Dynamic MAC address change mechanism for wireless communication

The dynamic MAC address change mechanism in wireless communication systems addresses privacy concerns by using dual MAC address modes for encryption and authentication, ensuring continuous service functionality and user privacy.

JP7862124B2Active Publication Date: 2026-05-19ZTE CORP
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
ZTE CORP
Filing Date
2024-09-02
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing wireless communication systems face privacy concerns due to the transmission of MAC addresses in plaintext, allowing tracking of user locations and impacting higher-tier services like WLAN access and billing when MAC addresses are randomized.

Method used

A dynamic MAC address change mechanism that includes single and dual MAC address modes, where the immutable MAC address is used for encryption and the mutable MAC address is changed dynamically, with mechanisms for maintaining mapping tables and using three-way handshakes to resolve collisions.

Benefits of technology

This approach enhances privacy by making stations untraceable and minimizes the impact on higher-tier services by ensuring continuous encryption and authentication, even with MAC address changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007862124000004
    Figure 0007862124000004
  • Figure 0007862124000005
    Figure 0007862124000005
  • Figure 0007862124000006
    Figure 0007862124000006
Patent Text Reader

Abstract

To provide a dynamic MAC address change mechanism for wireless communications.SOLUTION: Methods, systems and devices relate to digital wireless communication, and more specifically, to techniques relating to a dynamic change MAC address of a station for subsequent transmissions. In one exemplary aspect, a method of dynamic change MAC address includes specifying a MAC address change mode and a new MAC address to be used by the station. In another exemplary aspect, a method of dual MAC address change mode in the dynamic change MAC address mechanism includes separating an unchanged MAC address of the station from a changeable MAC address of the station, and keeping the mapping between them. In another exemplary aspect, a method includes transmitting a MAC address change request message from the station (or access point) to initiate the MAC address change procedure.SELECTED DRAWING: None
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This patent document generally relates to wireless communication.

Background Art

[0002] A wireless communication system can include a network of one or more access points (APs) that communicate with one or more wireless stations (STAs). An AP can emit a wireless signal that conveys management information, control information, or user data to one or more STAs. An STA can transmit a wireless signal to an AP at the same frequency channel using a technique such as time division duplex (TDD), or at different frequencies using a technique such as frequency division duplex (FDD).

[0003] Institute of Electrical and Electronics Engineers (IEEE) 802.11 defines specifications for wireless local area networks (WLANs) over license-exempt or license-shared access frequency bands. The basic unit of a WLAN is a basic service set (BSS). An infrastructure BSS can include a BSS with stations by associating with an access point (AP) to connect to a wired network or the Internet. In an infrastructure BSS, both the access point and the stations can share the same frequency channel through using a carrier sense multiple access / collision avoidance (CSMA / CA) technique, which is a type of TDD mechanism for multiple access and data transmission.

Summary of the Invention

Problems to be Solved by the Invention

[0004] This document relates to digital wireless communication, and more specifically, to methods, systems, and devices related to techniques for dynamically changing the media access control (MAC) address of a station to protect user device privacy from its tracked MAC address.

[0005] In one exemplary aspect, a method for a dynamic MAC address change mechanism for wireless communication is provided to support two types of MAC address change modes, namely, a single MAC address mode and a dual MAC address mode. [Means for solving the problem]

[0006] In one exemplary embodiment, a method is provided for a single MAC address change mode for using one MAC address for station identification, encryption and decryption of user data in transmission.

[0007] In one exemplary embodiment, a method for a dual MAC address mode is provided for separating a mutable MAC address from an immutable MAC address used in authentication and security key generation for user data encryption and / or decryption in the MAC frame header. The mutable MAC address is shown in plain text within the MAC frame header. The immutable MAC address may not be shown in plain text within the MAC frame header during the STA-AP association period and remains unchanged when the mutable MAC address changes. Both the mutable and immutable MAC addresses can be used to identify the station.

[0008] In one exemplary embodiment, a method for dual MAC address mode includes a mechanism for the AP to maintain a mapping table between the mutable MAC address of the STA and the immutable MAC address of the STA.

[0009] In one exemplary embodiment, a method for dual MAC address mode includes a mechanism for the STA to maintain a mapping table between the STA's mutable MAC address and the STA's immutable MAC address.

[0010] In another exemplary aspect, a method for a dynamic MAC address change mechanism for wireless communication is provided, which uses communication between the STA and the AP to change the MAC address of the STA and prevent it from being tracked.

[0011] In one exemplary embodiment, the method of a dynamic MAC address change mechanism includes transmitting a MAC address change request message and a MAC address change response message for bidirectional handshake in the case of a non-MAC address collision.

[0012] In one exemplary embodiment, a method for MAC address change request and response messages includes a defined MAC address change mode and the encrypted MAC address of the STA in the MAC address change information element.

[0013] In one exemplary embodiment, the method of a dynamic MAC address change mechanism includes transmitting a MAC address change request message, a MAC address change response message, and a MAC address change acknowledgment message for three-way handshake to resolve MAC address collisions during the changing of the station's MAC address.

[0014] One or more implementation details are described in the accompanying attachments, drawings, and the description below. Other features will also be evident from the description and drawings, and from the claims. The present invention provides, for example, the following: (Item 1) A method for wireless communication, wherein the method is The wireless device transmits a request message to a network device, wherein the wireless device requests a change to a first media access control (MAC) address currently associated with the wireless device. The wireless device receives a response message from the network device containing a second MAC address, and the network device provides the second MAC address for use by the wireless device. Further communication with the network device is performed using the third MAC address selected based on the aforementioned response message. Methods that include... (Item 2) The method described in item 1, wherein the first MAC address is the same as the second MAC address. (Item 3) The method according to item 1, wherein the wireless device successfully verifies that the second MAC address is not currently being used by another wireless device, and then selects the third MAC address which is the same as the second MAC address. (Item 4) The method according to item 1, wherein the wireless device selects a third MAC address different from the second MAC address due to determining that the second MAC address is currently being used by another wireless device. (Item 5) The third MAC address is, Transmitting another request message containing the third MAC address to the network device, The network device receives a response indicating that the third MAC address is acceptable for use. The method described in item 4, as selected by [the specified method]. (Item 6) The method according to item 1, wherein the request message includes the second MAC address in the request message. (Item 7) A method for wireless communication, wherein the method is In a network device, receiving a request message from a wireless device, wherein the wireless device requests a change to a first Media Access Control (MAC) address currently associated with the wireless device by the request message, determining the suitability of a second MAC address for the wireless device based on the request message, transmitting a third MAC address to the wireless device based on the suitability, A method comprising: (Item 8) The method according to item 7, wherein the first MAC address is the same as the second MAC address. (Item 9) The method according to item 7, wherein determining the suitability includes confirming that the second MAC address is not currently being used by another wireless device. (Item 10) The method according to item 7, wherein determining the suitability includes authenticating the second MAC address using an authentication server. (Item 11) The method according to item 7, wherein the third MAC address is the same as the second MAC address if the suitability is qualified, and the third MAC address is different from the second MAC address if the suitability is unqualified. (Item 12) The method according to item 7, further comprising performing communication with the wireless device using the third MAC address. (Item 13) A method for wireless communication, the method comprising: A method of transmitting, from a wireless device to a network device, a field indicating the ability of the wireless device to change the MAC address of the wireless device using a single MAC address mode in which a single media access control (MAC) address controls both the identification of the wireless device and the encryption and decryption of messages communicated with the network device, and / or a dual MAC address mode in which a first MAC address controls the identification of the wireless device and a second MAC address different from the first MAC address controls the encryption and decryption of the messages communicated with the network device. (Item 14) The method according to item 13, wherein the mapping between the first MAC address and the second MAC address is established using encrypted message exchanges. (Item 15) The method according to item 13, wherein the field is included in an information element within a MAC protocol data frame. (Item 16) The method according to item 13, further comprising changing the currently used MAC address of the wireless device to a different MAC address by using the ability. (Item 17) A method for wireless communication, the method comprising: receiving, by a network device from a wireless device, a field indicating the ability of the wireless device to change the MAC address of the wireless device using a single MAC address mode in which a single media access control (MAC) address controls both the identification of the wireless device and the encryption and decryption of messages communicated with the network device, and / or a dual MAC address mode in which a first MAC address controls the identification of the wireless device and a second MAC address different from the first MAC address controls the encryption and decryption of the messages communicated with the network device; and changing the currently used MAC address of the wireless device to a different MAC address by using the ability of the wireless device. Methods that include... (Item 18) The method according to item 17, wherein the mapping between the first MAC address and the second MAC address is established using encrypted message exchange. (Item 19) The field is the method described in item 17, which is included in the information element. [Brief explanation of the drawing]

[0015] [Figure 1] Figure 1 illustrates an exemplary infrastructure basic service set (BSS) with stations.

[0016] [Figure 2] Figure 2 illustrates an exemplary authentication signaling process for a dynamic MAC address change mechanism.

[0017] [Figure 3A] Figures 3A-3D illustrate an example of the signaling process for the MAC address change mechanism initiated by the STA. [Figure 3B] Figures 3A-3D illustrate an example of the signaling process for the MAC address change mechanism initiated by the STA. [Figure 3C] Figures 3A-3D illustrate an example of the signaling process for the MAC address change mechanism initiated by the STA. [Figure 3D] Figures 3A-3D illustrate an example of the signaling process for the MAC address change mechanism initiated by the STA.

[0018] [Figure 4A] Figures 4A-4B illustrate an example of the signaling process for a MAC address change mechanism initiated by an AP. [Figure 4B] Figures 4A-4B illustrate an example of the signaling process for a MAC address change mechanism initiated by an AP.

[0019] [Figure 5] Figure 5 illustrates exemplary MAC frame formats for MAC address change requests, responses, and Ack messages.

[0020] [Figure 6] Figure 6 illustrates an exemplary MAC frame format for a beacon frame containing MAC address change mode support capability information.

[0021] [Figure 7] Figure 7 is a block diagram of an exemplary apparatus for implementing one or more of the methods described in this book.

[0022] [Figure 8] Figure 8 is a flowchart for an exemplary method of wireless communication.

[0023] [Figure 9] Figure 9 is a flowchart for another exemplary method of wireless communication. [Modes for carrying out the invention]

[0024] Wireless local area communications (HDI) is rapidly becoming the most commonly used mechanism for communication between devices, either directly or via networks such as the Internet. Multiple wireless devices (e.g., smartphones, tablets, etc.) can attempt to transmit and receive data over a shared communication spectrum in a given environment (e.g., airports, homes, buildings, sports venues, etc.). In addition, wireless devices (e.g., sensors, cameras, control units, etc.) are increasingly being used in networks for a variety of applications (e.g., factory automation, vehicle communications, etc.).

[0025] In some cases, data transmission is based on an air interface, such as those defined by the IEEE 802.11 series standards. In this specification, devices may share a transmission medium that includes a set of rules. In IEEE 802.11, a Basic Service Set (BSS) is the building block of a wireless local area network (WLAN). A set of wireless stations (also called stations) associated within a wireless coverage area may establish a BSS and provide basic services for the WLAN.

[0026] According to the IEEE 802.11 specification, the MAC address carried in the MAC frame header is used to identify a station for either transmitting or receiving MAC packets. A MAC frame format may contain one or more of the following MAC addresses:

[0027] 1) Receiving Address (RA): The address of the station that will receive and process this MAC packet.

[0028] 2) Transmission Address (TA): The address of the station that transmits this MAC packet.

[0029] 3) Destination Address (DA): The address of the destination station to receive this MAC packet.

[0030] 4) Source Address (SA): The address of the original station that transmitted this MAC packet.

[0031] Currently, MAC addresses, which are carried within the MAC frame header, are transmitted in plaintext over the air interface. This allows designated receiving stations to respond to transmissions. In addition, it allows all other receiving stations within the coverage area to identify the transmitting station and postpone (i.e., backoff) new transmissions to prevent collisions with ongoing transmissions. However, transmitting a station's MAC address wirelessly in plaintext can raise some privacy concerns if the MAC address is to be used to identify a particular station and track a user's location.

[0032] To address these privacy concerns, industry practice has implemented a mechanism called MAC address randomization, where a station randomly selects a MAC address and can use it for association with the AP network. However, such industry practice does not completely resolve privacy concerns. Trackers can still use a station's randomized MAC address to track a user's location.

[0033] In existing industry practice, MAC address randomization can be performed before the association procedure (i.e., pre-association). However, after being associated with an AP, it may not be possible for an STA to randomly change its MAC address on its own, as the STA's MAC address is bundled with the authentication and security key generation during the authentication and association procedure. If the STA's MAC address is changed, it will cause a change in the station's encryption, and user data in the MAC frame will no longer be able to be decrypted by the receiving station (i.e., the STA or AP).

[0034] Furthermore, the randomization of MAC addresses initiated by STAs in industry practice can affect higher-tier services such as WLAN access permission and billing, as these services are bundled with the STA's MAC address. If the STA's MAC address is randomized, these service features will no longer function.

[0035] This patent document describes a technique for dynamically changing the MAC address of a station. In some embodiments, the change may be achieved using two-way or three-way handshakes with the associated access point.

[0036] The station's dynamic MAC address change mechanism includes the following two modes:

[0037] (1) Single MAC Address Mode: The MAC address of the station can be changed, but only one MAC address of the STA is maintained and always used in this mode. Both the AP and STA maintain only the most recent MAC address of the STA for communication and use this MAC address to encrypt user data for transmission or decrypt received user data. The STA's MAC address is used to identify the STA. Neighboring STAs can use the STA's MAC address to configure their network access vector or NAV and prevent ongoing transmissions from being collided with new transmissions.

[0038] (2) Dual MAC address mode: In this mode, the MAC address of the station is separated as follows:

[0039] A) An unchangeable MAC address used for encrypting or decrypting user data.

[0040] B) A changeable MAC address, shown in the MAC frame header and transmitted wirelessly in plain text.

[0041] Thus, the station's unchangeable MAC address can still be used for encryption or decryption of user data, in accordance with the IEEE 802.11 specification, and can be bundled with higher-tier services such as WLAN access permission and billing. Therefore, it would reduce or eliminate the impact of MAC address changes on higher-tier services.

[0042] A station's changeable MAC address can, on the other hand, be used by neighboring stations to configure their NAVs and prevent ongoing transmissions from being collided with by new transmissions. Additionally, it would make the station untraceable.

[0043] This patent document describes a mechanism for stations and access points to use dynamic MAC address change messages to specify a new MAC address for a station to be used in subsequent transmissions.

[0044] Figure 1 illustrates an exemplary infrastructure BSS. The infrastructure may include multiple stations STA1(111), STA2(112), and STA(113). Each station may be located within the coverage of a first access point AP1(121) and a second access point AP2(122), and AP1 and AP2 form an infrastructure BSS, i.e., BSS1, BSS2. Access points AP1(121) and AP2(122) may be interconnected via switches through a distribution system (DS) and coordinated via an access controller (150) to form a multi-infrastructure BSS(100). The access controller (150) may include network functions located at the gateway of any AP(121 or 122) in the BSS(100). In some embodiments, when the access controller (150) is located at the gateway of the DS, the access controller (150) may include a full MAC protocol stack or a partial MAC protocol stack.

[0045] In some embodiments, a station, for example, STA1(111), may communicate with an access point AP2(122). Since the station, for example, STA2(112), is in the same coverage area, it may be able to listen to transmissions between STA1(111) and AP2(122). This allows STA2(112) to perform virtual sensing of the medium, set up a NAV, and, if an ongoing transmission between STA1(111) and AP2(122) is detected, prevent collisions with those transmissions in the shared radio environment.

[0046] On the other hand, since the MAC address of STA1(111) is transmitted wirelessly in plaintext, any nearby STA, such as STA3(113), can read the MAC address of STA1(111) from the received MAC frame header. This could raise privacy concerns if the MAC address of STA1(111) is used to identify this particular station and track the user's location.

[0047] To address this privacy issue, the present invention provides a mechanism for dynamic MAC address modification, including two previously described MAC address modification modes.

[0048] (1) Single MAC Address Mode: The MAC address of the station may change, but only one MAC address of the STA will always be used to identify the STA and to encrypt or decrypt user data to or from the STA.

[0049] (2) Dual MAC address mode: The MAC address of the STA is separated as follows:

[0050] A) Unchangeable MAC Address: This is used for encrypting or decrypting user data. The unchangeable MAC address is used in authentication and association procedures and bundled with the security key generation procedure specified by the IEEE 802.11 specification. This address of the station will not change throughout the entire association with the AP. It may even not be presented in the MAC frame header to identify the STA after the STA's changeable MAC address has been generated by the dynamic MAC address change mechanism.

[0051] B) Changeable MAC Address: This is indicated in the MAC frame header transmitted wirelessly in plain text. It is used by other stations to identify the station and configure the NAV. The STA's changeable MAC address can be updated at any time using dynamic MAC address change request and response messages or other means.

[0052] In some embodiments of either single MAC address mode or dual MAC address mode, AP2(122) and STA(111) use dynamic MAC address change requests and responses (or, if applicable, acknowledgments) to specify a new MAC address for STA(111) to be used for subsequent transmissions.

[0053] In some embodiments of dual MAC address mode, AP2(122) and STA(111) maintain a mapping between the modifiable MAC address and the immutable MAC address for STA(111), since both the modifiable MAC address and the immutable MAC address may be used to identify the same station.

[0054] In some embodiments of the dual MAC address mode, AP2(122) and STA(111) use the immutable MAC address of STA(111) to encrypt or decrypt user data of transmissions addressed to the modifiable MAC address of STA(111).

[0055] In some embodiments of the dual MAC address mode, AP2(122) and STA(111) identify STA(111) via the changeable MAC address of STA(111) in the MAC frame header of the MPDU transmitted in plaintext over the air interface.

[0056] Figure 2 illustrates an exemplary signaling process for authentication for a dynamic MAC address change mechanism. In this example, the wireless local access network includes an STA (251), an AP (252), and an authentication server (253).

[0057] In step 201, STA(251) sends an authentication request message to AP(252) containing the MAC address of RA=AP (i.e., AP-Addr) and the MAC address of TA=STA (i.e., STA-Addr0). The MAC address of STA(251), i.e., STA-Addr0, may not be the same as the default value of the MAC address assigned by the device manufacturer.

[0058] In step 202, after receiving an authentication request from STA(251), AP(252) forwards it to AS(253).

[0059] In step 203, after authenticating STA(251), AS(253) sends an authentication response back to AP(252).

[0060] In step 204, AP(252) forwards the authentication response to STA(251).

[0061] In step 205, if authentication is successful, STA(251) sends an association request message to AP(252).

[0062] In step 206, if AP(252) enables the association requested by STA(251), AP(252) processes the association request message and sends an association response message back to STA(251).

[0063] During association, STA(251) and AP(252) may exchange information about their ability to support MAC address change mode.

[0064] In step 207, STA(251) and AP(252) may perform handshake and security negotiation as defined by IEEE 802.11ai. STA(251) and AP(252) may optionally negotiate a new MAC address for STA(251) for subsequent transmissions.

[0065] In step 208, AP(252) may use the DHCP protocol to assign an IP address to STA(251).

[0066] In step 209, AP(252) can communicate with STA(251) using its MAC address, i.e., STA-Addr0, until a new MAC address is generated by the dynamic MAC address change mechanism.

[0067] AP(252) shall internally maintain the MAC address of STA(251), i.e., STA-Addr0.

[0068] Figure 3A illustrates an exemplary signaling process 300 of the dynamic MAC address change mechanism initiated by the STA in the case of a non-MAC address collision. The STA(351) and AP(352) communicate with each other via the MAC address of the STA(351) (i.e., MAC-Addr1) and the MAC address of the AP(352) (i.e., AP-Addr).

[0069] The MAC address (i.e., MAC-Addr0) is the original MAC address of the STA(351) used in the authentication and security key generation procedures. MAC-Addr0 may be changed during the handshake and security negotiation phases.

[0070] In single MAC address mode, STA-Addr1 is the MAC address used for station identification and user data encryption / decryption.

[0071] In dual MAC address mode, STA-Addr0 is the unchangeable MAC address, and STA-Addr1 is the changeable MAC address of STA(351). If the changeable MAC address of STA(351) has not yet been generated, initially the unchangeable MAC address is the same as the changeable MAC address.

[0072] AP(352) may broadcast information in its beacon or probe response frame indicating its ability to support the following MAC address change modes: single MAC address mode or dual MAC address mode, or both single MAC address mode and dual MAC address mode.

[0073] Based on AP(352)'s ability to support MAC address change modes, and the MAC address change mode capability itself, STA(351) may select and set one MAC address change mode in a MAC address change request message.

[0074] In step 301, STA(351) listens for transmissions within the coverage area and selects an available MAC address that is not being used by another STA. STA(351) may initiate a MAC address change procedure whenever necessary (for example, when a timer expires after association with AP(352) using the current MAC address over a period of time, or when it detects that its current MAC address conflicts with the MAC address of another STA).

[0075] In step 302, STA(351) sends a MAC address change request message to AP(352) containing the MAC address of RA=AP(352) (i.e., AP-Addr), STA(351)'s MAC address for communicating with TA=AP(352) (i.e., STA-Addr1), and STA(351)'s encrypted new MAC address (i.e., STA-Addr2) which will be carried within the MAC address change IE and used to identify STA(351) in future communications with AP(352). STA(351) sets a MAC address change mode (either single MAC address or dual MAC address) within the MAC address change IE. Other STAs, upon receiving the MAC address change request message, can still treat it as a normal message, set up NAV, and prevent the new transmission from colliding with ongoing transmissions. However, it would not be possible for a tracker receiving this message to associate STA-Addr1 with STA-Addr2, which will be used by STA(351) in future transmissions.

[0076] In step 303, after receiving the MAC address change request message, AP(352) verifies that the new MAC address of STA(351) (i.e., STA-Addr2) is not being used by another STA.

[0077] In step 304, AP(352) may optionally communicate with the authentication server(353) and perform re-authentication of STA(351) using the new MAC address STA-Addr2.

[0078] In step 305, AP(352) sends a MAC address change response with RA=STA-Addr1, TA=AP-Addr, and STA(351)'s encrypted new MAC address, i.e., STA-Addr2 carried in the MAC address change IE. AP(352) will replace STA-Addr1 with STA-Addr2 in the MAC frame header of the MPDU in future transmissions with STA(351).

[0079] Regarding the dual MAC address mode, AP(352) will internally maintain a mapping between STA-Addr0 and STA-Addr2. After the MAC address change process is complete, both AP(352) and STA(351) will use STA-Addr0 for encrypting or decrypting user data on the MPDU addressed to STA-Addr2.

[0080] After receiving the MAC address change response message, STA(351) checks the MAC address change IE. If the proposed MAC address Info=STA-Addr2 in the MAC address change request, it confirms that the MAC address change procedure is complete.

[0081] In step 306, AP(352) uses STA-Addr2 in the MAC header of the MPDU to communicate with STA(351).

[0082] Figure 3B illustrates another exemplary signaling process 310 of the dynamic MAC address change mechanism initiated by the STA in the case of a MAC address collision. The STA(351) and AP(352) communicate with each other via the MAC address of the STA(351) (i.e., STA-Addr1) and the MAC address of the AP(352) (i.e., AP-Addr).

[0083] In single MAC address mode, STA-Addr1 is the MAC address used for station identification and user data encryption / decryption.

[0084] In dual MAC address mode, STA-Addr0 is the unchangeable MAC address, and STA-Addr1 is the changeable MAC address of STA(351). If the changeable MAC address of STA has not yet been generated, initially the unchangeable MAC address is the same as the changeable MAC address.

[0085] AP(352) may broadcast MAC address change mode support capability information in a beacon or probe response frame. Based on the MAC address change mode support capability information from AP(352) and the MAC address change mode capability itself, STA(351) may select and set one MAC address change mode in a MAC address change request message.

[0086] In step 311, STA(351) listens for transmissions within the coverage area and selects an available MAC address that is not being used by another STA. STA(351) may initiate a MAC address change procedure whenever necessary (for example, when a timer expires after association with AP(352) using the current MAC address for a period of time, or when it detects that its current MAC address conflicts with the MAC address of another STA).

[0087] In step 312, STA(351) sends a MAC address change request message to AP(352) with RA=AP-Addr, TA=STA-Addr1, and the encrypted new MAC address of STA(351) (i.e., STA-Addr2) which will be carried within the MAC address change IE and used to identify STA(351) in future communications with AP(352). STA(351) sets MAC address change mode within the MAC address change IE. Other STAs, upon receiving the MAC address change request message, can still treat it as a normal message, set NAV, and prevent the new transmission from colliding with an ongoing transmission. However, it would not be possible for a tracker receiving this message to associate STA-Addr1 with STA-Addr2 which will be used by STA(351) in future transmissions.

[0088] In step 313, after receiving the MAC address change request message, AP(352) checks STA(351)'s new MAC address and finds that STA-Addr2 is being used by another STA. Therefore, AP(352) proposes another new MAC address for STA(351) for future communications, namely STA-Addr3.

[0089] In step 314, AP(352) may optionally communicate with the authentication server(353) and perform re-authentication of STA(351) using the new MAC address STA-Addr3.

[0090] In step 315, AP(352) sends a MAC address change response message with RA=STA-Addr1, TA=AP-Addr, and the encrypted new proposed MAC address for STA(351) to be carried within the MAC address change IE, i.e., STA-Addr3.

[0091] After receiving a MAC address change response message, the STA(351) checks for MAC address change IE. If MAC address Info is not the same as STA-Addr2 proposed in the MAC address change request message, it verifies that the new MAC address, i.e., STA-Addr3, is not being used by another STA.

[0092] In step 317, STA(351) sends a MAC address change Ack message with RA=AP-Addr, TA=STA-Addr1, and the encrypted new MAC address, i.e., STA-Addr3, to confirm the completion of the MAC address change procedure.

[0093] After receiving the MAC address change Ack message, AP(352) verifies that the MAC address in MAC Address Info IE is the same as STA-Addr3.

[0094] Regarding dual MAC address mode, AP(351) will internally maintain a mapping between STA-Addr0 and STA-Addr3. AP(352) and STA(351) will use STA-Addr0 for data encryption or decryption on the MPDU addressed to STA-Addr3.

[0095] In step 318, AP(352) then uses STA-Addr3 in the MAC header of the MPDU to communicate with STA(351).

[0096] Figure 3C illustrates another exemplary signaling process 320 of the dynamic MAC address change mechanism initiated by the STA in the case of a non-MAC address collision. The STA(351) and AP(352) communicate with each other using the MAC address of the STA(351) (i.e., MAC-Addr1) and the MAC address of the AP(352) (i.e., AP-Addr).

[0097] In single MAC address mode, STA-Addr1 is the MAC address used for station identification and user data encryption / decryption.

[0098] In dual MAC address mode, STA-Addr0 is the unchangeable MAC address of STA(351), and STA-Addr1 is the changeable MAC address of STA(351).

[0099] AP(352) may broadcast MAC address change mode support capability information in a beacon or probe response frame. Based on the MAC address change mode support capability information from AP(352) and the MAC address change mode capability itself, STA(351) may select and set one MAC address change mode in a MAC address change request message.

[0100] In step 321, STA(351) listens for transmissions within the coverage area and selects an available MAC address that is not being used by another STA. STA(351) may initiate a MAC address change procedure whenever necessary (for example, when a timer expires after association with AP(352) using the current MAC address over a period of time, or when it detects that its current MAC address conflicts with the MAC address of another STA).

[0101] In step 322, STA(351) sends a MAC address change request message to AP(352) with RA=AP-Addr, STA(351)'s new MAC address (i.e., STA-Addr2) which will be used for future communication with TA=AP(352), and the encrypted MAC address of STA(351) that will be carried in the MAC address change IE (i.e., STA-Addr1). STA(351) will set the MAC address change mode (either single MAC address or dual MAC address) in the MAC address change IE. Other STAs, upon receiving the MAC address change request message, can still treat it as a normal message, set up NAV, and prevent the new transmission from colliding with an ongoing transmission. However, it would not be possible for a tracker receiving this message to associate STA-Addr1 with STA-Addr2 which will be used by STA(351) in future transmissions.

[0102] In step 323, after receiving the MAC address change request message, AP(352) verifies that STA-Addr2 is not being used by another STA.

[0103] In step 324, AP(352) may optionally communicate with the authentication server(353) and perform re-authentication of STA(351) using the new MAC address STA-Addr2.

[0104] In step 325, AP(352) sends a MAC address change response with RA=STA-Addr2, TA=AP-Addr, and the encrypted MAC address, i.e., STA-Addr1, which was carried in the MAC address change IE.

[0105] Regarding the dual MAC address mode, AP(351) will internally maintain a mapping between STA-Addr0 and STA-Addr2. After the MAC address change process is complete, both AP(352) and STA(351) will use STA-Addr0 for encrypting or decrypting user data within the MPDU addressed to STA-Addr2.

[0106] After receiving the MAC address change response message, STA(351) checks the MAC address in the MAC address change IE. If the MAC address Info is the same as the STA-Addr1 sent in the MAC address change request message, it confirms that the MAC address change procedure is complete.

[0107] In step 326, AP(352) uses STA-Addr2 in the MAC header of the MPDU to communicate with STA(351).

[0108] Figure 3D illustrates another exemplary signaling process 330 of the dynamic MAC address change mechanism initiated by the STA in the case of a MAC address collision. The STA(351) and AP(352) communicate with each other via the MAC address of the STA(351) (i.e., MAC-Addr1) and the MAC address of the AP(352) (i.e., AP-Addr).

[0109] In single MAC address mode, STA-Addr1 is the MAC address used for station identification and user data encryption / decryption.

[0110] In dual MAC address mode, STA-Addr0 is the unchangeable MAC address, while STA-Addr1 is the changeable MAC address of STA(351).

[0111] AP(352) may broadcast MAC address change mode support capability information in a beacon or probe response frame. Based on the MAC address change mode support capability information from AP(352) and the MAC address change mode capability itself, STA(351) may select and set one MAC address change mode in a MAC address change request message.

[0112] In step 331, STA(351) listens for transmissions within the coverage area and selects an available MAC address that is not being used by another STA. STA(351) may initiate a MAC address change procedure whenever necessary (for example, when a timer expires after association with AP(352) using the current MAC address for a period of time, or when it detects that its current MAC address conflicts with the MAC address of another STA).

[0113] In step 332, STA(351) sends a MAC address change request message to AP(352) containing RA=AP-Addr, STA(351)'s new MAC address to be used for future communication with TA=AP(352) (i.e., STA-Addr2), and the encrypted MAC address of STA(351) (STA-Addr1) carried within the MAC address change IE. STA(351) will then set MAC address change mode within the MAC address change IE. Other STAs, upon receiving the MAC address change request message, can still treat it as a normal message, set NAV, and prevent the new transmission from colliding with an ongoing transmission. However, it would not be possible for a tracker receiving this message to associate STA-Addr1 with STA-Addr2, which will be used by STA(351) in future transmissions.

[0114] In step 333, after receiving the MAC address change request message, AP(352) checks STA-Addr2 and finds that it is being used by another STA. AP(352) then proposes a new available MAC address for STA(351) for future communications, namely STA-Addr3.

[0115] In step 334, AP(352) may optionally communicate with the authentication server(353) and perform re-authentication of STA(351) using the new MAC address, i.e., STA-Addr3.

[0116] In step 335, AP(352) sends a MAC address change response message with RA=STA-Addr2, TA=AP-Addr, and the encrypted new proposed MAC address, i.e., STA-Addr3, which is carried within the MAC address change IE.

[0117] In step 336, after receiving the MAC address change response message, STA(351) checks the MAC address in the MAC address change IE and finds that MAC address Info is not the same as STA-Addr1 in the MAC address change request message. STA(351) then verifies that the new MAC address, i.e., STA-Addr3, is not being used by another STA.

[0118] Another station with the same conflicting MAC address, i.e., STA-Addr2, may receive this MAC address change response message. However, it may not be able to decode the MAC address change IE within the MAC address change response message, and / or it may not be in the correct protocol processing state for the MAC address change response. Therefore, it will discard the received MAC address change response message.

[0119] In step 337, STA(351) sends a MAC address change Ack message with RA=AP-Addr, TA=STA-Addr3, and the encrypted MAC address, i.e., "STA-Addr1" within the MAC address change IE.

[0120] After receiving the MAC Change Ack message, AP(352) verifies that STA-Addr3 is the MAC address for STA(351) in the MAC Address Change IE of the MAC Address Change Response message. It then verifies the completion of the MAC Address Change procedure.

[0121] Regarding dual MAC address mode, AP(351) will internally maintain a mapping between STA-Addr0 and STA-Addr3. AP(352) and STA(351) will use STA-Addr0 for encrypting or decrypting user data within the MPDU addressed to STA-Addr3.

[0122] In step 338, AP(352) uses STA-Addr3 in the MAC header of the MPDU to communicate with STA(351).

[0123] Figure 4A illustrates an exemplary signaling process 400 of the AP-initiated dynamic MAC address change mechanism in the case of a non-MAC address collision. STA(451) and AP(452) communicate with each other using the MAC address of STA(451) (i.e., STA-Addr1) and the MAC address of AP(452) (i.e., AP-Addr).

[0124] In single MAC address mode, STA-Addr1 is the MAC address used for station identification and encryption / decryption.

[0125] In dual MAC address mode, STA-Addr0 is the immutable MAC address of STA(351), and STA-Addr1 is the mutable MAC address of STA(351). If the mutable MAC address of STA has not yet been generated, initially the mutable MAC address is the same as the immutable MAC address.

[0126] AP(452) may obtain information on STA(451)'s ability to support MAC address changes during the association process, determine the MAC address change mode, i.e., single MAC address mode or dual MAC address mode, and set it in the MAC address change request message to be sent to STA(451).

[0127] In step 401, AP(452) listens for transmissions within the coverage area and selects an available MAC address that is not being used by another STA. AP(452) may initiate a MAC address change for the STA when necessary.

[0128] In step 402, AP(452) sends a MAC address change request message to AP(451) containing the MAC address of RA=STA(451) (i.e., STA-Addr1), the MAC address of TA=AP(452) (i.e., AP-Addr), and an encrypted new MAC address (i.e., STA-Addr2) that will be carried in the MAC address change IE for STA(451) to be used in future communications with AP(452). STA-Addr1 is the MAC address used by STA(451) carried in the plaintext of the MAC frame header. Other STAs, upon receiving the MAC address change request message, can still treat it as a normal message, set up NAV, and prevent the new transmission from colliding with ongoing transmissions. However, it would not be possible for a tracker receiving this message to associate STA-Addr1 with STA-Addr2, which will be used by STA(451) in future communications with AP(452).

[0129] In step 403, after receiving the MAC address change request message, STA(451) verifies that STA-Addr2 is not being used by another STA.

[0130] In dual MAC address mode, STA(451) internally maintains a mapping between STA-Addr0 and STA-Addr2. After the MAC address change process is complete, STA(351) continues to use STA-Addr0 for data encryption or decryption on the MPDU addressed to STA-Addr2.

[0131] In step 404, STA(451) sends a MAC address change response message containing the MAC address of RA=AP(452) (i.e., AP-Addr), the MAC address of TA=STA(451) (i.e., STA-Addr1), and the encrypted new MAC address (STA-Addr2) carried within the MAC address change IE.

[0132] In step 405, upon receiving the MAC address change response message, AP(452) verifies that STA-Addr2 is the proposed MAC address for STA(451). It then verifies the completion of the MAC address change procedure.

[0133] Regarding dual MAC address mode, AP(452) will internally maintain a mapping between STA-Addr0 and STA-Addr2 for STA(451), and will use STA-Addr0 for data encryption or decryption on MPDUs addressed to STA-Addr2.

[0134] In step 406, AP(452) will continue communicating with STA(451) using the new MAC address (i.e., STA-Addr2).

[0135] Figure 4B illustrates another exemplary signaling process 410 of the dynamic MAC address change mechanism initiated by the AP in the case of a MAC address collision. STA(451) and AP(452) communicate with each other using the MAC address of STA(451) (i.e., MAC-Addr1) and the MAC address of AP(452) (i.e., AP-Addr).

[0136] In single MAC address mode, STA-Addr1 is the MAC address used for station identification and encryption / decryption.

[0137] In dual MAC address mode, STA-Addr0 is the immutable MAC address of STA(451), and STA-Addr1 is the mutable MAC address of STA(451). If the mutable MAC address of STA has not yet been generated, initially the mutable MAC address is the same as the immutable MAC address.

[0138] AP(452) may acquire STA(451)'s ability to support MAC address changes during the association process, determine the MAC address change mode, i.e., single MAC address mode or dual MAC address mode, and set it in the MAC address change request message that will be sent to STA(451).

[0139] In step 411, AP(452) listens for transmissions within the coverage area and selects an available MAC address that is not being used by another STA. The AP may initiate a MAC address change for the STA when necessary.

[0140] In step 412, AP(452) sends AP(451) a MAC address change request message containing the MAC address of RA=STA(451) (i.e., STA-Addr1), the MAC address of TA=AP(452) (i.e., AP-Addr), and an encrypted new MAC address (i.e., STA-Addr2) carried within the MAC address change IE for STA(451) to be used in future communications with AP(452). STA-Addr1 is the MAC address used by STA(451) carried in the plaintext of the MAC frame header. Other STAs, upon receiving the MAC address change request message, can still treat it as a normal message, set up NAV, and prevent the new transmission from colliding with ongoing transmissions. However, it would not be possible for a tracker receiving this message to associate STA-Addr1 with STA-Addr2, which will be used by STA(451) in future transmissions with AP(452).

[0141] In step 413, after receiving the MAC address change request message, STA(451) checks STA-Addr2 and finds that it is being used by another STA. STA(451) then proposes a different new MAC address for future communication with AP(352).

[0142] In step 414, STA(451) sends a MAC address change request message containing the MAC address of RA=AP(452) (i.e., AP-Addr), the MAC address of TA=STA(451) (i.e., STA-Addr1), and an encrypted new proposed MAC address (STA-Addr3) carried within the MAC address change IE.

[0143] In step 415, after receiving the MAC address change response message, AP(452) checks and finds that STA-Addr3 is not the same as the proposed MAC address for STA(451), i.e., STA-Addr2. It then verifies that the new proposed MAC address (STA-Addr3) by STA(451) is not being used by another STA.

[0144] In dual MAC address mode, AP(452) internally maintains a mapping between STA-Addr0 and STA-Addr3. After the MAC address change process is complete, AP(452) will use STA-Addr0 for data encryption or decryption on the MPDU addressed to STA-Addr3.

[0145] In step 416, AP(452) sends a MAC address change Ack message with RA=STA-Addr1, TA=AP-Addr, and an encrypted new MAC address for STA(451), i.e., STA-Addr3.

[0146] After receiving a MAC address change Ack message, STA(451) checks whether the MAC address in the MAC address change IE is the same as the proposed STA-Addr3. If "yes", it confirms the completion of the MAC address change procedure.

[0147] Regarding dual MAC address mode, STA(451) internally maintains a mapping between STA-Addr0 and STA-Addr3, and uses STA-Addr0 for data encryption or decryption on MPDUs addressed to STA-Addr3.

[0148] In step 417, AP(452) will communicate with STA(451) using the new MAC address (i.e., STA-Addr2).

[0149] Figure 5 illustrates an exemplary MAC frame format 500 for MAC address change request and response messages.

[0150] Frame control field (510): This field provides control information about this MAC frame. The first three subfields of the frame control field are protocol version, type, and subtype. The remaining subfields of the frame control field depend on the settings of the type and subtype subfields.

[0151] Duration field (520): It has a length of 16 bits. The content of this field varies depending on the frame type and subtype, whether the frame is transmitted during a race-free period, and the QoS capabilities of the transmission STA.

[0152] RA field (530): This is the MAC address of the receiving STA.

[0153] TA field (540): This is the MAC address of the transmission STA.

[0154] MAC Address Change IE(550): This is an information element that carries MAC address information, including Info ID(551), length(552), MAC address mode(533), and MAC address Info(554).

[0155] The MAC address change mode (553) can be set to either single MAC address mode or dual MAC address mode in a MAC address change request message in order to change the MAC address of a station. Once set, the MAC address change mode (553) in the MAC address change response (or Ack) message will also be set to the same mode.

[0156] MAC address info(554) contains the encrypted MAC address of the STA, which may be a new MAC address for the station or the station's current MAC address.

[0157] FCS(560): Frame Check Sequence (FCS) is a field of the CRC used by the receiving station to verify the packet being received.

[0158] Tables 1 and 2 show the relevant MAC address parameter settings for MAC address change request and response messages. [Table 1] [Table 2] [Table 3]

[0159] Figure 6 illustrates an exemplary MAC frame format 600 for a beacon or probe response, or capability negotiation, for MAC address change mode support IE.

[0160] Frame control field (610): This provides control information about this MAC frame.

[0161] Duration field (620): Its length is 16 bits.

[0162] RA field (630): This is the MAC address of the receiving station.

[0163] TA field (640): This is the MAC address of the transmission station.

[0164] MAC Address Change Mode Support IE(660): This is an information element that carries MAC address change mode support, including an Info ID(661), a length(662), a single MAC address mode support indicator(663), and a dual MAC address mode support indicator(664). If a single MAC address mechanism is supported, it will set the single MAC address mode support indicator. If a dual MAC address mechanism is supported, it will set the dual MAC address mode support indicator.

[0165] As an example, a method for dynamically changing a station's MAC address for subsequent transmissions for wireless communication includes support for two MAC address change modes: single MAC address mode and dual MAC address mode.

[0166] In some embodiments, a method for changing the MAC address of a station in single MAC address mode includes using a single dynamic MAC address, identifying the station, and encrypting and decrypting user data in MAC frames addressed to the station's dynamic MAC address.

[0167] In some embodiments, a method for changing the MAC address of a station in dual MAC address mode includes separating the station's unchangeable MAC address from the station's changeable MAC address, the station's unchangeable MAC address being used for user data encryption or decryption, and the changeable MAC address being used to identify the station, transmitted in plaintext within the MAC frame header.

[0168] In some embodiments, the method includes transmitting a MAC address change request message from a station (or access point), initiating a MAC address change procedure, and specifying a new MAC address for the station to be used in subsequent transmissions between the station and the access point.

[0169] In some embodiments, the method includes receiving a MAC address change response message from a station (or access point) and confirming the completion of the MAC address change procedure.

[0170] In some embodiments, the method includes, in the event of a collision in the new MAC address transmitted in the MAC address change request message, transmitting a MAC address change response message from the station (or access point) with a different new MAC address for the station.

[0171] In some embodiments, the method includes receiving a MAC address change acknowledgment from a station (or access point) and confirming the completion of the MAC address change procedure.

[0172] In some embodiments, the method includes transmitting a defined MAC address change mode with the encrypted new MAC address of the station within an information element of a MAC address change request message, such that the new MAC address of the station would not be able to relate to the current MAC address of the station at the time of use, which is transmitted wirelessly in plain text.

[0173] In some embodiments, the method includes transmitting the station's new MAC address in plaintext, but also transmitting a defined MAC address change mode with the station's current MAC address encrypted within the MAC address change information element. Therefore, even the station's new MAC address, transmitted in plaintext, may not be related to the station's current MAC address at the time of use.

[0174] In another exemplary embodiment, a dual MAC address mode method for dynamically changing a station's MAC address for subsequent transmission includes maintaining a mapping between the station's immutable MAC address and its mutable MAC address, such that the mapping between the station's immutable MAC address and mutable MAC address is maintained in both the access point and the station.

[0175] Figure 7 is a block diagram representation of an exemplary apparatus or hardware platform 705 that may be used to implement one or more of the methods described herein. Hardware platform 705, such as a network device or base station or access point or wireless device (e.g., STA), may include processor electronics 710, such as a microprocessor, which implements one or more of the techniques presented herein. Hardware platform 705 may include transceiver electronics 715 for receiving and / or receiving wired or wireless signals via one or more communication interfaces, such as an antenna 720 and / or a wired interface. Hardware platform 705 may implement other communication interfaces with defined protocols for transmitting and receiving data. Hardware platform 705 may include one or more memories (not expressly shown) configured to store information such as data and / or instructions. In some implementations, processor electronics 710 may include at least a portion of transceiver electronics 615. In some embodiments, at least a portion of the disclosed techniques, modules, or functions are implemented using hardware platform 705.

[0176] Figure 8 is a flowchart for an exemplary method 800 of wireless communication. Method 800 may be implemented by a wireless device (e.g., STA111, 112, or 113). Method 800 includes transmitting a request message (802) from the wireless device to a network device, by which the wireless device requests a change to a first medium access control (MAC) address currently associated with the wireless device.

[0177] Method 800 includes the wireless device receiving a response message from a network device, which includes a second MAC address provided by the network device for use by the wireless device (804).

[0178] Method 800 includes performing further communication with a network device using a third MAC address selected based on the response message (808).

[0179] Figure 9 shows another method 900 of wireless communication. Method 900 can be implemented by a network device such as AP1 or AP2, as depicted in Figure 1. Method 900 is Method 900 includes receiving a request message from a wireless device (902) in a network device, the request message in which the wireless device requests a change to a first medium access control (MAC) address currently associated with the wireless device. Method 900 includes determining the suitability of a second MAC address for the wireless device based on the request message (904). Method 900 also includes transmitting a third MAC address to the wireless device based on the suitability (906).

[0180] With respect to methods 800 and 900, as illustrated in Figures 3A-3D, in some cases the first and second MAC addresses may be the same.

[0181] In some embodiments, whether a third MAC address is the same as a second MAC address may depend on whether the second MAC address is unique and unused at any point within the wireless network serviced by the network device. Verification of the uniqueness and availability of the second MAC address may be performed by the network device. See, for example, steps 303, 304, 313, 314, 323, 324, 333, or 334.

[0182] Another method of wireless communication involves transmitting a field from a wireless device to a network device indicating the wireless device's ability to change its MAC address using a single MAC address mode (where a single medium access control (MAC) address controls the identification of the wireless device and the encryption and decryption of messages communicated with the network device) and / or a dual MAC address mode (where a first MAC address controls the identification of the wireless device, and a second MAC address different from the first MAC address controls the encryption and decryption of messages communicated with the network device). Examples of message formats are illustrated with reference to Figures 5 and 6.

[0183] Another method of wireless communication involves a network device receiving a field from a wireless device indicating the wireless device's ability to change its MAC address, using single MAC address mode (where a single medium access control (MAC) address controls the identification of the wireless device and the encryption and decryption of messages communicated with the network device), and / or dual MAC address mode (where a first MAC address controls the identification of the wireless device, and a second MAC address different from the first MAC address controls the encryption and decryption of messages communicated with the network device), and using the wireless device's ability to change the currently used MAC address of the wireless device to a different MAC address.

[0184] In methods 800 and 900, the STA initiates a MAC address change. In some cases, an AP or network device may initiate a MAC address change, as described with respect to Figures 4A-4B. For example, one method may involve the network device transmitting a request message (e.g., 402 or 412) to the wireless device. A request message indicates that a network device is requesting a change to the first MAC address currently associated with a wireless device. The network device may include a second MAC address, which is a candidate MAC address for the change. The method further includes the network device receiving a response message from the wireless device (e.g., 404 or 414) containing either the second MAC address (to confirm the change) or a third MAC address (in case the wireless device finds that the second MAC address is in use). Upon receiving the response message, the network device may send an acknowledgment that the MAC address change is complete. Further communication may take place using the new MAC address in single-MAC address mode or dual-MAC address mode.

[0185] From the perspective of a wireless device, a correspondence to the above method may include the wireless device receiving a request message from a network device, the request message in which the network device requests a change to a first MAC address currently associated with the wireless device, the request including a second MAC address which is a candidate address for the change; the wireless device checking whether the second MAC address is being used by another wireless device; and the wireless device transmitting a response message to the network device carrying a third MAC address (which may be the same as the second MAC address or different from one proposed by the wireless device). The method may further include the wireless device receiving an ACK from the network device, thereby completing the MAC address change.

[0186] In some embodiments, one or more of the methods described herein may be implemented by a wireless transmission device having a processor configured to perform the method (for example, as depicted in Figure 7). In this context, the terms “transmit” or “receive” mean either the processor controlling transceiver electronics to produce a waveform containing the described message to be transmitted or received, or simply the processor performing a baseband operation in which it transmits or receives digital information contained within the corresponding transmitted or received signal.

[0187] Additional examples and aspects of the methods described above are also disclosed with reference to the message formats shown in Figures 3A-3D and 4A-4B, and Figure 5-6.

[0188] As stated above, specific embodiments of the disclosed technology are described herein for illustrative purposes, but it should be understood that various modifications can be made without departing from the scope of the invention. Therefore, the disclosed technology is not limited to those provided for in the appended claims.

[0189] The embodiments, modules, and functional operations described and disclosed herein may be implemented in digital electronic networks, or in computer software, firmware, or hardware, or in combination of one or more of the structures disclosed herein and their structural equivalents. The disclosed and other embodiments may be implemented as one or more modules of computer program instructions encoded on a computer-readable medium for execution by or to control the operation of one or more computer program products, i.e., data processing devices. The computer-readable medium may be a machine-readable storage device, a machine-readable storage board, a memory device, a composition that produces a machine-readable propagating signal, or one or more of these. The term “data processing device” includes, for example, a programmable processor, a computer, or all devices, devices, and machines for processing data, including multiple processors or computers. In addition to hardware, a device may include code that generates an execution environment for the computer program, such as processor firmware, a protocol stack, a database management system, an operating system, or code that constitutes one or more of these. The propagated signal is an artificially generated signal, such as a mechanically generated electrical, optical, or electromagnetic signal that is generated to encode information for transmission to a suitable receiver device.

[0190] Computer programs (also known as programs, software, software applications, scripts, or code) can be written in any form of a programming language, including compiled or interpreted languages, and can be deployed in any form, including as standalone programs or as modules, components, subroutines, or other units suitable for use in a computer environment. Computer programs do not necessarily correspond to files in a file system. A program can be stored in a single file dedicated to it, in part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in part of a file that holds other programs or data (e.g., one or more modules, subprograms, or parts of code). Computer programs can be deployed to run on one computer, or on multiple computers located on one site, or distributed across multiple sites and interconnected by a communication network.

[0191] The processes and logic flows described in this book can be implemented by one or more programmable processors that execute one or more computer programs to perform their functions by acting on input data and generating outputs. The processes and logic flows can also be implemented by special-purpose logic networks, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits), and the devices themselves can be implemented as such.

[0192] Processors suitable for executing computer programs include, as an example, both general-purpose and special-purpose microprocessors, and any one or more processors of any type of digital computer. Generally, a processor will receive instructions and data from read-only memory or random-access memory, or both. Essential elements of a computer are a processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer will also include, or be operably coupled to, one or more mass storage devices for storing data, such as magnetic, magneto-optical disks, or optical disks, for receiving data, transmitting data, or both. However, a computer is not required to have such devices. Computer-readable media suitable for storing computer program instructions and data include, as an example, all forms of non-volatile memory, media, and memory devices, such as semiconductor memory devices, such as EPROM, EEPROM, and flash memory devices, magnetic disks, such as internal hard disks or removable disks, magneto-optical disks, and CD-ROM and DVD-ROM disks. Processors and memory can be complemented by or incorporated into special-purpose logic networks.

[0193] This patent document contains many details, which should be interpreted not as limitations on the scope of any invention or claim, but rather as descriptions of features that may be specific to a particular embodiment of a particular invention. Features described in this patent document in the context of a separate embodiment may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any preferred secondary combination in multiple embodiments. Furthermore, features described above as acting in a combination, and initially claimed as such, may, in some cases, be removed from the claimed combination, and the claimed combination may be subject to secondary combinations or variations of secondary combinations.

[0194] Similarly, while operations are depicted in the drawings in a specific order, this should not be understood as requiring that such operations be performed in a specific or sequential order, or that all illustrated operations be performed, in order to achieve a desired result. Furthermore, the separation of various system components in the embodiments described in this patent document should not be understood as requiring such separation in all embodiments.

[0195] Only a few implementations and examples are described, and other implementations, enhancements, and modifications may also be made based on what is described and illustrated in this patent document.

Claims

1. A method of wireless communication, The station receives capability information from the access point (AP) indicating that the AP supports dual-media access control (MAC) address mode, In response to receiving the capability information, the station is activated in the dual MAC address mode, in which the station transmits an unchangeable MAC address to the AP in an association request frame. A method comprising, in the dual MAC address mode, the MAC address of the station comprising the immutable MAC address and the modifiable MAC address.

2. The method according to claim 1, wherein user data is encrypted or decrypted by the station using the unchangeable MAC address.

3. The station, in response to receiving the capability information, transmits an instruction to the AP for support regarding the dual MAC address mode. The method according to claim 1, further comprising:

4. The method according to claim 1, wherein the changeable MAC address is transmitted wirelessly.

5. The method according to claim 1, wherein the changeable MAC address is located in the MAC header of the transmitted frame.

6. The method according to claim 1, wherein the unmodified MAC address is used for encryption or decryption of user data, used in authentication and association procedures, bundled with a security key generation procedure, and not present in the transmitted frame MAC header.

7. A station for wireless communication, wherein the station comprises one or more processors, and the one or more processors are configured to cause the station to carry out the method according to any one of claims 1 to 6.

8. A non-temporary computer-readable program storage medium having code stored thereon, wherein the code, when executed by one or more processors, causes a device to implement the method according to any one of claims 1 to 6.