Privacy-Preserving Station Discovery Using Identity Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless local area networks, especially in Neighborhood Area Networks (NAN), the broadcast of beacon frames for station discovery lacks privacy protection as MAC addresses are openly shared, making user information vulnerable to unauthorized access.
Innovation Solution
A security identity discovery method is introduced where identity codes are used instead of MAC addresses, and ciphertexts are employed for authentication, ensuring that only authenticated stations can confirm identities through specific algorithms, thereby enhancing privacy protection during the discovery process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If beacon frames are broadcast for station discovery, then station discovery capability is improved, but user privacy protection deteriorates due to MAC address exposure
Solution Approach 1:
The patent introduces an intermediary authentication mechanism using challenge-response pairs and session keys. Instead of directly exposing MAC addresses in beacon frames, the system uses authentication frames with challenge tokens that mediate the identification process. The session key acts as an intermediary that allows stations to verify each other's identities without revealing permanent MAC addresses, thus resolving the contradiction between discovery capability and privacy protection.
Solution Approach 2:
The patent creates temporary copies of identification information in the form of challenge-response tokens and session keys. Instead of using the original MAC address directly in broadcasts, the system generates ephemeral authentication tokens that serve as temporary copies for verification purposes. These copied identification elements can be discarded after authentication, preventing long-term privacy exposure while maintaining discovery functionality.
2Measurement precision
If MAC addresses are used for station identification, then identification accuracy is improved, but security protection deteriorates due to unauthorized access
Solution Approach 1:
The patent fundamentally changes the identification parameter from static MAC addresses to dynamic authentication tokens. The system transitions from using fixed hardware addresses to using time-varying challenge-response pairs and session keys. This parameter change maintains identification accuracy because the authentication mechanism still uniquely identifies stations, while simultaneously improving security because the identifying information changes frequently and cannot be easily intercepted or spoofed.
Solution Approach 2:
The patent implements preliminary authentication actions before allowing normal communication. Stations must first exchange challenge-response pairs and establish session keys before they can communicate using their identification information. This preliminary action ensures that only authenticated stations can access the network, preventing unauthorized access while maintaining accurate identification of legitimate users.
3Object-affected harmful factors
If encryption is implemented for identity protection, then privacy protection is improved, but communication complexity increases
Solution Approach 1:
The patent applies encryption selectively rather than to all communications. Instead of encrypting all data transmissions, the system only encrypts the authentication phase using challenge-response mechanisms and session key establishment. This partial application of encryption provides sufficient privacy protection for the critical identity disclosure moment while avoiding the excessive complexity that would result from encrypting all communications. The simplicity of unencrypted data transmission is preserved for non-sensitive communications.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention provides a security identity discovery method, through hiding or omitting MAC addresses of the first station and a second station in a frame for identity discovery between the two stations, adopting identity codes to identify the identities of the two stations and authenticating the identities by using a ciphertext, improves the degree of privacy protection during identity discovery of the stations.