Privacy-Preserving Station Discovery Using Identity Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless local area networks, especially in Neighborhood Area Networks (NAN), the broadcast of beacon frames for station discovery lacks privacy protection as MAC addresses are openly shared, making user information vulnerable to unauthorized access.

Innovation Solution

A security identity discovery method is introduced where identity codes are used instead of MAC addresses, and ciphertexts are employed for authentication, ensuring that only authenticated stations can confirm identities through specific algorithms, thereby enhancing privacy protection during the discovery process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If beacon frames are broadcast for station discovery, then station discovery capability is improved, but user privacy protection deteriorates due to MAC address exposure

Engineering Contradiction:
Improvestation discovery capabilityVSAvoidprivacy vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism using challenge-response pairs and session keys. Instead of directly exposing MAC addresses in beacon frames, the system uses authentication frames with challenge tokens that mediate the identification process. The session key acts as an intermediary that allows stations to verify each other's identities without revealing permanent MAC addresses, thus resolving the contradiction between discovery capability and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates temporary copies of identification information in the form of challenge-response tokens and session keys. Instead of using the original MAC address directly in broadcasts, the system generates ephemeral authentication tokens that serve as temporary copies for verification purposes. These copied identification elements can be discarded after authentication, preventing long-term privacy exposure while maintaining discovery functionality.

Inventive Principle:
Principle #26Copying

2Measurement precision

If MAC addresses are used for station identification, then identification accuracy is improved, but security protection deteriorates due to unauthorized access

Engineering Contradiction:
Improveidentification accuracyVSAvoidsecurity protection
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent fundamentally changes the identification parameter from static MAC addresses to dynamic authentication tokens. The system transitions from using fixed hardware addresses to using time-varying challenge-response pairs and session keys. This parameter change maintains identification accuracy because the authentication mechanism still uniquely identifies stations, while simultaneously improving security because the identifying information changes frequently and cannot be easily intercepted or spoofed.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements preliminary authentication actions before allowing normal communication. Stations must first exchange challenge-response pairs and establish session keys before they can communicate using their identification information. This preliminary action ensures that only authenticated stations can access the network, preventing unauthorized access while maintaining accurate identification of legitimate users.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If encryption is implemented for identity protection, then privacy protection is improved, but communication complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidcommunication complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies encryption selectively rather than to all communications. Instead of encrypting all data transmissions, the system only encrypts the authentication phase using challenge-response mechanisms and session key establishment. This partial application of encryption provides sufficient privacy protection for the critical identity disclosure moment while avoiding the excessive complexity that would result from encrypting all communications. The simplicity of unencrypted data transmission is preserved for non-sensitive communications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2822310B1Secure identity discovery and communication method
Publication Date: 2017.05.03 HUAWEI TECH CO LTD
  • EP2822310B1 patent drawingFigure 1
  • EP2822310B1 patent drawingFigure 2
  • EP2822310B1 patent drawingFigure 3

AI summary

The present invention provides a security identity discovery method, through hiding or omitting MAC addresses of the first station and a second station in a frame for identity discovery between the two stations, adopting identity codes to identify the identities of the two stations and authenticating the identities by using a ciphertext, improves the degree of privacy protection during identity discovery of the stations.