Multi-profile connection of a station to an access point of a wireless telecommunications network
The method of verifying message integrity with multiple keys in wireless networks addresses interference and security issues, providing flexible and secure access management with granular control.
Patent Information
- Application Number
- FR2023002492
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-17
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2043-03-17
Smart Images

Figure 00000014_0000 
Figure 00000014_0001
Abstract
Description
Title of the invention: Multi-profile connection of a station to an access point of a wireless telecommunications network FIELD OF THE INVENTION
[0001] The present invention relates to the field of connecting a station to an access point of a wireless telecommunications network, in particular a Wi-Fi type network.
[0002] It concerns more particularly the allocation of a profile to a station, defining its rights within the telecommunications network.
[0003] In a home network, several mechanisms have been proposed for managing the rights of a given station and access control.
[0004] For example, the physical address of the station, for example its MAC address ("Medium Access Control") can be used to identify a given station and thus distinguish different profiles depending on the stations at the access point. However, this method has the disadvantage of being incompatible with dynamic MAC address mechanisms ("MAC address randomization").
[0005] Another method consists of creating several separate telecommunications networks, each corresponding to a separate profile. Typically, a first Wi-Fi network grants all rights to the connected stations, and a second Wi-Fi network, called "guest", grants minimal rights, for example access to an external network (Internet) without allowing access to local resources connected to the Wi-Fi network.
[0006] This method, however, has many drawbacks.
[0007] Thus, each telecommunications network deployed necessarily occupies a location on the spectrum of the frequency band used. The addition of even a single “guest” network generates interference on the Wi-Fi frequency bands, leading on the one hand to network congestion and on the other hand to increased energy consumption.
[0008] Furthermore, it is difficult to offer more than two distinct profiles, especially since each telecommunications network deployed, as we have seen, consumes the available resources. The granularity of access rights management is therefore necessarily very low.
[0009] Another method is to move access rights management to an application layer. Users must then log in to a captive web portal and enter usernames and passwords corresponding to their profile.
[0010] This method has the disadvantage of requiring an additional step to users of the stations and therefore impact the user experience. In addition, it leaves free access to the physical layer of the telecommunications network, which generates vulnerability to attacks and malicious acts against this network and against the access point.
[0011] There is therefore a need to improve the current state-of-the-art proposals. Summary of the invention
[0012] For these purposes, according to a first aspect, the present invention can be implemented by a method for connecting a station to an access point of a wireless telecommunications network comprising an authentication phase in which said station uses a key to transmit a message to said access point, and in which said access point verifies the integrity of said message using a plurality of stored keys, and, if a stored key among said plurality makes it possible to verify said integrity, assigns an access profile to said station, corresponding to said stored key.
[0013] It is thus possible to define a plurality of keys, each key being able to correspond to a user or a group of users, independently of the stations that they can use.
[0014] The proposed mechanism is easy to configure for the administrator who, in the context of a family deployment, is not necessarily an IT specialist, and it is also transparent for each user who only needs to know and configure a password, in the same way as in the usual mechanisms.
[0015] If a user has several stations, using the same password will allow him to obtain the same access profile for each of his stations.
[0016] According to preferred embodiments, the invention comprises one or more of the following features which can be used separately or in partial combination with each other or in total combination with each other: - said authentication phase complies with the IEEE 802.1 li standard and said key is a primary key, PMK. In particular, the invention applies particularly well to Wi-Fi networks in WPA2-Personal security mode, which allows family use, in particular without deploying a Radius server. - the said message is a second message in a 4-way handshake process. Thus, the mechanism is completely transparent from the stations' point of view, and involves a minor modification for the access points. - the said access profile corresponds to a virtual local network. It is thus possible to provide great flexibility in access rights and to deport the configuration of access rights to the configuration of virtual local networks ap owned. - said access profile determines access to an external network and / or to local resources connected to said wireless local network. It is thus possible to manage, for example, visitor profiles (which can connect to the external network but not to local resources), “child” profiles (which can connect to local resources but not to the external network), etc. - said access point traverses said plurality by testing each stored key to verify the integrity of said message until a given key verifies said integrity, and assigns said corresponding profile to said given key. It is possible to order the keys so that the first ones stored are the most common in order to minimize the average connection times to the network.
[0017] Another aspect of the invention relates to an access point to a wireless telecommunications network, comprising a processor configured to enable the connection of a station following an authentication phase in which said access point receives a message from said station, and in which said access point verifies the integrity of said message using a plurality of stored keys, and, if a stored key among said plurality makes it possible to verify said integrity, assign an access profile to said station, corresponding to said stored key, said access profile being used for said connection.
[0018] Another aspect of the invention relates to a computer program capable of being implemented on an access point to a wireless telecommunications network, the program comprising code instructions which, when executed by a processor, carry out the steps of the method as previously defined.
[0019] Another aspect of the invention relates to a data medium on which at least one series of program code instructions has been stored for the execution of a method as previously defined.
[0020] Other characteristics and advantages of the invention will appear on reading the following description of a preferred embodiment of the invention, given by way of example and with reference to the appended drawings. BRIEF DESCRIPTION OF THE FIGURES
[0021] The attached drawings illustrate the invention: [Fig.l] illustrates a context for implementing a process
[0022] [Fig.2] shows a diagram of a timing diagram of an exchange between a station and an access point according to one embodiment of the method.
[0023] DETAILED DESCRIPTION OF EMBODIMENTS OF THE INVENTION
[0024] [Fig.l] illustrates a context of implementation of a telecommunications network making it possible to connect one or more stations to an access point.
[0025] This telecommunications network can be a wireless local area network, commonly called WLAN for “Wireless Local Area Network” in English.
[0026] This wireless local area network may comply with the Wi-Fi, or wifi, protocols as specified in the IEEE 802.11 family (or ISO / IEC 8802-11) standards documents.
[0027] Such a network is identified by a network identifier SSID (for “service set identifier”). In infrastructure mode (connection of a station to an access point), it is used to identify the wireless access point.
[0028] The stations can be of different natures, their common feature being to have means allowing connection to the network. These are essentially radiocommunication components and electronic and computer components allowing the implementation of the protocol stacks necessary for the management of the protocols associated with the network and the reception and transmission of data packets.
[0029] In [Fig.l], three types of STA stations are represented: a computer ORD, a mobile communication terminal, MOB, and a connected television TV.
[0030] The mobile terminal MOB is typically a smartphone type smart phone or a digital tablet.... The computer can be a fixed computer (or "desktop" according to the English vocabulary) or portable (or "laptop").
[0031] The TV can be natively connected or connected via an associated device such as, for example, an HDMI key connected to the TV.
[0032] An example of an external device communicating with a TV is Chromecast. Chromecast is a real-time media streaming device (media gateway) developed and marketed by Google. The device plugs into the HDMI port of a TV and communicates, via Wi-Fi, with another device connected to the Internet (computer, smartphone, tablet, etc.), in order to display on the TV the multimedia content received from an application compatible with Google Cast technology, from the Google Chrome browser on a computer, or from certain Android devices.
[0033] Obviously, other types of STA stations may be required to connect to a wireless local area network. These include connected objects which, in the context of the Internet of Things (IoT), connect to each other or to a server in order to deploy all of their functionalities.
[0034] According to an infrastructure deployment mode, the stations connect to the wireless local area network via one or more access points PA. These access points act as hubs, through which the data flows from / to the stations necessarily pass.
[0035] These access points therefore allow the control of access to the wireless local network by the STA stations. These must identify themselves to an access point and this, the If necessary, grants them the rights corresponding to its profile. If it cannot identify itself correctly, the station cannot access the wireless local network.
[0036] This wireless local network can be a home network, i.e. corresponding to a user's home.
[0037] The wireless local network can also be a business network, particularly for small businesses (SMEs / VSEs), places open to the public (restaurants, bars, cafes, etc.), etc.
[0038] Access points can also be of different types, in particular depending on the type of location in which the wireless local network is deployed.
[0039] An access point may be a dedicated device, marketed as such. It may also form a gateway to an external network such as the Internet.
[0040] For example, boxes allowing access to the Internet from a domestic environment usually offer the Wi-Fi access point function.
[0041] For example, in a domestic environment, the access point can be embedded in an internet connection box, commonly called an “internet box” or domestic gateway.
[0042] The connection of a station to an access point requires an authentication phase of this station ST A with the access point PA.
[0043] In the context of a Wi-Fi network, the WPA2-Personal security mode can be used. Many devices are compatible with this security mode. It is particularly suitable for a home environment, in which access is controlled by secret phrases (or "passwords") and not by authentication servers such as Radius servers.
[0044] Other security modes are also possible, such as for example WPA3-Personal.
[0045] This authentication phase can be a 4-way handshake, as defined by the IEEE 802.11i standard. This standard defines an authentication mechanism commonly called WPA2 (for “Wi-Fi Protected Access 2”).
[0046] However, other mechanisms may be possible, in particular future developments of the protocols defined for Wi-Fi standards or for other families of protocols which could, for example, be derived from them.
[0047] This mechanism is an exchange of 4 messages passing between a STA station and a PA access point which allows: - confirm mutual knowledge of a common key and thus ensure a certain form of authentication, and - derive and install time keys on the station and on the access point and to provide assurance of the use of new encryption and integrity keys.
[0048] This common key can be a PMK (for “Pairwise Master Key” in English).
[0049] A deployment mode of a wireless local area network is called "personal" mode or PSK for "Pre-Shared Key" in English or pre-shared key). In this deployment mode, the master key PMK is calculated beforehand by the user of the station and the access point.
[0050] Typically, this PMK master key is derived from the PSK (commonly referred to as the passphrase). The passphrase can be configured by an administrator within the access point settings.
[0051] The administrator can communicate it to potential users of the local network who can enter it when trying to connect to the local network. Many stations have an operating system that offers the possibility of storing the secret phrase so that the user does not have to enter it again.
[0052] The passphrase can contain 8 to 63 ASCII characters or 64 hexadecimal symbols (256 bits). If a passphrase in the form of ASCII characters is used, it is converted to a 256-bit master key PMK, for example by applying a PBKDF2 key derivation function.
[0053] This PBKDF2 derivation mechanism (abbreviation of “Password-Based Key Derivation Function 2”) is for example described in the associated Wikipedia page: https: / / fr.wikipedia.org / wiki / PBKDF2.
[0054] In another deployment mode, an authentication server may be set up and the latter derives the master key and distributes it to the stations and access points. This authentication server may be compliant with the IEEE 802.IX standard.
[0055] In the proposed method, a plurality of primary keys (PMK for example) can be defined, each being associated with an access profile to the wireless local area network. The access point then has knowledge of all of these primary keys while each station only has knowledge of one (or more generally a subset) of these primary keys.
[0056] Thus, an administrator can communicate to each station a primary key, or a corresponding secret phrase, which corresponds to the profile that he wishes to assign to it.
[0057] It is thus possible to define as many profiles as desired, simply by provisioning a primary key in the access point and associating this primary key with the access rights (and other parameters) corresponding to this profile.
[0058] The master key PMK is never directly used for encryption or integrity control. It is used for the generation of temporary encryption keys, PTK, for exchanges between a given PA access point and a given STA station.
[0059] The temporary key PTK (for “Pairwise Transcient Key”) actually comprises several temporal keys, each with a dedicated use: - the key confirmation key, KCK (for “Key Confirmation Key”), which is mainly used during the 4-way handshake, - the key encryption key, KEK (for “Key Encryption Key”), - the temporary key TK (for “Temporary Key”), - the temporary MIC key, TMK (“Temporary MIC Key”).
[0060] The temporary key PTK is derived from the master key PMK, a fixed character string, the MAC address of the access point, the MAC address of the station, and two random numbers generated, one by the station and the other by the access point.
[0061] [Fig.2] illustrates the proposed 4-way handshake mechanism.
[0062] In a first message, the access point PA transmits a first random number to the station STA which wishes to authenticate. According to the 802.1 li standard, this random number is called "Annonce".
[0063] In a step E1, the station STA generates a second random number, called “Snonce” according to the 802.1 11 standard.
[0064] From two random numbers, the master key PMK, and the MAC addresses, the access point PA can determine the temporary key PTK.
[0065] The station STA can then transmit a message m2 to the access point PA containing the second random number, Snonce, and an integrity code, MIC (for “Message Integrity Check”) using the key confirmation key, KCK (from the temporary key PTK).
[0066] This message m2 is not encrypted. Upon receipt, in a step E2, the access point can therefore extract the second random number, Snonce. It can then calculate itself, in the same way as the access point, a temporary key PTK.
[0067] In the proposed method, the access point has a plurality of common keys. These common keys can be PMK primary keys from which it can derive as many PTK temporary keys as there are PMK primary keys.
[0068] Furthermore, there are no theoretical limits to the number of common keys stored in an access point and therefore usable by a station, and therefore no limit to the number of possible access profiles.
[0069] From this temporary key, the access point can then verify the integrity of the received message. This verification can consist of verifying the integrity of the integrity field MIC contained in the second message. It can thus ensure that the station STA knows the primary key PMK because it was able to correctly derive the temporary key PTK, then the temporal keys (key confirmation key, KCK) having allowed the generation of the integrity code, MIC.
[0070] The access point may verify the integrity of the m2 message using a plurality of stored keys.
[0071] It can check the integrity of the message iteratively with the keys of the stored plurality. If a tested key does not allow the integrity to be checked, then a new key is tested (arrow looping back to step E2, in [Fig.2]). If a tested key allows the integrity of the message to be checked, then the tests can be interrupted and this key is selected. If no key allows the integrity of the message m2 to be checked, then the connection of the station STA is rejected.
[0072] These stored keys may be PMK primary keys.
[0073] According to one embodiment, the plurality of stored keys is stored within the access point PA in the form of a list. The access point PA can browse the list and verify the integrity of the message m2 received from the station for each key in the list until a key actually allows the integrity of the message to be verified.
[0074] The access point can then stop scanning the list because it can be assumed that each key is only stored once in the list.
[0075] It can then assign an access profile to the station, corresponding to this stored key.
[0076] Thus, the access point can memorize a set of correspondences between a key and a profile.
[0077] The profile can be stored as a profile identifier, or as a set of parameters that define it. These parameters are typically access rights.
[0078] The profile identifier can define, directly or indirectly, a virtual local area network. This virtual network can be of the VLAN type for “Virtual Local Area Network”. This virtual local area network makes it possible to define access rights to the wireless local area network for the station concerned, with the desired granularity.
[0079] The access point memory may contain a set of associations in the form of the following table:
[0080] [Tables 1] PMK1 VLAN1 PMK2 VLAN2 PMK3 VLAN3
[0081] Each key is thus associated with a virtual network corresponding to the access profile corresponding to the key and defining the station's access rights to the network.
[0082] Respectively, in the example of Table 1, the master key PMK1 is associated with a virtual local area network VLAN1, the master key PMK2 is associated with a virtual local area network VLAN2 and master key PMK3 is associated with a virtual LAN VLAN3.
[0083] It is entirely possible to provide for several keys to be associated with the same profile. This may be the case if one wishes to provide for changes in access rights and to be able to manage these changes simply by modifying the associations without having to change the master keys communicated to the different users and configured in the different stations of a computer / home automation system.
[0084] Profiles can correspond to family members (parents, children, etc.) and visitors, for a home network. They can correspond to different roles within a company such as a small business, etc.
[0085] In particular, access profiles can govern access to a network outside the private local network (Internet, extranet, etc.), to certain local resources (connected hard drives, connected printer, etc.), etc.
[0086] Some profiles may only have access to the Internet, accessible through the local network, but not to local resources connected to the local network. This may be the case, for example, of a visitor who is given free access to the Internet and to a particular resource (such as a printer) but who is not allowed to access the personal data of the family or company.
[0087] Conversely, some profiles may only have access to local resources but not to the Internet. This may be the case, for example, for a child under a certain age, for a home network.
[0088] Also, local resources can be categorized, so that some resources may only be accessible to certain profiles.
[0089] In summary, all kinds of configuration are possible within the framework of the proposed connection method, which therefore offers great flexibility in the management of access rights.
[0090] An access profile can be easily assigned to a user by providing them with the associated secret phrase, or master key. The mechanism is therefore extremely simple to implement, and the same secret phrase can be used by a user on all of their stations, so as to obtain the same access profile.
[0091] Furthermore, this mechanism is independent of the physical address (MAC) of each station, and therefore does not suffer from the problem of dynamic physical addresses like certain proposals in the state of the art.
[0092] Virtual local area networks can be deployed upstream, for example during the initialization of one of the access points of the wireless telecommunications network. They can also be deployed by an access point when it receives a message from a station corresponding to a virtual local area network.
[0093] When a station determines an access profile for a given station, it can therefore check whether the corresponding virtual local area network is deployed, and if not, trigger its deployment.
[0094] An m3 message can then be transmitted to station ST A, in accordance with the specifications of the IEEE 802.1 li standard.
[0095] This third message m3 contains a group temporary key, GTK (“Group Transcient Key”), encrypted with the key encryption key, KEK, and derived from a group master key, GMK (“Group Master Key”) and a random number “GNonce”, as well as an integrity field, MIC, calculated on the content of this third message.
[0096] Upon receipt of this third message m3, the station initiates a step E3 for verifying the integrity of the received message. This verification may consist of verifying the integrity of this integrity field MIC. This makes it possible to ensure that the access point knows the master key PMK and that it has correctly derived the temporary key PTK and then the temporal keys (in particular the key encryption key, KEK).
[0097] The 4th message, m4, confirms the success of the entire 4-way handshake authentication phase. It indicates that the station has successfully installed the keys and is ready to begin encrypting the data. Upon receipt, the station and the access point know that each party has obtained, calculated, and installed the various encryption keys for the protocol.
[0098] At this stage, the access point can actually connect the STA station to the corresponding virtual local area network.
[0099] In this embodiment based on the specifications of the IEEE 802.1 11 standard, we therefore see that only step E2, implemented by the access point PA, is modified. The protocol itself is not modified and the STA station is not impacted either.
[0100] Thus, section 8.5.3.2 of the IEEE 802.1 11 standard describes a step a) of deriving a master key PTK, a step b) of verifying the MIC field of message 2 (i.e. of message m2 as previously described).
[0101] A step c) can be provided for if the authenticator manages several master keys, PTK, to resume from step a) by trying a new master key PTK.
[0102] Different profiles can be defined for different members of the family, in particular for minor children for example, but access control also aims to prohibit access to the network for third parties who are outside the home but within the radio range of the access points.
[0103] In these various situations, different profiles can be defined, in particular for the public authorized to use the local network (or not), the company's personnel, etc.
[0104] The primary keys (or the secret phrases used to generate them) can be shared in a manner known per se, but each in a differentiated manner to distinct users: each user will then have a primary key, which they can use with its STA station, in order to obtain access to the local network with access rights granted by its profile. The station can in particular connect to a virtual local network corresponding to this profile and determined by the primary key entered by the user.
[0105] Of course, the present invention is not limited to the examples and the embodiment described and shown, but is defined by the claims. It is in particular susceptible of numerous variants accessible to those skilled in the art.
Claims
Claims
1. Method for connecting a station to an access point of a wireless telecommunications network comprising an authentication phase in which said station (STA) uses a key to transmit a message (m2) to said access point (PA), and in which said access point verifies the integrity of said message using a plurality of stored keys, and, if a stored key among said plurality makes it possible to verify said integrity, assigns an access profile to said station, corresponding to said stored key.
2. Method according to the preceding claim in which said authentication phase complies with the IEEE 802.1 li standard and said key is a primary key, PMK.
3. A method according to the preceding claim, wherein said message is a second message of a 4-way handshake process.
4. Method according to one of the preceding claims in which said access profile corresponds to a virtual local network.
5. Method according to one of the preceding claims in which said access profile determines access to an external network and / or to local resources connected to said wireless local network.
6. A method according to one of the preceding claims, wherein said access point traverses said plurality testing each stored key to verify the integrity of said message until a given key verifies said integrity, and assigns said corresponding profile to said given key.
7. Access point (PA) to a wireless telecommunications network, comprising a processor configured to enable the connection of a station (STA) following an authentication phase in which said access point receives from said station (STA) a message (m2), and in which said access point verifies the integrity of said message using a plurality of stored keys, and, if a stored key among said plurality makes it possible to verify said integrity, assign an access profile to said station, corresponding to said stored key, said access profile being used for said connection.
8. Internet access box comprising an access point according to the preceding claim.
9. A computer program capable of being implemented on an access point to a wireless telecommunications network, the program comprising code instructions which, when executed by a processor, performs the steps of the method defined in claims 1 to 6.
10. Data carrier on which at least one series of program code instructions has been stored for executing a method according to one of claims 1 to 6.