Multi-profile connection of a station to an access point of a radiocommunication network via secure transmission of a selected passphrase
Patent Information
- Application Number
- PCT/EP2026/054279
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-10
- Filing Date
- 2026-02-17
- Publication Date
- 2026-09-17
Smart Images

Figure EP2026054279_17092026_PF_FP_ABST
Abstract
Description
Multi-profile connection of a station to an access point of a radio communication network via secure transmission of a selected password
[0001] The present invention relates to the field of connecting a station to an access point of a wireless telecommunications network, in particular a Wi-Fi network. More specifically, it relates to assigning a profile to a station, defining its rights within the telecommunications network.
[0002] In a home network, several mechanisms have been proposed for managing the rights of a given station and controlling access.
[0003] For example, the physical address of the station, such as its MAC (Medium Access Control) address, can be used to identify a given station and thus distinguish different profiles depending on the stations at the access point. However, this method has the disadvantage of being incompatible with dynamic MAC address mechanisms (MAC address randomization).
[0004] Another method involves creating several separate telecommunications networks, each corresponding to a distinct profile. Typically, a first Wi-Fi network grants all rights to connected stations, and a second Wi-Fi network, called "guest," grants minimal rights, for example, access to an external network (the Internet) without allowing access to local resources connected to the Wi-Fi network.
[0005] However, this method has many drawbacks.
[0006] Thus, each deployed telecommunications network necessarily occupies a space on the spectrum of the frequency band in use. The addition of even a single "guest" network generates interference on the Wi-Fi frequency bands, leading to both network congestion and increased energy consumption.
[0007] Furthermore, it makes it difficult to offer more than two distinct profiles, especially since each deployed telecommunications network, as we have seen, consumes available resources. The granularity of access rights management is therefore necessarily very limited.
[0008] Another method involves offloading access rights management to an application layer. Users must then log in to a captive web portal and enter usernames and passwords corresponding to their profile.
[0009] This method has the drawback of requiring an additional step for station users, thus impacting the user experience. Furthermore, it leaves the physical layer of the telecommunications network unrestricted, creating a vulnerability to attacks and malicious activity targeting both the network and the access point.
[0010] Therefore, there is a need to improve current state-of-the-art proposals.
[0011] The invention aims to improve upon the state of the art. In particular, it proposes to use passwords, or phrases, as identifiers for a rights profile.
[0012] More specifically, a method is proposed for connecting an access point to a station capable of being associated, in which said access point has a set of passphrases, each passphrase being associated with a rights profile, comprising steps implemented by said access point of: Receiving an association request from said station; Detecting the presence of a passphrase identifier in said request; Establishing a connection based on said passphrase
[0013] Thus, based on a passphrase, typically chosen or selected by a user or application on the station, a rights profile can be determined for that station from a set of profiles previously defined by an administrator on the access point. The station user must be provided with the appropriate passphrase so that the station can connect with the correct rights profile.
[0014] This rights profile allows you to define the station's access rights to the various resources accessible through this radio communication network.
[0015] The connection is only established if an identifier is detected in the request. Otherwise, the connection is not established. As we will see later, if the identifier is absent, the access point requires an encrypted identifier using an encryption key known to the access point.
[0016] According to preferred embodiments, the invention comprises one or more of the following features, which may be used separately, in partial combination, or in total combination: the access point transmits information within a beacon signal indicating its ability to interpret the request from the station. This allows for compatibility management between equipment that may or may not implement the described method.The process further includes the following steps: In the absence of said identifier, transmission of a public key from said access point, then receipt of a provision request containing said password encrypted using a public key; Determination of said password by said access point; Assignment of a rights profile to said station based on said password; the public key could be provided to the station in another way; the key could be transmitted by an entity separate from the access point, for example a server connected to the communication network; said access point transmits said public key in response to a key request transmitted by said station.
[0017] Another object relates to a method of connecting a station to an access point suitable for association, in which said access point has a set of passphrases, each passphrase being associated with a rights profile, comprising steps implemented by said station of: Issuing an association request intended for said access point, in which, if said station has previously been associated with said access point, is inserted an identifier of a passphrase; Establishing a connection based on said passphrase.
[0018] According to preferred embodiments, the invention comprises one or more of the following features, which may be used separately, in partial combination, or in total combination: The method further comprises the steps of: If said station has not been previously associated with said access point, issuing a suitable key request to receive a public key from said access point, and then a provisioning request containing said passphrase encrypted using said public key. Said association request contains information indicating the ability of said station to issue said key and provisioning requests.
[0019] According to embodiments, these two processes may also include the following features: The process further includes a security phase conforming to the WPA3-SAE protocol. The said passphrase identifier is transmitted in the third message of a 4-step handshake.
[0020] Another object relates to an access point suitable for a connection from a station capable of being associated, in which said access point has a set of passphrases, each passphrase being associated with a rights profile, comprising steps implemented by said access point of: Receiving an association request from said station; Detecting the presence of an identifier of a passphrase present in said request; Establishing a connection based on said passphrase.
[0021] Another object relates to a station adapted for connection to an access point suitable for association, in which said access point has a set of passphrases, each passphrase being associated with a rights profile, comprising steps implemented by said station of: Issuing an association request intended for said access point, in which, if said station has previously been associated with said access point, is inserted an identifier of a passphrase; Establishing a connection based on said passphrase.
[0022] Another aspect of the invention relates to a computer program capable of being implemented by an access point or station, the program comprising code instructions which, when executed by a processor, cause the processor to carry out the steps of the process as previously defined.
[0023] Other aspects, objectives, advantages, and features of the invention will become clearer upon reading the following detailed description of preferred embodiments thereof, given by way of non-limiting example, and made with reference to the accompanying drawings in which:
[0024] This illustrates a possible implementation context for a local radio communication network allowing one or more stations to be connected to an access point;
[0025] laillustre an illustrative chronogram of a method of implementing the proposed processes;
[0026] laillustre un chronogram detailing an example of implementation of the SAE protocol according to the 802-11 standard;
[0027] laillustrates the 4-step handshake mechanism that can be used in one embodiment.
[0028] DETAILED DESCRIPTION OF SPECIFIC IMPLEMENTATION METHODS
[0029] This illustrates a context for implementing a telecommunications network that allows one or more stations to be connected to an access point.
[0030] This telecommunications network can be a wireless local area network, commonly called WLAN for "Wireless Local Area Network" in English.
[0031] This wireless local area network can conform to Wi-Fi, or wifi, protocols as specified in the IEEE 802.11 family normative documents (or ISO / IEC 8802-11).
[0032] Such a network is identified by a network identifier SSID (for "service set identifier"). In infrastructure mode (connecting a station to an access point), it is used to identify the wireless access point.
[0033] Stations can be of various types, but they all share the common characteristic of having the means to be connected. Specifically, in one embodiment, these means enable connection to the network. They essentially consist of radio communication components and electronic and computer components that allow the implementation of the protocol stacks necessary for managing network protocols and for receiving and transmitting data packets.
[0034] On the, three types of STA stations are represented: a computer ORD, a mobile communication terminal, MOB, and a connected television TV.
[0035] The mobile terminal (MOB) is typically a smartphone or a tablet…. The computer can be a desktop computer (or “desktop” according to English terminology) or a laptop.
[0036] The TV can be natively connected or connected via an associated device such as an HDMI dongle connected to the TV.
[0037] An example of an external device that communicates with a TV is Chromecast. Chromecast is a real-time media streaming device (media gateway) developed and marketed by Google. The device plugs into a TV's HDMI port and communicates, via Wi-Fi, with another internet-connected device (computer, smartphone, tablet, etc.) to display media content on the TV, received from a Google Cast-compatible app, the Google Chrome browser on a computer, or certain Android devices.
[0038] Of course, other types of STA stations may also need to connect to a wireless local area network. These include connected objects which, within the framework of the Internet of Things (IoT), connect to each other or to a server in order to deploy all of their functionalities.
[0039] In an infrastructure deployment model, stations connect to the wireless local network via one or more access points (APs). These access points act as hubs, through which data flows to and from the stations must pass.
[0040] These access points allow STA stations to control access to the wireless local area network. The stations must authenticate themselves with an access point, which then grants them the rights corresponding to its profile. If a station cannot authenticate correctly, it cannot access the wireless local area network.
[0041] This local wireless network can be a home network, that is, corresponding to a user's home.
[0042] The wireless local area network can also be a business network, particularly for small businesses (SMEs / VSEs), places open to the public (restaurants, bars, cafes…), etc.
[0043] Access points can also be of different types, depending in particular on the type of location in which the wireless local area network is deployed.
[0044] An access point can be a dedicated device, marketed as such. It can also form a gateway to an external network such as the internet.
[0045] For example, devices that provide internet access from a home environment usually offer the function of a Wi-Fi access point.
[0046] For example, in a home environment, the access point can be integrated into an internet connection box, commonly called an "internet box" or home gateway. An example of such a box is the Livebox™ from Orange.
[0047] Another example of an access point could be a Wi-Fi repeater.
[0048] The connection between a station and an access point can be done in peer-to-peer mode.
[0049] It includes a security phase. Indeed, an access point allows stations to access resources available through the radio communication network.
[0050] These resources include in particular: Access to external networks, such as the Internet but also a possible extranet or a cloud computing server, files stored on local equipment connected to the radio communication network, such as an internal hard drive in a computer, or connected to an Internet connection box, or to a NAS type box, physical equipment such as a printer, a surveillance camera, IoT connected objects, etc.
[0051] For a business or an individual, it is important that access to these resources be protected. Therefore, in order to connect to an access point, a workstation must meet certain security requirements.
[0052] Various techniques are used to do this.
[0053] In the following, we will mainly describe the WPA3-SAE mechanism, but other mechanisms are also conceivable, including evolutions of this mechanism or derivations particularly adapted to certain contexts.
[0054] The previous mechanism, WPA2-Personal, offered an evolution, MPSK (for "Multi Pre-Shared Key"), whereby several keys, PSKs, can be defined from multiple passphrases. One of the objectives is to reduce the risk of compromise of the master passphrase.
[0055] The MPSK mechanism relies on the access point's ability to identify the passphrase used by the station during a 4-way handshake.
[0056] However, it is not possible to use such a mechanism with WPA3-SAE, because according to this protocol, the exchanges of the 4-step handshake phase are initiated directly on the basis of a pass phrase previously agreed upon during a first SAE phase (for "Simultaneous Authentication of Equals").
[0057] An alternative method is therefore proposed to allow the use of a set of passphrases within the WPA3-SAE protocol. In particular, it remains compatible with all devices using this protocol and, therefore, does not require modification.
[0058] To do this, it is proposed to indicate the passphrase prior to the exchanges of the handshake phase in time, so that this can be carried out on the basis of this passphrase to finalize the connection between the station and the access point.
[0059] Figures 2 and 3 illustrate two chronograms illustrating two modes of implementation of the proposed processes.
[0060] It is assumed that the access point (AP) has a set of passphrases, each associated with a rights profile.
[0061] One of these passphrases is communicated to a STA station. For example, it can be transmitted in written or oral form by a radio communication network manager or administrator, or via a graphic code such as a QR code, etc. This passphrase is determined according to a rights profile desired by this administrator for the STA station in question. Use cases will be discussed in more detail later.
[0062] It is also assumed that the STA station wants to connect to the AP access point.
[0063] It is proposed to implement a secure channel between the STA station and the AP access point allowing the station to transmit the selected passphrase to the AP access point prior to the steps of the secure connection protocol requiring knowledge of this passphrase.
[0064] In particular, this S1 phase of transmitting a passphrase can be implemented before an SAE authentication phase, "Simultaneous Authentication of Equals", explained in particular in the 802.11 standard, in chapter 12.4.5.
[0065] This S1 phase of transmitting a passphrase can rely on a particular protocol to guarantee the security of the transmitted information (i.e. the passphrase).
[0066] Various protocols can be implemented to ensure this security. In one embodiment, it is proposed to base the S1 phase protocol on a protocol derived from the PKEX protocol of the "Easy Connect" or DPP standard. Based on this PKEX protocol, new messages are proposed, and some PKEX messages are modified to adapt the protocol for the secure transmission of the passphrase. Given the modifications made to the PKEX protocol, a new protocol name can be added to the Easy Connect standard.
[0067] The Wi-Fi Easy Connect™ mechanism, also known as the Device Provisioning Protocol (DPP), is a secure method for connecting devices to a Wi-Fi network without requiring passwords. Wi-Fi Easy Connect uses an encrypted channel to send Wi-Fi credentials between devices, employing the PKEX protocol, defined in IETF draft Harkins pkex05, entitled "Public Key Exchange".
[0068] According to one embodiment, the access point is expected to communicate, initially, its ability to support this new capability, that is to say, on the one hand, to have a set of passphrases associated with rights profiles, and on the other hand, to be able to ensure the transmission of a passphrase by the STA station according to a secure mechanism in phase S1.
[0069] According to one embodiment, the access point AP thus transmits information within a beacon signal M0 indicating its ability to interpret requests that will subsequently be transmitted by the STA station.
[0070] This M0 message can be the signaling message periodically sent by the access point (AP) to inform nearby devices about the existence of its associated Wi-Fi network. The access point sends a beacon approximately every 100 ms to advertise its network. Nearby Wi-Fi stations listen for these M0 beacons to detect and list available networks. When a STA station wants to connect, it sends a connection request frame to the access point.
[0071] The M0 beacon message contains various information fields, including: SSID (for "Service Set Identifier"): the identifier of the Wi-Fi radio communication network associated with the access point AP, BSSID (for "Basic Service Set Identifier"): MAC address of the access point, The frequency used for the communication channel, The encryption method used (WPA2, WPA3…), The time interval between consecutive beacon messages (usually 100 ms), The capabilities of the radio communication network (802.11 a / b / g / n / ac / ax), etc.
[0072] In addition, the M0 beacon message may include an optional "Extended Capabilities" field. This optional field can be used to transmit information indicating the station's ability to interpret requests that will subsequently be transmitted by the STA. This information can be binary and therefore encoded on a single bit, in a predetermined position within the "Extended Capabilities" field.
[0073] According to the proposed method, in the S1 phase of transmitting a passphrase, the STA station sends an association request M1, intended for the access point AP.
[0074] This association request may conform to an "association request" message according to the DPP protocol.
[0075] In one embodiment, this M1 association request contains information indicating the STA station's capacity to issue key and provision requests subsequently planned in phase S1 established between the station and the access point. In other words, this information indicates whether the STA station is suitable for implementing the protocol exchanges corresponding to this phase S1.
[0076] Indeed, the proposed methods rely on a new protocol enabling the secure transmission of the passphrase (selected from a set of available passphrases) from the workstation to the access point. Each party must be modified to support this protocol. It may also be beneficial to communicate compatibility information between the two parties to ensure proper communication regardless of each party's situation. In particular, it is essential to ensure compatibility between parties that are adapted and those that are not to this new protocol.
[0077] This information can be binary and therefore conveyed by a single bit within the M1 association request.
[0078] Furthermore, the M1 association request can contain a second piece of information indicating whether the station has previously been associated with the access point (AP). To do this, the station can maintain a history of the access points to which it has been associated.
[0079] This illustrates a situation where the STA station has previously been associated with the access point.
[0080] This illustrates a situation where the STA station has not previously been associated with the AP access point.
[0081] As can be seen, the protocol simplifies exchanges when the STA station has been previously associated with the access point, saving the time required for protocol exchanges and the associated resources (energy, etc.).
[0082] If the STA station has previously been associated with the access point (AP), the M1 association request may also contain an identifier for the selected passphrase. This identifier is not the passphrase itself, nor is it an equivalent that would allow a third party to determine the passphrase from this information. As will be seen later, this identifier is only meaningful to the access point (AP), so its potential eavesdropping by a cyber attacker would not allow them to determine the passphrase. For example, this identifier could be a sequential number of the passphrase within the set of passphrases available to the access point.
[0083] The passphrase identifier was transmitted by the access point (AP) to the STA station during a previous association. Therefore, the STA station can be configured to remember the access point(s) with which it has been associated, along with a corresponding passphrase identifier.
[0084] Furthermore, according to one embodiment, the issuance of the request in association M1 may be subject to the receipt of the appropriate information in the tag message M0 as previously described.
[0085] In response to receiving this M1 association request, the AP access point can transmit an M1' association response (or "Association Response" according to the DPP protocol terminology).
[0086] The transmission of the passphrase identifier in the M1 association message is sufficient to allow the access point AP and the STA station to continue the secure connection process according to the state of the art.
[0087] If the STA station has not been previously associated with the access point (AP), the STA station does not have an identifier for the selected passphrase. Therefore, another mechanism, described in [reference], must be implemented to allow the access point (AP) to obtain the passphrase from the STA station.
[0088] The STA station can transmit an M2 exchange request (or "Exchange Request" according to DPP protocol terminology) to the AP access point. The AP access point can respond to this request with an "Exchange Response" message, M2'.
[0089] The dialogue corresponding to this S1 phase of transmitting a passphrase (in the case where the STA station has not previously been associated with the AP access point) may also include the sending of an M3 key request.
[0090] This M3 request is adapted to receive, in response M3', a public key B R from the access point.
[0091] This M3 / M3' exchange can be compared to the "PKEX Commit Reveal Request" / "PKEX Commit Reveal Response" exchange described in Figure 5 of the "Wi-Fi Easy Connect™" standard; however, the access point does not need to know the station's public key. Therefore, the M3 key request may not contain any parameters, or at least not the station's keys. The sole purpose of the key request may be to trigger the transmission of the public key. R from the access point to the STA station.
[0092] According to an embodiment based on this PKEX protocol, the public key B R The access point can be transmitted according to the SIV encryption method defined by IETF RFC 5297 entitled "Synthetic Initialization Vector (SIV) Authenticated Encryption Using the Advanced Encryption Standard (AES)".
[0093] The access point generates a shared secret z for SIV encryption, so that the public key BR is inserted in the form AES-SIV(B R ) z in the reply message M3'.
[0094] This shared secret can be generated according to the Wi-Fi Easy Connect™ standard:
[0095]
[0096] It depends on a shared code ("code") between the STA station and the AP access point. For each new STA station, a new code must be exchanged. This code lends trust to the public key B. R from the AP access point.
[0097] HKDF is a derivation function defined by IETF RFC 5869, entitled "HMAC-based Extract-and-Expand Key Derivation Function (HKDF)".
[0098] Station STA can thus know the public key B R from the AP access point.
[0099] She can use this public key to encrypt the transmission of the selected passphrase.
[0100] More specifically, the STA station generates an ephemeral private / public key pair, b i / B i respectively, at each execution of phase S1 of transmission of a passphrase.
[0101] A secret q=HKDF(b i x B R ) allows the exchange of a cryptographic representation of the selected passphrase. It depends on the public key B R of the access point and the ephemeral private key b i from the STA station.
[0102] In addition, a salt can be used to prevent certain attacks, such as "rainbow table" attacks in case of compromise of the hash function.
[0103] The STA station can then transmit to the AP access point an M4 provisioning request containing said encrypted passphrase using said public key.
[0104] For example, according to one embodiment, this query may contain the following fields: Public key Bi of station STA, An AES-SIV encrypted field (salt) q An AES-SIV (SHA256(pp+salt)) encrypted field q
[0105] "PP" represents the passphrase. "salt" represents a salt.
[0106] The access point (AP) may respond with a reply message, M4'. This message may not have substantial content and may only serve to acknowledge receipt of the M4 provisioning request by the access point.
[0107] In an S2 step, the AP access point can then determine the passphrase from this identifier present in the message transmitted by the STA station (and selected by a user or application of the STA station).
[0108] In an S3 step, the AP access point assigns a rights profile to the STA station based on the selected passphrase.
[0109] The associations between passphrase and access profiles can be planned in advance.
[0110] According to one embodiment, rights profiles can correspond, directly or indirectly, to virtual local networks.
[0111] These virtual networks can be of the VLAN type, for "Virtual Local Area Network". They allow you to define access rights to the wireless local network for the station in question, with the desired level of granularity.
[0112] A table of correspondence between the passphrases, PP1, PP2, … can then be provided. and virtual networks, VLAN1, VLAN2, …, corresponding to as many rights profiles.PP1PP2… VLAN1 VLAN2…
[0113] Furthermore, the login process can continue based on the selected passphrase.
[0114] This connection process can correspond to the classic mechanisms of association between a station and an access point as described in the standardization of Wi-Fi radio communication networks.
[0115] In particular, a security phase can be implemented. According to one embodiment, this S4 security phase can conform to the SAE protocol, "Simultaneous Authentication of Equals." This authentication phase is explained in detail in the 802.11 standard, section 12.4.5.
[0116] This SAE protocol relies on the transmission of several messages: a commit message (or "SAE commit message"), a confirm message (or "SAE confirm message"), an authentication request ("SAE Authentication Request"), to which an authentication response message ("SAE Authentication Response") is replied; and an association request ("SAE Association Request"), to which an association response message ("SAE Association Response") is replied.
[0117] Each party can issue a "commit" message at any time. It can only issue a "confirm" message after issuing a "commit" message. When both parties have received a "commit" message and a "confirm" message, authentication is complete (an authentication acceptance message can be issued).
[0118] The principle of the SAE protocol is peer-to-peer, without either party being privileged or considered "master" in the authentication process. Generally speaking, either party can therefore initiate the process and issue the "commit" message.
[0119] In addition, the proposed methods include, in an S5 phase, the establishment of a connection based on the selected passphrase.
[0120] In particular, it may be proposed, in one embodiment, to perform a 4-step handshake in order to finalize the connection according to the selected passphrase.
[0121] In this same S5 phase, the selected passphrase identifier is transmitted from the access point (AP) to the station (STA). This way, the station knows this identifier and can use it during a subsequent association attempt with the same access point. As mentioned previously, a simplified exchange can then be implemented when an association has already been established between a station and an access point, leveraging the knowledge of this passphrase identifier.
[0122] This S5 four-step handshake, or four-pass handshake, finalizes the connection according to the selected passphrase, allowing multiple keys to be derived from this passphrase. This passphrase will not be used directly in subsequent exchanges between the access point (AP) and the station (STA).
[0123] More specifically, from a pass phase, PSK, a master key PMK (for "Pairwise Master Key") is first derived.
[0124] The passphrase can contain 8 to 63 ASCII characters or 64 hexadecimal symbols (256 bits). If a passphrase in ASCII character form is used, it is converted to a 256-bit PMK master key, for example by applying a PBKDF2 key derivation function.
[0125] This PBKDF2 derivation mechanism (short for "Password-Based Key Derivation Function 2") is described, for example, in the associated Wikipedia page: https: / / fr.wikipedia.org / wiki / PBKDF2.
[0126] In an alternative deployment method, an authentication server can be implemented, which derives the master key and distributes it to workstations and access points. This authentication server can be compliant with the IEEE 802.1X standard.
[0127] The PMK master key is never directly used for encryption or integrity checking. It is used to generate temporary encryption keys, PTK, for exchanges between a given access point (PA) and STA station.
[0128] The temporary key PTK (for "Pairwise Transient Key") actually comprises several temporal keys, each with a dedicated use: the key confirmation key, KCK (for "Key Confirmation Key"), which is mainly used during the 4-way handshake, the key encryption key, KEK (for "Key Encryption Key"), the temporary key TK (for "Temporary Key"), and the temporary MIC key, TMK ("Temporary MIC Key").
[0129] The temporary PTK key is derived from the master key PMK, a fixed string of characters, the MAC address of the access point, the MAC address of the station, and two random numbers, one generated by the station and the other by the access point.
[0130] Laillustrates the 4-way handshake mechanism that can be used in one embodiment of the proposed process.
[0131] In the first mh1 message, the access point (AP) transmits a first random number to the STA station that wishes to authenticate itself. According to the 802.11i standard, this random number is called the "Announcement".
[0132] In a step Sh1, the STA station generates a second random number, called "Snonce" according to the 802.11i standard.
[0133] From two random numbers, the PMK master key, and the MAC addresses, the AP access point can determine the temporary PTK key.
[0134] The STA station can then transmit an mh2 message to the AP access point containing the second random number, Snonce, and an integrity code, MIC (for "Message Integrity Check") using the key confirmation key, KCK (from the temporary key PTK).
[0135] This mh2 message is not encrypted. Upon receiving it, in an Sh2 step, the access point can therefore extract the second random number, Snonce. It can then calculate a temporary PTK key itself, in the same way as the access point.
[0136] Using this temporary key, the access point can then verify the integrity of the received message. This verification may consist of checking the integrity of the MIC integrity field contained in the second message. It can thus ensure that the STA station correctly knows the PMK primary key because it was able to correctly derive the PTK temporary key, and then the temporal keys (key confirmation key, KCK) used to generate the MIC integrity code.
[0137] The access point can verify the integrity of the mh2 message using the key in its possession.
[0138] If this key does not allow verification of the integrity of the mh2 message, then the connection from the STA station is rejected.
[0139] In the favorable case, an mh3 message can then be transmitted to the STA station, in accordance with the specifications of the IEEE 802.11i standard.
[0140] This third mh3 message contains a Group Temporal Key, GTK (“Group Temporal Key”), encrypted with the key encryption key, KEK, and derived from a Group Master Key, GMK (“Group Master Key”) and a random number “GNonce”, as well as an integrity field, MIC, calculated on the content of this third message.
[0141] According to one embodiment, the passphrase identifier is transmitted in this third message, mh3, of the 4-step handshake.
[0142] Upon receiving this third mh3 message, the station initiates an Sh3 step to verify the integrity of the received message. This verification may consist of checking the integrity of the MIC integrity field. This ensures that the access point knows the PMK master key and that it has correctly derived the PTK temporary key and then the temporal keys (including the key encryption key, KEK).
[0143] The fourth message, mh4, acknowledges the successful completion of the entire 4-way handshake authentication phase. It indicates that the STA station has correctly installed the keys and is ready to begin data encryption. Upon receiving it, both the station and the access point know that each party has obtained, calculated, and installed the various encryption keys for the protocol.
[0144] At this stage, the AP access point can effectively connect the STA station to the local Wi-Fi radio communication network, and they can exchange data by encrypting it with the keys derived and exchanged during this time-based handshake authentication phase, "4-way handshake".
[0145] The authentication process enabling the connection can thus take place in accordance with the state of the art as described by the 802.11 standard, but on the basis of a passphrase selected by the STA station from a set of available passphrases.
[0146] The STA station can then access the resources available on the local radio communication network according to the access rights profile corresponding to the selected passphrase.
[0147] The local radio communication network administrator can define a set of passphrase / rights profile pairs as needed.
[0148] In the case of a home network, it can define different use cases. For example
[0149] For friends visiting the house, it can offer a minimal service of connection to the external network "Internet", but not to internal resources (file system, printers, IoT...).
[0150] For friends of a student child, it can offer access to a range of resources relevant to the student's work. These friends, visiting the home, can then access collaborative files to complete their shared assignments.
[0151] Passphrases can be determined in various ways, which are known in themselves. They can be set arbitrarily by the administrator, they can be randomly generated, etc.
[0152] Generally speaking, a passphrase is a string of characters. These characters can be letters (uppercase or lowercase), numbers, and special characters, usually directly accessible from the keyboard. The term "passphrase" is often used rather than "password" because passphrases often contain sequences of words that sometimes resemble a sentence for mnemonic purposes, but the two terms are often used interchangeably.
[0153] Of course, the present invention is not limited to the examples and embodiment described and illustrated, but is defined by the claims. In particular, it is susceptible of numerous variations accessible to those skilled in the art.
Claims
Method of connecting an access point (AP) to a station (STA) capable of being associated, wherein said access point has a set of passphrases, each passphrase being associated with a rights profile, comprising steps implemented by said access point (AP) of:Receiving (S1) an association request (M1) from said station (STA);Detecting the presence of an identifier of a passphrase present in said request;Establishment (S5) of a connection based on said passphrase. A method according to the preceding claim, wherein said access point (AP) transmits information within a beacon signal (M0) indicating its ability to interpret said request from said station.
3. A method according to any one of the preceding claims, further comprising the steps of: In the absence of said identifier, transmission of a public key (B R) of said access point and then receiving a provisioning request (M4) containing said encrypted passphrase using said public key. Determination (S2) of said passphrase by said access point. Assignment (S3) of a rights profile to said station based on said passphrase.
4. Method according to the preceding claim, wherein said access point (AP) transmits said public key (B R) in response to a key request (M3) transmitted by said station (STA)5. Method of connecting a station (STA) to an access point (AP) capable of being associated, wherein said access point has a set of passphrases, each passphrase being associated with a rights profile, comprising steps implemented by said station (STA) of: Issuing (S1) an association request to said access point, in which, if said station has been previously associated with said access point, an identifier of a passphrase is inserted; Establishing (S5) a connection based on said passphrase.
6. Method according to the preceding claim, further comprising steps of: If said station has not been previously associated with said access point, issuance of a key request (M3) adapted to receive a public key (B R) said access point and then a provisioning request (M4) containing said encrypted passphrase using said public key.
7. Method according to the preceding claim, wherein said association request (M1) contains information indicating a capacity of said station to issue said key and provisioning requests (M3, M4). Method according to any one of the preceding claims, further comprising a security phase (S4) conforming to the WPA3-SAE protocol. Method according to any one of the preceding claims, wherein said passphrase identifier is transmitted in a third message (mh3) of a 4-step handshake.Access point (AP) suitable for a connection of a station (STA) capable of being associated, wherein said access point has a set of passphrases, each passphrase being associated with a rights profile, comprising steps implemented by said access point (AP) of: Receiving (S1) an association request (M1) from said station (STA); Detecting the presence of an identifier of a passphrase present in said request; Establishing (S5) a connection based on said passphrase.11.A station (STA) adapted for connection to an access point (AP) capable of being associated, wherein said access point has a set of passphrases, each passphrase being associated with a rights profile, comprising steps implemented by said station (STA) of: Issuing (S1) an association request intended for said access point, in which, if said station has previously been associated with said access point, an identifier of a passphrase is inserted; Establishing (S5) a connection based on said passphrase.
12. A computer program capable of being implemented by an access point (AP) or by a station (STA), the program comprising code instructions which, when these instructions are executed by a processor, cause the processor to implement the steps of the method defined in any one of claims 1 to 9.