Method for performing connection management of station device within wireless communications system for protection from identity confusion caused by attacks from attacker device, and associated apparatus

The STA device in wireless communications systems uses probe requests, responses, and a 4-way handshake with beacon protection to prevent connection to wrong networks, addressing SSID and icon confusion attacks without side effects, ensuring secure communication.

WO2026066960A1PCT designated stage Publication Date: 2026-04-02MEDIATEK INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-04
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing wireless communication systems are vulnerable to identity confusion attacks, such as SSID confusion and icon confusion, where a user's device is tricked into connecting to a wrong network, and existing solutions introduce side effects or are not effective.

Method used

A method involving a STA device that transmits probe requests and receives responses, performs a 4-way handshake, and disconnects upon reaching a threshold of non-valid beacons to protect against such attacks, along with a beacon protection mechanism to enhance security without introducing side effects.

Benefits of technology

Enhances security by preventing connection to wrong networks, ensuring secure communication without replacing the STA device, and mitigating identity confusion attacks effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025118908_02042026_PF_FP_ABST
    Figure CN2025118908_02042026_PF_FP_ABST
Patent Text Reader

Abstract

A method for performing connection management of a station (STA) device within a wireless communications system for protection from identity confusion (e.g., SSID confusion and / or icon confusion caused by attacks from an attacker device) and associated apparatus are provided. The method may include: transmitting at least one probe request from the STA device to an access point (AP) device of an adversary, the adversary to a user of the STA device, wherein the AP device may act as the attacker device; receiving at least one probe response from the AP device; transmitting at least one association request from the STA device to the AP device; receiving at least one association response from the AP device; performing a four-way (4-way) handshake between the STA device and the AP device; and in response to a number of non-valid beacons from the AP device reaching a predetermined threshold, disconnecting from the AP device.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD FOR PERFORMING CONNECTION MANAGEMENT OF STATION DEVICE WITHIN WIRELESS COMMUNICATIONS SYSTEM FOR PROTECTION FROM IDENTITY CONFUSION CAUSED BY ATTACKS FROM ATTACKER DEVICE, AND ASSOCIATED APPARATUS

[0001] CROSS REFERENCE TO RELATED APPLICATION

[0002] This application claims the benefit of U.S. Provisional Application No. 63 / 699,244, filed on September 26th, 2024. The content of the application is incorporated herein by reference.BACKGROUND OF THE INVENTION1. FIELD OF THE INVENTION

[0003] The present invention is related to communications management, and more particularly, to a method for performing connection management of a station (STA) device within a wireless communications system for protection from identity confusion (e.g., the service set identifier (SSID) confusion and / or icon confusion caused by attacks from an attacker device) , and to associated apparatus such as the STA device.

[0004] 2. DESCRIPTION OF THE PRIOR ART

[0005] According to the related art, a STA device with Wi-Fi functions may still be compromised if an end user of the STA device is tricked into using a wrong network after finding a “correct” SSID such as the SSID of a target network that he or she is looking for. When viewing a network list on a screen or a touch-sensitive display panel of the STA device and finding the SSID, the user may think that the target network is available. For example, the STA device may seem to operate as usual, as if it is connecting to the target network, but in reality, it is connecting to the wrong network. Some suggestions may be proposed for trying to correct the problem, but further problems such as some side effects may be introduced. Thus, a novel method and associated architecture are needed for solving the problems of the related art without introducing any side effect or in a way that is less likely to introduce a side effect.SUMMARY OF THE INVENTION

[0006] It is an objective of the present invention to provide a method for performing connection management of a STA device within a wireless communications system for protection from identity confusion (e.g., the SSID confusion and / or icon confusion caused by attacks from an attacker device) , and to provide associated apparatus such as the STA device, in order to solve the above-mentioned problems.

[0007] At least one embodiment of the present invention provides a method for performing connection management of a STA device within a wireless communications system for protection from identity confusion (e.g., SSID confusion and / or icon confusion) , where the identity confusion is caused by at least one attack (e.g., one or more attacks) from an attacker device. For example, the method may comprise: transmitting at least one probe request from the STA device to an access point (AP) device of an adversary, the adversary to a user of the STA device, wherein the AP device is arranged to act as the attacker device; receiving at least one probe response from the AP device; transmitting at least one association request from the STA device to the AP device; receiving at least one association response from the AP device; performing a four-way (4-way) handshake between the STA device and the AP device; and in response to a number of non-valid beacons from the AP device reaching a predetermined threshold, disconnecting from the AP device.

[0008] At least one embodiment of the present invention provides a STA device, for performing connection management of the STA device within a wireless communications system for protection from identity confusion (e.g., SSID confusion and / or icon confusion) , where the identity confusion is caused by at least one attack (e.g., one or more attacks) from an attacker device. The STA device may comprise a processing circuit that is arranged to control operations of the STA device. The STA device may further comprise at least one communications control circuit that is coupled to the processing circuit and arranged to perform communications control, wherein the at least one communications control circuit is arranged to perform wireless communications operations for the STA device. For example, the STA device is arranged to transmit at least one probe request from the STA device to an AP device of an adversary, the adversary to a user of the STA device, wherein the AP device is arranged to act as the attacker device; the STA device is arranged to receive at least one probe response from the AP device; the STA device is arranged to transmit at least one association request from the STA device to the AP device; the STA device is arranged to receive at least one association response from the AP device; the STA device is arranged to perform a 4-way handshake between the STA device and the AP device; and in response to a number of non-valid beacons from the AP device reaching a predetermined threshold, the STA device is arranged to disconnect from the AP device.

[0009] It is an advantage of the present invention that the method of the present invention, as well as the associated apparatus such as the STA device, can enhance the security of the wireless communications system, and more particularly, can help the user escape from the trap of the wrong network with an update of the STA device, having no need to replace the STA device with a new device. In addition, the method of the present invention and the associated apparatus such as the STA device can solve the related art problem without introducing any side effect or in a way that is less likely to introduce a side effect.

[0010] These and other objectives of the present invention will no doubt become obvious to those of ordinary skill in the art after reading the following detailed description of the preferred embodiment that is illustrated in the various figures and drawings.BRIEF DESCRIPTION OF THE DRAWINGS

[0011] FIG. 1 is a diagram of a wireless communications system according to an embodiment of the present invention.

[0012] FIG. 2 illustrates a protection control scheme of a method for performing connection management of a STA device within a wireless communications system for protection from identity confusion according to an embodiment of the present invention.

[0013] FIG. 3 illustrates a main working flow of the method according to an embodiment of the present invention.DETAILED DESCRIPTION

[0014] Certain terms are used throughout the following description and claims, which refer to particular components. As one skilled in the art will appreciate, electronic equipment manufacturers may refer to a component by different names. This document does not intend to distinguish between components that differ in name but not in function. In the following description and in the claims, the terms "include" and "comprise" are used in an open-ended fashion, and thus should be interpreted to mean "include, but not limited to ... " . Also, the term "couple" is intended to mean either an indirect or direct electrical connection. Accordingly, if one device is coupled to another device, that connection may be through a direct electrical connection, or through an indirect electrical connection via other devices and connections.

[0015] FIG. 1 is a diagram of a wireless communications system 100 according to an embodiment of the present invention. For better comprehension, the wireless communications system 100, as well as any wireless communications device therein, may be compatible or backward compatible with one or more versions of the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards, but the present invention is not limited thereto. The wireless communications system 100 may comprise multiple wireless communications devices. As shown in FIG. 1, the multiple wireless communications devices within the wireless communications system 100 may comprise the AP device 110 and the STA device 120, where the AP device 110 may comprise a processing circuit 112, at least one communications control circuit (e.g., one or more communications control circuits) , which may be collectively referred to as the communications control circuit 114, and at least one antenna (e.g., one or more antennas) of the communications control circuit 114, and the STA device 120 may comprise a processing circuit 122, at least one communications control circuit (e.g., one or more communications control circuits) , which may be collectively referred to as the communications control circuit 124, and at least one antenna (e.g., one or more antennas) of the communications control circuit 124.

[0016] In the architecture shown in FIG. 1, the processing circuit 112 can be arranged to control operations of the AP device 110 to make the AP device 110 act as at least one AP in the wireless communications system 100, such as multiple APs integrated into the AP device 110, and the communications control circuit 114 can be arranged to perform communications control, and more particularly, perform wireless communications operations with the STA device 120 (or the communications control circuit 124 thereof) for the AP device 110. In addition, the processing circuit 122 can be arranged to control operations of the STA device 120 to make the STA device 120 act as at least one STA in the wireless communications system 100, such as multiple STAs integrated into the STA device 120, and the communications control circuit 124 can be arranged to perform communications control, and more particularly, perform wireless communications operations with the AP device 110 (or the communications control circuit 114 thereof) for the STA device 120.

[0017] According to some embodiments, the processing circuit 112 can be implemented by way of at least one processor / microprocessor, at least one random access memory (RAM) , at least one bus, etc., and the communications control circuit 114 can be implemented by way of at least one wireless network control circuit and at least one wired network control circuit, but the present invention is not limited thereto. Examples of the AP device 110 may include, but are not limited to:a Wi-Fi router. In addition, the processing circuit 122 can be implemented by way of at least one processor / microprocessor, at least one RAM, at least one bus, etc., and the communications control circuit 124 can be implemented by way of at least one wireless network control circuit, but the present invention is not limited thereto. Examples of the STA device 120 may include, but are not limited to: a multifunctional mobile phone, a laptop computer, an all-in-one computer and a wearable device.

[0018] As shown in FIG. 1, the multiple wireless communications devices within the wireless communications system 100 may comprise the AP device 110 and the STA device 120. This is for illustrative purposes only, and is not meant to be a limitation of the present invention. According to some embodiments, the multiple wireless communications devices within the wireless communications system 100 may be implemented by way of multiple multi-link devices (MLDs) .

[0019] According to some embodiments, the STA device 120 (or the communications control circuit 124 therein) may comprise a Wi-Fi combo chipset. The Wi-Fi combo chipset can be implemented by integrating multiple wireless technologies, typically Wi-Fi and Bluetooth, onto a single chip. This integration can reduce the size, the power consumption, and the associated costs while enhancing device interoperability and simplifying design for the manufacturer of the STA device 120 (or the communications control circuit 124 therein) . The Wi-Fi combo chipset can be arranged to include components like radio frequency (RF) transceivers, amplifiers, baseband processors, etc. for handling both Wi-Fi and Bluetooth communications, and more particularly, further include more components for handling more functions. This is for illustrative purposes only, and is not meant to be a limitation of the present invention. According to some embodiments, the architecture of the STA device 120 (or the communications control circuit 124 therein) may vary.

[0020] FIG. 2 illustrates a protection control scheme of a method for performing connection management of a STA device within a wireless communications system (e.g., the aforementioned any wireless communications device within the wireless communications system 100, such as the STA device 120 like a non-access-point (non-AP) STA device) for protection from identity confusion (e.g., SSID confusion and / or icon confusion) according to an embodiment of the present invention, where the identity confusion is caused by at least one attack (e.g., one or more attacks) from an attacker device. Four stages 210, 220, 230 and 240 involved with the protection control scheme may also be referred to as Stages #1, #2, #3 and #4, respectively, and some operations under an SSID confusion attack (see H. Gollier and M. Vanhoef, “SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network” , the Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) , 2024; “Gollier” hereinafter) may be illustrated in the stages 210, 220 and 230 as shown in FIG. 2, but the present invention is not limited thereto. The STA device 120 may act as the client 201 in the protection control scheme, and might be regarded as “vulnerable” under the SSID confusion attack if the client 201 were not arranged to deal with the SSID confusion attack. An adversary to a user of the aforementioned any wireless communications device (e.g., the STA device 120) may intentionally prepare the adversary’s own AP device 202 for replacing the AP device 110, so that the AP device 202 may be arranged to act as the attacker device mentioned above. In particular, the AP device 202 may be implemented by way of at least one device, the aforementioned at least one device including but not limited to: the wrong AP 202W, arranged to advertise a wrong network such as the network that the adversary wants to trick the victim (e.g., the client 201 such as the STA device 120) into connecting with, as well as the attacker 202A implemented as a multi-channel machine-in-the-middle position (MC-MitM) between the victim and the wrong network, with the MC-MitM being established by a rogue AP (e.g., the rogue AP on a channel different from the wrong network) created by the adversary. For example, in the stages 210, 220 and 230, the client 201 may seem to operate as usual, as if it is connecting to a target network (e.g., a trusted network) provided by the AP device 110, but in reality, it is connecting to the wrong network.

[0021] The method of the present invention, as well as the associated apparatus such as the aforementioned any wireless communications device (e.g., the STA device 120) , can enhance the security of the wireless communications system 100, and more particularly, can help the user escape from the trap of the wrong network, and when the wireless communications device such as the STA device 120 is arranged to act as the client 201 shown in FIG. 2, the associated operations may comprise:

[0022] (1) in the stage 210, the client 201 such as the STA device 120 may transmit at least one probe request (e.g., the probe request ProbeReq1 among the probe requests ProbeReq1 and ProbeReq2) from the STA device 120 to the AP device 202 of the adversary (i.e., the adversary to the user of the STA device 120) , where within the AP device 202, the attacker 202A may forward any probe requests {ProbeReq1} as the probe requests {ProbeReq2} to the wrong AP 202W, for example, if the probe requests {ProbeReq1} carry an optional SSID equal to the SSID SSID_TN of the target network, the attacker 202A may replace the SSID SSID_TN therein with the SSID SSID_WN of the wrong network, for being forwarded as the probe requests {ProbeReq2} to the wrong AP 202W;

[0023] (2) in the stage 210, the client 201 such as the STA device 120 may receive at least one probe response (e.g., the probe response ProbeResp1 among the probe responses ProbeResp1 and ProbeResp2) from the AP device 202, where within the AP device 202, the attacker 202A may modify any probe responses {ProbeResp2} and beacons {Beacon2} from the wrong AP 202W (in particular, by replacing the SSID SSID_WN therein with the SSID SSID_TN) to be the probe responses {ProbeResp1} and beacons {Beacon1} for being forwarded to the client 201, and therefore, in the stage 220, the victim (e.g., the client 201 such as the STA device 120) may try connecting with the target network such as the trusted network (as if it is nearby, even when it is not available) , so the connection process may start by sending and receiving one or more (open) authentication frames that are forwarded to and from the wrong AP 202W via the attacker 202A without modification;

[0024] (3) in the stage 220, after the (open) authentication is completed, the client 201 such as the STA device 120 may transmit at least one association request (e.g., the association request AssocReq1 among the association requests AssocReq1 and AssocReq2) from the STA device 120 to the AP device 202, where the attacker 202A may modify any association requests {AssocReq1} from the client 201 (in particular, by replacing the SSID SSID_TN therein with the SSID SSID_WN) to be the association requests {AssocReq2} for being forwarded to the wrong AP 202W;

[0025] (4) in the stage 220, the client 201 such as the STA device 120 may receive at least one association response (e.g., the association response AssocResp1 among the association responses AssocResp1 and AssocResp2) from the AP device 202, where the attacker 202A may be arranged to forward any association response AssocResp2 as the association response AssocResp1 to the client 201 without modification, since the association response AssocResp2 does not contain an SSID;

[0026] (5) in the stage 220, after the association, the client 201 such as the STA device 120 may perform an 802.1X authentication handshake for a case of connecting to an enterprise Wi-Fi network, and may perform a 4-way handshake between the STA device 120 and the AP device 202 to negotiate fresh session keys to encrypt and authenticate data frames, where although the negotiated keys may be dependent on the medium access control (MAC) addresses of the client 201 (or the victim) , the adversary may continue with the SSID confusion attack, and more particularly, use the attacker 202A (or the MC-MitM) to create a rogue clone of the AP using the same MAC address as that of the wrong AP 202W;

[0027] (6) in the stage 230, after the client 201 (e.g., the STA device 120) is connected to the wrong AP 202W, the client 201 may exchange data frames with the wrong AP 202W, where the attacker 202A may forward all traffic between the client 201 and the wrong AP 202W, and rewrite the SSID SSID_WN to the SSID SSID_TN for the traffic forwarded to the client 201 (as well as the beacons {Beacon2} forwarded as the beacons {Beacon1} to the client 201) , so the client 201 may operate as if the target network such as the trusted network is nearby; and

[0028] (7) in the stage 240, in response to the number CNT of non-valid beacons from the AP device 202 reaching a predetermined threshold CNT_th, the client 201 such as the STA device 120 may disconnect from the AP device 202, where the predetermined threshold CNT_th can be a positive integer, and more particularly, can be either implemented as a fixed value that is greater than one, for detecting successive errors, or implemented as another fixed value that is equal to one, for detecting a single error;

[0029] where the client 201 (or the victim) that was intending to connect with the target network such as the trusted network may instead successfully authenticate with and connect to the wrong network at the end of the stage 230 for the case that a vulnerable protocol is used, but the present invention is not limited thereto. Whether the authentication succeeds may depend on the protocol, and more particularly, depend on whether the SSID is used for deriving the pairwise master key or session keys. For example, if the SSID is used for doing so, the attacker 202A cannot successfully continue with the SSID confusion attack by just passively forwarding the 4-way handshake messages between the client 201 and the wrong network, since they would derive different keys. Regarding the SSID confusion attack, please refer to Gollier for the associated details such as which protocols are (or are not) vulnerable.

[0030] In the stage 240, the client 201 (e.g., the STA device 120) may monitor the number CNT of the non-valid beacons from the AP device 202, in order to selectively disconnect from the AP device 202 according to whether the number CNT of the non-valid beacons from the AP device 202 reaches the predetermined threshold CNT_th. For example, the number CNT of the non-valid beacons from the AP device 202 may represent the number CNT of successive errors of receiving the non-valid beacons. In this situation, the predetermined threshold CNT_th can be implemented as the aforementioned fixed value that is greater than one, for detecting the successive errors.

[0031] While Gollier describes issues with IEEE 802.11 not authenticating the SSID in all cases and some upper layer components using the current SSID to disable protections (e.g., disabling a virtual private network (VPN) in a trusted network such as that mentioned above) , and describes a man-in-the-middle attack (e.g., the SSID confusion attack) that allows a STA to be made to believe it associated with a different SSID when that STA has same credentials enabled for multiple SSIDs, the present invention proposes an extension to the IEEE 802.11 standard to mitigate this issue with beacon protection. This allows STA / Supplicant to disconnect the peer when an SSID it believes the network to use is not guaranteed the same SSID that the AP / Authenticator uses. For better comprehension, the beacon protection mentioned above can be implemented with the mechanisms for the beacon protection that are introduced to address the vulnerability of beacon frames to forgery, for helping authenticate received beacon frames and mitigate risks associated with spoofed beacons, but the present invention is not limited thereto.

[0032] While Gollier, in section 5.2 thereof, proposes two potential protocol updates to avoid the issues, with the two potential protocol updates including (1) mixing in SSID into key derivation for all cases and (2) include SSID in an authenticated frame, both updates need some additional consideration due to likely interoperability issues. The proposed method of the present invention focuses on simpler mitigations on the use of the beacon protection and the thresholding of the successive errors that could effectively reduce the attack surface of STA. This can be achieved by Proposed text changes to a draft standard such as IEEE P802.11REVme / D5.0, and the Proposed text changes may comprise: in Section 9.4.2.240 RSNXE (in which “RSNXE” stands for Robust Security Network eXtension element, which is an extension of the Robust Security Network (RSN) information element, designed to provide more flexibility and address potential interoperability issues related to the RSN element itself) thereof, inserting a new row into “Table 9-373” of the draft standard immediately above the last Reserved row as shown below (ignoring the header row) , illustrated as Table 1 of the present invention.

[0033] Table 1

[0034] Table 1 illustrates an example of a sub-field (which may be named as “Beacon Protection Disconnect” for indicating the capability and / or the support thereof) within the Extended RSN Capabilities field, for being applied to the Proposed text changes mentioned above, where “ANA” stands for Assigned Numbers Authority, indicating that the Bit (or Bits) of this field can be determined by the ANA in order to ensure that different elements within the IEEE 802.11 standard (and related standards like the IEEE 802.15 standard) have unique identifiers, preventing conflicts and ensuring interoperability. Based on the Proposed text changes mentioned above, a STA can set this field to 1 to indicate the support for the disconnection from the peer when the beacon protection detects successive errors; otherwise, it can set the field to 0. For example, the aforementioned any wireless communications device such as the STA 120 can be designed to have the capability of the Beacon Protection Disconnect, and can set this field to 1 to indicate the support for the disconnection from the peer when the beacon protection detects successive errors. While acting as the client 201 (e.g., the client 201 of the AP device 202) in the protection control scheme shown in FIG. 2, the wireless communications device such as the STA device 120 can perform the Beacon Protection Disconnect (e.g., the operation of disconnecting from the AP device 202 in response to the number CNT of the non-valid beacons from the AP device 202 reaching the predetermined threshold CNT_th) in the stage 240, and therefore can escape from the trap of the wrong network.

[0035] In the above embodiments, the SSID confusion can be taken as an example of the identity confusion. This is for illustrative purposes only, and is not meant to be a limitation of the present invention. According to some embodiments, the identity confusion may comprise at least one of the SSID confusion and the icon confusion. More particularly, the icon confusion can be taken as an example of the identity confusion for the case where the SSID is replaced by an icon in a newer Wi-Fi network, and the wireless communications system 100, as well as the aforementioned any wireless communications device therein, can be compatible with one or more newer versions of the IEEE 802.11 standards, such as the newer versions in which the icon can be used for replacing the SSID. In this case, the non-valid beacons may contain non-valid icon data. For brevity, similar descriptions for these embodiments are not repeated in detail here.

[0036] FIG. 3 illustrates a main working flow of the method according to an embodiment of the present invention. The aforementioned any wireless communications device such as the STA device 120 can operate according to the working flow shown in FIG. 3, and more particularly, can act as the client 201 in the protection control scheme shown in FIG. 2 to eventually escape from the trap of the wrong network.

[0037] In Step 310, the STA device 120 may transmit the aforementioned at least one probe request (e.g., the probe request ProbeReq1 among the probe requests ProbeReq1 and ProbeReq2) from the STA device 120 to the AP device 202 of the adversary (i.e., the adversary to the user of the STA device 120) , where the AP device 202 is arranged to act as the attacker device mentioned above.

[0038] In Step 320, the STA device 120 may receive the aforementioned at least one probe response (e.g., the probe response ProbeResp1 among the probe responses ProbeResp1 and ProbeResp2) from the AP device 202.

[0039] In Step 330, the STA device 120 may transmit the aforementioned at least one association request (e.g., the association request AssocReq1 among the association requests AssocReq1 and AssocReq2) from the STA device 120 to the AP device 202.

[0040] In Step 340, the STA device 120 may receive the aforementioned at least one association response (e.g., the association response AssocResp1 among the association responses AssocResp1 and AssocResp2) from the AP device 202.

[0041] In Step 350, the STA device 120 may perform the 4-way handshake between the STA device 120 and the AP device 202.

[0042] In Step 360, in response to the number CNT of non-valid beacons from the AP device 202 reaching the predetermined threshold CNT_th, the STA device 120 may disconnect from the AP device 202.

[0043] As the wireless communications device such as the STA 120 can be designed to have the capability of the Beacon Protection Disconnect, when acting as the client 201 in the protection control scheme shown in FIG. 2, the wireless communications device such as the STA device 120 can perform the Beacon Protection Disconnect in the stage 240 to monitor the number of non-valid beacons from the AP device 202, and disconnect from the AP device 202 when the number CNT of non-valid beacons from the AP device 202 reaches the predetermined threshold CNT_th, and therefore can escape from the trap of the wrong network. For brevity, similar descriptions for this embodiment are not repeated in detail here.

[0044] For better comprehension, the method may be illustrated with the working flow shown in FIG. 3, but the present invention is not limited thereto. According to some embodiments, one or more steps may be added, deleted, or changed in the working flow shown in FIG. 3.

[0045] Those skilled in the art will readily observe that numerous modifications and alterations of the device and method may be made while retaining the teachings of the invention. Accordingly, the above disclosure should be construed as limited only by the metes and bounds of the appended claims.

Claims

1.A method for performing connection management of a station (STA) device within a wireless communications system for protection from identity confusion, the identity confusion being caused by at least one attack from an attacker device, the method comprising:transmitting at least one probe request from the STA device to an access point (AP) device of an adversary, the adversary to a user of the STA device, wherein the AP device is arranged to act as the attacker device;receiving at least one probe response from the AP device;transmitting at least one association request from the STA device to the AP device;receiving at least one association response from the AP device;performing a four-way (4-way) handshake between the STA device and the AP device; andin response to a number of non-valid beacons from the AP device reaching a predetermined threshold, disconnecting from the AP device.2.The method of claim 1, wherein the predetermined threshold is a positive integer.3.The method of claim 2, wherein the predetermined threshold is implemented as a fixed value that is greater than one.4.The method of claim 1, wherein the identity confusion comprises at least one of service set identifier (SSID) confusion and icon confusion.5.The method of claim 1, further comprising:monitoring the number of the non-valid beacons from the AP device, in order to selectively disconnect from the AP device according to whether the number of the non-valid beacons from the AP device reaches the predetermined threshold.6.The method of claim 1, wherein the number of the non-valid beacons from the AP device represents a number of successive errors of receiving the non-valid beacons.7.The method of claim 6, wherein the predetermined threshold is implemented as a fixed value that is greater than one.8.The method of claim 1, wherein the STA device is arranged to set a sub-field within an extended robust security network (RSN) capabilities field, the sub-field of beacon protection disconnect, as a predetermined value to indicate support for disconnection from a peer when beacon protection detects successive errors.9.The method of claim 8, wherein while acting as a client of the AP device, the STA device is arranged to perform the beacon protection disconnect, for escaping from a trap of a wrong network of the AP device.10.The method of claim 1, wherein the STA device is implemented as a non-access-point (non-AP) station (STA) device; and the AP device is implemented by way of at least one device, the at least one device including: a wrong AP, arranged to advertise a wrong network which is a network that the adversary wants to trick a victim into connecting with, as well as an attacker implemented as a multi-channel machine-in-the-middle position (MC-MitM) between the victim and the wrong network, with the MC-MitM being established by a rogue AP, the rogue AP on a channel different from the wrong network, created by the adversary.11.A station (STA) device, for performing connection management of the STA device within a wireless communications system for protection from identity confusion, the identity confusion being caused by at least one attack from an attacker device, the STA device comprising:a processing circuit, arranged to control operations of the STA device; andat least one communications control circuit, coupled to the processing circuit, arranged to perform communications control, wherein the at least one communications control circuit is arranged to perform wireless communications operations for the STA device;wherein:the STA device is arranged to transmit at least one probe request from the STA device to an access point (AP) device of an adversary, the adversary to a user of the STA device, wherein the AP device is arranged to act as the attacker device;the STA device is arranged to receive at least one probe response from the AP device;the STA device is arranged to transmit at least one association request from the STA device to the AP device;the STA device is arranged to receive at least one association response from the AP device;the STA device is arranged to perform a four-way (4-way) handshake between the STA device and the AP device; andin response to a number of non-valid beacons from the AP device reaching a predetermined threshold, the STA device is arranged to disconnect from the AP device.12.The STA device of claim 11, wherein the predetermined threshold is a positive integer.13.The STA device of claim 12, wherein the predetermined threshold is implemented as a fixed value that is greater than one.14.The STA device of claim 11, wherein the identity confusion comprises at least one of service set identifier (SSID) confusion and icon confusion.15.The STA device of claim 11, wherein the STA device is arranged to monitor the number of the non-valid beacons from the AP device, in order to selectively disconnect from the AP device according to whether the number of the non-valid beacons from the AP device reaches the predetermined threshold.16.The STA device of claim 11, wherein the number of the non-valid beacons from the AP device represents a number of successive errors of receiving the non-valid beacons.17.The STA device of claim 16, wherein the predetermined threshold is implemented as a fixed value that is greater than one.18.The STA device of claim 11, wherein the STA device is arranged to set a sub-field within an extended robust security network (RSN) capabilities field, the sub-field of beacon protection disconnect, as a predetermined value to indicate support for disconnection from a peer when beacon protection detects successive errors.19.The STA device of claim 18, wherein while acting as a client of the AP device, the STA device is arranged to perform the beacon protection disconnect, for escaping from a trap of a wrong network of the AP device.20.The STA device of claim 11, wherein the STA device is implemented as a non-access-point (non-AP) station (STA) device; and the AP device is implemented by way of at least one device, the at least one device including: a wrong AP, arranged to advertise a wrong network which is a network that the adversary wants to trick a victim into connecting with, as well as an attacker implemented as a multi-channel machine-in-the-middle position (MC-MitM) between the victim and the wrong network, with the MC-MitM being established by a rogue AP, the rogue AP on a channel different from the wrong network, created by the adversary.