Variable Authentication Identifier for AP Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless access points (APs) in WLANs face privacy concerns as they can be tracked using their static SSIDs, which are broadcasted, allowing unauthorized devices to identify their location and connect maliciously, compromising privacy.
Innovation Solution
Implementing a variable authentication identifier (AID) instead of a static SSID, using a token shared between the AP and stations (STAs) to authenticate membership in a service set, ensuring only authorized devices can connect while maintaining AP privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a static SSID is broadcasted for AP identification, then devices can easily identify and connect to the AP, but the AP becomes trackable and vulnerable to unauthorized connections
Solution Approach 1:
The patent applies dynamics by transitioning from a static SSID to a dynamic AID that changes over time. The AID is updated periodically or upon authentication events, making it impossible for unauthorized devices to track the AP using a persistent identifier. This dynamic approach maintains connectivity while eliminating tracking vulnerability.
Solution Approach 2:
The patent changes the identification parameter from a fixed SSID string to a variable AID that can take multiple values. The AID is derived from authentication credentials and changes based on the authentication state and time, thereby preserving connection functionality while preventing unauthorized tracking.
2Object-affected harmful factors
If a variable AID is used instead of static SSID, then AP privacy is enhanced and tracking is prevented, but authentication complexity increases
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where the AID is derived from existing authentication credentials (such as pre-shared keys or certificates) rather than requiring completely new authentication protocols. This intermediary approach maintains privacy while leveraging existing authentication infrastructure to manage complexity.
Solution Approach 2:
The patent performs preliminary authentication actions during initial connection setup, establishing the AID generation mechanism in advance. Once the AID derivation method is established through preliminary authentication, subsequent connections can use the predefined mechanism without adding significant complexity, as the computational overhead is performed once during setup.
3Productivity
If beacon frames are broadcasted with SSID information, then STAs can discover and connect to the WLAN, but the AP location and identity become exposed
Solution Approach 1:
The patent applies local quality by providing different identification information to different audiences: authenticated STAs receive the actual AID for connection, while unauthenticated devices only see obscured or generic identifiers in beacon frames. This localized information distribution enables network discovery for legitimate users while preventing identity exposure to unauthorized devices.
Data Source
AI summary
This disclosure provides methods, devices and systems for using a variable authentication identifier (AID) for access point (AP) privacy. For example, instead of a persistent SSID, an AID is used by a station (STA) to authenticate the AP before connecting to the AP. The AP is associated with a service set, and the STA has stored a secret token associated with the service set. Before connecting to the AP, a broadcasted probe request from the STA includes no identifying information other than the token. The AP generates the AID from the token and provides the AID in a probe response. The STA is able to identify the AP as being associated with a service set and connect to the AP using the token and AID without the token and the AID being used by another device not associated with the service set to identify the AP.


