WLAN MAC Header Encryption for Device Tracking Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless local area network (WLAN) communications face issues with privacy as identifiable characteristics, such as power management and data transmission patterns, can be externally visible and used to identify and track client devices, leading to unauthorized tracking and profiling.

Innovation Solution

Encrypting certain Media Access Control (MAC) header fields in WLAN transmissions, including power management, retry, and data fields, with over-the-air (OTA) values to prevent identification and tracking, while allowing decryption for legitimate communication partners.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If MAC header fields are transmitted in clear text for standard WLAN communication, then communication compatibility and ease of operation are maintained, but device privacy is compromised and devices can be tracked and fingerprinted

Engineering Contradiction:
Improveprivacy informationVSAvoidcommunication compatibility
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The MAC header is segmented into two parts: unencrypted fields (source address, destination address, frame control) that maintain compatibility, and encrypted fields (power management, retry, more data, EOSP, TID) that protect privacy. This segmentation allows the system to simultaneously achieve privacy protection and communication compatibility by encrypting only the sensitive portions while leaving the structural identifiers visible.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the MAC header are treated differently regarding encryption. The power management bit, retry bit, more data bit, EOSP bit, and TID field are encrypted to protect device behavior patterns, while the address fields remain unencrypted to maintain basic communication functionality. This local differentiation of encryption quality resolves the contradiction between privacy and compatibility.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If MAC header fields are encrypted to prevent tracking, then device privacy and security are improved, but the complexity of the communication protocol increases

Engineering Contradiction:
Improveunauthorized trackingVSAvoidprotocol complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The encryption of MAC header fields is performed in advance during the frame assembly process, before transmission. The transmitter encrypts the power management, retry, more data, EOSP, and TID fields as part of the normal frame construction workflow, so that by the time the frame is transmitted, the privacy protection is already in place without adding complexity to the transmission itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption mechanism uses the existing cryptographic infrastructure already present in WLAN security protocols. Rather than creating a new complex encryption system specifically for MAC headers, the patent leverages the existing AES encryption and key management mechanisms, effectively copying the proven security approach and adapting it to the MAC header context, thereby minimizing additional protocol complexity.

Inventive Principle:
Principle #26Copying

3Loss of information

If real-time MAC header bits are encrypted during transmission, then privacy protection is enhanced, but the processing time and computational overhead increase

Engineering Contradiction:
Improveidentifiable characteristicsVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The encryption of MAC header fields is performed as a preliminary step during frame assembly, before the frame is queued for transmission. This allows the encryption to be done in advance when the frame is being constructed, rather than adding processing delays at the point of transmission or reception, thereby minimizing the impact on real-time communication performance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption of MAC header fields is merged with the existing frame assembly and encryption workflow. Rather than being a separate, additional processing step, the MAC header encryption is integrated into the normal frame construction process where cryptographic operations are already being performed, thereby utilizing existing computational resources and minimizing additional processing time.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12513512B2Encrypting MAC header fields for WLAN privacy enhancement
Publication Date: 2025.12.30 APPLE INC
  • US12513512B2 patent drawing
  • US12513512B2 patent drawing
  • US12513512B2 patent drawing

AI summary

Embodiments are disclosed for encrypting media access control (MAC) Header fields for Wireless LAN (WLAN) privacy enhancement. For example, a transceiver of a station (STA) or an access point (AP) can set a real time Media Access Control (MAC) header bit in a payload of an aggregated MAC Protocol Data Unit (A-MPDU) subframe to an actual value of a power management (PM) field of a MAC header of the A-MPDU subframe. The transceiver can encrypt the payload, set the PM field to an over the air (OTA) PM value, and transmit the A-MPDU subframe over the air. The OTA PM value can include all zeros, a predetermined value, or a randomized value The transceiver can also set static MAC header bits in the payload of the A-MPDU subframe to corresponding actual values of an aggregated MAC service data unit (A-MSDU) present field of the A-MPDU subframe.