Methods, devices, and computer programs for managing security capabilities for BSS privacy enhancement

WO2026180381A1PCT designated stage Publication Date: 2026-09-03CANON KK +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2026/054784
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-27
Filing Date
2026-02-23
Publication Date
2026-09-03

Smart Images

  • Figure EP2026054784_03092026_PF_FP_ABST
    Figure EP2026054784_03092026_PF_FP_ABST
Patent Text Reader

Abstract

At least an embodiment of a communication method in a station, STA, in a wireless network, the method comprising obtaining a key that is pre-shared between the station and an access-point, AP, de-encrypting an information field of a beacon transmitted by the AP using an encryption key obtained from the pre-shared key, and authenticating with the AP using information obtained from the information field.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHODS, DEVICES, AND COMPUTER PROGRAMS

[0002] FOR MANAGING SECURITY CAPABILITIES FOR BSS PRIVACY ENHANCEMENT

[0003] FIELD OF THE DISCLOSURE

[0004] The present disclosure relates to wireless communications and more specifically to managing authentication in a multi-link device wireless network, for example for managing security capabilities for Basic Service Set (BSS) privacy enhancement.

[0005] BACKGROUND OF DISCLOSURE

[0006] The approaches described in this section could be pursued, but are not necessarily approaches that have been previously conceived or pursued. Therefore, unless otherwise indicated herein, the approaches described in this section are not prior art to the claims in this application and are not admitted to be prior art by inclusion in this section. Furthermore, all embodiments are not necessarily intended to solve all or even any of the problems brought forward in this section.

[0007] Wireless communication networks are widely deployed to provide various communication services such as voice, video, packet data, messaging, broadcast, etc. These wireless networks may be multiple-access networks capable of supporting multiple users by sharing the available network resources. Examples of such multipleaccess networks include Code Division Multiple Access (CDMA) networks, Time Division Multiple Access (TDMA) networks, Frequency Division Multiple Access (FDMA) networks, Orthogonal FDMA (OFDMA) networks, and Single-Carrier FDMA (SC-FDMA) networks. The 802.11 family of standards adopted by the Institute of Electrical and Electronics Engineers (IEEE - RTM) provides a great number of mechanisms for wireless communications between stations.

[0008] Today, the evolution of wireless systems has brought privacy concerns at the forefront, driven by user demand and requirements of the General Data Protection Regulation (GDPR). The global wireless industry is faced with the growing need to protect users’ personally identifiable information from increasingly sophisticated user tracking and user profiling activities, while continuing to improve wireless services and the user experience.

[0009] The Personally Identifiable Information (PH) corresponds to any data that identifies an individual or from which identity or contact information of an individual can be derived. A device’s Media Access Control (MAC) address is an example of PH.A dedicated task group 802.11 bi has been initiated in 2019 to address those privacy concerns. Its objective is to specify Enhanced Data Privacy (EDP) features to be added in the current standard to increase privacy.

[0010] A set of EDP features referred to as Basic Service Set (BSS) Privacy Enhancement (BPE) features makes it possible to protect privacy of Access-Point (AP) Multi-Link Devices (MLDs) and associated non-AP MLDs. An AP MLD supporting such BPE features is referred to as a BPE AP MLD and a non-AP MLD supporting such BPE features is referred to as a BPE non-AP MLD.

[0011] One of the BPE features is the transmission of Privacy Beacon frame by the BPE AP MLD instead of legacy Beacon frame (as defined in the IEEE 802.11-2020 standard) which allows not sending in clear BPE AP MLD discovery information (e.g., Service Set Identifier (SSID), capability or operation elements) in clear over the air.

[0012] The header of a Privacy Beacon frame is anonymized according to a BPE frame anonymization procedure. The Privacy Beacon frame contains also an Identity Hash field allowing a non-AP station (STA) affiliated with a BPE non-AP MLD to identify or discover an AP affiliated with a BPE AP MLD and a frame body field encrypted with a Group Temporal Key (GTK) including some Information Element (IE).

[0013] However, even if the non-AP STA affiliated with the BPE non-AP MLD discovers the AP affiliated with the BPE AP MLD, the BPE non-AP MLD cannot initiate an authentication procedure (and further association procedure) with the BPE AP MLD to establish a Robust Security Network Association as the non-AP STA affiliated with the BPE non-AP MLD is not aware of the security capabilities of the AP associated with the BPE AP MLD, typically advertised in a legacy Beacon frame in a Robust Security Network (RSN) element and optionally a RSN extension element (RSNXE), a RSN Override element, a RSN Override 2 element, a RSNXE Override element which include supported encryption methods, authentication mechanisms, and management frame protection settings.

[0014] Therefore, there is a need to improve communication in such systems.

[0015] SUMMARY OF THE DISCLOSURE

[0016] The present disclosure has been devised to address one or more of the foregoing concerns.

[0017] The current disclosure describes a method to reliably and securely provide information enabling a BPE non-AP MLD to initiate an authentication procedure (andfurther association procedure) with a BPE AP MLD to establish a Robust Security Network Association.

[0018] According to a first aspect of the disclosure, it is provided a communication method in a station, STA, in a wireless network, the method comprising:

[0019] obtaining a key that is pre-shared between the station and an access-point, AP; de-encrypting an information field of a beacon transmitted by the AP using an encryption key obtained from the pre-shared key; and

[0020] authenticating with the AP using information obtained from the information field.

[0021] Accordingly, the method of the disclosure makes it possible for a BPE non-AP MLD to initiate an authentication procedure (and further association procedure) with a BPE AP MLD to establish a Robust Security Network Association.

[0022] According to some particular embodiments, the method further comprises identifying the AP as a function of the pre-shared key.

[0023] Still according to some particular embodiments, the method further comprises computing a hash value from data of the beacon for each of a plurality of pre-shared keys, the pre-shared key being obtained from the set of pre-shared keys as a function of the computed hash values and of a hash value from the beacon.

[0024] Still according to some particular embodiments, the encryption key is the preshared key. Alternatively, the encryption key may be obtained from a mapping table associating pre-shared keys with encryption keys.

[0025] Still according to some particular embodiments, the information field comprises an encrypted Robust Security Network, RSN, element of the AP.

[0026] Still according to some particular embodiments, the information field further comprises at least one of an encrypted RSN extension element, RSNXE, an encrypted RSN Override element, an encrypted RSN Override 2 element and an encrypted RSNXE Override element.

[0027] Still according to some particular embodiments, the beacon is a Privacy Beacon. Still according to some particular embodiments, the beacon is received in response to transmitting a beacon solicit request. The beacon may be an unprotected Privacy Beacon.

[0028] Still according to some particular embodiments, the pre-shared key is used to obfuscate address fields in the beacon.

[0029] Still according to some particular embodiments, the station is a Basic Service Set, BSS, Privacy Enhancement, BPE non-AP affiliated with a BPE non-AP multi-link device MLD and wherein the AP is a BPE AP affiliated with a BPE AP MLD.According to a second aspect of the disclosure, it is provided a processing unit in a Basic Service Set, BSS, Privacy Enhancement, BPE, non-access point, AP, multi-link device, MLD, for communicating, the processing unit being configured to carry out each of the steps of the method described above.

[0030] Accordingly, the device of the disclosure makes it possible for a BPE non-AP MLD to initiate an authentication procedure (and further association procedure) with a BPE AP MLD to establish a Robust Security Network Association.

[0031] According to a third aspect of the disclosure, it is provided a communication method in an access-point, AP, in a wireless network, the method comprising: obtaining a key that is pre-shared between the AP and a station, STA; encryption an information field of a beacon to be transmitted to the STA, using an encryption key obtained from the pre-shared key; and

[0032] authenticating with the STA using information obtained by the STA from the information field.

[0033] Accordingly, the method of the disclosure makes it possible for a BPE non-AP MLD to initiate an authentication procedure (and further association procedure) with a BPE AP MLD to establish a Robust Security Network Association.

[0034] According to some particular embodiments, the pre-shared key is used to obfuscate address fields in the beacon.

[0035] Still according to some particular embodiments, the encryption key is the preshared key. Alternatively, the encryption key may be obtained from a mapping table associating pre-shared keys with encryption keys.

[0036] Still according to some particular embodiments, the information field comprises an encrypted Robust Security Network, RSN, element of the AP.

[0037] Still according to some particular embodiments, the information field further comprises at least one of an encrypted RSN extension element, RSNXE, an encrypted RSN Override element, an encrypted RSN Override 2 element and an encrypted RSNXE Override element.

[0038] Still according to some particular embodiments, the beacon is a Privacy Beacon. Still according to some particular embodiments, the beacon is transmitted in response to receiving a beacon solicit request. The beacon may be an unprotected Privacy Beacon.

[0039] Still according to some particular embodiments, the station is a Basic Service Set, BSS, Privacy Enhancement, BPE non-AP affiliated with a BPE non-AP multi-link device MLD and wherein the AP is a BPE AP affiliated with a BPE AP MLD.According to a fourth aspect of the disclosure, it is provided a processing unit in a Basic Service Set, BSS, Privacy Enhancement, BPE, access point, AP, multi-link device, MLD, for communicating, the processing unit being configured to carry out each of the steps of the method described above.

[0040] Accordingly, the device of the disclosure makes it possible for a BPE non-AP MLD to initiate an authentication procedure (and further association procedure) with a BPE AP MLD to establish a Robust Security Network Association.

[0041] At least parts of the methods according to some embodiments of the disclosure may be computer implemented. Accordingly, some embodiments of the present disclosure may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a "circuit", a "module", or a "system". Furthermore, some embodiments of the present disclosure may take the form of a computer program product embodied in any tangible medium of expression having computer usable program code embodied in the medium.

[0042] Since some embodiments of the present disclosure can be implemented in software, some embodiments of the present disclosure can be embodied as computer readable code for provision to a programmable apparatus on any suitable carrier medium. A tangible carrier medium may comprise a storage medium such as a floppy disk, a CD-ROM, a hard disk drive, a magnetic tape device or a solid-state memory device, and the like. A transient carrier medium may include a signal such as an electrical signal, an electronic signal, an optical signal, an acoustic signal, a magnetic signal or an electromagnetic signal, e.g., a microwave or RF signal.

[0043] BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Embodiments of the disclosure will now be described, by way of example only, and with reference to the following drawings in which:

[0045] Figure 1 illustrates an example of a network system in which some embodiments of the disclosure may be implemented;

[0046] Figure 2 illustrates a frame format of a Privacy Beacon frame in accordance with the IEEE 802.11TGbi draft 1.0 standard;

[0047] Figure 3 illustrates an example of a frame format of a Privacy Beacon frame according to some embodiments of the disclosure;

[0048] Figure 4 illustrates a frame format of an unprotected Privacy Beacon frame in accordance with the IEEE 802.11TGbi draft 1.0 standard;Figure 5 illustrates an example of a frame format of an unprotected Privacy Beacon frame according to some embodiments of the disclosure;

[0049] Figure 6 illustrates, using a flowchart, an example of some steps carried out in a BPE AP affiliated with a BPE AP MLD to advertise its security capabilities according to some embodiments of the disclosure;

[0050] Figure 7 illustrates, using a flowchart, an example of some steps carried out in a BPE STA affiliated with a BPE non-AP MLD to retrieve the security capabilities of a BPE AP affiliated with a BPE AP MLD according to some embodiments of the disclosure;

[0051] Figure 8 illustrates, using a flowchart, an example of some steps carried out in a BPE AP affiliated with a BPE AP MLD to advertise its security capabilities (following a solicit request from the BPE non-AP MLD) according to some embodiments of the disclosure;

[0052] Figure 9 illustrates, using a flowchart, an example of some steps carried out in a BPE STA affiliated with a BPE non-AP MLD to retrieve the security capabilities of a BPE AP affiliated with a BPE AP MLD according to some embodiments of the disclosure; and Figure 10 schematically illustrates an example of a communication device configured to implement at least some embodiments of the present disclosure.

[0053] DETAILED DESCRIPTION OF THE DISCLOSURE

[0054] According to some embodiments, a new frame body is added to a Privacy Beacon frames that is transmitted by a Basic Service Set (BSS) Privacy Enhancement (BPE) Access Point (AP), such as an AP affiliated with a BPE AP Multi-Link Device (MLD) to a non-AP station (STA), such as a non-AP STA affiliated with a BPE non-AP MLD. The new frame body contains Information Elements (IE) encrypted with a preconfigured Identity Key (pre-shared between the BPE AP MLD and the BPE non-AP MLD), for example as a Robust Security Network Information Element (RSNE), according to the security capabilities of the BPE AP MLD. The new frame body may also contain a Robust Security Network extension Information Element (RSNXE), a RSN Override element, a RSN Override 2 element and / or a RSNXE Override element.

[0055] For the sake of illustration, Figure 1 represents an IEEE 802.11 network (i.e., a Wi-Fi network, WiFi is a trademark) system 100 comprising four wireless devices: an access point station (AP) 105 and three non-AP stations (STAs) 110a, 110b, and 110c. According to the illustrated example, the AP station and the non-AP stations are AP multi-link device (MLD) and non-AP MLDs, respectively, grouping APs referred to asaffiliated APs and grouping non-APs referred to as affiliated non-AP STAs (also referred to as affiliated stations), respectively. Of course, the number of non-AP MLDs 110a, 110b, and 110c may be different from three. Likewise, the number of affiliated APs per AP MLD and the number of affiliated non-AP STAs per non-AP MLD may vary. As illustrated with dotted lines, AP MLD 105 provides wireless connections between non-AP MLDs 110a, 110b, 110c and a wider network, such as the Internet (not represented).

[0056] AP MLD 105 may comprise, be implemented as, or known as a Node B, Radio Network Controller (RNC), evolved Node B (eNB), 5G Next generation base station (gNB), Base Station Controller (BSC), Base Transceiver Station (BTS), Base Station (BS), Transceiver Function (TF), Radio Router, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Radio Base Station (RBS), or some other terminology. It can be a standalone product or it may be integrated in a device, for instance in a broadband remote access server (BRAS).

[0057] Non-AP MLDs 110a, 110b, and / or 110c may comprise, be implemented as, or known as a subscriber’s station, a subscriber unit, a Mobile Station (MS), a remote station, a remote terminal, a User Terminal (UT), a user agent, a user’s device, a User Equipment (UE), a User Station (STA), or some other terminology. In some implementations, a non-AP MLD may be or may comprise a cellular telephone, a cordless telephone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device having wireless connection capability, or some other suitable processing devices connected to a wireless modem. Accordingly, one or more aspects taught herein may be incorporated into a phone (e.g., a cellular phone or a smartphone), a computer (e.g., a laptop), a tablet, a portable communication device, a portable computing device (e.g., a personal data assistant), an entertainment device (e.g., a music or video device, or a satellite radio), a Global Positioning System (GPS) device, or any other suitable device that is configured to communicate via a wireless or wired medium. In some aspects, some of the non-AP MLDs 110a, 110b, and 110c may be wireless nodes. Such a wireless node may provide, for example, connectivity for or to a network (e.g., a wide area network such as the Internet or a cellular network) via a wired or wireless communication link.

[0058] AP M LD 105 manages a set of stations comprising here the non-AP M LDs 110a, 110b, and 110c. In the context of the disclosure, AP MLD 105 and its associated non-AP MLDs 110a, 110b, and 110c supports Enhanced Data Privacy (EDP) features referred to as BSS Privacy Enhancement (BPE) features as specified in the IEEE 802.11TGbi draft 1.0 standard and allowing to protect privacy of AP MLD 105 and itsassociated non-AP MLDs110a, 110b, and 110c. An AP MLD supporting BPE features is referred to as a BPE AP MLD. An AP affiliated with a BPE AP MLD is referred to as a BPE AP. A non-AP MLD supporting BPE features is referred to as a BPE non-AP MLD. A non-AP STA affiliated with a BPE non-AP MLD is referred to as a BPE STA.

[0059] Figure 2 illustrates a frame format of a Privacy Beacon frame in accordance with the IEEE 802.11TGbi draft 1.0 standard (section 9.3.4.4 (Privacy Beacon frame format)).

[0060] As illustrated, Privacy Beacon frame 200 contains a Frame Control field 210, a Duration field 211, an Address 1 field 212, an Address 2 field 213, an Identity Hash field 220, a Timestamp field 230, a Frame Body field 240 and a Frame Check Sequence (FCS) field 290.

[0061] A Protected Frame field of the Frame Control field 210 is set if the Privacy Beacon frame is protected (meaning that the Privacy Beacon frame has a Frame Body 240), otherwise it is not set. The Address 1 field 212 is set to the broadcast address. The Address 2 field 213 is set to the anonymized Basic Service Set Identifier (BSSID) as specified in section 10.71.3 of the IEEE 802.11TGbi draft 1.0 standard. The BSSID corresponds to the MAC address of the AP affiliated with the BPE AP MLD transmitting the Privacy Beacon frame.

[0062] Identity Hash field 220 is set to a value as described in 10.71.8.1 (BPE AP MLD Discovery) of the IEEE 802.11TGbi draft 1.0 standard. It corresponds to a hash generated from the Address 2 field 213, and a preconfigured or pre-shared Identity Key.

[0063] Timestamp field 230 format is described in section 9.4.1.10 (Timestamp field) of the IEEE 802.11-2020 standard and is anonymized as described in 10.71.5.5 (Timestamp anonymization) of the IEEE 802.11TGbi draft 1.0 standard.

[0064] Frame Body field 240 of the Privacy Beacon frame contains a list of Information Elements (IE) specified in section 9.3.4.4 (Privacy Beacon frame format) of the IEEE 802.11TGbi draft 1.0 standard. The frame body is encrypted (as illustrated by the thick outline) by the GTK of the AP affiliated with the BPE AP MLD transmitting the Privacy Beacon frame.

[0065] Figure 3 illustrates an example of a frame format of a Privacy Beacon frame according to some embodiments of the disclosure.

[0066] Compared to the frame format of the Privacy Beacon frame 200 in Figure 2, as specified in the IEEE 802.11TGbi draft 1.0 standard, the frame format of Privacy Beacon frame 300 illustrated in Figure 3 further contains a Protected Security Capabilities IE 350,Frame Control field 210’, Duration field 21 T, Address 1 field 212’, Address 2 field 213’, Identity Hash field 220’, Timestamp field 230’, Frame Body field 240’ and FCS field 290’ of Privacy Beacon frame 300 being similar to Frame Control field 210, Duration field 211, Address 1 field 212, Address 2 field 213, Identity Hash field 220, Timestamp field 230, Frame Body field 240 and FCS field 290 of Privacy Beacon frame 200 in Figure 2.

[0067] According to the illustrated example, the Protected Security Capabilities Information Element (IE) 350 contains an Element ID field 351, a Length field 352 and a Protected Security lEs field 360.

[0068] Element I D field 351 is set to a particular value (not already assigned by the IEEE 802.11-2020 standard) indicating the presence of the Protected Security Capabilities lEs (e.g., Protected Security lEs field 360).

[0069] Length field 352 indicates the number of octets in the Protected Security Capabilities IE 350, excluding Element ID field 351 and Length field 352.

[0070] Protected Security lEs field 360 contains, in an implementation, a list of encrypted security lEs 370 including at least the RSNE 371 specified in section 9.4.2.23 (RSNE) of the IEEE 802.11-2020 standard and, according to the security capabilities of the BPE AP MLD, a RSNXE 372 specified in section 9.4.2.240 (RSNXE) of the IEEE 802.11-2020 standard and / or the RSNE Override element 374 specified in WPA3 Specification (Version 3.3 Personal compatibility mode), and / or a RSNE Override 2 element 375 specified in WPA3 Specification (Version 3.3 Personal compatibility mode), and / or a RSNXE Override element 376 specified in WPA3 Specification (Version 3.3 Personal compatibility mode). It may also contain other security lEs 377 relative to the security capabilities. As illustrated by the thick outline, the list of the security lEs 370 is encrypted in the Protected Security lEs field 360 by a cypher suite taking as input an encryption key. The encryption key is also referred to in the disclosure as Protected Security Capabilities Key. According to some embodiments, a data field varying over time (e.g., Address 2 field 213) may be encrypted with the list of the security lEs 370 in the Protected Security lEs field 360 so that the Protected Security lEs vary over time (which makes it more difficult to identify and analyse).

[0071] Figure 4 illustrates a frame format of an unprotected Privacy Beacon frame in accordance with the IEEE 802.11TGbi draft 1.0 standard.

[0072] As illustrated, an unprotected Privacy Beacon frame (e.g., unprotected Privacy Beacon frame 400 in Figure 4) corresponds to a Privacy Beacon frame (e.g., PrivacyBeacon frame 200 in Figure 2), without a Frame Body (e.g., Frame Body 240 in Figure 2).

[0073] Accordingly, unprotected Privacy Beacon frame 400 comprises a Frame Control field 210”, a Duration field 211”, an Address 1 field 212”, an Address 2 field 213”, an Identity Hash field 220”, a Timestamp field 230” and an FCS field 290” that are similar to Frame Control field 210, a Duration field 211, an Address 1 field 212, an Address 2 field 213, an Identity Hash field 220, a Timestamp field 230 and a FCS field 290 of Privacy Beacon frame 200 in Figure 2, respectively.

[0074] Figure 5 illustrates an example of a frame format of an unprotected Privacy Beacon frame according to some embodiments of the disclosure.

[0075] As illustrated, an unprotected Privacy Beacon frame (e.g., unprotected Privacy Beacon frame 500 in Figure 5) corresponds to a Privacy Beacon frame (e.g., Privacy Beacon frame 300 in Figure 3) without a Frame Body (e.g., without Frame Body 240’ in Figure 3).

[0076] Accordingly, unprotected Privacy Beacon frame 500 comprises a Frame Control field 210”’, a Duration field 21 T”, an Address 1 field 212’”, an Address 2 field 213’”, an Identity Hash field 220’”, a Timestamp field 230’”, a Protected Security Capabilities IE 350’ and a FCS field 290’” that are similar to Frame Control field 21 O’, Duration field 21 T, Address 1 field 212’, Address 2 field 213’, Identity Hash field 220’, Timestamp field 230’, Protected Security Capabilities IE 350 and FCS field 290’ of Privacy Beacon frame 300 in Figure 3, respectively.

[0077] Likewise, according to the illustrated example, Protected Security Capabilities IE 350’ contains an Element ID field 35T, a Length field 352’ and a Protected Security lEs field 360’, Element ID field 35T being set to a particular value indicating the presence of the Protected Security Capabilities lEs and Length field 352’ indicating the number of octets in the Protected Security Capabilities IE 350’, excluding Element ID field 35T and Length field 352’.

[0078] Likewise also, and still according to the illustrated example, Protected Security lEs field 360’ contains a list of encrypted security lEs 370’ including at least the RSNE 37T specified in section 9.4.2.23 (RSNE) of the IEEE 802.11-2020 standard and, according to the security capabilities of the BPE AP MLD, a RSNXE 372’ specified in section 9.4.2.240 (RSNXE) of the IEEE 802.11-2020 standard and / or the RSNE Override element 374’ specified in WPA3 Specification (Version 3.3 Personal compatibility mode), and / or a RSNE Override 2 element 375’ specified in WPA3 Specification (Version 3.3Personal compatibility mode), and / or a RSNXE Override element 376’ specified in WPA3 Specification (Version 3.3 Personal compatibility mode). It may also contain other security lEs 377’ relative to the security capabilities. Again, and as illustrated by the thick outline, the list of the security lEs 370’ is encrypted in the Protected Security lEs field 360’ by a cypher suite taking as input the Protected Security Capabilities Key. According to some embodiments, a data field varying over the time (e.g., Address 2 field 213) is encrypted with the list of the security lEs 370’ in the Protected Security lEs field 360’ so that the Protected Security lEs vary over the time (which makes it more difficult to identify and analyse).

[0079] Figure 6 illustrates, using flowchart 600, an example of some steps carried out in a BPE AP affiliated with a BPE AP MLD to advertise its security capabilities according to some embodiments of the disclosure.

[0080] It is observed that according to the IEEE 802.11TGbi draft 1.0 standard, the BPE APs affiliated with a BPE AP MLD transmit Privacy Beacon frames (according to the frame format provided in section 9.3.4.4 of this standard) instead of legacy Beacon frames (according to the frame format provided in section 9.3.3.2 of this standard).

[0081] It is also observed that according to the IEEE 802.11TGbi draft 1.0 standard, a BPE AP MLD stores a pre-shared Identity Key (also referred to as preconfigured Identity Key) which has been previously shared with a BPE non-AP MLD. The pre-shared Identity Key allows a BPE STA affiliated with the BPE non-AP MLD to identify or discover a BPE AP affiliated with the BPE AP MLD.

[0082] According to some embodiments of the present disclosure, the BPE AP MLD also stores a Protected Security Capabilities Key which has been previously shared with a BPE non-AP MLD. The Protected Security Capabilities Key allows a BPE AP affiliated with the BPE AP MLD to advertise its security capabilities while ensuring its privacy. The Protected Security Capabilities Key is used as an input of a cypher algorithm used to encrypt a plaintext corresponding to the security capabilities. Still according to some embodiments of the present disclosure, a mapping table is defined in the BPE AP MLD and in the BPE non-AP MLDs to associate each of the pre-shared Identity Keys with a Protected Security Capabilities Key. According to some embodiments, the pre-shared Identity Key and the Protected Security Capabilities Key are the same key.

[0083] For the sake of illustration, the cipher suite used here is the Hybrid Public Key Encryption (HPKE) cipher suite in single-shot mode with pre-shared key (PSK) mode asspecified in RFC 9180. It is referred to as HPKE-PSK-SingleShot. Other cipher suites may be used.

[0084] For the encryption (at the sender’s end), HPKE-PSK-SingleShot takes as inputs a key PSK that is pre-shared between the sender and the receiver, a plaintext message and Additional Authentication Data (AAD). As outputs, it delivers a ciphertext (i.e. , the encrypted message) and an Authentication Tag for verifying the integrity of the message and AAD.

[0085] For the decryption (at the receiver’s end), HPKE-PSK-SingleShot takes as inputs the same PSK used by the sender, the ciphertext (i.e., the encrypted message) and AAD. As outputs, it delivers a decrypted message corresponding to the original plaintext message and a Tag Verification (if the tag is correct, the message is considered as verified, i.e., it is considered as being authentic and unmodified).

[0086] According to some embodiments of the disclosure, a BPE AP associated with a BPE AP MLD encrypts its security capabilities by using its Protected Security Capabilities Key and adds the encrypted security capabilities within a Privacy Beacon frame (e.g., Privacy Beacon frame 300 in Figure 3) when such a Privacy Beacon frame is to be transmitted, for example as illustrated in step 605. As described above, the Protected Security Capabilities Key may be the pre-shared Identity Key or may be a Protected Security Capabilities Key associated with the pre-shared Identity Key. According to other embodiments, the Protected Security Capabilities Key may be another pre-shared key, different from the pre-shared Identity Key, for example a pre-shared key common to several BPE AP MLDs.

[0087] To that end, the BPE AP constructs an AAD, for example as specified in section 12.5.4.3.3 (Construct AAD) of the IEEE 802.11TGbi draft 1.0 standard, which includes a Frame Control, an Address 1, an Address 2 and an Identity Hash, for example Frame Control field 210’, Address 1 field 212’, Address 2 field 213’ and Identity Hash field 220’ of Privacy Beacon frame 300 in Figure 3.

[0088] As specified in the IEEE 802.11-2020 standard, the BPE AP encapsulates its security capabilities in a RSNE (e.g., RSNE 371 in Figure 3) and if necessary, a RSNXE (e.g., RSNXE 372 in Figure 3) and / or a RSNE Override element (e.g., RSNE Override element 374 in Figure 3) and / or a RSNE Override 2 element (e.g., RSNE Override 2 element 375 in Figure 3) and / or a RSNXE Override element (e.g., RSNXE Override element 376 in Figure 3) and / or other security lEs (e.g., other security lEs 377 in Figure 3) relative to the security capabilities.Next, the BPE AP concatenates, in a container (e.g., container 370 in Figure 3), the list of the generated security lEs (e.g., RSNE 371 and / or RSNXE 372 and / or RSNE Override element 374 and / or RSNE Override 2 element 375 and / or RSNXE Override element 376 and / or security lEs 377 relative to the security capabilities). Then, the BPE AP launches the encryption process with the cypher suite, HPKE-PSK-SingleShot taking as inputs, the Protected Security Capabilities Key as PSK, the container comprising the list of the generated security lEs as a plaintext message and the constructed AAD as AAD. As outputs, the BPE AP retrieves a ciphertext (corresponding to the list of encrypted security lEs) and a generated Authentication Tag.

[0089] Next, at step 610, the BPE AP generates a Privacy Beacon frame (e.g., Privacy Beacon frame 300 in Figure 3) containing a Protected Security Capabilities IE (e.g., Protected Security Capabilities IE 350 in Figure 3) with a Protected Security lEs field (e.g., Protected Security lEs field 360 in Figure 3) which includes the ciphertext and the Authentication Tag (not represented).

[0090] Next, at step 615, the BPE AP transmits the Privacy Beacon frame (e.g., Privacy Beacon frame 300 in Figure 3).

[0091] Figure 7 illustrates, using flowchart 700, an example of some steps carried out in a BPE STA affiliated with a BPE non-AP MLD to retrieve the security capabilities of a BPE AP affiliated with a BPE AP MLD according to some embodiments of the disclosure.

[0092] It is noted that according to some embodiments of the present disclosure and before retrieving security capabilities of a BPE AP affiliated with a BPE AP MLD, from a Privacy Beacon frame, the BPE non-AP MLD should store a pre-shared Identity Key (also referred to as a preconfigured Identity Key) which has been previously shared with the BPE AP MLD. The pre-shared Identity Key allows a BPE STA affiliated with the BPE non-AP MLD to identify or discover a BPE AP affiliated with the BPE AP MLD.

[0093] It is also noted that according to some embodiments of the present disclosure, the BPE non-AP MLD should also store a Protected Security Capabilities Key which has been previously shared with the BPE AP MLD. The Protected Security Capabilities Key allows it to retrieve the security capabilities of a BPE AP affiliated with the BPE AP MLD while ensuring its privacy. The Protected Security Capabilities Key is used as an input of a cypher algorithm used to encrypt a plaintext corresponding to the security capabilities (at the BPE AP’s end) and to decrypt the encrypted security capabilities (at the BPE STA’s end). As described above and according to some embodiments of the present disclosure, a mapping table is defined in the BPE AP MLD and in the BPE non-AP MLDsto associate each of the pre-shared Identity Keys with a Protected Security Capabilities Key. According to some embodiments, the pre-shared Identity Key and the Protected Security Capabilities Key are the same key.

[0094] Upon receiving a Privacy Beacon frame (e.g., Privacy Beacon frame 300 in Figure 3) (step 705), a BPE STA affiliated with the BPE non-AP MLD identifies or discovers the BPE AP MLD with its stored pre-shared Identity Keys (step 710), for example as it is described in section 10.71.8.2 (BPE AP MLD Beaconing) of the IEEE 802.11TGbi draft 1.0 standard.

[0095] Once discovered with a given stored pre-shared Identity Key referred to pre_key, the BPE STA uses its mapping table (if needed, e.g., if the Protected Security Capabilities Key is different from the pre_key) to retrieve the Protected Security Capabilities Key corresponding to the pre_key (step 715).

[0096] Next, the BPE STA extracts the list of encrypted security lEs and the authentication tag (step 720) from the Protected Security lEs field (e.g., Protected Security lEs field 360 in Figure 3) of the Protected Security Capabilities IE (e.g., Protected Security Capabilities IE 350 in Figure 3) of the received Privacy Beacon frame (e.g., Privacy Beacon frame 300 in Figure 3).

[0097] Once the encrypted security lEs have been extracted, the BPE STA initiates their decryption (step 725). To that end, the BPE STA constructs an AAD, for example as specified in section 12.5.4.3.3 (Construct AAD) of the IEEE 802.11TGbi draft 1.0 standard, which may include the Frame Control field (e.g., Frame Control field 210’ in Figure 3), the Address 1 field (e.g., Address 1 field 212’ in Figure 3), the Address 2 field (e.g., Address 2 field 213’ in Figure 3) and the Identity Hash field (e.g., Identity Hash field 220’ in Figure 3) of the received Privacy Beacon.

[0098] Next, the BPE STA launches the decryption process with the cypher suite, HPKE-PSK-SingleShot taking as inputs, the Protected Security Capabilities Key pre_key as PSK, the encrypted Security lEs extracted at step 720 as ciphertext and the constructed AAD as AAD. As outputs, it delivers a decrypted message corresponding to the list of decrypted security lEs, that is validated if the Tag Verification computed during the decryption process corresponds to the Authentication Tag extracted from the Privacy Beacon frame at step 720. The Security Capabilities are derived directly from the list of decrypted security lEs including the RSNE (e.g., RSNE 371 in Figure 3) and potentially, a RSNXE (e.g., RSNXE 372 in Figure 3) and / or a RSNE Override element (e.g., RSNE Override element 374 in Figure 3) and / or a RSNE Override 2 element (e.g., RSNE Override 2 element 375 in Figure 3 and / or a RSNXE Override element (e.g., RSNXEOverride element 376 in Figure 3) and / or other security lEs (e.g., other security lEs 377 in Figure 3).

[0099] Next, the BPE AP MLD initiates (step 730) a standard authentication procedure with the BPE AP MLD through its affiliated BPE STA, based on the security capabilities of the BPE AP affiliated with the BPE AP MLD retrieved at step 725.

[0100] Figure 8 illustrates, using flowchart 800, an example of some steps carried out in a BPE AP affiliated with a BPE AP MLD to advertise its security capabilities (following a solicit request from the BPE non-AP MLD) according to some embodiments of the disclosure.

[0101] As observed above and according to the IEEE 802.11TGbi draft 1.0 standard, the BPE APs affiliated with a BPE AP MLD transmit Privacy Beacon frames (according to the frame format provided in section 9.3.4.4 of this standard) instead of legacy Beacon frames (according to the frame format provided in section 9.3.3.2 of this standard).

[0102] As also observed above and that according to the IEEE 802.11TGbi draft 1.0 standard, a BPE AP MLD stores a pre-shared Identity Key (also referred to as preconfigured Identity Key) which has been previously shared with a BPE non-AP MLD. The pre-shared Identity Key allows a BPE STA affiliated with the BPE non-AP MLD to identify or discover a BPE AP affiliated with the BPE AP MLD.

[0103] In addition and according to some embodiments of the present disclosure, the BPE AP MLD also stores a Protected Security Capabilities Key which has been previously shared with a BPE non-AP MLD. The Protected Security Capabilities Key allows a BPE AP affiliated with the BPE AP MLD to advertise its security capabilities while ensuring its privacy. The Protected Security Capabilities Key is used as an input of a cypher algorithm used to encrypt a plaintext corresponding to the security capabilities.

[0104] Still according to some embodiments of the present disclosure, a mapping table is defined in the BPE AP MLD and in the BPE non-AP MLDs to associate each of the pre-shared Identity Keys with a Protected Security Capabilities Key. According to some embodiments, the pre-shared Identity Key and the Protected Security Capabilities Key are the same key.

[0105] Upon receiving an unprotected Privacy Beacon Solicit Request frame from a BPE non-AP MLD (step 802), the BPE AP encrypts its security capabilities by using its Protected Security Capabilities Key (step 805), for example similarly to the encryption step 605 in Figure 6.Still for the sake of illustration, the cipher suite used here is the Hybrid Public Key Encryption (HPKE) cipher suite in single-shot mode with pre-shared key (PSK) mode as specified in RFC 9180. It is referred to as HPKE-PSK-SingleShot. Other cipher suites may be used.

[0106] Still for the encryption (at the sender’s end), HPKE-PSK-SingleShot takes as inputs a key PSK that is pre-shared between the sender and the receiver, a plaintext message and Additional Authentication Data (AAD). As outputs, it delivers a ciphertext (i.e. , the encrypted message) and an Authentication Tag for verifying the integrity of the message and AAD.

[0107] For the decryption (at the receiver’s end), HPKE-PSK-SingleShot takes as inputs the same PSK used by the sender, the ciphertext (i.e., the encrypted message) and AAD. As outputs, it delivers a decrypted message corresponding to the original plaintext message and a Tag Verification (if the tag is correct, the message is considered as verified, i.e., it is considered as being authentic and unmodified).

[0108] According to some embodiments of the disclosure, a BPE AP associated with a BPE AP MLD encrypts its security capabilities by using its Protected Security Capabilities Key and adds the encrypted security capabilities within an unprotected Privacy Beacon frame (e.g., unprotected Privacy Beacon frame 500 in Figure 5) to be transmitted.

[0109] To that end, the BPE AP constructs an AAD, for example as specified in section 12.5.4.3.3 (Construct AAD) of the IEEE 802.11TGbi draft 1.0 standard, which includes a Frame Control, an Address 1, an Address 2 and an Identity Hash, for example Frame Control field 210’”, Address 1 field 212’”, Address 2 field 213’” and Identity Hash field 220’” of unprotected Privacy Beacon frame 500 in Figure 5.

[0110] As specified in the IEEE 802.11-2020 standard, the BPE AP encapsulates its security capabilities in a RSNE (e.g., RSNE 37T in Figure 5) and if necessary, a RSNXE (e.g., RSNXE 372’ in Figure 5) and / or a RSNE Override element (e.g., RSNE Override element 374’ in Figure 5) and / or a RSNE Override 2 element (e.g., RSNE Override 2 element 375’ in Figure 5) and / or a RSNXE Override element (e.g., RSNXE Override element 376’ in Figure 5) and / or other security lEs (e.g., other security lEs 377’ in Figure 5) relative to the security capabilities.

[0111] Next, the BPE AP concatenates, in a container (e.g., container 370’ in Figure 5), the list of the generated security lEs (e.g., RSNE 37T and / or RSNXE 372’ and / or RSNE Override element 374’ and / or RSNE Override 2 element 375’ and / or RSNXE Override element 376’ and / or security lEs 377’ relative to the security capabilities). Then, the BPE AP launches the encryption process with the cypher suite, HPKE-PSK-SingleShot takingas inputs, the Protected Security Capabilities Key as PSK, the container comprising the list of the generated security lEs as a plaintext message and the constructed AAD as AAD. As outputs, the BPE AP retrieves a ciphertext (corresponding to the list of encrypted security lEs) and a generated Authentication Tag.

[0112] Again, a data field varying over time may also be concatenated with the generated security lEs so that the Protected Security lEs vary over time (which makes it more difficult to identify and analyse).

[0113] Next, at step 810, the BPE AP generates an unprotected Privacy Beacon frame (e.g., Privacy Beacon frame 500 in Figure 5) containing a Protected Security Capabilities IE (e.g., Protected Security Capabilities IE 350’ in Figure 5) with a Protected Security lEs field (e.g., Protected Security lEs field 360’ in Figure 5) which includes the ciphertext and the Authentication Tag (not represented).

[0114] Next, at step 815, the BPE AP transmits the unprotected Privacy Beacon frame (e.g., unprotected Privacy Beacon frame 500 in Figure 5).

[0115] Figure 9 illustrates, using flowchart 900, an example of some steps carried out in a BPE STA affiliated with a BPE non-AP MLD to retrieve the security capabilities of a BPE AP affiliated with a BPE AP MLD according to some embodiments of the disclosure.

[0116] It is noted that according to some embodiments of the present disclosure and before retrieving security capabilities of a BPE AP affiliated with a BPE AP MLD, from a Privacy Beacon frame, the BPE non-AP MLD should store a pre-shared Identity Key (also referred to as a preconfigured Identity Key) which has been previously shared with the BPE AP MLD. The pre-shared Identity Key allows a BPE STA affiliated with the BPE non-AP MLD to identify or discover a BPE AP affiliated with the BPE AP MLD.

[0117] It is also noted that according to some embodiments of the present disclosure, the BPE non-AP MLD should also store a Protected Security Capabilities Key which has been previously shared with the BPE AP MLD. The Protected Security Capabilities Key allows it to retrieve the security capabilities of a BPE AP affiliated with the BPE AP MLD while ensuring its privacy. The Protected Security Capabilities Key is used as an input of a cypher algorithm used to encrypt a plaintext corresponding to the security capabilities (at the BPE AP’s end) and to decrypt the encrypted security capabilities (at the BPE STA’s end). As described above and according to some embodiments of the present disclosure, a mapping table is defined in the BPE AP MLD and in the BPE non-AP MLDs to associate each of the pre-shared Identity Keys with a Protected Security CapabilitiesKey. According to some embodiments, the pre-shared Identity Key and the Protected Security Capabilities Key are the same key.

[0118] As illustrated, a first step (step 901) is directed to transmitting, from the BPE STA affiliated with the BPE non-AP MLD to a BPE AP affiliated with the BPE AP MD, an unprotected Privacy Beacon Solicit Request to solicit an unprotected Privacy Beacon frame (e.g., unprotected Privacy Beacon frame 500 in Figure 5) from the BPE AP.

[0119] In response, the BPE STA receives an unprotected Privacy Beacon (e.g., unprotected Privacy Beacon frame 500 in Figure 5) from the BPE AP (step 905).

[0120] Next, the BPE STA identifies or discovers the BPE AP MLD with its stored preshared Identity Keys (step 910, that may be similar to step 710 in Figure 7), for example as it is indicated in section 10.71.8.2 (BPE AP MLD Beaconing) of the IEEE 802.11TGbi draft 1.0 standard.

[0121] Once discovered with a given stored pre-shared Identity Key referred to pre_key, the BPE STA uses its mapping table to retrieve the Protected Security Capabilities Key corresponding to the pre_key (step 915, that may be similar to step 715 in Figure 7).

[0122] Next, the BPE STA extracts the list of encrypted security lEs and the authentication tag (step 920) from the Protected Security lEs field (e.g., Protected Security lEs field 360’ in Figure 5) of the Protected Security Capabilities IE (e.g., Protected Security Capabilities IE 350’ in Figure 5) of the received unprotected Privacy Beacon frame (e.g., unprotected Privacy Beacon frame 500 in Figure 5).

[0123] Once the encrypted security lEs have been extracted, the BPE STA initiates their decryption (step 925). To that end, the BPE STA constructs an AAD, for example as specified in section 12.5.4.3.3 (Construct AAD) of the IEEE 802.11TGbi draft 1.0 standard, which may include the Frame Control field (e.g., Frame Control field 210’” in Figure 5), the Address 1 field (e.g., Address 1 field 212’” in Figure 5), the Address 2 field (e.g., Address 2 field 213’” in Figure 5) and the Identity Hash field (e.g., Identity Hash field 220’” in Figure 5) of the received unprotected Privacy Beacon.

[0124] Next, the BPE STA launches the decryption process with the cypher suite, HPKE-PSK-SingleShot taking as inputs, the Protected Security Capabilities Key pre_key as PSK, the encrypted Security lEs extracted at step 920 as ciphertext and the constructed AAD as AAD. As outputs, it delivers a decrypted message corresponding to the list of decrypted security lEs, that is validated if the Tag Verification computed during the decryption process corresponds to the Authentication Tag extracted at step 920. The Security Capabilities are derived directly from the list of decrypted security lEs including the RSNE (e.g., RSNE 37T in Figure 5) and potentially, a RSNXE (e.g., RSNXE 372’ inFigure 5) and / or a RSNE Override element (e.g., RSNE Override element 374’ in Figure 5) and / or a RSNE Override 2 element (e.g., RSNE Override 2 element 375’ in Figure 5 and / or a RSNXE Override element (e.g., RSNXE Override element 376’ in Figure 5) and / or other security lEs (e.g., other security lEs 377’ in Figure 5).

[0125] Next, the BPE AP MLD initiates (step 930) a standard authentication procedure with the BPE AP MLD through its affiliated BPE STA, based on the security capabilities of the BPE AP affiliated with the BPE AP MLD retrieved at step 925.

[0126] Figure 10 schematically illustrates an example of a communication device that may correspond to any of the stations described by reference to Figure 1, of a wireless network, configured to implement at least some embodiments of the disclosure. The communication device, referenced 1000, may preferably be a device such as a microcomputer, a workstation, or a light portable device. Communication device 1000 may comprise a communication bus 1005 to which may be connected:

[0127] - a central processing unit 1001, such as a processor, denoted CPU;

[0128] - a memory 1003, denoted MEM, for storing an executable code of methods or steps of the methods according to embodiments of the disclosure as well as the registers adapted to record variables and parameters necessary for implementing the methods; and

[0129] - at least two communication interfaces 1002 and 1002’ connected to the wireless communication network, for example a communication network according to one of the IEEE 802.11 family of standards, via transmitting and receiving antennas 1004 and 1004’, respectively.

[0130] Preferably, communication bus 1005 may provide communication and interoperability between the various elements included in the communication device 1000 or connected to it. The representation of the bus is not limiting and in particular the central processing unit is operable to communicate instructions to any element of the communication device 1000 directly or by means of another element of the communication device 1000.

[0131] The executable code may be stored in a memory that may either be read only, a hard disk, or on a removable digital medium such as for example a disk. According to an optional variant, the executable code of the programs can be received by means of the communication network, via the interface 1002 or 1002’, in order to be stored in the memory 1003 of communication device 1000 before being executed.In some embodiments, communication device 1000 may be a programmable apparatus which uses software to implement embodiments of the disclosure. However, alternatively, some embodiments of the disclosure may be implemented, totally or in partially, in hardware (for example, in the form of an Application Specific Integrated Circuit or ASIC).

[0132] Embodiment(s) of the disclosure can also be realized by a computer of a system or apparatus that reads out and executes computer executable instructions (e.g., one or more programs) recorded on a storage medium (which may also be referred to more fully as a “non-transitory computer-readable storage medium”) to perform the functions of one or more of the above-described embodiment(s) and / or that includes one or more circuits (e.g., application specific integrated circuit (ASIC)) for performing the functions of one or more of the above-described embodiment(s), and by a method performed by the computer of the system or apparatus by, for example, reading out and executing the computer executable instructions from the storage medium to perform the functions of one or more of the above-described embodiment(s) and / or controlling the one or more circuits to perform the functions of one or more of the above-described embodiment(s). The computer may comprise one or more processors (e.g., central processing unit (CPU), micro processing unit (MPU)) and may include a network of separate computers or separate processors to read out and execute the computer executable instructions. The computer executable instructions may be provided to the computer, for example, from a network or the storage medium. The storage medium may include, for example, one or more of a hard-disk, a random-access memory (RAM), a read-only memory (ROM), a storage of distributed computing systems, an optical disk (such as a compact disc (CD), digital versatile disc (DVD), etc.), a flash memory device, a memory card, and the like.

[0133] Expressions such as “comprise”, “include”, “incorporate”, “contain”, “is” and “have” are to be construed in a non-exclusive manner when interpreting the description and its associated claims, namely construed to allow for other items or components which are not explicitly defined also to be present. Reference to the singular is also to be construed in be a reference to the plural and vice versa.

[0134] A person skilled in the art will readily appreciate that various parameters disclosed in the description may be modified and that various embodiments disclosed may be combined without departing from the scope of the disclosure.

Claims

CLAIMS1. A communication method in a station, STA, in a wireless network, the method comprising:obtaining a key that is pre-shared between the station and an accesspoint, AP;de-encrypting an information field of a beacon transmitted by the AP using an encryption key obtained from the pre-shared key; andauthenticating with the AP using information obtained from the information field.

2. The method of claim 1, further comprising identifying the AP as a function of the pre-shared key.

3. The method of claim 2, further comprising computing a hash value from data of the beacon for each of a plurality of pre-shared keys, the pre-shared key being obtained from the set of pre-shared keys as a function of the computed hash values and of a hash value from the beacon.

4. The method of any one of claims 1 to 3, wherein the encryption key is the preshared key.

5. The method of any one of claims 1 to 3, wherein the encryption key is obtained from a mapping table associating pre-shared keys with encryption keys.

6. The method of any one of claims 1 to 5, wherein the information field comprises an encrypted Robust Security Network, RSN, element of the AP.

7. The method of claim 6, wherein the information field further comprises at least one of an encrypted RSN extension element, RSNXE, an encrypted RSN Override element, an encrypted RSN Override 2 element and an encrypted RSNXE Override element.

8. The method of any one of claims 1 to 7, wherein the beacon is a Privacy Beacon.

9. The method of any one of claims 1 to 7, wherein the beacon is received in response to transmitting a beacon solicit request.

10. The method of claim 9, wherein the beacon is an unprotected Privacy Beacon.

11. The method of any one of claims 1 to 10, wherein the pre-shared key is used to obfuscate address fields in the beacon.

12. The method of any one of claims 1 to 11, wherein the station is a Basic Service Set, BSS, Privacy Enhancement, BPE non-AP affiliated with a BPE non-AP multi-link device MLD and wherein the AP is a BPE AP affiliated with a BPE AP MLD.

13. A communication method in an access-point, AP, in a wireless network, the method comprising:obtaining a key that is pre-shared between the AP and a station, STA; encryption an information field of a beacon to be transmitted to the STA, using an encryption key obtained from the pre-shared key; and authenticating with the STA using information obtained by the STA from the information field.

14. The method of 13, wherein the pre-shared key is used to obfuscate address fields in the beacon.

15. The method of claim 13 or claim 14, wherein the encryption key is the preshared key.

16. The method of claim 13 or claim 14, wherein the encryption key is obtained from a mapping table associating pre-shared keys with encryption keys.

17. The method of any one of claims 13 to 16, wherein the information field comprises an encrypted Robust Security Network, RSN, element of the AP.

18. The method of claim 17, wherein the information field further comprises at least one of an encrypted RSN extension element, RSNXE, an encrypted RSN Overrideelement, an encrypted RSN Override 2 element and an encrypted RSNXE Override element.

19. The method of any one of claims 13 to 18, wherein the beacon is a Privacy Beacon.

20. The method of any one of claims 13 to 18, wherein the beacon is transmitted in response to receiving a beacon solicit request.

21. The method of claim 20, wherein the beacon is an unprotected Privacy Beacon.

22. The method of any one of claims 13 to 21, wherein the station is a Basic Service Set, BSS, Privacy Enhancement, BPE non-AP affiliated with a BPE non-AP multi-link device MLD and wherein the AP is a BPE AP affiliated with a BPE AP MLD.

23. A computer program product for a programmable apparatus, the computer program product comprising a sequence of instructions for implementing each of the steps of the method according to any one of claims 1 to 22 when loaded into and executed by the programmable apparatus.

24. A non-transitory computer-readable storage medium storing instructions of a computer program for implementing each of the steps of the method according to any one of claims 1 to 22.

25. A processing unit in a Basic Service Set, BSS, Privacy Enhancement, BPE, non-access point, AP, multi-link device, MLD, for communicating, the processing unit being configured to carry out each of the steps of the method according to any one of claims 1 to 12.

26. A processing unit in a Basic Service Set, BSS, Privacy Enhancement, BPE, access point, AP, multi-link device, MLD, for communicating, the processing unit being configured to carry out each of the steps of the method according to any one of claims 13 to 22.