Client-driven randomized and changing media access control (mac) address (rcm) mechanism
US-2024422202-A1 · Dec 19, 2024 · US
US2016135041A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016135041-A1 |
| Application number | US-201514926616-A |
| Country | US |
| Kind code | A1 |
| Filing date | Oct 29, 2015 |
| Priority date | Nov 10, 2014 |
| Publication date | May 12, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods, systems, apparatuses, and devices are described for wireless station privacy using media access control (MAC) address randomization. The wireless station may identify a MAC address for use with over-the-air transmissions and a persistent MAC address for backend communications. The wireless station may communicate the OTA MAC address and the persistent MAC address to an access point. The wireless station and the access point may exchange data frames and perform MAC replacement techniques to map the OTA MAC address to the persistent MAC address. The persistent MAC address may provide for data routing, mobility management, etc., whereas the OTA MAC address may provide for privacy for the wireless transmissions.
Opening claim text (preview).
What is claimed is: 1 . A method for wireless communication at a wireless station, comprising: determining a first media access control (MAC) address associated with over-the-air (OTA) communications between the wireless station and an access point during a communication session; determining a second MAC address associated with backend communications via the access point during the communication session; and communicating the first MAC address and the second MAC address to the access point via a secure channel. 2 . The method of claim 1 , further comprising: generating a random MAC address, the random MAC address comprising a third MAC address, wherein the third MAC address is used as a source address prior to communicating the first MAC address and the second MAC address to the access point via the secure channel. 3 . The method of claim 1 , further comprising: generating a random MAC address, the random MAC address comprising the first MAC address; and transmitting at least one message to the access point comprising the random MAC address via the secure channel. 4 . The method of claim 1 , further comprising: performing, with the access point, a security association process to establish the secure channel. 5 . The method of claim 4 , further comprising: transmitting information indicative of the first MAC address and the second MAC address to the access point in a message 4 of the security association process, wherein the security association process is a 4-way handshake procedure, wherein the first MAC address and the second MAC address are encrypted. 6 . The method of claim 4 , further comprising: transmitting information indicative of the first MAC address and the second MAC address to the access point in a message 1 of the security association process, wherein the security association process is a 2-way handshake procedure. 7 . The method of claim 1 , further comprising: receiving a data frame from the access point during the communication session, the data frame comprising information indicative of the first MAC address; replacing the first MAC address in the data frame with the second MAC address; and decoding the data frame based at least in part on the second MAC address. 8 . The method of claim 1 , further comprising: identifying a data frame to be transmitted to the access point during the communication session, the data frame comprising information indicative of the second MAC address; replacing the second MAC address in the data frame with the first MAC address; and transmitting the data frame to the access point using the first MAC address as a source address. 9 . The method of claim 1 , further comprising: receiving a data frame from the access point during the communication session, the data frame comprising a MAC frame having the second MAC address as a destination address being encapsulated with a MAC frame header having the first MAC address as a destination address; removing the MAC frame encapsulating the second MAC address; and decoding the data frame based at least in part on the second MAC address. 10 . The method of claim 1 , further comprising: identifying a data frame to be transmitted to the access point during the communication session; encapsulating a MAC frame having the second MAC address as a destination address using a MAC frame header having the first MAC address as a destination address; and transmitting the data frame to the access point, the data frame comprising the encapsulated MAC frame. 11 . The method of claim 1 , wherein the second MAC address is valid for the communication session. 12 . The method of claim 11 , further comprising: deriving the second MAC address based at least in part on a pairwise master key known by the wireless station and the access point. 13 . The method of claim 1 , wherein the first MAC address is valid for the communication session. 14 . The method of claim 1 , further comprising: changing the first MAC address during the communication session based at least in part on a pairwise master key known by both the wireless station and the access point. 15 . The method of claim 1 , wherein the second MAC address is a permanent MAC address of the wireless station. 16 . An apparatus for wireless communication, comprising: a processor; memory in electronic communication with the processor; and instructions being stored in the memory, the instructions being executable by the processor to: determine a first media access control (MAC) address associated with over-the-air (OTA) communications between a wireless station and an access point during a communication session; determine a second MAC address associated with backend communications via the access point during the communication session; and communicate the first MAC address and the second MAC address to the access point via a secure channel. 17 . The apparatus of claim 16 , further comprising instructions executable by the processor to: generate a random MAC address, the random MAC address comprising a third MAC address, wherein the randomly generated third MAC address is used as a source address prior to communicating the first MAC address and the second MAC address to the access point via the secure channel. 18 . The apparatus of claim 16 , further comprising instructions executable by the processor to: generate a random MAC address, the random MAC address comprising the first MAC address; and transmit at least one message to the access point comprising the random MAC address via the secure channel. 19 . The apparatus of claim 16 , further comprising instructions executable by the processor to: perform, with the access point, a security association process to establish the secure channel. 20 . The apparatus of claim 19 , further comprising instructions executable by the processor to: transmit information indicative of the first MAC address and the second MAC address to the access point in a message 4 of the security association process, wherein the security association process is a 4-way handshake procedure, wherein the first MAC address and the second MAC address are encrypted. 21 . The apparatus of claim 16 , further comprising instructions executable by the processor to: receive a data frame from the access point during the communication session, the data frame comprising information indicative of the first MAC address; replace the first MAC address in the data frame with the second MAC address; and decode the data frame based at least in part on the second MAC address. 22 . The apparatus of claim 16 , further comprising instructions executable by the processor to: identify a data frame to be transmitted to the access point during the communication session, the data frame comprising information indicative of the second MAC address; replace the second MAC address in the data frame with the first MAC address; and transmit the data frame to the access point using the first MAC address as a source address. 23 . The apparatus of claim 16 , further comprising instructions executable by the processor to: receive a data frame from the access point during the communication session, the data frame comprising a MAC frame having the second MAC address as a destination address being encapsulated with a MAC frame header having the first MAC address as a destination address; remove the MAC frame encapsulating the second MAC address; an
Address table lookup; Address filtering · CPC title
WLAN [Wireless Local Area Networks] · CPC title
Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title
Parsing or analysis of headers · CPC title
Layer-2 addresses, e.g. medium access control [MAC] addresses · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.