Privacy-Enhanced BSS Discovery with Encrypted Beacons
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems, particularly WLANs based on IEEE 802.11 standards, face significant privacy challenges due to openly discoverable access points, leakage of personally identifiable information (PII) and personally correlated information (PCI), and lack of encryption in beacon frames, allowing for tracking and fingerprinting of devices.
Innovation Solution
Implementing a privacy enhanced BSS (PE BSS) that includes encrypted beacons, random and changing MAC addresses, encrypted frame exchanges, and privacy-enhanced frame formats to secure association and discovery operations, while maintaining compatibility with legacy systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If beacon frames are transmitted openly for discovery operations, then device discoverability and network establishment are improved, but device privacy and security deteriorate due to tracking and fingerprinting
Solution Approach 1:
The beacon frame is segmented into public information elements and private information elements. Public elements contain necessary discovery information (SSID, basic network parameters) while private elements contain sensitive information (MAC address, detailed device identifiers) that are encrypted or omitted, thus enabling discoverability while preventing tracking
Solution Approach 2:
Sensitive personally identifiable information (PII) and personally correlated information (PCI) are extracted and removed from the beacon frame content. The beacon transmits only essential network access information while excluding tracking-enabling data, resolving the contradiction between discoverability and privacy protection
2Reliability
If MAC addresses are kept constant for device identification, then device tracking and network management are improved, but device privacy deteriorates due to persistent identification
Solution Approach 1:
The MAC address is transformed from a static identifier to a dynamic identifier that changes periodically or per network session. The device uses different MAC addresses at different times while maintaining consistent network access through higher-layer identification mechanisms, thus preventing tracking while preserving network management capability
Solution Approach 2:
Different identification qualities are applied in different contexts: constant identification (using higher-layer credentials) for network authentication and management, but changing identification (MAC addresses) for wireless medium access and broadcast communications, thus achieving both reliability and privacy
3Adaptability or versatility
If all stations can receive and process beacon frames, then network accessibility is improved, but security deteriorates due to unauthorized access and information leakage
Solution Approach 1:
Instead of encrypting the entire beacon frame (which would prevent any discovery), only partial encryption is applied to specific sensitive information elements while leaving public elements unencrypted. This allows stations to receive and process beacon frames for basic discovery while preventing unauthorized access to sensitive information
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Systems, methods, and mechanisms for a privacy enhanced basic service set (BSS), including privacy enhancements for both access points and wireless stations as well as privacy enchantments for authentication, association, and discovery operations. Further, the systems, methods, and mechanisms disclosed may continue to support legacy wireless stations and are thus, backward compatible. A station may communicate with a legacy BSS of a wireless network to transition to a PE BSS of the wireless network. The station may receive, from the PE BSS of the wireless network, an encrypted beacon, wherein the encrypted beacon is decoded based on information received from the legacy BSS and perform, with the PE BSS of the wireless network, an encrypted handshake procedure to authenticate and associate with the PE BSS of the wireless network.