IP Library Granted Patent US 11,770,699
Granted Patent B2
US 11,770,699 · App. 17/529,874 · Granted Sep 26, 2023

Media access control (MAC) address privacy handling

Inventor: Hui Luo (Marlboro, NJ)
Assignee: Cypress Semiconductor Corporation
H04W12/02H04L47/24H04L61/50H04L63/205H04W12/03H04W12/0431H04W12/106H04W76/10H04L2101/622
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,770,699
App. No.
17/529,874
Granted
Sep 26, 2023
Kind
B2
Abstract

Implementations disclosed describe techniques to allow wireless devices to initially connect with randomized MAC addresses and send an encrypted permanent MAC for differentiated services. In one method, a first wireless device connects to an access point (AP) using a randomized MAC address. The first wireless device receives a request for a permanent MAC address from the AP. The first wireless device determines whether to send the permanent MAC address. Responsive to determining to send the permanent MAC address, the first wireless device encrypts the permanent MAC address to obtain an encrypted MAC address and sends a response to the request, including the encrypted MAC address, to the AP.

Claims (49)

1. A method of operating a wireless device, the method comprising:

connecting to an access point (AP) using a first media access control (MAC) address, the first MAC address being a randomized MAC address;

receiving, from the AP, a request for a permanent MAC address;

determining whether to send the permanent MAC address;

responsive to determining to send the permanent MAC address, encrypting the permanent MAC address to obtain an encrypted MAC address; and

sending, to the AP, a response to the request, the response comprising the encrypted MAC address, wherein the receiving the request and sending the response comprises a four-way handshake comprising:

receiving, from the AP, a first message, wherein the first message comprises a first nonce generated at the AP;

sending, to the AP, a second message, wherein the second message comprises a second nonce generated at the wireless device;

deriving a pairwise temporal key (PTK) using a pairwise master key (PMK), the first nonce, the second nonce, the first MAC address, and the permanent MAC address;

receiving, from the AP, a third message, wherein the third message comprises an encrypted session key and the request for the permanent MAC address; and

sending, to the AP, a fourth message, wherein the fourth message comprises the encrypted MAC address, wherein the encrypted MAC address is encrypted using at least a portion of the PTK.

2. The method of claim 1 , wherein the receiving the request comprises receiving the request in at least one of a beacon frame, a probe response, or a message of a multi-way handshake between the wireless device and the AP.

3. The method of claim 1 , wherein the receiving the request comprises receiving the request in a beacon frame or a probe response from the AP, wherein connecting to the AP comprises sending a first response to the beacon frame or the probe response, the first response comprising the first MAC address.

4. The method of claim 1 , wherein the third message and the fourth message are formatted in a key data encapsulation (KDE) format.

5. The method of claim 1 , wherein the second message further comprises a first message integrity code (MIC), wherein the third message comprises a second MIC, and wherein the fourth message comprises a third MIC.

6. The method of claim 1 , wherein the determining whether to send the permanent MAC address comprises checking a policy that specifies that the permanent MAC address is shareable with the AP.

7. A wireless station (STA) comprising:

a memory device to store a permanent media access control (MAC) address of the wireless STA; and

a processing device coupled to the memory device, wherein the processing device is to:

generate a randomized MAC address;

connect to an access point (AP) using the randomized MAC address;

receive, from the AP, a request for the permanent MAC address;

determine whether to send the permanent MAC address;

responsive to a determination to send the permanent MAC address, encrypt the permanent MAC address to obtain an encrypted MAC address; and

send, to the AP, a response to the request, the response comprising the encrypted MAC address, wherein the request and the response are part of a four-way handshake in which the wireless STA is to:

receive, from the AP, a first message, wherein the first message comprises a first nonce generated at the AP;

send, to the AP, a second message, wherein the second message comprises a second nonce generated at the wireless station;

derive a pairwise temporal key (PTK) using a pairwise master key (PMK), the first nonce, the second nonce, the first MAC address, and the permanent MAC address;

receive, from the AP, a third message, wherein the third message comprises an encrypted session key and the request for the permanent MAC address; and

send, to the AP, a fourth message, wherein the fourth message comprises the encrypted MAC address, wherein the encrypted MAC address is encrypted using at least a portion of the PTK.

8. The wireless STA of claim 7 , wherein the request is included in at least one of a beacon frame, a probe response, or a message of a multi-way handshake between the wireless STA and the AP.

9. The wireless STA of claim 7 , wherein the request is included in a beacon frame or a probe response from the AP, and wherein the processing device is to connect to the AP by sending a first response to the beacon frame or the probe response, the first response comprising the randomized MAC address.

10. The wireless STA of claim 7 , wherein the third message and the fourth message are formatted in a key data encapsulation (KDE) format.

11. The wireless STA of claim 7 , wherein the second message further comprises a first message integrity code (MIC), wherein the third message comprises a second MIC, and wherein the fourth message comprises a third MIC.

12. The wireless STA of claim 7 , wherein the memory device is to further store a policy, and wherein the processing device is to determine whether to send the permanent MAC address by checking the policy that specifies that the permanent MAC address is shareable with the AP.

13. A wireless network of wireless devices comprising:

a first wireless device; and

a second wireless device, wherein the first wireless device and the second wireless device are connected using a first media access control (MAC) address, the first MAC being a randomized MAC address, and wherein:

the second wireless device is to send to the first wireless device a first message comprising a first nonce generated at the second wireless device;

the first wireless device is to send to the second wireless device a second message comprising a second nonce generated at the first wireless device;

the first wireless device is to derive a temporal key using at least the first nonce, the second nonce, the first MAC address, and the permanent MAC address;

the second wireless device is to send to the first wireless device a third message comprising an encrypted session key and a request for a permanent MAC address;

the first wireless device is to encrypt the permanent MAC address with at least a portion of the temporal key to obtain an encrypted MAC address; and

the first wireless device is to send to the second wireless device a fourth message comprising the encrypted MAC address.

14. The wireless network of claim 13 , wherein the third message and the fourth message are formatted in a key data encapsulation (KDE) format.

15. The wireless network of claim 13 , wherein the second message further comprises a first message integrity code (MIC), wherein the third message comprises a second MIC, and wherein the fourth message comprises a third MIC.

16. The wireless network of claim 13 , wherein the first wireless device is to store a policy, and wherein the first wireless device is to determine whether to send the permanent MAC address by checking the policy that specifies that the permanent MAC address is shareable with the second wireless device.

17. The wireless network of claim 13 , wherein the second wireless device is to change a Quality of Service (QoS) parameter from a first value to a second value based on the permanent MAC address.

18. The wireless network of claim 13 , wherein the second wireless device is to apply an access control policy to the first wireless device based on the permanent MAC address.

Assignments (2)
MERGER Recorded Nov 14, 2025
From: CYPRESS SEMICONDUCTOR CORPORATION
To: INFINEON TECHNOLOGIES AMERICAS CORP.
Reel/Frame 073571/0456 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: LUO, HUI
To: CYPRESS SEMICONDUCTOR CORPORATION
Reel/Frame 064994/0783 →