IP Library › Granted Patent US 11,765,577
Granted Patent B2
US 11,765,577 · App. 16/887,952 · Granted Sep 19, 2023

Identity obscuration for a wireless station

Inventors: Yong Liu (Campbell, CA); Christiaan A. Hartman (San Jose, CA); Tianyu Wu (Cupertino, CA); Qi Wang (Sunnyvale, CA); Jarkko L. Kneckt (Los Gatos, CA); Jinjing Jiang (San Jose, CA); Su Khiong Yong (Palo Alto, CA); Guoqing Li (Campbell, CA)
Assignee: Apple Inc.
H04W12/02H04W12/037
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,765,577
App. No.
16/887,952
Granted
Sep 19, 2023
Kind
B2
Abstract

Disclosed herein are system, method, and computer program product embodiments for identity obscuration of a station (STA) connected to a wireless network to prevent the tracking of the STA. Embodiments include a STA configured to establish a security association with an access point (AP) based on an original long term identity for the station and an identity of the AP. The STA can transmit a new long term identity for the STA to the AP based on the security association. The STA can then transmit a request frame to change the original short term identity assigned to the STA to the AP. The STA can receive a response frame from the AP. The response frame can include a new short term identity assigned to the station by the AP. The STA can then map its new long term identity to its new short term identity assigned by the AP.

Claims (61)

1. A station, comprising:

a transceiver; and

at least one processor communicatively coupled to the transceiver, wherein the at least one processor is configured to:

establish, using the transceiver, a first security association with an access point (AP) based at least in part on an original long term identity for the station, wherein the first security association uses a first set of cryptographic keys;

generate a new long term identity for the station;

establish, using the first security association, a second security association with the AP based at least in part on the new long term identity for the station and an identity of the AP, wherein the second security association uses a second set of cryptographic keys that is different from the first set of cryptographic keys;

transmit, using the second security association, a request frame to the AP to change an original short term identity assigned to the station;

receive, using the second security association, a response frame from the AP that comprises a new short term identity assigned to the station by the AP; and

map the new short term identity for the station to the new long term identity assigned to the station by the AP.

2. The station of claim 1 , wherein the station operates according to an Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, the new short term identity comprises an association identifier (AID) assigned by the AP, and the new long term identity comprises a media access control (MAC) address.

3. The station of claim 1 , wherein the at least one processor is further configured to:

receive, using the transceiver, an association response frame from the AP that comprises the original short term identity assigned to the station.

4. The station of claim 1 , wherein the at least one processor is further configured to:

encrypt the new long term identity using an encryption key in the first set of cryptographic keys; and

transmit, using the transceiver, the encrypted new long term identity to the AP.

5. The station of claim 1 , wherein the at least one processor is further configured to:

set at least one of a sequence control (SC) field or a packet number (PN) field in a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field in a frame to a random value in response to the new short term identity being assigned to the station.

6. The station of claim 1 , wherein the at least one processor is further configured to:

mask at least one of a High Throughput Control (HTC) field or a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field in a frame in response to the new short term identity being assigned to the station.

7. The station of claim 1 , wherein to receive the response frame from the AP the at least one processor is further configured to:

receive, using the second security association, the response frame from the AP based at least in part on a short term identity change period.

8. The station of claim 1 , wherein the at least one processor is further configured to:

transmit a frame to the AP, wherein the frame comprises first data representing the new short term identity for the station and second data representing the identity of the AP, and the frame excludes the new long term identity.

9. A method for hiding an identity of a station in a wireless network, comprising:

establishing, using a transceiver, a first security association with an access point (AP) based at least in part on an original long term identity for the station, wherein the first security association uses a first set of cryptographic keys;

generating, by at least one processor, a new long term identity for the station;

establishing, using the first security association, a second security association with the AP based at least in part on the new long term identity for the station and an identity of the AP, wherein the second security association uses a second set of cryptographic keys that is different from the first set of cryptographic keys;

transmitting, using the second security association, a request frame to the AP to change an original short term identity assigned to the station;

receiving, using the second security association, a response frame from the AP that comprises a new short term identity assigned to the station by the AP; and

mapping, by the at least one processor, the new short term identity for the station to the new long term identity assigned to the station by the AP.

10. The method of claim 9 , wherein the station operates according to an Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, the new short term identity comprises an association identifier (AID) assigned by the AP, and the new long term identity comprises a media access control (MAC) address.

11. The method of claim 9 , wherein the generating the new long term identity for the station further comprises:

generating, by the at least one processor, the new long term identity for the station based at least in a part on a random value.

12. The method of claim 9 , further comprising:

encrypting, by the at least one processor, the new long term identity using an encryption key in the first set of cryptographic keys; and

transmitting, using the transceiver, the encrypted new long term identity to the AP.

13. The method of claim 9 , further comprising:

setting, by the at least one processor, at least one of a sequence control (SC) field or a packet number (PN) field in a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field in a frame to a random value in response to the new short term identity being assigned to the station.

14. The method of claim 9 , further comprising:

masking, by the at least one processor, at least one of a High Throughput Control (HTC) field or a Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) field in a frame in response to the new short term identity being assigned to the station.

15. An access point (AP), comprising:

a transceiver; and

at least one processor communicatively coupled to the transceiver, wherein the at least one processor is configured to:

establish, using the transceiver, a first security association with a station based at least in part on an original long term identity for the station, wherein the first security association uses a first set of cryptographic keys;

receive, using the first security association, a new long term identity for the station from the station;

establish, using the first security association, a second security association with the station based at least in part on the new long term identity for the station and an identity of the AP, wherein the second security association uses a second set of cryptographic keys that is different from the first set of cryptographic keys;

receive, using the second security association, a request frame from the station to change an original short term identity assigned to the station by the AP;

transmit, using the second security association, a response frame to the station that comprises a new short term identity assigned to the station by the AP; and

map the new short term identity for the station to the new long term identity assigned to the station by the AP.

16. The AP of claim 15 , wherein the AP operates according an Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, the new short term identity comprises an association identifier (AID) assigned to the station by the AP, and the new long term identity comprises a media access control (MAC) address.

17. The AP of claim 15 , wherein the at least one processor is further configured to:

transmit, using the transceiver, an association response frame to the station that comprises the original short term identity assigned to the station by the AP.

18. The AP of claim 15 , wherein the at least one processor is further configured to:

decrypt the new long term identity for the station using a decryption key in the first set of cryptographic keys.

19. The AP of claim 15 , wherein to transmit the response frame to the station the at least one processor is further configured to:

transmit, using the second security association, the response frame to the station based at least in part on a short term identity change period.

20. The AP of claim 15 , wherein the at least one processor is further configured to:

determine a maximum number of stations associated with the AP;

partition a short term identity space into a set of blocks;

select a block in the set of blocks based at least in part on a random value; and

select the new short term identity for the station from the selected block in response to receiving the request frame from the station to change the original short term identity assigned to the station.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2020
From: LIU, YONG; HARTMAN, CHRISTIAAN A.; WU, TIANYU; WANG, QI; KNECKT, JARKKO L.; JIANG, JINJING; YONG, SU KHIONG; LI, GUOQING
To: APPLE INC.
Reel/Frame 052792/0066 →
Continuity (2)
Provisional Application 62873659 · Jul 12, 2019
Related Publication 20210014679A1 · Jan 14, 2021