Method and apparatus for communication

By encrypting and using integrity checks in the IEEE 802.11ax A control subfield, security and privacy issues in this subfield are resolved, improving the security and user experience of wireless LAN communication.

CN114501453BActive Publication Date: 2025-11-28APPLE INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111231758.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-10-19
Filing Date
2021-10-22
Publication Date
2025-11-28
Estimated Expiration
2041-10-22

AI Technical Summary

Technical Problem

The information contained in the IEEE 802.11ax A control subfield may raise security and privacy concerns, and these issues may be further complicated by additional information that may be added in future standards.

Method used

By encrypting the A control subfield and including an indicator or preamble in the frame to indicate whether it is encrypted, while using integrity checks to protect the subfield, information security and privacy are ensured.

Benefits of technology

It improves communication security and privacy in wireless LANs, prevents information from being viewed or modified by unauthorized recipients, and enhances trust in communication technologies and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114501453B_ABST
    Figure CN114501453B_ABST
Patent Text Reader

Abstract

The present disclosure relates to protected high throughput control subfields. During operation, an electronic device can encrypt an A control subfield. The electronic device can then provide a frame addressed to a second electronic device, where the frame includes a media access control (MAC) header, and the MAC header includes the encrypted A control subfield. Note that the encrypted A control subfield can be jointly encrypted with data in a payload in the frame. Further, the encrypted A control subfield can be separated from the payload in the frame by one or more additional subfields, or can be adjacent to the payload in the frame. Further, the MAC header can include an indicator indicating whether the A control subfield is encrypted. Additionally, the frame can include a preamble indicating whether the A control subfield is encrypted. The frame can be received by the second electronic device. Upon receiving the frame, the second electronic device can decrypt the A control subfield.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The described implementations relate generally to wireless communications between electronic devices, including techniques for protecting a high throughput (HT) control subfield in a media access control (MAC) header in a frame communicated in a wireless local area network (WLAN). BACKGROUND

[0002] Many electronic devices communicate with each other using a wireless local area network (WLAN), such as those based on a communication protocol compliant with an Institute of Electrical and Electronics Engineers (IEEE) standard such as the IEEE 802.11 standard (sometimes referred to as "Wi-Fi"). During communication using a communication protocol compliant with an IEEE 802.11 standard in a WLAN, a transmitter can communicate information to a receiver in a high throughput (HT) control subfield in a MAC header in a frame. The HT control subfield for IEEE 802.11η, the very high throughput (VHT) variant HT control subfield for IEEE 802.11ac, or the high efficiency (HE) variant HT control subfield for IEEE 802.11ax is 32 bits in length. In IEEE 802.11η and IEEE 802.11ac, the HT / VHT control subfield is primarily used for fast link adaptation purposes, while in IEEE 802.11ax, the HE variant HT control subfield (sometimes referred to as an "aggregated control subfield" or "A control subfield") is redefined to be able to carry multiple types of control information. Within the A control subfield, a high efficiency control identifier is used to identify different types of control information. In the following discussion, the HE control subfield or the A control subfield is referred to as the "A control subfield."

[0003] However, the various information contained in the IEEE 802.11ax A control subfield can raise security and / or privacy concerns. These security and privacy concerns can be complicated by additional information that can be added in future standards. SUMMARY

[0004] In a first set of implementations, an electronic device that provides a frame is described. The electronic device includes an antenna node that is communicably coupled to an antenna, and an interface circuit that communicates with a second electronic device. During operation, the interface circuit optionally encrypts an A control subfield that includes control information for one or more features associated with a wireless communication protocol. The interface circuit then provides a frame addressed to the second electronic device, where the frame includes a MAC header, and the MAC header includes the encrypted A control subfield.

[0005] Note that the encrypted A-control subfield can be jointly encrypted with data in a payload in the frame. Further, the encrypted A-control subfield can be separated from the payload in the frame by one or more additional subfields. Alternatively, the encrypted A-control subfield can be adjacent to the payload in the frame.

[0006] Further, the MAC header can include an indicator indicating whether the A-control subfield is encrypted. For example, the MAC header can include a Counter Mode Cipher Block Chaining (CBC)-MAC Protocol (CCMP) header, and the CCMP header can include the indicator.

[0007] Additionally, the frame can include a preamble indicating whether the A-control subfield is encrypted.

[0008] In some embodiments, the MAC header can include an encrypted Quality of Service (QoS) subfield. Further, when an updated A-control subfield is carried in a QoS null frame, the QoS null frame can use a sequence number space separate from a sequence number space of the frame. Note that sequence numbers in the QoS null frame can be monotonically increasing.

[0009] Further, the frame can be compatible with an IEEE 802.11be standard or an IEEE 802.11 standard after IEEE 802.11be.

[0010] Additionally, the frame can include a packet extension padding, such as when additional processing time is needed for decryption of A-control.

[0011] In some embodiments, the interface circuit can exclude updates to the A-control subfield when retransmitting the frame.

[0012] Further, the frame can include a preamble, and the preamble can include an indication that the A-control subfield is valid when retransmitting the frame. Alternatively, the MAC header can include an indication that the A-control subfield is valid when retransmitting the frame. Note that the indication can be protected using additional associated data (AAD).

[0013] Further, the interface circuit can aggregate the frame with one or more retransmitted frames including different A-control subfields in an aggregated MAC protocol data unit (A-MPDU).

[0014] Other embodiments provide a second electronic device that performs operations corresponding to at least some of the operations performed by the electronic device. For example, the second electronic device can include a second interface circuit. During operation, the second interface circuit can receive a frame addressed to the second electronic device, where the frame includes a MAC header and the MAC header includes an encrypted A-control subfield. The second interface circuit can then optionally decrypt the A-control subfield.

[0015] Note that when the frame is a retransmission, the second interface circuit can discard the A-Control subfield when the A-Control subfield of other frames aggregated with the retransmitted frame includes an update to the A-Control subfield.

[0016] Other embodiments provide an integrated circuit (sometimes referred to as a “communication circuit”) for use with the electronic device or the second electronic device. The integrated circuit can perform at least some of the aforementioned operations.

[0017] Other embodiments provide a computer-readable storage medium for use with the electronic device or the second electronic device. The program instructions stored in the computer-readable storage medium, when executed by the electronic device or the second electronic device, can cause the electronic device or the second electronic device to perform at least some of the aforementioned operations of the electronic device or the second electronic device.

[0018] Other embodiments provide a method. The method includes at least some of the aforementioned operations performed by the electronic device or the second electronic device.

[0019] In a second set of embodiments, an electronic device that provides a frame is described. The electronic device includes an antenna node that is communicatively coupled to an antenna, and an interface circuit that communicates with a second electronic device. During operation, the interface circuit can optionally perform an integrity check associated with at least a portion of a frame based at least in part on an A-Control subfield. The interface circuit then provides the frame addressed to the second electronic device, where the frame includes a MAC header, and the MAC header includes the A-Control subfield as input to the integrity check.

[0020] Note that the integrity check can include additional associated data (AAD).

[0021] Other embodiments provide the second electronic device that performs operations corresponding to at least some of the operations performed by the electronic device. For example, the second electronic device can include a second interface circuit. During operation, the second interface circuit can receive a frame addressed to the second electronic device, where the frame includes a MAC header, and the MAC header includes an A-Control subfield as input to an integrity check. The second interface circuit can then optionally perform the integrity check based at least in part on the A-Control subfield.

[0022] Other embodiments provide an integrated circuit (sometimes referred to as a “communication circuit”) for use with the electronic device or the second electronic device. The integrated circuit can perform at least some of the aforementioned operations.

[0023] Other embodiments provide a computer-readable storage medium for use with the electronic device or the second electronic device. The program instructions stored in the computer-readable storage medium, when executed by the electronic device or the second electronic device, can cause the electronic device or the second electronic device to perform at least some of the aforementioned operations of the electronic device or the second electronic device.

[0024] Other embodiments provide a method. The method includes at least some of the aforementioned operations performed by the electronic device or the second electronic device.

[0025] The purpose of this summary is to present some example embodiments in order to provide a basic understanding of some aspects of the subject matter described herein. Accordingly, it will be appreciated that the above-described features are merely examples and should not be construed to narrow the scope or spirit of the subject matter described herein in any way. Other features, aspects, and advantages of the subject matter described herein will become apparent from the following DETAILED DESCRIPTION, Figures, and Claims. BRIEF DESCRIPTION OF DRAWINGS

[0026] The included drawings are for illustrative purposes and are in no way limiting of the embodiments presented herein. These drawings are included to demonstrate various potential structures and arrangements for the disclosed systems and techniques for intelligently and efficiently managing communications between multiple associated user devices. These drawings in no way limit any alterations in form and detail of the embodiments that can become apparent to those skilled in the art upon reading the detailed description, or that can be developed through testing and practice. The embodiments are to be understood based on the detailed description below, in conjunction with the accompanying drawings, in which like reference characters refer to like structural elements in the various drawings.

[0027] Figure 1 An example network environment for communication between electronic devices is shown in accordance with some embodiments of the present disclosure.

[0028] Figure 2 An example method for providing a frame is shown in accordance with some embodiments of the present disclosure.

[0029] Figure 3 An example method for receiving a frame is shown in accordance with some embodiments of the present disclosure.

[0030] Figure 4 Communication between components in an electronic device such as Figure 1 is shown in accordance with some embodiments of the present disclosure.

[0031] Figure 5 An example method for providing a frame is shown in accordance with some embodiments of the present disclosure.

[0032] Figure 6Exemplary methods for receiving frames according to some embodiments of this disclosure are shown.

[0033] Figure 7 Examples of some embodiments according to this disclosure are shown. Figure 1 An example of communication between components in an electronic device.

[0034] Figure 8 Examples of control subfields in different Media Access Control (MAC) headers according to some embodiments of this disclosure are shown.

[0035] Figure 9 An example of the High Throughput (HT) control subfield in the MAC header according to some embodiments of this disclosure is shown.

[0036] Figure 10 An example of the Very High Throughput (VHT) control subfield in the MAC header according to some embodiments of this disclosure is shown.

[0037] Figure 11 Examples of values ​​for the High Efficiency (HE) control identifier in the HE-variant HT control subfield of the MAC header according to some embodiments of this disclosure are shown.

[0038] Figures 12 to 14 An example of a control subfield A according to some embodiments of this disclosure is shown.

[0039] Figure 15 Some embodiments according to this disclosure are shown. Figure 1 Examples of electronic devices.

[0040] It should be noted that similar reference numerals throughout the accompanying drawings refer to the corresponding components. Furthermore, multiple instances of the same component are designated by a common prefix, which is separated from the instance number by a dashed line. Detailed Implementation

[0041] Some embodiments include an electronic device that provides a frame. During operation, the electronic device can encrypt an A-Control subfield. The electronic device can then provide a frame addressed to a second electronic device, where the frame includes a MAC header, and the MAC header includes the encrypted A-Control subfield. Note that the encrypted A-Control subfield can be jointly encrypted with data in a payload in the frame. Also, the encrypted A-Control subfield can be separate from the payload in the frame by one or more additional subfields, or can be adjacent to the payload in the frame. Also, the MAC header can include an indicator that indicates whether the A-Control subfield is encrypted. In addition, the frame can include a preamble that indicates whether the A-Control subfield is encrypted. The frame can be received by the second electronic device. After receiving the frame, the second electronic device can decrypt the A-Control subfield.

[0042] In some embodiments, the electronic device can perform an integrity check associated with at least a portion of a frame based at least in part on an A-Control subfield. The electronic device can then provide the frame addressed to the second electronic device, where the frame includes a MAC header, and the MAC header includes the A-Control subfield as input to the integrity check. Note that the integrity check can include an AAD. The frame can be received by the second electronic device. After receiving the frame, the second electronic device can perform the integrity check based at least in part on the A-Control subfield.

[0043] By transmitting the frame, these communication techniques can improve the security and / or privacy of information included in the frame. As a result, the communication techniques can prevent information from being viewed or modified by unintended recipients. These capabilities can enhance trust in the communication techniques, and can improve user experience and customer satisfaction when using the electronic device and / or the second electronic device.

[0044] Note that the communication techniques can be used during wireless communication between electronic devices in accordance with a communication protocol, such as a communication protocol that is compatible with the IEEE 802.11 standard (sometimes referred to as Wi-Fi). In some embodiments, the communication techniques are used with IEEE 802.1 lbe, which is used as an illustrative example in the following discussion. However, the communication techniques can also be used with a wide variety of other communication protocols, and can also be used in electronic devices (such as portable electronic devices or mobile devices) that can incorporate a variety of different radio access technologies (RATs) to provide connectivity over different wireless networks that give different services and / or capabilities.

[0045] An electronic device can include hardware and software to support WPANs in accordance with wireless personal area network (WPAN) communication protocols, such as those standardized by the Bluetooth Special Interest Group and / or those developed by Apple (Cupertino, California) known as Apple Wireless Direct Link (AWDL). In addition, an electronic device can communicate via a wireless wide area network (WW AN), a wireless metropolitan area network (WMAN), a WLAN, near-field communication (NFC), a cellular telephone or data network, such as using a third generation (3G) communication protocol, a fourth generation (4G) communication protocol (e.g., Long Term Evolution or LTE, LTE-Advanced (LTE-A)), a fifth generation (5G) communication protocol, or other current or future developed advanced cellular communication protocol, and / or another communication protocol. In some embodiments, the communication protocol includes a peer-to-peer communication technology.

[0046] In some embodiments, an electronic device can also operate as part of a wireless communication system that can include a set of client devices that can also be referred to as station or client electronic devices that are interconnected to an access point, for example, as part of a WLAN, and / or to each other, for example, as part of a WPAN and / or an “ad hoc” wireless network such as a Wi-Fi Direct connection. In some embodiments, a client device can be any electronic device capable of communicating via WLAN technology (e.g., in accordance with a WLAN communication protocol). In addition, in some embodiments, WLAN technology can include a Wi-Fi (or more generally, a WLAN) wireless communication subsystem or radio, and the Wi-Fi radio can implement IEEE 802.11 technology, such as one or more of: IEEE 802.11a; IEEE 802.11b; IEEE 802.11g; IEEE 802.11-2007; IEEE 802.11n; IEEE 802.11-2012; IEEE 802.11-2016; IEEE 802.11ac; IEEE 802.11ax, IEEE 802.11ba, IEEE 802.11be, or other current or future developed IEEE 802.11 technology.

[0047] In some embodiments, the electronic device can act as a communication hub that provides access to a WLAN and / or to a WW AN, and thus provides access to a wide variety of services that can be supported by various applications executing on the electronic device. Thus, the electronic device can include an "access point" that communicates wirelessly with other electronic devices, such as using Wi-Fi, and provides access to another network, such as the Internet, via IEEE 802.3 (which is sometimes referred to as "Ethernet"). However, in other embodiments, the electronic device can not be an access point. As an illustrative example, in the following discussion, the electronic device is or includes an access point.

[0048] Additionally, it should be appreciated that the electronic devices described herein can be configured as multi-mode wireless communication devices that are also capable of communicating via different 3G and / or second generation (2G) RATs. In these scenarios, the multi-mode electronic device or UE can be configured to prefer attachment to an LTE network that gives faster data rate throughput as compared to other 3G legacy networks that give lower data rate throughput. For example, in some implementations, the multi-mode electronic device is configured to fall back to a 3G legacy network, such as an Evolved High Speed Packet Access (HSPA+) network or a Code Division Multiple Access (CDMA) 2000 Evolution-Data Optimized (EV-DO) network, when LTE and LTE-A networks are otherwise unavailable. More generally, the electronic devices described herein are capable of communicating with other current or future developed cellular telephone technologies.

[0049] According to various embodiments described herein, the terms "wireless communication device," "electronic device," "mobile device," "mobile station," "wireless station," "wireless access point," "station," "access point," and "user equipment (UE)" can be used to describe one or more consumer electronic devices that can be capable of performing processes associated with various embodiments of the present disclosure.

[0050] Figure 1A block diagram illustrating an example of an electronic device communicating wirelessly is presented. It is noteworthy that one or more electronic devices 110 (such as a smartphone, laptop computer, notebook computer, tablet computer, or other such electronic device) and access point 112 can wirelessly communicate in a WLAN using the IEEE 802.11 communication protocol. Therefore, electronic device 110 may be associated with or have one or more connections to access point 112. For example, electronic device 110 and access point 112 may wirelessly communicate by: detecting each other by scanning a wireless channel, transmitting and receiving beacons or beacon frames on a wireless channel, establishing a connection (e.g., by transmitting a connection request), and / or transmitting and receiving packets or frames (packets or frames may include requests and / or additional information such as data as a payload). It should be noted that access point 112 may provide access to a network such as the Internet via the Ethernet protocol and may be a physical access point implemented on a computer or electronic device or a virtual or “software” access point. In the following discussion, electronic device 110 is sometimes referred to as the “receiving electronic device.”

[0051] See below for reference Figure 15 Furthermore, electronic device 110 and access point 112 may include subsystems such as a networking subsystem, a memory subsystem, and a processor subsystem. Additionally, electronic device 110 and access point 112 may include a radio component 114 within the networking subsystem. More generally, electronic device 110 and access point 112 may include any electronic device with a networking subsystem (or may be included within any electronic device with a networking subsystem) that enables electronic device 110 and access point 112 to communicate wirelessly with another electronic device. This may include transmitting beacons on a wireless channel to enable the electronic devices to make initial contact with or detect each other, followed by the exchange of subsequent data / management frames (such as connection requests) to establish a connection, configure security options (e.g., IPSec), and transmit and receive packets or frames via the connection.

[0052] like Figure 1 As can be seen, wireless signals 116 (represented by sawtooth lines) are transmitted by one or more radio components 114-1 and 114-2 in electronic device 110-1 and access point 112, respectively. For example, as previously mentioned, electronic device 110-1 and access point 112 can exchange packets or frames using the Wi-Fi communication protocol in a WLAN. See below for reference. Figures 2 to 14As further shown, one or more radio components 114-1 may receive radio signals 116 transmitted by one or more radio components 114-2 via one or more links between electronic device 110-1 and access point 112. Alternatively, the one or more radio components 114-1 may transmit radio signals 116 received by the one or more radio components 114-2.

[0053] It should be noted that the one or more radio components 114-1 may consume additional power in a higher power mode. If the one or more radio components 114-1 remain in a higher power mode even when not transmitting or receiving packets or frames, the power consumption of electronic device 110-1 may increase unnecessarily. As a result, electronic device 110 may include a wake-up radio component (WUR) 118 that listens for and / or receives wake-up frames (and / or other wake-up communications) from, for example, access point 112. When a particular electronic device (such as electronic device 110-1) receives a wake-up frame, WUR 118-1 may selectively wake up radio component 114-1, for example, by providing a wake-up signal that selectively transitions at least one of the one or more radio components 114-1 from a low-power mode to a high-power mode.

[0054] As previously mentioned, information in the control subfields of the existing IEEE 802.11 standard may raise security and / or privacy concerns. These security and privacy concerns may be complicated by additional information (such as additional control identifiers) that may be added to future standards.

[0055] To address these challenges, please refer to the appendix below. Figures 2 to 14 In some embodiments of the disclosed communication technology, frames can be transmitted between two or more electronic devices in a WLAN, such as between access point 112 and electronic device 110-1, or between electronic device 110-1 and electronic device 110-2. Using access point 112 and electronic device 110-1 as an example, access point 112 may optionally encrypt an A control subfield and provide a frame including the encrypted A control subfield to electronic device 110-1. After receiving the frame, electronic device 110-1 may extract the encrypted A control subfield and may optionally decrypt it.

[0056] Alternatively or otherwise, access point 112 may optionally perform an integrity check associated with at least a portion of the frame, based at least in part on the A control subfield. It should be noted that this integrity check may include AAD.

[0057] The access point 112 can then provide the frame including the A-Control subfield to the electronic device 110-1. After receiving the frame, the electronic device 110-1 can extract the A-Control subfield and can optionally perform a second integrity check associated with at least a portion of the frame based at least in part on the A-Control subfield. Note that the second integrity check can include an AAD.

[0058] In some embodiments, the electronic device 110-1 can perform a remedial action based at least in part on a result or output of the second integrity check. For example, the electronic device 110-1 can set a flag associated with the frame, discard content (such as a payload) of the frame, and / or request retransmission of the frame by the access point 112. Alternatively, based at least in part on the result or output of the second integrity check (e.g., when comparing the result or output indicating the integrity check and the result or output of the second integrity check are the same), the electronic device 110-1 can continue normal processing of the frame (such as processing of a payload in the frame).

[0059] In general, this communication technique can improve security and / or privacy during communication between electronic devices in a WLAN. Notably, the integrity check can be used to encrypt and / or protect information in a MAC header.

[0060] Note that the access point 112 and one or more electronic devices (such as electronic devices 110-1 and / or 110-2) can be compatible with IEEE 802.11 standards that include trigger-based channel access, such as IEEE 802.11ax. However, the access point 112 and one or more electronic devices can communicate with one or more legacy electronic devices that are not compatible with IEEE 802.11 standards (i.e., do not use multi-user trigger-based channel access). In some embodiments, the access point 112 and the one or more electronic devices use multi-user transmissions, such as OFDMA. For example, the one or more radio(s) 114-2 can provide one or more trigger frames to one or more electronic devices. Further, in response to receiving the one or more trigger frames, the one or more radio(s) 114-1 can provide one or more group or block acknowledgements (BAs) to the one or more radio(s) 114-2. For example, the one or more radio(s) 114-1 can provide one or more group acknowledgements during an associated allocation time slot and / or in an allocation channel in one or more group acknowledgements. However, in some embodiments, one or more of the electronic devices 110 can individually provide acknowledgements to the one or more radio(s) 114-2. Thus, the one or more radio(s) 114-1 (and, more generally, radio(s) 114 in electronic devices 110-1 and / or 110-2) can provide one or more acknowledgements to the one or more radio(s) 114-2.

[0061] In the described embodiments, processing a packet or frame in one of the electronic devices 110 and the access point 112 includes receiving a wireless signal 116 encoding the packet or frame, decoding / extracting the packet or frame from the received wireless signal 116 to obtain the packet or frame, and processing the packet or frame to determine information contained in the packet or frame (such as data in a payload).

[0062] Generally, communications via WLAN in this communication technology can be characterized by a variety of communication performance metrics. For example, a communication performance metric can include any / all of: RSSI, data rate, data rate of successful communications (sometimes referred to as “throughput”), latency, error rate (such as retry rate or retransmission rate), mean square error of equalized signal versus equalization target, inter-symbol interference, multipath interference, signal-to-noise ratio (SNR), eye width, ratio of number of bytes successfully communicated during a time interval (such as, for example, a time interval between 1 and 10 seconds) to an estimated maximum number of bytes that could be communicated in that time interval (where the latter is sometimes referred to as the “capacity” of the communication channel or link), and / or ratio of actual data rate to estimated data rate (sometimes referred to as “utilization”).

[0063] While we have described above the preferred embodiments of this application, those skilled in the art will readily devise their own Figure 1The network environment shown in FIG. 1 is described by way of example, but in alternative embodiments, different numbers and / or types of electronic devices can be present. For example, some embodiments can include more or fewer electronic devices. As another example, in other embodiments, different electronic devices can transmit and / or receive packets or frames. In some embodiments, multiple links can be used during communication between electronic devices 110 and / or 112. Thus, one of electronic devices 110 and / or 112 can perform operations in communication techniques.

[0064] Figure 2 A flowchart showing an example method 200 for providing a frame is presented. The method can be performed by an electronic device, such as electronic device 110-1 or access point 112 in FIG. 1. Note that communication with a second electronic device can be compatible with an IEEE 802.11 communication protocol. Figure 1

[0065] During operation, the electronic device can optionally encrypt an A-Control subfield (operation 210). The electronic device can then provide a frame addressed to the second electronic device (operation 212), where the frame includes a MAC header, and the MAC header includes the encrypted A-Control subfield.

[0066] Note that the encrypted A-Control subfield can be jointly encrypted with data in a payload in the frame. Further, the encrypted A-Control subfield can be separated from the payload in the frame by one or more additional subfields. Alternatively, the encrypted A-Control subfield can be adjacent to the payload in the frame.

[0067] Further, the MAC header can include an indicator indicating whether the A-Control subfield is encrypted. For example, the MAC header can include a CCMP header, and the CCMP header can include the indicator. In addition, the frame can include a preamble indicating whether the A-Control subfield is encrypted.

[0068] In some embodiments, the MAC header can include an encrypted QoS subfield. Further, when an updated A-Control subfield is carried in a QoS null frame, the QoS null frame can use a sequence number space separate from a sequence number space of the frame. Note that sequence numbers in the QoS null frame can be monotonically increasing.

[0069] Further, the frame can be compatible with an IEEE 802.11be standard or an IEEE 802.11 standard after IEEE 802.11be.

[0070] In addition, the frame can include a packet extension padding.

[0071] ​In some embodiments, the electronic device optionally performs one or more additional operations (operation 214). For example, when retransmitting the frame, the electronic device can exclude updates to the A control subfield.

[0072] Further, the frame can include a preamble, and when retransmitting the frame, the preamble can include an indication that the A control subfield is valid. Alternatively, when retransmitting the frame, the MAC header can include an indication that the A control subfield is valid. Note that the indication can be protected using an AAD.

[0073] Further, the electronic device can aggregate the frame with one or more retransmitted frames that include different A control subfields in an A-MPDU.

[0074] Figure 3 A flow diagram showing an exemplary method 300 for receiving a frame is presented. The method can be performed by a second electronic device (such as electronic device 110-2 or access point 112 in Figure 1 Note that the communication with the electronic device can be compatible with an IEEE 802.11 communication protocol.

[0075] During operation, the second electronic device can receive a frame addressed to the second electronic device (operation 310), where the frame includes a MAC header and the MAC header includes an A control subfield that is encrypted. The second electronic device can then optionally decrypt the A control subfield (operation 312).

[0076] In some embodiments, the second electronic device optionally performs one or more additional operations (operation 314). For example, when the frame is a retransmission, when A control subfields of other frames aggregated with the retransmitted frame include updates to the A control subfield, the second electronic device can discard the A control subfield.

[0077] Further communication techniques are shown in Figure 4 A flow diagram showing an example of communication between components in access point 112 and electronic device 110-1 is presented. During operation, interface circuit (IC) 410 in access point 112 can encrypt A control subfield 412. Interface circuit 410 can then generate frame 414 that includes the encrypted A control subfield 412, and can transmit frame 414 to electronic device 110-1.

[0078] After receiving frame 414, interface circuit 416 in electronic device 110-1 can extract the encrypted A control subfield 412. Interface circuit 416 can then decrypt the encrypted A control subfield 412 to recover A control subfield 418.

[0079] Figure 5A flow diagram illustrating an exemplary method 500 for providing a frame is presented. The method can be performed by an electronic device (such as the electronic device 110-1 or the access point 112 in FIG. 1) in communication with a second electronic device. Note that the communication with the second electronic device can be compatible with an IEEE 802.11 communication protocol. Figure 1

[0080] During operation, the electronic device can optionally perform an integrity check associated with at least a portion of the frame based at least in part on the A-Control subfield (operation 510). Note that the integrity check can include the AAD. The electronic device can then provide the frame addressed to the second electronic device (operation 512), where the frame includes a MAC header and the MAC header includes the A-Control subfield as input to the integrity check.

[0081] Figure 6 A flow diagram illustrating an exemplary method 600 for receiving a frame is presented. The method can be performed by a second electronic device (such as the electronic device 110-2 or the access point 112 in FIG. 1) in communication with an electronic device. Note that the communication with the electronic device can be compatible with an IEEE 802.11 communication protocol. Figure 1

[0082] During operation, the second electronic device can receive the frame addressed to the second electronic device (operation 610), where the frame includes a MAC header and the MAC header includes an A-Control subfield as input to an integrity check. The second electronic device can then optionally perform the integrity check based at least in part on the A-Control subfield (operation 612).

[0083] In some embodiments of the method 200 ( Figure 2 ), the method 300 ( Figure 3 ), the method 500 ( Figure 5 ), and / or the method 600 and in some or all of the following figures, there can be additional or fewer operations. Additionally, one or more of the operations can be included in a different order. Furthermore, two or more operations can be combined into a single operation or at least partially performed in parallel.

[0084] In Figure 7 ​​The communication techniques are further illustrated by a diagram presenting an example showing communications between components in the access point 112 and the electronic device 110-1. During operation, the interface circuit (IC) 710 in the access point 112 can perform an integrity check 712 based at least in part on the A-Control subfield 714 (e.g., the integrity check 712 can use the A-Control subfield 714 as an input). Then, the interface circuit 710 can generate a frame 716 that includes the A-Control subfield 714, and can transmit the frame 716 to the electronic device 110-1. Note that the frame 716 can optionally include a result or output of the integrity check 712.

[0085] After receiving the frame 716, the interface circuit 718 in the electronic device 110-1 can extract the A-Control subfield 714. Then, the interface circuit 718 can perform an integrity check 720 based at least in part on the A-Control subfield 714 (e.g., the integrity check 720 can use the A-Control subfield 714 as an input). Next, based at least in part on a result or output of the integrity check 720, and optionally on a result or output of the integrity check 712 (e.g., based at least in part on a comparison of the result or output of the integrity check 720 and, optionally, the result or output of the integrity check 712), the interface circuit 718 can perform a remedial action 722. For example, the interface circuit 718 can set a flag associated with the frame 716, discard contents of the frame 716, and / or request a retransmission of the frame 716. Alternatively, based at least in part on the result or output of the integrity check 720 (e.g., when the comparison indicates that the result or output of the integrity check 712 and the result or output of the integrity check 720 are the same), the electronic device 110-1 can continue normal processing of the frame 716 (such as processing of a payload in the frame 716).

[0086] Although Figure 4 and Figure 7 communications between components are shown as unidirectional or bidirectional communications (e.g., lines with single or double arrows), a given communication operation can generally be unidirectional or bidirectional.

[0087] We now further discuss the communication techniques. Figures 8 to 11 The control subfield formats and contents are summarized. Notably, Figure 8 examples of control subfields in different MAC headers are presented, Figure 9 examples of HT control subfields in MAC headers are presented, Figure 10 examples of VHT control subfields in MAC headers are presented, and Figure 11 examples of values of HE control identifiers in HE-variant HT control subfields in MAC headers are presented.

[0088] Currently, the HT Control subfield and the VHT Control subfield are not encrypted or integrity protected. For example, the AAD does not include the Duration / Identifier field or the HT Control subfield. This is because the contents of these fields or subfields can change during normal operation, such as due to rate changes before retransmission. The HT Control subfield can also be inserted or removed during normal operation, such as during retransmission of aggregated MAC protocol data units or A-MPDUs, where the original A-MPDU included a Modulation and Coding Scheme Request (MRQ) that has already generated a response.

[0089] However, the new type of information contained in the IEEE 802.11ax A Control subfield presents security and privacy issues. In addition, new control identifiers can be added in future standards. Furthermore, privacy issues can also occur with the QoS Control subfield, which is included in the MAC header before the HT Control subfield and includes traffic identifiers, frame and buffer sizes at the transmitter. Thus, in some embodiments, the disclosed communication techniques can be used with other subfields, such as: the QoS Control subfield, the Address field, or the Sequence Number (SN) field.

[0090] When one or more control subfields are not secure, communications in a WLAN can be vulnerable to security attacks. For example, in an Operating Mode Indication (OMI) A Control subfield attack, an attacker can exploit the OMI A Control subfield to record failed transmissions or blocked transmissions from a station or client (sometimes referred to as a “recipient electronic device”) to an access point when the access point does not return an acknowledgement frame. The attacker can replace the real OMI A Control subfield in the recorded failed transmissions and replay the modified frames to the access point before the station can access the channel again. Thus, the access point can take the false OMI A Control subfield, causing multiple failures for subsequent downlink (DL) transmissions to the station until the station can inform the access point. In addition, in a buffer status report attack, an attacker can replay a modified buffer status report to indicate a “0” or empty buffer, so that the station cannot receive any trigger frames (or transmission opportunities) from the access point.

[0091] Alternatively, communications in a WLAN can be vulnerable to privacy attacks when one or more control subfields are insecure. For example, in another type of buffer status report attack, a tracker can analyze the statistical values of buffer status reports to determine traffic pattern information that a station is generating. This traffic pattern information can allow an inference of the type of application that a user is using. For example, the access category index (ACI) High and QueueSizeHigh in the buffer status report (BSR) A control subfield can indicate from the station side which type of traffic is the heaviest load. This can allow a tracker to send targeted video stream advertisements when a station is determined to be high consumption of downlink video traffic.

[0092] As shown in FIGS. 1 1 A and 1 1 B, in some embodiments of communication technology, the A control subfield can be protected using encryption. Notably, there can be different formats of encrypted A control subfields (as shown in FIGS. 12A and 12B) as compared to an unencrypted A control subfield (shown in FIG. 10). Figures 12 to 14 Figure 12 As shown in FIGS. 1 1 A and 1 1 B, in some embodiments of communication technology, the A control subfield can be protected using encryption. Notably, there can be different formats of encrypted A control subfields (as shown in FIGS. 12A and 12B) as compared to an unencrypted A control subfield (shown in FIG. 10). Figure 13 Figure 14 For example, authentication encryption can be performed on the A control subfield in a MAC service data unit (MSDU) (such as the counter mode cipher block chaining (CBC)-MAC protocol or CCMP, which is also referred to as AES-CCMP, or the Galois counter mode protocol or GCMP). (However, these encryption techniques are used as examples, and in other embodiments, various other or additional encryption techniques can be used.) In some embodiments, the A control subfield is encrypted by the payload data.

[0093] There can be different options for the location where the encrypted A control subfield is placed. For example, the encrypted A control subfield can be separated from the encrypted payload by a CCMP header. Alternatively, the encrypted A control subfield can be placed next to the encrypted payload, such as in a common encrypted block.

[0094] Note that if the A control subfield is encrypted, a receiving extremely high throughput (EHT) station can need to perform decryption on the normal 8-byte A control subfield, which can then be sent to the processing engine of the A control subfield.

[0095] Additionally, there is often a need for backward compatibility with so-called legacy electronic devices, which are compatible with earlier IEEE 802.1 1 standards. This raises the question of how a station will know if it needs to decrypt the A control subfield. In some embodiments, an EHT station (e.g., in IEEE 802.1 1 be) can always encrypt the A control subfield, such as in an EHT physical layer protocol data unit (PPDU), or in a legacy PPDU format if the receiver-transmitter address pair indicates that the PPDU is between EHT stations. ​​

[0096] Alternatively, the A-Control subfield can be optionally encrypted. In these embodiments, the header can include an indication that the A-Control subfield is encrypted. For example, a bit in the EHT Preamble can indicate or signal whether the A-Control subfield is encrypted, or a reserved bit in the CCMP header can indicate that the A-Control subfield is encrypted. However, if the CCMP header is not protected, it can be exploited by an attacker.

[0097] Another issue is that there can be bit delays in retrieving the information contained in the A-Control subfield. This can be problematic because the delay in processing this information should be minimized. If more turnaround time is needed (e.g., due to strict A-Control subfield processing constraints), then Packet Extension (PE) padding can be used to provide more time for the receiver to decrypt the A-Control subfield.

[0098] Furthermore, there can be issues if the encrypted A-Control subfield needs to be updated (or removed) during retransmission. Notably, in these cases, the AAD can be changed, so the transmitter cannot encrypt the A-Control subfield again using the same nonce. Instead, a new Packet Number (PN) is needed. But the retransmission can fail the replay check because it can have a smaller sequence number, but a larger packet number.

[0099] To address this issue, the transmitter can not allow A-Control subfield updates in retransmitted MPDUs. Instead, only new MPDUs can have updated A-Control subfields. Additionally, the A-Control subfields in the A-MPDU can have different content. Thus, new MPDUs with updated A-Control subfields can be aggregated with retransmitted MPDUs.

[0100] Furthermore, the receiver can have different options or embodiments. Notably, the receiver can discard the A-Control subfield in any retransmitted MPDUs. Alternatively, there can be an indication of the validity of the A-Control subfield in the transmitted MPDUs. For example, the indication can be provided by a bit in the Preamble or MAC header. Note that if the indication is included in the MAC header, it can be protected by the AAD.

[0101] In addition, during retransmission, the updated A-Control subfield can have other issues. For example, the QoS Data MPDUs can be exhausted such that there are no new QoS Data MPDUs to update the A-Control subfield. In this case, one solution can use a QoS Null frame to carry the new A-Control subfield. Notably, the sequence number of the current QoS Null frame is arbitrarily assigned. Thus, encrypting the A-Control subfield in the QoS Null frame can cause replay check failure. Thus, the QoS Null frame can not be protected. This problem can be solved by using a separate sequence number space for the QoS Null frame. In this space, the sequence number can be monotonically increasing (as opposed to the current method where the sequence number is arbitrarily assigned), such that the QoS Null frame can be encrypted. Alternatively, a new robust behavior or management frame can be defined. This new behavior frame can include the A-Control subfield in its payload.

[0102] In some embodiments, if adding encryption to the A-Control subfield is too challenging for the current implementation of frame encryption flow, then only integrity check to the A-Control subfield can be used in some embodiments of the communication techniques. Notably, the A-Control subfield can be part of the input of the AAD. Because the updated AAD can require a new packet number, the same or similar rules as previously discussed for retransmission processing can be used. Alternatively, if the A-Control subfield is carried in a QoS Null frame, the same or similar rules as previously discussed for QoS Null frame can be used.

[0103] Note that in some embodiments of the communication techniques, the receiver can determine the frame format (such as HT, VHT, or HE) based at least in part on the transmitter address and / or capabilities.

[0104] In general, the disclosed communication techniques can protect the information in the A-Control subfield by using encryption and / or integrity check. These capabilities can improve the security and / or privacy of the communications in WLANs.

[0105] Note that the format of the packets or frames transmitted during the communication techniques can include more or less bits or fields. Alternatively or additionally, the location of the information in these packets or frames can be changed. Thus, the order of the fields can be altered.

[0106] While the foregoing embodiments show embodiments of the communication techniques using sub-bands, in other embodiments, the communication techniques can involve concurrent use of different time slots and / or different sub-bands, different frequency bands and / or a combination of different time slots.

[0107] Further, while the foregoing implementations show the use of Wi-Fi during the communication technology, in other implementations of the communication technology, Bluetooth or Bluetooth Low Energy is used to communicate at least a portion of the information in the communication technology. Further, the information communicated in the communication technology can be communicated in one or more frequency bands, including: a 900 MHz frequency band, a 2.4 GHz frequency band, a 5 GHz frequency band, a 6 GHz frequency band, a 7 GHz frequency band, a 60 GHz frequency band, a Citizens Broadband Radio Service (CBRS) frequency band, a frequency band used by LTE, etc.

[0108] As described herein, various aspects of the present technology can include gathering and using data available from a variety of sources, e.g., to improve or enhance functionality. The present disclosure contemplates that, in some instances, this gathered data can include personal information data that uniquely identifies or can be linked to a specific person. Such personal information data can include demographic data, location-based data, telephone numbers, email addresses, twitter ID's, home addresses, data or records pertaining to a user's health or wellness, date of birth, or any other identifying information or personal information. The present disclosure recognizes that the use of such personal information data in the present technology can be used to the benefit of the user.

[0109] The present disclosure contemplates that the entities responsible for the collection, analysis, disclosure, transfer, storage, or other use of such personal information data will comply with well-established privacy policies and / or privacy practices. In particular, such entities should implement and consistently use privacy policies and practices that are generally recognized as meeting or exceeding industry or governmental requirements for maintaining the privacy and security of personal information data. Such policies should be easily accessible by users, and should be updated as the collection and / or use of data changes. Personal information from users should be collected for legitimate and reasonable uses of the entity and not shared or sold outside of those legitimate uses. Further, such collection / sharing should occur after receiving the informed consent of the users. Additionally, such entities should consider taking any needed steps for safeguarding and securing access to such personal information data and ensuring that others with access to the personal information data adhere to their privacy policies and procedures. Further, such entities can subject themselves to evaluation by third parties to certify their adherence to widely accepted privacy policies and practices. In addition, policies and practices should be adapted for the particular types of personal information data being collected and / or accessed and adapted to specific legal, government regulatory, or self-regulatory constraints within a country of collection, access, or processing. For instance, in the United States, collection of certain health data may be subject to federal and / or state laws, such as the Health Insurance Portability and Accountability Act (HIPAA); whereas health data collected in other countries may be subject to other regulations and practices and should be handled accordingly.

[0110] Regardless of the foregoing, the present disclosure also contemplates embodiments in which users selectively block the use of, or access to, personal information data. That is, the present disclosure contemplates that hardware and / or software elements can be provided to prevent or block access to such personal information data. For example, the present technology can be configured to allow users to selectively "opt in" or "opt out" of permitting the collection of personal information data during registration for services, or anytime thereafter. In addition to providing such "opt in" and "opt out" options, the present disclosure contemplates providing notifications relating to the access or use of personal information. For instance, a user can be notified upon downloading an app that their personal information data will be accessed and then reminded again just prior to the app accessing the personal information data.

[0111] Moreover, the present disclosure contemplates that the entities responsible for the collection, analysis, disclosure, transfer, storage, or other use of such personal information data will comply with well-established privacy policies and / or privacy practices. In particular, such entities should implement and consistently use privacy policies and practices that

[0112] Thus, while the present disclosure contemplates various embodiments using personal information data, it is also contemplated that the present disclosure can be used in embodiments that do not involve such personal information data. That is, the embodiments of the present technology can be practiced without relying on personal information data in a central database.

[0113] We now describe embodiments of electronic devices. Figure 15 A block diagram of an electronic device 1500 (which can be a cellular phone, smart watch, access point, wireless speaker, IoT device, another electronic device, etc.) is presented according to some embodiments. The electronic device includes a processing subsystem 1510, a memory subsystem 1512, and a networking subsystem 1514. The processing subsystem 1510 includes one or more devices configured to perform computational operations. For example, the processing subsystem 1510 can include one or more microprocessors, application-specific integrated circuits (ASICs), microcontrollers, graphics processing units (GPUs), programmable logic devices, and / or one or more digital signal processors (DSPs).

[0114] Memory subsystem 1512 includes one or more devices for storing data and / or instructions for processing subsystem 1510 and / or networking subsystem 1514. For example, memory subsystem 1512 can include dynamic random access memory (DRAM), static random access memory (SRAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other memory. In some embodiments, instructions for processing subsystem 1510 in memory subsystem 1512 include a program or set of instructions (such as program instructions 1522 or operating system 1524) executable by processing subsystem 1510. For example, a ROM can store programs, utilities, or processes to be executed in a non-volatile manner, and a DRAM can provide volatile data storage and can store instructions related to the operation of electronic device 1500. Note that one or more computer programs can constitute a computer-program mechanism, computer-readable storage medium, or software. Further, the instructions in the various modules of memory subsystem 1512 can be implemented in: a high-level procedural language, an object-oriented programming language, and / or in an assembly or machine language. Furthermore, the programming language can be compiled or interpreted, for example, as can be configurable or configured (both of which are used interchangeably herein) to be executed by processing subsystem 1510. In some embodiments, one or more computer programs are distributed over network-coupled computer systems so that the one or more computer programs are stored and executed in a distributed fashion.

[0115] In addition, memory subsystem 1512 can include a mechanism for controlling access to memory. In some embodiments, memory subsystem 1512 includes a memory hierarchy including one or more caches coupled to memory in electronic device 1500. In some of these embodiments, one or more of the caches are located in processing subsystem 1510.

[0116] In some embodiments, memory subsystem 1512 is coupled to one or more high-capacity mass storage devices (not shown). For example, memory subsystem 1512 can be coupled to a magnetic or optical disk drive, a solid state drive, or another type of high-capacity storage device. In these embodiments, memory subsystem 1512 can be used by electronic device 1500 as fast-access storage for frequently used data, while the mass storage device is used to store less frequently used data.

[0117] The networking subsystem 1514 includes one or more devices configured to couple to and communicate over wired and / or wireless networks (i.e., to perform network operations), such as: control logic 1516, one or more interface circuits 1518, and a set of antennas 1520 (or antenna elements) in an adaptive array that can be selectively turned on and / or off by the control logic 1516 to produce a variety of alternative antenna patterns, or “beam patterns.” Alternatively, instead of the set of antennas, in some embodiments the electronic device 1500 includes one or more nodes 1508, e.g., pads or connectors, that can be coupled to the set of antennas 1520. Thus, the electronic device 1500 can or can not include the set of antennas 1520. For example, the networking subsystem 1514 can include a Bluetooth TM networking systems, cellular networking systems (e.g., 3G / 4G / 5G networks such as UMTS, LTE, etc.), universal serial bus (USB) networking systems, IEEE 802.12 (e.g., networking systems described in the standards mentioned above, Ethernet networking systems, and / or another networking system.

[0118] In some embodiments, the networking subsystem 1514 includes one or more radios, such as a wake-up radio for receiving wake-up frames and wake-up beacons, and a main radio for transmitting and / or receiving frames or packets during normal operating modes. The wake-up radio and the main radio can be implemented separately (such as using separate components or separate integrated circuits) or in a common integrated circuit.

[0119] The networking subsystem 1514 includes processors, controllers, radios, sockets / plugs, and / or other devices for coupling to, communicating over, and handling data and events for each supported networking system. Note that the mechanisms for coupling to, communicating over, and handling data and events on a network of each network system are sometimes collectively referred to as the “network interface” for that network system. Also, in some embodiments, a “network” or “connection” between electronic devices does not yet exist. Thus, the electronic device 1500 can use mechanisms in the networking subsystem 1514 for performing simple wireless communications between electronic devices, e.g., transmitting one or more advertisement frames and / or scanning for advertisement frames transmitted by other electronic devices.

[0120] Within electronic device 1500, processing subsystem 1510, memory subsystem 1512, and networking subsystem 1514 are coupled together using bus 1528, which facilitates data transfer between these components. Bus 1528 can include electrical, optical, and / or optical and electrical connections that the subsystems use to transmit commands and data among one another. Although only one bus 1528 is shown for clarity, different implementations of the electronic device 1500 can include different numbers or configurations of electrical, optical, and / or optical and electrical connections between the subsystems.

[0121] In some embodiments, electronic device 1500 includes display subsystem 1526 for displaying information on a display, which can include a display driver and a display such as a liquid-crystal display, a multi-touch touchscreen, etc. Display subsystem 1526 can be controlled by processing subsystem 1510 to display information (e.g., information related to an incoming, outgoing, or active communication session) to a user.

[0122] Electronic device 1500 can also include user input subsystem 1530 that allows a user of electronic device 1500 to interact with electronic device 1500. For example, user input subsystem 1530 can take a variety of forms, such as: buttons, a keypad, a dial, a touchscreen, an audio input interface, a visual / image capture input interface, input in the form of sensor data, etc.

[0123] Electronic device 1500 can be (or can be included in) any electronic device with at least one network interface. For example, electronic device 1500 can include: a cellular telephone or smartphone, a tablet computer, a laptop computer, a notebook computer, a personal or desktop computer, a netbook computer, a media player device, a wireless speaker, an IoT device, an e-book device, a device, a smartwatch, a wearable computing device, a portable computing device, a consumer electronic device, a vehicle, a door, a window, a portal, an access point, a router, a switch, a communication appliance, a test appliance, and any other type of electronic computing device with wireless communication capabilities that can include communicating via one or more wireless communication protocols.

[0124] Although specific components are used to describe electronic device 1500, different components and / or subsystems can be present in electronic device 1500 in alternative implementations. For example, electronic device 1500 can include one or more additional processing subsystems, memory subsystems, networking subsystems, and / or display subsystems. Additionally, one or more of the subsystems can not be present in electronic device 1500. Moreover, in some embodiments, electronic device 1500 can include Figure 15one or more additional subsystems not shown in FIG. 15. In some embodiments, the electronic device can include an analytics subsystem that performs at least some of the operations in the communication techniques. Also, while separate subsystems are shown in Figure 15 separate subsystems are shown in FIG. 15, in some embodiments some or all of a given subsystem or component can be integrated into one or more of the other subsystems or components in the electronic device 1500. For example, in some embodiments the program instructions 1522 are included in the operating system 1524 and / or the control logic component 1516 is included in the one or more interface circuits 1518.

[0125] Further, the circuits and components in the electronic device 1500 can be implemented using any combination of analog and / or digital circuitry, including: bipolar, PMOS and / or NMOS gates or transistors. Also, signals in the various

[0126] The integrated circuit can implement some or all of the functionality of the networking subsystem 1514. The integrated circuit can include hardware mechanisms and / or software mechanisms for transmitting wireless signals from the electronic device 1500 and receiving signals at the electronic device 1500 from other electronic devices. Wireless radios are well known in the art other than the mechanisms described herein, and are therefore not described in detail. Generally, the networking subsystem 1514 and / or the integrated circuit can include any number of wireless radios. Note that the wireless radios in multiple-radio embodiments function in a manner similar to the single-radio embodiments described.

[0127] In some embodiments, the networking subsystem 1514 and / or the integrated circuit includes a configuration mechanism (such as one or more hardware mechanisms and / or software mechanisms) that configures the wireless radios to transmit and / or receive on a given communication channel (e.g., a given carrier frequency). For example, in some embodiments the configuration mechanism can be used to switch a wireless radio from monitoring for and / or transmitting on a given communication channel to monitoring for and / or transmitting on a different communication channel. (Note that as used herein "monitoring" includes receiving signals from other electronic devices and possibly performing one or more processing operations on the received signals)

[0128] In some embodiments, the output of the process for designing an integrated circuit or portion thereof that includes one or more of the circuits described herein can be a computer- readable medium, such as a tape or optical or magnetic disk, for example. The computer- readable medium can be encoded with data structures or other information describing the circuits that can be physically instantiated as an integrated circuit or portion thereof. While various formats can be used for such encoding, these data structures are commonly written in formats including Caltech Intermediate Format (CIF), Calma GDS II Stream Format (GDSII), Electronic Design Interchange Format (EDIF), Open Access (OA), or Open Artwork System Interchange Standard (OASIS). Those of skill in the art of integrated circuit design can develop such data structures from the schematic diagrams and corresponding descriptions set forth above in the detailed description and encode the data structures on the computer-readable medium. Those of skill in the art of manufacturing can use such encoded data in the fabrication of integrated circuits including one or more of the circuits described herein.

[0129] While the foregoing discussion uses the Wi-Fi communication protocol as an illustrative example, in other embodiments a wide variety of communication protocols can be used, and more generally a wide variety of wireless communication technologies can be used. Thus, the communication technology can be used in a variety of network interfaces. Moreover, while some of the operations in the foregoing embodiments are implemented in hardware or software, generally the operations in the foregoing embodiments can be implemented in a wide variety of configurations and architectures. Thus, some or all of the operations in the foregoing embodiments can be performed in hardware, in software, or in both hardware and software. For example, at least some of the operations in the communication technology can be implemented using program instructions 1522, the operating system 1524 (such as a driver for the interface circuit in the networking subsystem 1514), or in firmware in the interface circuit in the networking subsystem 1514. Alternatively or additionally, at least some of the operations in the communication technology can be implemented in a MAC layer and / or a physical layer in the interface circuit in the networking subsystem 1514. In some embodiments, the communication technology is implemented at least partially in the MAC layer and / or the physical layer in the interface circuit in the networking subsystem 1514.

[0130] While examples of numerical values are provided in the foregoing discussion, in other embodiments different numerical values are used. Thus, the numerical values provided are not intended to be limiting.

[0131] We refer in the foregoing description to "some embodiments". It is to be noted that "some embodiments" describe a subset of all possible embodiments, but do not always specify the same subset of embodiments.

[0132] The foregoing description is intended to enable any person skilled in the art to make and use the disclosure, and is provided in the context of a particular application and its requirements. Additionally, the foregoing description is presented in the context of one or more embodiments of the disclosure. They are not intended to be exhaustive or to limit the disclosure to the precise forms disclosed. Many modifications and variations are possible in light of the above teachings. It is, therefore, to be understood that what is described above is not intended to limit the disclosure to the specific embodiments disclosed herein. Rather, the disclosure is to cover all modifications and variations of this disclosure that come within the scope of the appended claims and their equivalents. Furthermore, the discussion of the foregoing embodiments is intended to enable those skilled in the art to make and use the disclosure, and is not intended to limit the disclosure to the particular embodiments discussed. Thus, the disclosure is not intended to be limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.

Claims

1. An electronic device comprising: an antenna node configured to be communicatively coupled to an antenna; and an interface circuit communicatively coupled to the antenna node configured to communicate with a second electronic device, wherein the interface circuit is configured to: provide, from the interface circuit, a frame addressed to the second electronic device, wherein the frame comprises a media access control (MAC) header comprising an encrypted aggregate A control subfield comprising control information for one or more features associated with a wireless communication protocol; wherein the MAC header comprises a counter mode cipher block chaining (CBC)-MAC protocol (CCMP) header and the encrypted aggregate A control subfield is located in the MAC header before the CCMP header, and wherein one bit in an extremely high throughput (EHT) preamble or one bit in the CCMP header indicates that the aggregate A control subfield has been encrypted.

2. The electronic device of claim 1, wherein the encrypted aggregate A control subfield is jointly encrypted with data in a payload in the frame.

3. The electronic device of claim 2, wherein the encrypted aggregate A control subfield is separated from the payload in the frame by one or more additional subfields.

4. The electronic device of claim 1, wherein the MAC header comprises a packet extension padding based at least in part on a presence of the encrypted aggregate A control subfield in the MAC header and a minimum delay associated with processing of the encrypted aggregate A control subfield.

5. The electronic device of claim 1, wherein the MAC header comprises an indicator indicating whether an A control field is encrypted.

6. The electronic device of claim 1, wherein the MAC header comprises an encrypted quality of service (QoS) subfield.

7. The electronic device of claim 6, wherein when an updated aggregate A control subfield is carried in a QoS null frame, the QoS null frame uses a sequence number space separate from a sequence number space of the frame.

8. The electronic device of claim 7, wherein sequence numbers in QoS null frames monotonically increase.

9. The electronic device of claim 1, wherein the frame comprises a packet extension padding.

10. The electronic device of claim 1, wherein when the frame is retransmitted, the interface circuit is configured to exclude an update to the encrypted aggregate A control subfield.

11. The electronic device of claim 1, wherein the frame comprises a preamble and when the frame is retransmitted, the preamble comprises an indication that the encrypted aggregate A control subfield is valid.

12. The electronic device of claim 1, wherein when the frame is retransmitted, the MAC header comprises an indication that the encrypted aggregate A control subfield is valid.

13. The electronic device of claim 12, wherein the indication is protected using additional associated data (AAD).

14. The electronic device of claim 1, wherein the interface circuit is configured to aggregate the frame with one or more retransmissions of frames comprising a different aggregated A control subfield of an aggregated MAC protocol data unit (A-MPDU).

15. A method for providing a frame from an electronic device, comprising: encrypting an aggregated A control subfield comprising control information for one or more features associated with a wireless communication protocol; and providing the frame addressed to a second electronic device, wherein the frame comprises a media access control (MAC) header comprising the encrypted aggregated A control subfield; wherein the MAC header comprises a counter mode cipher block chaining (CBC)-MAC protocol (CCMP) header, and the encrypted aggregated A control subfield is located before the CCMP header in the MAC header, and wherein one bit in an extremely high throughput (EHT) preamble or one bit in the CCMP header indicates that an aggregated A control subfield has been encrypted.

16. The method of claim 15, wherein the encrypted aggregated A control subfield is jointly encrypted with data in a payload in the frame.

17. A processor of an electronic device, comprising: circuitry communicatively coupled to an antenna node configured to receive signals from an antenna of the electronic device; and circuitry configured to decrypt an encrypted aggregated A control subfield received in a frame from a second electronic device, the encrypted aggregated A control subfield comprising control information for one or more features associated with a wireless communication protocol, wherein the frame comprises a media access control (MAC) header comprising the encrypted aggregated A control subfield; wherein the MAC header comprises a counter mode cipher block chaining (CBC)-MAC protocol (CCMP) header, and the encrypted aggregated A control subfield is located before the CCMP header in the MAC header, and wherein one bit in an extremely high throughput (EHT) preamble or one bit in the CCMP header indicates that an aggregated A control subfield has been encrypted.

Citation Information

Patent Citations

  • Aggregated control information for a wireless communication network

    US20200280975A1