Privacy Enhanced BSS Encryption and MAC Randomization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems, particularly in WLANs based on the IEEE 802.11 standard, face challenges in ensuring privacy for access points and wireless stations, especially during authentication, association, and discovery operations. Legacy systems are not privacy optimized, leading to potential leaks of personally identifiable information (PII) and personally correlated information (PCI).
Innovation Solution
The implementation of a privacy-enhanced Basic Service Set (BSS) that includes encrypted beacons, passive and active scanning mechanisms, association and re-association procedures, random and changing MAC addresses, and encrypted frame exchanges. This system enhances privacy by limiting discoverability and tracking of access points and wireless stations, while maintaining backward compatibility with legacy devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If encrypted beacons and authentication procedures are implemented, then privacy protection is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The system segments BSS operations into legacy mode (unencrypted beacons) and privacy-enhanced mode (encrypted beacons with OWE). This allows devices to choose appropriate privacy levels and prevents information leakage only where needed, rather than requiring complete system reconfiguration.
Solution Approach 2:
The patent introduces an intermediary key establishment mechanism (OWE handshake) that mediates between the need for privacy and device compatibility. The intermediary allows legacy devices to coexist with privacy-enhanced devices without requiring full encryption infrastructure.
2Object-affected harmful factors
If MAC addresses are randomized and changing, then tracking and discoverability are reduced, but device identification and connection stability become more difficult
Solution Approach 1:
The system implements dynamic MAC address randomization where the BSS ID changes periodically or based on conditions. This provides tracking protection while maintaining connection stability through the dynamic nature of the identifier, allowing devices to reconnect using updated identifiers.
Solution Approach 2:
The patent employs periodic changes to BSS identifiers and encryption keys. This periodic action prevents continuous tracking while ensuring that legitimate devices can re-establish connections at regular intervals, balancing privacy with reliability.
3Object-affected harmful factors
If privacy-enhanced modes are implemented, then information security is improved, but backward compatibility with legacy devices deteriorates
Solution Approach 1:
The system applies different quality levels of privacy protection to different BSS operations. Legacy BSS operations remain unencrypted for compatibility, while privacy-enhanced BSS operations use OWE encryption. This local differentiation allows information security improvements without forcing legacy device incompatibility.
Solution Approach 2:
The access point is designed with multi-functionality to support both legacy BSS mode and privacy-enhanced BSS mode simultaneously. This universality allows the system to serve both legacy and modern devices, maintaining backward compatibility while offering enhanced privacy options.
4Object-affected harmful factors
If encrypted handshakes and authentication procedures are used, then authentication security is improved, but operational time and complexity increase
Solution Approach 1:
The system performs preliminary key establishment through the OWE handshake before actual data transmission begins. This preliminary action secures the communication channel in advance, ensuring authentication security is established before time-sensitive operations occur.
Solution Approach 2:
The patent implements optimized authentication procedures that skip unnecessary legacy handshake steps when OWE is available. This rushing through of essential security measures reduces the time penalty associated with enhanced authentication while maintaining security.
Data Source
AI summary
Systems, methods, and mechanisms for a privacy enhanced basic service set (BSS), including privacy enhancements for both access points and wireless stations as well as privacy enchantments for authentication, association, and discovery operations. Further, the systems, methods, and mechanisms disclosed may continue to support legacy wireless stations and are thus, backward compatible. A station may communicate with a legacy BSS of a wireless network to transition to a PE BSS of the wireless network. The station may receive, from the PE BSS of the wireless network, an encrypted beacon, wherein the encrypted beacon is decoded based on information received from the legacy BSS and perform, with the PE BSS of the wireless network, an encrypted handshake procedure to authenticate and associate with the PE BSS of the wireless network.


