Multi-Link Device Privacy via Segmented Service Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication networks, particularly WiFi networks based on IEEE 802.11 standards, face challenges in protecting the privacy and security of Multi-Link Devices (MLD) by preventing unauthorized access to premium services and hiding correlations between client devices and access points, which are not adequately addressed by existing technologies.
Innovation Solution
The implementation of a networking system that configures multiple access points with different service sets and radio bands, allowing for differentiated services and secure associations based on client device types, while hiding premium services and correlations from non-authorized clients, using techniques such as broadcasting service data, establishing security associations, and dynamically changing MAC addresses to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the access point broadcasts service data indicating all available services including premium services, then client devices can discover and connect to available services, but non-premium client devices can also discover and potentially access premium services they are not authorized for
Solution Approach 1:
The service data is segmented into different portions: unencrypted service data indicating non-premium services, and encrypted service data indicating premium services. This segmentation allows non-premium clients to discover and access only appropriate services, while premium services remain hidden from unauthorized devices.
Solution Approach 2:
Encryption acts as an intermediary mechanism between the access point and client devices. The encrypted service data for premium services requires authentication credentials to decrypt, serving as a mediator that prevents unauthorized discovery while allowing authorized premium clients to access the services.
2Adaptability or versatility
If the access point provides differentiated services to different client types, then premium clients receive enhanced services, but non-premium clients can identify and target premium services and client addresses
Solution Approach 1:
Different portions of service data have different encryption qualities: non-premium service data is unencrypted and easily discoverable, while premium service data is encrypted and only accessible to authorized clients. This local quality differentiation enables tailored service discovery based on client authorization status.
Solution Approach 2:
The service data changes its 'visibility color' based on client authorization: unencrypted (visible) for non-premium services, and encrypted (hidden) for premium services. This dynamic visibility control allows the system to adapt service discoverability to the client's authorization level.
3Device complexity
If the access point uses a single MAC address for all links, then device management is simplified, but the correlation between premium access points and client devices can be traced
Solution Approach 1:
The MAC address is segmented into two components: a static base MAC address for identification purposes, and a dynamic component that changes periodically or based on authorization status. This segmentation allows the system to maintain tracking capability through the base address while preventing correlation through the dynamic component.
Solution Approach 2:
The MAC address transitions from a static value to a dynamic value that changes over time or based on authorization status. Premium clients may receive dynamic MAC addresses that prevent tracking, while non-premium clients interact with the base MAC address, creating different tracking characteristics for different client types.
Data Source
AI summary
A method for communicating over a wireless network includes broadcasting, by a Multi-Link Device (MLD) device, service data indicative of one or more services for wireless communication with a client device; wherein the service data indicates that a service type is differentiated based on a type of the client device; establishing a security association with the client device; and in response to establishing a security association with the client device, granting access by the client device to a subset of the one or more services based on the type of the client device.


