WLAN MAC Header Encryption for Device Tracking Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless local area network (WLAN) communications face issues with privacy as identifiable characteristics, such as power management and data transmission patterns, can be externally visible and used to identify and track client devices, leading to unauthorized tracking and profiling.
Innovation Solution
Encrypting certain Media Access Control (MAC) header fields in WLAN transmissions, including power management, retry, and data fields, with over-the-air (OTA) values to prevent identification and tracking, while allowing decryption for legitimate communication partners.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If MAC header fields are transmitted in clear text for standard WLAN communication, then communication compatibility and ease of operation are maintained, but device privacy is compromised and devices can be tracked and fingerprinted
Solution Approach 1:
The MAC header is segmented into two parts: unencrypted fields (source address, destination address, frame control) that maintain compatibility, and encrypted fields (power management, retry, more data, EOSP, TID) that protect privacy. This segmentation allows the system to simultaneously achieve privacy protection and communication compatibility by encrypting only the sensitive portions while leaving the structural identifiers visible.
Solution Approach 2:
Different parts of the MAC header are treated differently regarding encryption. The power management bit, retry bit, more data bit, EOSP bit, and TID field are encrypted to protect device behavior patterns, while the address fields remain unencrypted to maintain basic communication functionality. This local differentiation of encryption quality resolves the contradiction between privacy and compatibility.
2Object-affected harmful factors
If MAC header fields are encrypted to prevent tracking, then device privacy and security are improved, but the complexity of the communication protocol increases
Solution Approach 1:
The encryption of MAC header fields is performed in advance during the frame assembly process, before transmission. The transmitter encrypts the power management, retry, more data, EOSP, and TID fields as part of the normal frame construction workflow, so that by the time the frame is transmitted, the privacy protection is already in place without adding complexity to the transmission itself.
Solution Approach 2:
The encryption mechanism uses the existing cryptographic infrastructure already present in WLAN security protocols. Rather than creating a new complex encryption system specifically for MAC headers, the patent leverages the existing AES encryption and key management mechanisms, effectively copying the proven security approach and adapting it to the MAC header context, thereby minimizing additional protocol complexity.
3Loss of information
If real-time MAC header bits are encrypted during transmission, then privacy protection is enhanced, but the processing time and computational overhead increase
Solution Approach 1:
The encryption of MAC header fields is performed as a preliminary step during frame assembly, before the frame is queued for transmission. This allows the encryption to be done in advance when the frame is being constructed, rather than adding processing delays at the point of transmission or reception, thereby minimizing the impact on real-time communication performance.
Solution Approach 2:
The encryption of MAC header fields is merged with the existing frame assembly and encryption workflow. Rather than being a separate, additional processing step, the MAC header encryption is integrated into the normal frame construction process where cryptographic operations are already being performed, thereby utilizing existing computational resources and minimizing additional processing time.
Data Source
AI summary
Embodiments are disclosed for encrypting media access control (MAC) Header fields for Wireless LAN (WLAN) privacy enhancement. For example, a transceiver of a station (STA) or an access point (AP) can set a real time Media Access Control (MAC) header bit in a payload of an aggregated MAC Protocol Data Unit (A-MPDU) subframe to an actual value of a power management (PM) field of a MAC header of the A-MPDU subframe. The transceiver can encrypt the payload, set the PM field to an over the air (OTA) PM value, and transmit the A-MPDU subframe over the air. The OTA PM value can include all zeros, a predetermined value, or a randomized value The transceiver can also set static MAC header bits in the payload of the A-MPDU subframe to corresponding actual values of an aggregated MAC service data unit (A-MSDU) present field of the A-MPDU subframe.


