Method and apparatus for privacy management in wireless networks

JP2025527404A5Active Publication Date: 2025-11-18CANON KK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025501503
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-26
Filing Date
2023-08-16
Publication Date
2025-11-18
Estimated Expiration
2043-08-16

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in managing privacy parameters beyond the Randomize and Change MAC (RCM) procedure, leading to unacceptable implementation costs and complexity, as they fail to effectively obfuscate personally identifiable information (PII) and maintain desired privacy levels.

Method used

A method and device for managing privacy levels in wireless networks by sharing and negotiating privacy-enhancing (PE) parameters between access points (APs) and non-AP stations, allowing stations to request and agree on a set of PE parameters to be obfuscated, ensuring compatibility and privacy alignment.

Benefits of technology

This approach reduces implementation costs and complexity while ensuring that wireless communications maintain desired privacy levels by dynamically adjusting and obfuscating multiple privacy parameters, addressing the limitations of existing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The present invention relates to a method for managing privacy levels in a wireless network comprising an access point (AP) station and at least one non-AP station, the method comprising: transmitting, by a first station, which is either a non-AP station or an AP station, to a second station, a message including information indicating a set of privacy-enhancing (PE) parameters to be obfuscated, the set of PE parameters corresponding to a privacy level requested by the first station, the second station being an AP if the first station is a non-AP station, and the second station being a non-AP station if the first station is an AP; and receiving, from the second station, a response indicating whether the second station accepts the requested privacy level.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to methods and devices for managing privacy in wireless networks, and more particularly to managing privacy profiles during wireless communications. [Background technology]

[0002] The approaches described in this section could be pursued, but are not necessarily approaches that have been previously conceived or pursued. Accordingly, unless otherwise indicated herein, the approaches described in this section are not prior art to the claims of this application, and no admission of prior art is made by inclusion in this section. Moreover, not all embodiments are necessarily intended to solve all, or even any, of the problems raised in this section.

[0003] Wireless communication networks are widely deployed to provide various communication services, such as voice, video, packet data, messaging, and broadcast. These wireless networks may be multiple-access networks capable of supporting multiple users by sharing available network resources. Examples of such multiple-access networks include code division multiple access (CDMA) networks, time division multiple access (TDMA) networks, frequency division multiple access (FDMA) networks, orthogonal FDMA (OFDMA) networks, and single-carrier FDMA (SC-FDMA) networks. The 802.11 family of standards adopted by the Institute of Electrical and Electronics Engineers (IEEE) provides numerous mechanisms for wireless communication between stations.

[0004] Today, the evolution of wireless systems has brought privacy concerns to the forefront, driven by user demands and requirements of the General Data Protection Regulation (GDPR). While the global wireless industry continues to improve wireless services and user experiences, it is faced with an increasing need to protect users' personally identifiable information from increasingly sophisticated user tracking and user profiling activities.

[0005] In the context of Wi-Fi networks, the media access control (MAC) address or EUI-48 address of a user device has been quickly identified as a key privacy parameter that can be used to track users without their consent. The IEEE 802.11 Working Group then proposed a procedure that involves dynamically changing the MAC address of a user device. This mechanism, called the Randomize and Change MAC (RCM) procedure, was first introduced as a privacy-enhancing feature in the 802.11aq Pre-Association Service Discovery Task Group and was eventually included in the standard IEEE Std 802.11-2020. The RCM procedure is an obfuscation procedure applied to MAC addresses. It involves periodically changing the MAC addresses of non-AP stations (i.e., stations that are not access points) to random values ​​while non-AP stations (STAs) are not associated with the network (or, equivalently, with an access point).

[0006] While changing only the MAC address is a first step to improving privacy, it is often not sufficient, and other elements, called personally identifiable information (PII) or privacy parameters, are also obfuscated. Obfuscation is typically achieved by dynamically modifying parameters to make them unidentifiable and / or untraceable. For example, in the RCM procedure specified in the standard IEEE Std 802.11-2020, every time a non-AP STA's MAC address is changed to a new random value, all counters in the sequence number (SN) space used to identify each transmitted frame (MSDU or MMPDU) are randomly reset, as is the seed for the scrambler used at the PHY level to shuffle the frame data payload before transmission.

[0007] Since 2019, a specific IEEE 802.11bi task group has been tasked with proposing new technical features beyond the RCM procedure to enhance privacy in 802.11. At its current stage, it specifies a set of privacy requirements for APs and / or non-AP STAs, implying the consideration of new privacy parameters, referred to as Privacy Extension (PE) parameters, to determine whether a non-AP STA is associated, and that these multiple PE parameters should be obfuscated simultaneously. This could lead to unacceptable implementation costs and complexity. It is desirable to manage the handling of PE parameters in the BSS to ensure that communications are performed at the desired privacy level while reducing implementation costs and complexity. Summary of the Invention

[0008] The present invention has been devised to address one or more of the problems set forth above. According to a first aspect of the present invention, there is provided a method for managing a privacy level in a wireless network comprising an access point (AP) station and at least one non-AP station, the method comprising: sending, to a second station, a message including information indicating a set of privacy-enhancing (PE) parameters to be obfuscated, the set corresponding to a privacy level requested by the first station; receiving a response from the second station indicating whether the second station accepts the requested privacy level; Includes.

[0009] In one embodiment, the message further includes an indication of the PE parameters supported by the first station.

[0010] In one embodiment, the information indicating the set of PE parameters is an information element that indicates, for each possible PE parameter, whether the PE parameter belongs to the set of PE parameters that corresponds to the requested privacy level.

[0011] In one embodiment, the information indicating the set of PE parameters is an information element including at least one privacy profile, the privacy profile corresponding to the set of PE parameters, and whether the privacy profile corresponds to the requested privacy level.

[0012] In one embodiment, the message further comprises a privacy alignment indication indicating whether the requested privacy level should be applied to stations belonging to a group of stations connected to the AP station. In one embodiment, the group of stations connected to the AP station includes all stations connected to the AP station.

[0013] In one embodiment, the first station is a non-AP station, and the message is a management frame transmitted during association of the non-AP station, and the method further comprises: Receiving a message from the AP station indicating denial of association when the AP does not accept the requested privacy level.

[0014] In one embodiment, The first station is a non-AP station, The indication of privacy alignment indicates that the requested privacy level should be applied to a group of stations, and the method includes, by the AP station: It further includes broadcasting a message to all stations in the group of stations requesting the requested privacy level.

[0015] In one embodiment, the method comprises the steps of: The method further includes denying association of the first station when at least one station of the group of stations cannot meet the requested privacy level.

[0016] In an embodiment, the method includes, by an AP station: deassociating stations within the group of stations that are unable to meet the requested privacy level; and accepting the association of the first station.

[0017] In one embodiment, The first station is an AP station The message is an action frame.

[0018] In one embodiment, the method comprises: The method further includes deassociating the second station if the requested privacy level cannot be met.

[0019] According to another aspect of the present invention, there is provided a method for managing privacy levels in a wireless network comprising an access point, an AP, a station, and at least one non-AP station, the method comprising: The method includes sending a message to another station that includes information indicating a set of privacy-enhancing (PE) parameters supported by the station.

[0020] According to another aspect of the present invention, there is provided a computer program product for a programmable device, the computer program product comprising sequences of instructions for performing the method according to the present invention when the computer program product is loaded and executed on the programmable device.

[0021] According to another aspect of the invention, there is provided a computer readable storage medium storing computer program instructions for carrying out a method according to the invention.

[0022] According to another aspect of the invention there is provided a computer program product which when executed causes the method of the invention to be carried out.

[0023] According to another aspect of the present invention, there is provided a first station device for managing a privacy level for communicating with a second station in a wireless network comprising an access point (AP) station and a non-AP station, the first station device being a non-AP station or an AP station, the first station device comprising: a processor; sending a message to a second station including information indicating a set of privacy-enhancing (PE) parameters to be obfuscated, the set of PE parameters corresponding to a privacy level requested by the first station; A processor configured to receive a response from the second station indicating whether the second station accepts the requested privacy level.

[0024] According to another aspect of the present invention, there is provided a station device for managing a privacy level in a wireless network comprising an access point (AP), a station, and at least one non-AP station, the station device being either a non-AP station or an AP station, the station device comprising: a processor; The system includes a processor configured to send a message to another station that includes information indicating a set of privacy-enhancing (PE) parameters supported by the station.

[0025] According to another aspect of the present invention, there is provided a privacy information element inserted into a message for managing a privacy level in a wireless network comprising an access point (AP), a station, and at least one non-AP station, the privacy information element comprising: A privacy information element is provided that contains information indicating a privacy enhancement (PE) to be obfuscated and / or a set of parameters to be supported by the station.

[0026] In one embodiment, the privacy information element comprises, for each PE parameter: a capabilities field indicating whether PE parameters are supported; and an enablement file indicating whether PE parameters are obfuscated.

[0027] In one embodiment, the privacy information element includes a profile identifier, the profile corresponding to a set of PE parameters, and the privacy information element includes, for the profile: a capabilities field indicating whether PE parameters are supported; and an enablement file indicating whether PE parameters are obfuscated.

[0028] According to another aspect of the present invention, there is provided a privacy information element inserted into a message for managing a privacy level in a wireless network comprising an access point (AP), a station, and at least one non-AP station, the privacy information element comprising: A privacy information element is provided that includes a set of PE parameters and a profile identifier for defining a profile corresponding to the set of PE parameters.

[0029] At least part of the methods according to the present invention may be computer-implemented. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects, all of which may be generally referred to herein as a "circuit," "module," or "system." Furthermore, the present invention may take the form of a computer program product embodied in any tangible medium of expression having computer-usable program code embodied in the medium.

[0030] Since the present invention can be implemented in software, the present invention can be embodied as computer readable code for provision to a programmable apparatus on any suitable carrier medium. A tangible, non-transitory carrier medium may comprise a storage medium such as a floppy disk, a CD-ROM, a hard disk drive, a magnetic tape device, or a solid-state memory device. A transient carrier medium may include a signal such as an electric, electronic, optical, acoustic, magnetic, or electromagnetic signal, e.g., a microwave or RF signal. [Brief explanation of the drawings]

[0031] Embodiments of the present invention will now be described, by way of example only, with reference to the following drawings: [Figure 1] FIG. 1 illustrates an example of a network system in which embodiments of the present invention may be used. [Figure 2a] FIG. 2a illustrates a frame format characterizing PE parameters according to an embodiment of the present invention. [Figure 2b] FIG. 2b illustrates a frame format characterizing PE parameters according to an embodiment of the present invention. [Figure 2c] FIG. 2c illustrates a frame format characterizing PE parameters according to an embodiment of the present invention. [Figure 2d]FIG. 2d illustrates a frame format characterizing PE parameters according to an embodiment of the present invention. [Figure 3a] FIG. 3a shows the main steps of a method for operating an association procedure including privacy functionality according to an embodiment of the invention. [Figure 3b] FIG. 3b shows the main steps of a method for operating an association procedure including privacy functionality according to an embodiment of the invention. [Figure 3c] FIG. 3c shows a table illustrating error return codes associated with an association procedure including privacy features according to an embodiment of the present invention. [Figure 4] FIG. 4 shows a frame format that characterizes an action frame. [Figure 5a] FIG. 5a shows the main steps of a method for operating a method for changing privacy levels by a non-AP STA according to an embodiment of the present invention. [Figure 5b] FIG. 5b shows the main steps of a method for operating a method for changing privacy levels by a non-AP STA according to an embodiment of the present invention. [Figure 6] FIG. 6 shows the main steps for operating a method for changing the privacy level by an AP in an embodiment of the present invention. [Figure 7] 1 illustrates an example of a communication device of a wireless network configured to implement at least one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0032] In this embodiment, the present invention proposes a global procedure for sharing PE parameters between non-AP STAs and APs during the association procedure. According to the embodiment, a station, either an AP or a non-AP, can request a change in privacy level after association. In this embodiment, a station, either an AP or a non-AP, can request that the entire BSS or a group of stations within the BSS adopt a certain level of privacy.

[0033] These procedures allow agreement between the AP and non-AP stations on a set of PE parameters to be applied, which corresponds to a level of privacy that may be requested by the non-AP station or the AP station.

[0034] In this specification, a station, either an AP or a non-AP, is said to support a PE parameter if the station can apply an obfuscation procedure to this PE parameter. A PE parameter is said to be enabled when an obfuscation procedure is activated by the station for this parameter. For example, an AP station is said to support a PE parameter corresponding to the AP station's MAC address if the AP station can process obfuscation of its MAC address.

[0035] Similarly, a station (either an AP or a non-AP) is said to support a PE parameter of another station when the station is capable of processing the obfuscation procedure of this parameter applied by the other station. For example, an AP station is said to support a PE parameter corresponding to a MAC address of a non-AP station when the AP station can process the obfuscation of the MAC address of the non-AP station applied by the non-AP station.

[0036] The AP and non-AP stations associated with the AP need to agree on a set of PE parameters to be used in their communications. The AP and non-AP stations can initially share their capabilities during the association phase, e.g., regarding supported PE parameters. The result of the sharing can be agreement on a set of PE parameters supported by both the AP and the non-AP station. The result can also be a lack of support for a common set of PE parameters. Note that a non-AP station can still associate with the AP as long as the AP does not require enablement of PE parameters not supported by the station (i.e., the station cannot process). The AP and non-AP station can secondarily negotiate the PE parameters to be enabled for communication, either during the association phase or while the two stations are already associated.

[0037] The IEEE 802.11bi task group specified two sets of PE capabilities. The first, called the Client Privacy Extension (CPE) feature set, prevents client (non-AP STA) identification and tracking. The second, called the BSS Privacy Enhancement (BPE) feature set, prevents BSS identification and tracking. From these, a CPE-enabled AP is called a CPE AP, and a CPE-enabled non-AP STA is called a CPE non-AP STA or CPE client. Similarly, a BPE-enabled AP is called a BPE AP, and a BPE-enabled non-AP STA is called a BPE non-AP STA or BPE client.

[0038] Typically, a CPE function is initiated by a CPE client, referred to as initiating the CPE client, and initiated by a BPE AP. The CPE function includes simultaneous obfuscation of multiple PE parameters, referred to as CPE parameters. Similarly, the BPE function includes simultaneous obfuscation of multiple PE parameters, referred to as BPE parameters. In this manner, each PE parameter is obfuscated by either a non-AP station or an AP station according to a dedicated obfuscation procedure associated with that PE parameter. This obfuscation procedure typically implies random modification of the parameter, but may vary depending on the nature of the PE parameter.

[0039] In this specification, PE parameters refer opaquely to CPE parameters and / or BPE parameters. The details of the obfuscation procedures associated with each PE parameter are outside the scope of this document.

[0040] By way of example, the CPE parameters currently identified by the IEEE 802.11bi task group are as follows:

[0041] The MAC address of a CPE client for over-the-air (OTA) communication is called the OTA MAC address and is indicated in either the Transmitter Address (TA) or Receiver Address (RA) field of the IEEE 802.11 frame (corresponding to address 2 or 3). Optionally, a CPE client can have several OTA MAC addresses, each used for a given purpose (data, measurement, etc.). The device's MAC address, or EUI-48 address, is an EUI (Extended Unique Identifier) ​​consisting of 48 bits. It can be universally or locally administered. Universally administered addresses are uniquely assigned to devices by their manufacturers. Locally administered addresses are assigned to devices by software or network administrators, replacing physically burned-in addresses. The second-least significant bit of the first octet of the MAC address, i.e., the seventh bit of the address, also called the "U / L bit" (for "universal / local bit"), indicates whether it is universally administered (when set to 0) or locally administered (when set to 1). The least significant bit of the first octet of a MAC address, i.e., the eighth bit of the address, also called the "i / G bit" (for "individual / group bit"), indicates whether the frame is being sent to only one receiving device (when set to 0, indicating a unicast transmission) or to multiple devices (when set to 1, indicating a multicast transmission).

[0042] The sequence number (SN) contained in the Sequence Number field of the Sequence Control field of the MAC header of an 802.11 frame (MSDU, A-MSDU, or MMPDU). This is a 12-bit field. The sequence number is incremented for each frame transmission and remains constant for frame retransmissions.

[0043] The packet number (PN) contained in the Packet Number field of the CCMP header in the plaintext MAC payload of the frame. This is a 48-bit packet number. It is used for frame encryption and allows for unique identification of the frame being transmitted for replay detection. The packet number is incremented with each frame transmission and remains constant for frame retransmissions.

[0044] Association Identifier AID (AID), a unique identifier assigned by the AP to the non-AP during association. It is a 16-bit field and is included in many frames for different uses, such as power saving or resource allocation in MU OFDMA.

[0045] Scrambler Seed (Section 802.11-2020-17.3.5.5) corresponds to the seed used by the PLCP / OFDM PHY DATA scrambler to initialize its initial state. This corresponds to a 7-bit parameter.

[0046] The BPE parameters are the same as the CPE parameters for a BPE client. For a BPE AP, the IEEE 802.11bi task group is identified as follows:

[0047] The OTA MAC address of the BPE AP indicated in either the Transmitter Address (TA) or Receiver Address (RA) field of the IEEE 802.11 frame, corresponding to address 2 or 3. Optionally, the BPE AP can have several OTA MAC addresses, each used for a given purpose (data, measurements...).

[0048] Scrambler Seed (802.11-2020 - Section 17.3.5.5) corresponds to the seed used by the PLCP / OFDM PHY DATA scrambler to initialize its initial state. This corresponds to a 7-bit parameter.

[0049] The Beacon Interval corresponds to the difference between two Target Beacon Transmission Times (TBTT), which is the time at which an AP should transmit its beacon frame. The Beacon Interval is given in Time Units (TU), where a TU is equal to 1024 microseconds. It is a 16-bit field set to the number of TUs between beacon transmissions and is included in the Beacon Interval field of the beacon frame.

[0050] Obviously, the above list of CPE / BPE parameters is not exhaustive, and other CPE / BPE parameters can be considered. For example, the BSS color introduced by the IEEE 802.11ax task group, which is used to identify the BSS, can also be considered as a BPE parameter. It is included in the BSS Color field of the BSS Color information of the HE Action element included in the beacon, probe response, and (Re)association frame. This is a 6-bit parameter.

[0051] FIG. 1 illustrates an 802.11 network (i.e., Wi-Fi network) system 100 that includes four wireless devices: an access point (AP) 110 and three non-AP stations (non-AP STAs) 120a, 120b, and 120c. Of course, the number of non-AP STAs 120a, 120b, and 120c may be different from three. The AP 110 provides wireless connectivity between the non-AP STAs 120a, 120b, and 120c and a wider network, such as the Internet. The connection of the non-AP STAs 120a, 120b, and 120c to the AP 110 is performed through a standardized process called association. Once the non-AP STAs 120a, 120b, and 120c are associated with the AP 110, the non-AP STAs 120a, 120b, and 120c can transmit data to and receive data from the network via the AP 110.

[0052] The AP 110 may comprise, be implemented as, or be known as a Node B, radio network controller (RNC), evolved Node B (eNB), 5G next-generation base station (gNB), base station controller (BSC), base transceiver station (BTS), base station (BS), transceiver function (TF), wireless router, wireless transceiver, basic service set (BSS), enhanced service set (ESS), radio base station (RBS), or some other terminology. It may be a standalone product or may be integrated into a device, such as a broadband remote access server (BRAS).

[0053] The non-AP STAs 120a, 120b, 120c may comprise, be implemented as, or be known as subscriber stations, subscriber devices, mobile stations (MS), remote stations, remote terminals, user terminals (UTs), user agents, user devices, user equipment (UEs), user stations, or some other terminology. In some implementations, the non-AP STAs 120a, 120b, 120c may be or comprise cellular telephones, cordless telephones, Session Initiation Protocol (SIP) telephones, wireless local loop (WLL) stations, personal digital assistants (PDAs), mobile devices with wireless connectivity, or some other suitable processing device connected to a wireless modem. Accordingly, one or more aspects taught herein may be incorporated into a telephone (e.g., a cell phone or smartphone), a computer (e.g., a laptop), a tablet, a portable communication device, a portable computing device (e.g., a personal data assistant), an entertainment device (e.g., a music or video device, or a satellite radio), a Global Positioning System (GPS) device, or any other suitable device configured to communicate via a wireless or wired medium. In some aspects, the non-AP STAs 120a, 120b, 120c may be wireless nodes. Such wireless nodes may, for example, provide connectivity for or to a network (e.g., a wide area network such as the Internet or a cellular network) via a wired or wireless communication link.

[0054] The AP 110 manages a set of STAs that collectively organize their access to the wireless medium for communication purposes. All STAs, the AP 110, and the non-AP STAs 120a, 120b, and 120c form a service set that may be referred to as a basic service set (BSSS), although other terminology may be used. Note that the AP 110 may manage more than one BSS; thus, each BSS is uniquely identified by a specific basic service set identifier (BSSID) and is managed by a separate virtual AP implemented in the physical AP 110.

[0055] To ensure user privacy, the AP STA 110 and non-AP STAs 120a, 120b, and 120c are configured with dot11MACPrivacyActivated set to true. This is a Management Information Base (MIB) variable controllable by an external management entity that defines whether non-AP STAs can apply certain mechanisms for enforcing privacy at the MAC level, including RCM procedures, when the variable is set to true, or whether they cannot apply them when the variable is set to false.

[0056] According to some embodiments of the present invention, the AP STA 110 is a CPE AP and the non-AP STAs 120a, 120b, 120c are CPE clients. According to other embodiments of the present invention, the AP STA 110 is a BPE AP and the non-AP STAs 120a, 120b, 120c are BPE clients. According to other embodiments, the AP STA 110 is both a CPE and a BPE AP and the non-AP STAs 120a, 120b, 120c are both CPE and BPE clients.

[0057] 2a, 2b, 2c, and 2d illustrate frame formats characterizing privacy parameters according to embodiments of the present invention.

[0058] 2a shows an information element (IE) dedicated to the management of all privacy extension (PE) parameters, in one embodiment, either CPE or BPE. The information element (IE) can be included in any management frame, such as a frame used during the association procedure. The privacy IE 200 allows defining the state of each PE parameter, taking into account the capabilities of the station that processes this PE parameter and its enablement state, which indicates whether obfuscation for this PE parameter is activated or not.

[0059] Privacy IE200 consists of: Element ID 201 for identifying an information element, A Length field 202 that defines the length of the information element; an element ID extension field 203 identifying the extension information element; A Privacy Alignment field 210 that a non-AP STA can use to request that the AP enforce support of at least the same PE parameters for all other associated non-AP STAs; Each privacy field 220, 221, 222, 223 defines the state of a PE parameter, e.g., OTA MAC address, sequence number, packet number, scrambler seed, and any other PE parameters, respectively. As shown in Figure 2c, the state of the PE parameters is - "Capability" field set to 1 when the non-AP STA or AP supports PE parameters, 0 otherwise.

[0060] An "Enable" field that is set to 1 when a non-AP STA or AP requests or confirms PE parameter obfuscation, otherwise 0. In some embodiments, a 0 value may be used to request or confirm the stopping of obfuscation when obfuscation is already activated.

[0061] FIG. 2b shows another embodiment of the Privacy IE 230. In this embodiment, the Privacy fields 220, 221, 222, and 223, which describe the status of a single PE parameter, are replaced by Privacy Profile fields 231, 232, and 233. Each Privacy Profile field is associated with a privacy profile corresponding to a set of PE parameters. The privacy profiles can be predefined or dynamically defined, as described in more detail below with respect to FIG. 2d. This embodiment is particularly useful in the WiFi Alliance, which often specifies predefined profiles for STAs. This allows for the management of a given set of PE parameters corresponding to a profile at once. Therefore, this embodiment is more compact than the first embodiment of FIG. 2a, in which each PE parameter is typically treated independently. This embodiment allows for the definition of several privacy profiles, thereby reducing the overhead of the previous embodiment. The Privacy Profile fields are composed of the same subfields shown in FIG. 2c to manage the capabilities and activation status of the privacy profiles. A station is said to support a profile when the station can handle obfuscation of all PE parameters in the set of PE parameters corresponding to the profile. A station is said to have enabled a profile when obfuscation of all PE parameters in the profile is enabled, meaning that obfuscation of all PE parameters in the profile is activated.

[0062] Figure 2d shows one embodiment of information elements (IEs) dedicated to the definition of a Privacy Profile. The Privacy Profile Set IE 250 defines which PE parameters 270, 271, 272, 273, 274, 275, and 276 are included in the profile and associates this set of PE parameters with a profile number (or identifier) ​​260. This IE can be included in any management or action frame as any information element defined in the 802.11 standard. Management frames are frames used to manage the BSS. Action frames are management frames that trigger the occurrence of an action. An AP can use these Privacy Profile Set IEs 250 to advertise the valid privacy profiles of the BSS to all associated non-AP STAs. The validated privacy profiles can then be used by the AP to manage the set of validated privacy profiles, for example, using the information elements shown in Figure 2b. These information elements 2b and 2d enable the definition and use of arbitrary profiles beyond the predefined ones.

[0063] Figures 3a and 3b show the main steps of a method for operating an association procedure implying privacy features in an embodiment of the present invention. This method gives an example of the use of the information elements described with respect to Figures 2a to 2d. The association procedure can be used by the AP and the STA to share their capabilities and to find agreement on the enabled features of each part.

[0064] The association comprises three main parts illustrated by Figures 3a and 3b: a probe transmission / reception, an authentication transmission / reception, and an association transmission / reception.

[0065] In step 300, a probe transmission / reception begins when a STA sends a probe request containing a set of IEs that characterize itself and ask for some properties of the AP. The probe transmission / reception allows the STA to scan neighboring BSSs and their capabilities. In step 360, a probe response sent by the AP provides essential characteristics of the BSS driven by the AP.

[0066] In step 350, the AP receives a probe request from a non-AP station. In step 360, the AP sends a probe response to the non-AP station. In step 310, the non-AP station receives a probe response from the AP. These transmissions and receptions are called probe transmissions and receptions. The probe transmissions and receptions allow the STA to scan neighboring BSSs and their capabilities. These capabilities may include capabilities related to privacy management. The probe response sent by the AP in step 360 provides essential properties of the BSS driven by the AP. It may include the PE parameter policy of the BSS.

[0067] Authentication transmission and reception is a transmission and reception during which the STA and the AP transmit and receive their identities at a mutually acceptable level. These transmissions and receptions include transmitting an authentication request in step 320. In step 370, the authentication request is received by the AP. The AP transmits an authentication response in step 380. This authentication is received by the non-AP station in step 330. For example, some parameters such as encryption keys may be transmitted and received during this phase during steps 320, 330, 370, and 380. In some embodiments, information elements related to privacy management may be included in frames transmitted and received during authentication.

[0068] The association transmission / reception is the final stage of the association procedure when the AP verifies the STA's membership in the BSS. Association begins with the STA sending an association request to the AP in step 340. The association request is received by the AP in step 390. The AP sends an authentication response to the non-AP station in step 391. The association response is received by the non-AP station in step 341. The AP responds with an association response 341, 391. If the station is authorized, the association response is provided with an association status error code set to the value 0, indicating successful association. If the station is not authorized, the association response is provided with an association status error code set to a non-zero value. The association status error code may indicate the reason for the AP's disapproval of the non-AP station. In some embodiments, the association request and response frames include a set of IEs that characterize the STA's own PE parameters and request certain properties of the PE parameters and / or AP, as shown in steps 340, 341, 390, and 391. Therefore, association state error codes may be related to privacy management. Capability transmissions and receptions are determined at this stage, and the AP informs the STA of certain parameters within the BSS. In some embodiments, information elements related to privacy management may be included in frames transmitted and received during association.

[0069] Probe request / response frames, authentication request / response frames, and association request / response frames are management frames. Therefore, they can contain different information elements, including information elements related to privacy management. Therefore, any type of privacy IE described in Figures 2a, 2b, and 2c can be transmitted and received between a STA and an AP during an association procedure. In one embodiment shown in Figures 3a and 3b, a privacy information element is transmitted and received during an association transmission and reception. A STA can transmit an association request with a privacy information element that characterizes the state of PE parameters supported by the STA (which means "can be handled or obfuscated").

[0070] As shown in FIG. 2c, the state of a PE parameter is divided into two parts: a capability field 240, which means the STA can support obfuscation of the corresponding PE parameter, and an enablement field 241, which means the STA requests that obfuscation of the corresponding PE parameter be enabled. The privacy information element of an association request frame can include some privacy fields with the capability field set to 1 and the capability field set to 0, and some other privacy fields with the capability field set to 1 and the capability field set to 1. When a STA sends a privacy information element containing a privacy field with the capability field set to 1 and the enablement field set to 0, it means that the STA notifies the AP that the corresponding PE parameter is supported by the STA but is not asked to be enabled at the time of transmission. When a STA sends a privacy information element containing a privacy field with the capability field set to 1 and the enablement field set to 1, it means that the STA asks the AP that the corresponding PE parameter should be obfuscated. A capability field set to 0 means that the station is not capable of handling parameter obfuscation. Note that if the capability field is set to 0 and the enable field is set to 1, this should not occur, as the station should not require obfuscation of PE parameters if it cannot handle this obfuscation.

[0071] When all enable fields are set to 0, the message corresponds to a simple signaling of the station's capacity for privacy without requesting any level of privacy. This only signaling message does not require a response by other stations.

[0072] When a station signals its capabilities regarding supported PE parameters, all supported PE parameters are typically signaled. In some embodiments, a station may signal only a portion of its capabilities. For example, when responding to a message by a station signaling its supported PE parameters, the AP may signal only its supported PE parameters within the group of PE parameters supported by the station.

[0073] In one embodiment, the capabilities field is implicit. In this case, the state shown in FIG. 2 includes only the enable field. In this embodiment, the station does not advertise its full capabilities to the other. The request to enable a PE parameter is made without knowledge of its support by the other. If the other does not support a PE parameter for which obfuscation is requested, it can send a response with the enable field set to 0 for this parameter (or any other type of signaling). This response corresponds to a refusal to obfuscate the PE parameter.

[0074] According to an embodiment, when one side refuses to obfuscate the PE parameters requested by the other side, the station may abandon the association process or disassociate itself from the BSS if the BSS is already associated. In some cases, the AP may also refuse association or deassociate the station if it was already associated.

[0075] In response, the AP sends an Association Response frame that can be applied by the STA and may include a Privacy IE to specify valid or invalid PE parameters. The list of PE parameters requested to be enabled by the STA may differ from the list of PE parameters sent by the AP in the Association Response frame. Some PE parameters that are only signaled as supported by the STA may be later enabled by the AP when the AP requests, for example, to increase the privacy level.

[0076] If the privacy adjustment field 210 is set to 1 in an information element sent by the AP, it means that the BSS is subject to a uniform privacy policy in which the provided PE parameters apply to all other associated STAs. In another embodiment, it means that the provided PE parameters apply to a predefined group of STAs. In this case, the privacy policy is applied uniformly to the group of STAs, rather than to the entire BSS.

[0077] When the privacy adjustment file 210 is set to 1 in an information element sent by a non-AP station, it means that the station requests the application of a group uniform policy defined by the AP in the BSS, or alternatively, in some embodiments, in a group of stations.

[0078] When a non-AP station requires a uniform level of privacy that applies to all stations in the BSS, the AP broadcasts this requirement to all associated non-AP stations. When some connected non-AP stations cannot meet the requested level of privacy, the AP may decide to disassociate these non-AP stations. Alternatively, in another embodiment, the AP may decide to deny association of non-AP stations requiring a level of privacy and retain already associated stations.

[0079] FIG. 3c shows a table of association status error codes used in one embodiment of the present invention.

[0080] If the association status error code in the association response is set to 0, indicating a state called SUCCESS, the STA's privacy level is acceptable to the AP.

[0081] If the Association Status Error Code in the Association Response is set to REFUSED_REASON_LOW_PRIVACY (e.g., value 131), the association procedure fails and the STA must resend another Association Request with a Privacy IE containing other PE parameters. In this case, the Association Response does not contain an indication of the PE parameters that may be allowed by the AP.

[0082] If the Association Status Error Code in the Association Response is set to REFUSED_WITH_SUGGESTED_HIGHER_PRIVACY (e.g., value 132), the AP includes a Privacy IE corresponding to the proposed PU parameters in the Association Response. To verify its membership in the BSS, the STA must retransmit another Association Request frame with a Privacy IE with the proposed PE parameters.

[0083] If the association status error code in the association response is set to REFUSED_WITH_SUGGESTED_OTHER_BSS (e.g., value 133), the AP suggests to the STA to perform another association procedure in another BSS linked to the AP, e.g., in a multilink environment, the linked BSS is announced in a multilink information element.

[0084] 4 shows a privacy action frame 400 that may be used in transmissions between an AP and a non-AP station. This privacy action frame 400 consists of: The Category field 410 is set to a predetermined value. This value may be defined as a new value for the Privacy Action frame added in the 802.11-2020 specification, such as value 37. An action field 420 that can be set to the value 0 to indicate a request and to the value 1 to indicate a response The field 430 can contain one or several privacy information elements. These information elements can be used to indicate a set of PE parameters, such as an updated set of PE parameters requested by the station's upper layers.

[0085] This privacy action frame is typically used in transmissions between an already associated non-AP station and an AP station to change the level of privacy of the communication.

[0086] 5a and 5b show the main steps of a method for operating a method for changing a privacy level by a non-AP STA in one embodiment of the present invention. This method aims to modify the level of privacy, which means the set of enabled PE parameters, between the non-AP station and the AP station. It is assumed that the non-AP station is already associated with a BSS controlled by the AP. Therefore, an initial level of privacy is already used between the non-AP station and the AP station.

[0087] A change in privacy level may be requested by a non-AP station, for example, as a requirement of an application running on the non-AP station. This is the case illustrated by Figures 5a and 5b. In some cases, the AP may be the station requesting the change, as will be described in more detail in connection with Figure 6.

[0088] When a STA associates with a BSS, the AP verifies the set of PE parameters enabled during the association procedure. The STA is linked to upper layers used to manage user applications. If some user applications require, for example, a higher privacy level, the STA receives a request to increase the privacy level from the upper layers in step 500. The STA then transmits a privacy action frame, for example, the action frame 400 described with reference to FIG. 4, to the AP.

[0089] Upon receiving the Privacy Request Action frame in step 511, the AP either accepts or rejects the new set of PE parameters. The AP responds to the received request by sending a Privacy Action frame in step 540. This Privacy Response Action frame contains the set of PE parameters that will be applied going forward. If the AP accepts the request, the set of PE parameters in the Privacy Response Action frame corresponds to the set of PE parameters requested by the non-AP station. If the AP rejects the request, the set of PE parameters in the Privacy Response Action frame corresponds to the previous set used before the request and will continue to be applied.

[0090] In step 520, it is tested whether the privacy request action frame includes a privacy IE with the privacy alignment field 210 set to 1. If the test is true, it means that the STA requests that the privacy level requested by the STA be applied to all STAs in the BSS, or alternatively, in some embodiments, a group of STAs within the BSS. In that case, the AP must request that all STAs in the BSS or in a group of STAs within the BSS change their corresponding privacy levels. This can be done in step 530 by having the AP broadcast the privacy request action frame to all other associated STAs.

[0091] In another embodiment, a privacy request action frame is broadcast by the AP to a group of STAs predefined by the AP, and if the STA responds with a privacy response action frame that rejects the privacy level upgrade, the AP deassociates the STA from the BSS.

[0092] Figure 6 shows the main steps of a method for changing a privacy level by an AP in one embodiment of the present invention. In step 600, a request to change the privacy level can be received from an upper layer on the AP side. A privacy request action frame containing a set of PE parameters is transmitted by the AP in step 610. Similar to the method described in connection with Figures 5a and 5b, if the station accepts the request, a privacy response action frame is transmitted by the requested non-AP STA. The set of PE parameters in the privacy response action frame is the new set of PE parameters requested by the AP. If the station rejects the privacy level change, the previous set of PE parameters that continues to be used is transmitted.

[0093] A change in privacy level requested by higher layers of the AP may concern all non-AP stations in the BSS, or at least a group of non-AP stations in the BSS. Thus, a request to change the privacy level may be broadcast to all stations or may be directed to a group of stations.

[0094] In some embodiments, when a station fails to respond affirmatively to a request, the AP decides to deassociate the station.

[0095] The methods described with respect to Figures 3, 5a, 5b, and 6 are merely examples of privacy management methods. In particular, the information elements and action frames described with respect to Figures 2a, 2b, 2c, 2d, and 4 can be used to implement any privacy policy in a BSS. The level of privacy and associated privacy policy can be requested by either the AP or any non-AP station connected to the AP.

[0096] In some embodiments, an AP requires that a uniform level of privacy be applied to a BSS, in which case non-AP stations that cannot meet the required level of privacy are not accepted during the association phase or are not disassociated if already associated.

[0097] In some embodiments, the AP can group non-AP stations according to any criteria. For example, stations can be grouped according to their capabilities, which may correspond to the generation of the standard or the technology implemented in the station (e.g., High-Efficiency, HE, Very High Throughput, EHT, etc.). In other embodiments, a group of stations can be composed of stations identified as exhibiting coherent movement. This can be the case, for example, for embedded devices such as a user's phone, a user's headset, and a device carried by a user as a connected watch, all connected to the same AP. The AP can also group stations identified as not moving in a first group and stations identified as moving in a second group.

[0098] An AP may create different groups of stations and require a uniform level of privacy within each group. Alternatively, the AP may decide to manage virtual BSSs, one for each group of stations. In that case, a uniform level of privacy may be applied to each virtual BSS managed by the AP.

[0099] 7 shows an example of a communication device 700 of a wireless network, typically one of the stations of FIG. 1, configured to implement at least one embodiment of the present invention. The communication device 700 may preferably be a device such as a microcomputer, a workstation, or a light portable device. The communication device 700 may comprise a communication bus 705 to which the following may be connected:

[0100] - a central processing unit 701, such as a processor called a CPU a memory 703, denoted MEM, for storing executable code of the method or steps of the method according to an embodiment of the invention, as well as registers adapted to record variables and parameters necessary to carry out the method; at least two communication interfaces 702 and 702' connected to a wireless communication network, for example a communication network according to one of the IEEE 802.11 family of standards, via transmit and receive antennas 704 and 704' respectively;

[0101] Preferably, a communications bus 705 may provide communication and interconnectivity between various elements included in or connected to communications device 700. The representation of a bus is not limiting, in particular a central processing unit may be operable to communicate instructions to any element of communications device 700 directly or by another element of communications device 700.

[0102] The executable code may be stored in a memory which may be read-only, either a hard disk or a removable digital medium such as a disk. According to an optional variant, the executable code of the program may be received by the communications network, via the interface 702 or 702', in order to be stored in the memory 703 of the communications device 700 and then executed.

[0103] In one embodiment, device 700 may be a programmable apparatus that uses software to implement embodiments of the present invention. However, alternatively, embodiments of the present invention may be implemented wholly or partly in hardware (e.g., in the form of an application specific integrated circuit or ASIC).

[0104] Any step of an algorithm of the present invention may be implemented in software by execution of a set of instructions or programs by a programmable computing machine such as a PC ("personal computer"), a DSP ("digital signal processor") or a microcontroller, or in hardware by a machine or dedicated component such as an FPGA ("field programmable gate array") or an ASIC ("application specific integrated circuit").

[0105] Although the present invention has been described with reference to particular embodiments, the present invention is not limited to those embodiments and modifications will be apparent to those skilled in the art that are within the scope of the present invention.

[0106] Many further modifications and variations will be suggested to those skilled in the art by reference to the exemplary embodiments described above, which are not intended to limit the scope of the invention, which is determined solely by the appended claims. In particular, different features from the various embodiments can be exchanged as desired.

[0107] Each of the above-described embodiments of the present invention can be practiced alone or in combination with other embodiments, and features from various embodiments can be combined as needed or where a combination of elements or features from the individual embodiments in a single embodiment is beneficial.

[0108] In the claims, the word "comprising" does not exclude other elements or steps, and the indefinite article "a" or "an" does not exclude a plurality. The mere fact that different features are recited in mutually different dependent claims does not indicate that a combination of these features cannot be used to advantage.

Claims

1. 1. A method for managing privacy levels in a wireless network comprising an access point (AP) station and at least one non-AP station, comprising: by a first station, which may be either a non-AP station or an AP station, sending a message to a second station including information indicating a set of Privacy Enhancement (PE) parameters to be obfuscated, the set of PE parameters corresponding to a privacy level requested by the first station; receiving a response from the second station indicating whether the second station accepts the requested privacy level; A method comprising:

2. The method of claim 1 , wherein the message further includes an indication of the PE parameters supported by the first station.

3. 2. The method of claim 1, wherein the information indicating the set of PE parameters is an information element including, for each possible PE parameter, an indication of whether the PE parameter belongs to the set of PE parameters corresponding to the requested privacy level.

4. 2. The method of claim 1, wherein the information indicating a set of PE parameters is an information element including at least one privacy profile, the privacy profile corresponding to the set of PE parameters, and the privacy profile corresponding to the requested privacy level.

5. 2. The method of claim 1, wherein the message further includes a privacy alignment indication indicating whether the requested privacy level should be applied to stations belonging to a group of stations connected to the AP station.

6. The method of claim 5 , wherein the group of stations connected to the AP station includes all stations connected to the AP station.

7. The method of claim 5, wherein the first station is a non-AP station, and the message is a management frame transmitted during association of the non-AP station, the method further comprising: If the AP does not accept the requested privacy level, receiving a message from the AP station indicating a denial of association.

8. 6. The method of claim 5, the first station is a non-AP station; the indication of privacy alignment indicates that the requested privacy level should be applied to the group of stations; The method includes the steps of: The method further comprising broadcasting a message requesting the requested privacy level to all stations in the group of stations.

9. 8. The method of claim 7, wherein the AP station: The method further comprising: denying the association of the first station if at least one station of the group of stations cannot meet the requested privacy level.

10. 8. The method of claim 7, wherein the AP station: disassociating the stations in the group of stations that are unable to meet the requested privacy level; accepting the association of the first station; The method further comprises:

11. The method of claim 1, the first station is an AP station; The method, wherein the message is an action frame.

12. 11. The method of claim 10, The method further comprising disassociating the second station if the requested privacy level cannot be met.

13. 1. A method for managing privacy levels in a wireless network comprising an access point (AP) station and at least one non-AP station, the method comprising: sending a message to another station including information indicating a set of privacy-enhancing (PE) parameters supported by said station; A method comprising:

14. A computer program product for a programmable device, comprising a set of instructions for carrying out the method of any one of claims 1 to 13 when deployed and executed by said programmable device.

15. A computer readable storage medium having stored thereon computer program instructions for carrying out the method of any one of claims 1 to 13.

16. A computer program which, when executed, causes the computer to carry out the method of any one of claims 1 to 13.

17. A first station device for managing a privacy level for communicating with a second station in a wireless network comprising an access point (AP) station and a non-AP station, the first station device being the non-AP station or the AP station, the first station device comprising: a processor; sending a message to the second station including information indicating a set of privacy-enhancing (PE) parameters to be obfuscated, the set of PE parameters corresponding to a privacy level requested by the first station device; receiving a response from the second station indicating whether the second station accepts the requested privacy level; a first station device comprising a processor configured to:

18. 1. A station device for managing a privacy level in a wireless network including an access point (AP) station and at least one non-AP station, the station device being either a non-AP station or the AP station, the station device comprising: a processor; Sending a message to another station containing information indicating the set of privacy enhancement (PE) parameters supported by that station 23. A station device comprising: a processor configured to:

19. A privacy information element inserted into a message for managing a privacy level in a wireless network comprising an access point (AP) station and at least one non-AP station, the privacy information element comprising: The privacy information element includes information indicating a set of privacy-enhancing (PE) parameters to be obfuscated and / or supported by a station.

20. 20. The privacy information element of claim 19, wherein the privacy information element comprises: a capability field indicating whether the PE parameters are supported; an enable field indicating whether the PE parameters are obfuscated; A privacy information element that contains, for each PE parameter, a state including:

21. 20. The privacy information element of claim 19, wherein the privacy information element includes a profile identifier, the profile corresponding to a set of PE parameters, and the privacy information element includes, for the profile: a capability field indicating whether the PE parameters are supported; an enable field indicating whether the PE parameters are obfuscated; A privacy information element containing a state including:

22. A privacy information element inserted into a message for managing a privacy level in a wireless network comprising an access point (AP) station and at least one non-AP station, the privacy information element comprising: The privacy information element includes a set of privacy-enhancing (PE) parameters and a profile identifier for defining a profile corresponding to the set of PE parameters.