.An apparatus at a wireless device, the apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:obtain an identifier of the wireless device;obtain an encryption key, wherein the encryption key is associated with the identifier; andcommunicate a frame between the wireless device and a first access point,wherein the frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.2.The apparatus according to claim 1, wherein the frame is communicated before a security establishment between the wireless device and the first access point is completed.3.The apparatus according to claim 1 or 2, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to obtain the identifier by:determining the identifier of the wireless device; andwherein the apparatus is further caused to transmit the determined identifier to the first access point, or to a second access point which belongs to a same network as the first access point.4.The apparatus according to any of claims 1 to 3, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to obtain the encryption key by:generating the encryption key.5.The apparatus according to claim 4, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to:transmit the encryption key to the first access point or to a second access point which belongs to a same network as the first access point,wherein the encryption key is transmitted together with the identifier.6.The apparatus according to any of claims 1 to 3, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to obtain the encryption key by:receiving the encryption key from the first access point or from a second access point which belongs to a same network as the first access point,wherein the encryption key is received together with the identifier.7.The apparatus according to any of claims 1 to 6, wherein the identifier and the encryption key are obtained during an initial connection of the wireless device to the first access point or a network of the first access point.8.The apparatus according to any of claims 1 to 7, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to communicate the frame by:transmitting a first frame to the first access point, wherein the identifier is carried in in a header field of the first frame and a first information element encrypted with the encryption key is carried in a payload field of the first frame.9.The apparatus according to claim 8, wherein the first frame is transmitted as a first pre-association security negotiation frame for a next connection to the first access point.10.The apparatus according to claim 9, wherein the first pre-association security negotiation frame is one of:a probe request frame,an authentication frame,an association request frame,an action frame, ora 4-way Handshake frame.11.The apparatus according to claim 10, wherein the first information element comprises at least one of:a device identifier of the wireless device in the first pre-association security negotiation frame for the next connection;an identifier of simultaneous authentication of equals password in the authentication frame for the next connection; oran identifier of pairwise master key in the association request for the next connection.12.The apparatus according to any of claims 1 to 11, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to communicate the frame by:receiving a second frame from the first access point, wherein the identifier is carried in a head field of the second frame, and a second information element encrypted with the encryption key is carried in a payload field of the second frame;retrieving the encryption key according to the identifier carried in the second frame; anddecrypting the second information element using the encryption key.13.The apparatus according to claim 12, wherein the second frame is received as a second pre-association security negotiation frame for a next connection from the first access point.14.The apparatus according to claim 13, wherein the second pre-association security negotiation frame is one of:a probe response frame,an authentication frame,an association response frame,an action frame, anda 4-way Handshake frame.15.The apparatus according to claim 14, wherein the second information element comprises at least one of:a device identifier of the wireless device in the second pre-association security negotiation frame for the next connection, oran identifier of simultaneous authentication of equals password in a second authentication frame for the next connection.16.The apparatus according to any of claims 1 to 15, wherein the identifier is an identifiable random medium access control (IRM) address of the wireless device.17.The apparatus according to any of claims 1 to 16, wherein the network is an extended service set.18.An apparatus at a first access point, the apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:obtain an identifier of a wireless device;obtain an encryption key, wherein the encryption key is associated with the identifier; andcommunicate a frame between the wireless device and the access point,wherein the frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.19.The apparatus according to claim 18, wherein the frame is communicated before a security establishment between the wireless device and the first access point is completed.20.The apparatus according to claim 18 or 19, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to obtain the identifier by:receiving the identifier from the wireless device or from a second access point which belongs to a same network as the first access point.21.The apparatus according to any of claims 18 to 20, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to obtain the encryption key by:receiving the encryption key from the wireless device or from a second access point which belongs to a same network as the first access point,wherein the encryption key is received together with the identifier.22.The apparatus according to any of claims 18 to 20, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to obtain the encryption key by:generating the encryption key.23.The apparatus according to any of claims 18 to 22, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to:transmit the identifier and the encryption key to the wireless device; and / ortransmit the identifier and the encryption key to a second access point which belongs to a same network as the access point.24.The apparatus according to any of claims 18 to 23, wherein the identifier and the encryption key are obtained during an initial connection of the wireless device to the first access point or a network of the first access point.25.The apparatus according to any of claims 18 to 24, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to communicate the frame by:receiving a first frame from the wireless device, wherein the identifier is carried in a header field of the first frame and a first information element encrypted with the encryption key is carried in a payload field of the first frame;retrieving the encryption key according to the identifier carried in the first frame; anddecrypting the first information element using the encryption key.26.The apparatus according to claim 25, wherein the first frame is received as a first pre-association security negotiation frame for a next connection to the first access point.27.The apparatus according to claim 26, wherein the first pre-association security negotiation frame is one of:a probe request frame,an authentication frame,an association request frame,an action frame, ora 4-way Handshake frame.28.The apparatus according to claim 27, wherein the first information element comprises at least one of:a device identifier of the wireless device in the first pre-association security negotiation frame for the next connection;an identifier of simultaneous authentication of equals password in the authentication frame for the next connection; oran identifier of pairwise master key in the association request for the next connection.29.The apparatus according to any of claims 18 to 28, wherein when the instructions are executed by the at least one processor, the instructions cause the apparatus at least to communicate the frame by:transmitting a second frame to the wireless device, wherein the identifier is carried in in a header field of the second frame and a second information element encrypted with the encryption key is carried in a payload field of the second frame.30.The apparatus according to claim 29, wherein the second frame is transmitted as a second pre-association security negotiation frame for a next connection to the wireless device.31.The apparatus according to claim 30, wherein the second pre-association security negotiation frame is one of:a probe response frame,an authentication frame,an association response frame,an action frame, anda 4-way Handshake frame.32.The apparatus according to claim 31, wherein the second information element comprises at least one of:a device identifier of the wireless device in the second pre-association security negotiation frame for the next connection, oran identifier of simultaneous authentication of equals password in a second authentication frame for the next connection.33.The apparatus according to any of claims 18 to 32, wherein the identifier is an identifiable random medium access control (IRM) address of the wireless device.34.The apparatus according to any of claims 18 to 33, wherein the network is an extended service set.35.A method performed at a wireless device, the method comprising:obtaining an identifier of the wireless device;obtaining an encryption key, wherein the encryption key is associated with the identifier; andcommunicating a frame between the wireless device and a first access point,wherein the frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.36.The method according to claim 35, wherein the frame is communicated before a security establishment between the wireless device and the first access point is completed.37.The method according to claim 35 or 36, wherein obtaining the identifier comprises:determining the identifier of the wireless device;wherein the method further comprises transmitting the identifier to the first access point, or to a second access point which belongs to a same network as the first access point.38.[Rectified under Rule 91, 25.07.2023]The method according to any of claims 35 to 37, wherein obtaining the encryption key comprises:generating the encryption key.39.The method according to claim 38, further comprising:transmitting the encryption key to the first access point or to a second access point which belongs to a same network as the first access point,wherein the encryption key is transmitted together with the identifier.40.The method according to any of claims 35 to 37, wherein obtaining the encryption key comprises:receiving the secret key from the first access point or a second access point which belongs to a same network as the first access point,wherein the encryption key is received together with the identifier.41.The method according to any of claims 35 to 40, wherein the identifier and the encryption key are obtained during an initial connection to the first access point or a network of the first access point.42.The method according to any of claims 35 to 41, wherein communicating the frame comprises:transmitting a first frame to the first access point, wherein the identifier is carried in in a header field of the first frame and a first information element encrypted with the encryption key is carried in a payload field of the first frame.43.The method according to claim 42, wherein the first frame is transmitted as a first pre-association security negotiation frame for a next connection to the first access point.44.The method according to claim 43, wherein the first pre-association security negotiation frame is one of:a probe request frame,an authentication frame,an association request frame,an action frame, ora 4-way Handshake frame.45.The method according to claim 44, wherein the first information element comprises at least one of:a device identifier of the wireless device in the first pre-association security negotiation frame for the next connection;an identifier of simultaneous authentication of equals password in the authentication frame for the next connection; oran identifier of pairwise master key in the association request for the next connection.46.The method according to any of claims 35 to 45, wherein communicating the frame comprises:receiving a second frame from the first access point, wherein the identifier is carried in a head field of the second frame, and a second information element encrypted with the encryption key is carried in a payload field of the second frame;retrieving the encryption key according to the identifier carried in the second frame; anddecrypting the second information element using the encryption key.47.The method according to claim 46, wherein the second frame is received as a second authentication pre-association security negotiation frame for a next connection from the first access point.48.The method according to claim 47, wherein the second pre-association security negotiation frame is one of:a probe response frame,an authentication frame,an association response frame,an action frame, anda 4-way Handshake frame.49.The method according to claim 46, wherein the second information element comprises at least one of:a device identifier of the wireless device in the second pre-association security negotiation frame for the next connection, oran identifier of simultaneous authentication of equals password in a second authentication frame for the next connection.50.The method according to any of claims 35 to 49, wherein the identifier is an identifiable random medium access control (IRM) address of the wireless device.51.The method according to any of claims 35 to 50, wherein the network is an extended service set.52.A method performed at a first access point, the method comprising:obtaining an identifier of a wireless device;obtaining an encryption key, wherein the encryption key is associated with the identifier; andcommunicating a frame between the wireless device and the first access point,wherein the frame comprises the identifier of the wireless device and an information element encrypted with the encryption key.53.The method according to claim 52, wherein the frame is communicated before a security establishment between the wireless device and the first access point is completed.54.The method according to claim 52 or 53, wherein obtaining the identifier comprises:receiving the identifier from the wireless device or from a second access point which belongs to a same network as the first access point.55.The method according to any of claims 52 to 54, wherein obtaining the encryption key comprises:receiving the encryption key from the wireless device or from a second access point which belongs to a same network as the first access point,wherein the encryption key is received together with the identifier.56.The method according to any of claims 52 to 54, wherein obtaining the encryption key comprises:generating the encryption key.57.The method according to any of claims 52 to 56, further comprising:transmitting the identifier and the encryption key to the wireless device; and / ortransmitting the identifier and the encryption key to a second access point which belongs to a same network as the access point.58.The method according to any of claims 52 to 57, wherein the identifier and the encryption key are obtained during an initial connection of the wireless device to the first access point or a network of the first access point.59.The method according to any of claims 52 to 58, wherein communicating the frame comprises:receiving a first frame from the wireless device, wherein the identifier is carried in in a header field of the first frame and a first information element encrypted with the encryption key is carried in a payload field of the first frame;retrieving the encryption key according to the identifier carried in the first frame; anddecrypting the first information element using the encryption key.60.The method according to claim 59, wherein the first frame is received as a first pre-association security negotiation frame for a next connection to the first access point.61.The method according to claim 60, wherein the first pre-association security negotiation frame is one of:a probe request frame,an authentication frame,an association request frame,an action frame, ora 4-way Handshake frame.62.The method according to claim 61, wherein the first information element comprises at least one of:a device identifier of the wireless device in the first pre-association security negotiation frame for the next connection;an identifier of simultaneous authentication of equals password in the authentication frame for the next connection; oran identifier of pairwise master key in the association request for the next connection.63.The method according to any of claims 52 to 62, wherein communicating the frame comprises:transmitting a second frame to the wireless device, wherein the identifier is carried in in a header field of the second frame and a second information element encrypted with the encryption key is carried in a payload field of the second frame.64.The method according to claim 63, wherein the second frame is transmitted as a second pre-association security negotiation frame for a next connection to the wireless device.65.The method according to claim 64, wherein the second pre-association security negotiation frame is one of:a probe response frame,an authentication frame,an association response frame,an action frame, anda 4-way Handshake frame.66.The method according to claim 65, wherein the second information element comprises at least one of:a device identifier of the wireless device in the second pre-association security negotiation frame for the next connection, oran identifier of simultaneous authentication of equals password in a second authentication frame for the next connection.67.The method according to any of claims 52 to 66, wherein the identifier is an identifiable random medium access control (IRM) address of the wireless device.68.The method according to any of claims 52 to 67, wherein the network is an extended service set.69.A computer-readable medium having computer program codes embodied thereon which, when executed on a computer, cause the computer to perform the method according to any of claims 35 to 51.70.A computer-readable medium having computer program codes embodied thereon which, when executed on a computer, cause the computer to perform the method according to any of claims 52 to 68.