Securing frames using integrity protection and encryption

By generating and verifying frames including security key identifiers, group numbers and integrity checks in wireless communication devices, the integrity and security issues of control information frames in wireless communication are solved, rapid response and security protection are achieved, and UE power and resource waste is avoided.

CN120752943APending Publication Date: 2025-10-03QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380094778.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-08-04
Filing Date
2023-12-27
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

In wireless communications, malicious attackers can attack control information frames, causing service denial, UE power consumption, and waste of radio frequency resources. Existing technologies make it difficult to effectively protect the integrity and security of control information frames.

Method used

Generate and verify frames including security key identifiers, packet numbers, and integrity checks in wireless communication devices. Verify the validity of frames by calculating integrity checks and comparing them with expected values ​​to prevent attackers from tampering with or replaying frames.

Benefits of technology

Effectively prevent the reception of invalid or malicious frames, save UE power and RF resources, ensure fast frame response and security, while maintaining backward compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120752943A_ABST
    Figure CN120752943A_ABST
Patent Text Reader

Abstract

The invention provides a method, a component, equipment and a system for security protection of a frame. In some examples, a frame is transmitted with a field that includes an identifier (ID) of a security key, a packet number (PN), and an integrity check that is based on one or more portions of a control frame and the security key. The device receiving the frame may validate the frame by calculating another integrity check based on the frame and the identified security key and comparing the calculated integrity check to the received integrity check.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to U.S. patent application No. 18 / 365,946, filed on August 4, 2023, which claims the benefit of and priority to U.S. Provisional Patent Application No. 63 / 487,879, filed on March 1, 2023, and U.S. Provisional Patent Application No. 63 / 504,189, filed on May 24, 2023, which are hereby assigned to the assignee of this application and are hereby expressly incorporated by reference in their entirety as if fully set forth below and for all applicable purposes. Technical Field

[0003] The present disclosure relates generally to wireless communications and, more particularly, to securing frames, particularly frames including control information. Background Art

[0004] A wireless local area network (WLAN) can be formed by one or more wireless access points (APs) that provide a shared wireless communication medium for use by multiple client devices (also known as wireless stations (STAs) or user equipment (UEs)). The fundamental building block of a WLAN that complies with the Institute of Electrical and Electronics Engineers (IEEE) 802.11 series of standards is the Basic Service Set (BSS) managed by the AP. Each BSS is identified by a Basic Service Set Identifier (BSSID) announced by the AP. The AP periodically broadcasts beacon frames to enable any STA within the AP's wireless range to establish or maintain a communication link with the WLAN.

[0005] In some WLANs, APs and STAs may engage in reliable (e.g., ultra-high reliability (UHR)) communications. UHR communications may rely on the transmission of control information for a number of purposes, such as, for example, acknowledgments, network allocation vector (NAV) settings, probing, triggering, cross-link control signaling, etc.

[0006] Malicious actors can attack wireless communications by targeting frames containing control information. Such attacks can result in denial of service, power consumption at the UE, reduced communication reliability, waste of radio frequency resources, etc. Summary of the Invention

[0007] The systems, methods and devices of the present disclosure each have several innovative aspects, no single one of which is solely responsible for the desirable attributes disclosed herein.

[0008] One innovative aspect of the subject matter described in this disclosure can be implemented in a wireless communication device. The wireless communication device includes: a memory including instructions; and one or more processors configured to execute the instructions and cause the device to: generate a frame including an identifier (ID) of a security key, a packet number (PN), and an integrity check, wherein: the integrity check is based on one or more portions of the frame and the generating includes calculating the integrity check based on at least the security key; and output the frame for transmission.

[0009] Another innovative aspect of the subject matter described in this disclosure can be implemented in a wireless communication device. The wireless communication device includes: a memory including instructions; and one or more processors configured to execute the instructions and cause the apparatus to: obtain a frame including an identifier (ID) of a security key, a packet number (PN), and an integrity check; and verify the validity of the frame based on a comparison of the integrity check with another integrity check based on at least the security key and one or more portions of the frame.

[0010] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communication. The method includes generating a frame including an identifier (ID) of a security key, a packet number (PN), and an integrity check, wherein the integrity check is based on one or more portions of the frame and the generating includes calculating the integrity check based on at least the security key; and transmitting the frame.

[0011] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communication. The method includes obtaining a frame including an identifier (ID) of a security key, a packet number (PN), and an integrity check; and responding to the frame based on a comparison of the integrity check with another integrity check based on at least the security key and one or more portions of the frame.

[0012] Details of one or more specific implementations of the subject matter described in this disclosure are set forth in the accompanying drawings and the following description. Other features, aspects, and advantages will become apparent from the description, drawings, and claims. Note that the relative dimensions of the following figures may not be drawn to scale. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 A schematic diagram of an example wireless communication network is shown.

[0014] Figure 2A The trigger frame is illustrated in block form.

[0015] Figure 2B A collection of trigger-based communications is illustrated.

[0016] Figure 3A and Figure 3B An example control message integrity check (MIC) field (CMF) is illustrated.

[0017] Figure 4 An example security trigger frame is illustrated.

[0018] Figure 5 This section illustrates an example of incorporating the CMF into the user information list field of a trigger frame.

[0019] Figure 6 An example security Null Data Packet (NDP) announcement frame is shown.

[0020] Figure 7 This section illustrates an example of incorporating the CMF into the STA Information List field of the NDP announcement frame.

[0021] Figure 8 An example secure M-BA frame is illustrated.

[0022] Figure 9 An example of incorporating the CMF into the per-AID TID information field of the secure M-BA frame is illustrated.

[0023] Figure 10 An example secure Multi-Traffic Identifier (Multi-TID) Block Acknowledgement Request (BAR) frame is illustrated.

[0024] Figure 11 Illustrated are example medium access control (MAC) protocol data units (PDUs) in accordance with certain aspects of the present disclosure.

[0025] Figure 12 An example algorithm for encrypting data of a MAC PDU (MPDU) according to previously known techniques is illustrated.

[0026] Figure 13 Example algorithms are illustrated for encrypting MAC header fields and protecting those fields for individually addressed Quality of Service (QoS) data frames or management frames.

[0027] Figure 14 Example algorithms are illustrated for encrypting MAC header fields and protecting those fields for QoS null frames, retried QoS data frames, or management frames.

[0028] Figure 15 An example of incorporating a header protection (HDR PRO) field into an MPDU is illustrated.

[0029] Figure 16 is an example call flow illustrating communications between an AP, a UHR STA, a non-UHR STA, and an attacker device.

[0030] Figure 17 A flow chart illustrating an example process that may be performed by a wireless transmitter that supports security protection of frames is shown.

[0031] Figure 18 A flow chart illustrating an example process that may be performed by a wireless receiver that supports securing frames is shown.

[0032] Figure 19 is a block diagram of an example access point (AP) and an example wireless station (STA), in accordance with certain aspects of the present disclosure.

[0033] Figure 20 A block diagram of an example wireless communication device that supports security protection of frames is shown.

[0034] Figure 21 A block diagram of an example wireless communication device that supports security protection of frames is shown.

[0035] The same reference numbers and names in different drawings represent the same elements. DETAILED DESCRIPTION

[0036] The following description refers to certain specific examples for the purpose of describing the innovative aspects of the present disclosure. However, one of ordinary skill in the art will readily recognize that the teachings herein can be applied in a variety of different ways. Some or all of the examples described may be implemented in a manner that is compatible with the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, the IEEE 802.15 standard, the Bluetooth Special Interest Group (SIG), or any other standard defined by the Bluetooth Special Interest Group (SIG). The described examples may be implemented in any device, system, or network capable of transmitting and receiving radio frequency (RF) signals in accordance with one or more of the Long Term Evolution (LTE), 3G, 4G, or 5G (New Radio (NR)) standards promulgated by the 3rd Generation Partnership Project (3GPP). The described examples may be implemented in any device, system, or network capable of transmitting and receiving RF signals in accordance with one or more of the following technologies or techniques: code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), spatial division multiple access (SDMA), rate splitting multiple access (RSMA), multi-user shared access (MUSA), single-user (SU) multiple-input multiple-output (MIMO), and multi-user (MU) MIMO. The described examples may also be implemented using other wireless communication protocols or RF signals suitable for use in one or more of a wireless personal area network (WPAN), a wireless local area network (WLAN), a wireless wide area network (WWAN), a wireless metropolitan area network (WMAN), or an Internet of Things (IoT) network.

[0037] Various aspects generally relate to securing frames, particularly frames that include control information. In some examples, a frame is transmitted with fields that include a security key identifier (ID), at least a portion of a packet number (PN), and at least a portion of an integrity check calculated based on one or more portions of the frame that include control information and the security key. The security key may be an integrity group transient key (IGTK), a pairwise transient key (PTK), or a transient key for control packets (which may be referred to as a control integrity transient key (CIGTK)). This CIGTK may be shared between the AP and the authenticated STA during or after authentication. The packet number may be an IGTK packet number or an integrity pairwise transient key (IPTK) packet number. In some cases, a frame may include only a portion of the complete PN, for example, the two least significant octets of the complete PN, and the remainder of the complete PN may be periodically or individually exchanged between devices via encrypted management frames. In some cases, a frame may include only a portion of the calculated integrity check, for example, the four least significant octets.

[0038] In some examples, the frame may be a trigger frame, a Null Data Packet (NDP) announcement frame, a Multi-Station Block Acknowledgement (M-BA) frame, a Compressed Block Acknowledgement frame, a Block Acknowledgement Request (BAR) frame, or another type of control frame. In various frames, the ID, PN, and integrity check may be included in an information field of the frame including a reserved value or included in the padding of the frame. A receiver receiving such a frame may verify the frame by calculating an integrity check for the frame using a security key identified by the ID included in the frame and comparing the calculated integrity check with the integrity check included in the frame. In addition, a receiver receiving such a frame may verify that the frame is not a replay of a frame already received by the receiver by checking that the PN of the frame is an expected PN (such as the next PN in a sequence).

[0039] In some Wi-Fi communication systems, the MAC header of a MAC PDU (also known as an MPDU, MAC frame, or packet) is not encrypted, and therefore the unencrypted MAC header is sent along with the encrypted data of the MAC PDU. In such cases, portions of some fields of the MAC header can be protected from alteration by being included in the Additional Authentication Data (AAD) of the MPDU. If an attacker attempts to alter portions of the fields included in the AAD of a transmitted MPDU or when sending a duplicate of the MPDU (e.g., an attack frame), the receiver can detect these alterations and reject (e.g., discard) the frame.

[0040] Because some Wi-Fi communication systems do not encrypt the header of the MPDU, the header of the MPDU sent by the STA can be used to track the STA's activities. For example, a STA participating in a video call via a Wi-Fi network can be tracked, and other activities of the same STA can also be linked to the STA.

[0041] Certain aspects of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages. In some examples, by validating control frames, a UE can avoid wasting power and radio frequency resources when the UE receives an invalid control frame from an attacker. Furthermore, the described techniques can be used to quickly validate control frames, allowing devices to quickly respond to control frames, in contrast to some techniques in which a large portion of the frame is encrypted, which can cause devices to spend a significant amount of time decrypting those portions of the frame. If an attacker duplicates a control frame, the receiver discards the duplication because the packet number does not match the expected packet number. If an attacker alters data in a legitimate control frame, the receiver discards the altered frame because the integrity check calculated by the receiver does not match the integrity check in the received frame. If an attacker attempts to impersonate a controller and transmit a frame, the receiver discards the frame because the attacker does not have the same security key and therefore the included integrity check will not match the integrity check calculated by the receiver. If an attacker copies the Control Message Integrity Check (MIC) field (CMF) from a legitimate frame into another frame, the receiver discards the frame because the packet number is not what was expected at the receiver or because the included integrity check does not match the integrity check calculated by the receiver. The techniques described herein also have the advantage of being backwards compatible, such that devices that are not programmed to use the described techniques can still successfully receive and respond to frames that include the ID, PN, and integrity check.

[0042] Various aspects of the present disclosure provide methods and apparatus for encrypting the MAC header of an MPDU sent by a node (e.g., an AP or STA) and for decrypting the MAC header at a receiving node. By encrypting the MPDU header, the privacy of the user of the node sending or receiving the MAC PDU can be protected.

[0043] The teachings herein may be incorporated into (eg, implemented within or performed by) various wired or wireless devices (eg, nodes). In some aspects, a wireless node implemented according to the teachings herein may comprise an access point (AP) or an access terminal (AT).

[0044] An AP may include, be implemented as, or be referred to as a Node B (NB), a Radio Network Controller (RNC), an evolved Node B (eNB), a Base Station Controller (BSC), a Base Transceiver Station (BTS), a Base Station (BS), a Transceiver Function (TF), a Radio Router, a Radio Transceiver, a Basic Service Set (BSS), an Extended Service Set (ESS), a Radio Base Station ("RBS"), an Integrated Access and Backhaul (IAB) node (e.g., an IAB donor node, an IAB parent node, and an IAB child node), or some other terminology.

[0045] AT may include, be implemented as or be referred to as the following: subscriber station, subscriber unit, mobile station, remote station, remote terminal, user terminal, user agent, user equipment, user equipment (UE), user station or some other terminology. In some specific implementations, AT may include cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless connection capability, station (STA) or some other suitable processing device connected to a wireless modem (such as augmented reality (AR) / virtual reality (VR) console and headset). Therefore, one or more aspects of this paper's teachings may be incorporated into the following: phone (e.g., cellular phone or smart phone), computer (e.g., laptop computer), portable communication device, portable computing device (e.g., personal data assistant), entertainment device (e.g., music or video device or satellite radio), global positioning system device or any other suitable device configured to communicate via wireless or wired medium. In some aspects, the node is a wireless node. For example, such a wireless node may provide connectivity for or to a network (e.g., a wide area network such as the Internet or a cellular network) via a wired or wireless communication link.

[0046] Figure 1 A block diagram of an example wireless communication network 100 is shown. According to some aspects, the wireless communication network 100 may be an example of a wireless local area network (WLAN), such as a Wi-Fi network (and will be referred to as WLAN 100 hereinafter). For example, the WLAN 100 may be a network that implements at least one of the IEEE 802.11 family of wireless communication protocol standards, such as those defined by the IEEE 802.11-2020 specification or its revisions, including but not limited to 802.11ay, 802.11ax, 802.11az, 802.11ba, 802.11bd, 802.11be, 802.11bf, and 802.11 revisions associated with Wi-Fi 8. The WLAN 100 may include a plurality of wireless communication devices, such as a wireless AP 102 and a plurality of wireless STAs 104. Although Figure 1 Only one AP 102 is shown in FIG. 1 , but the WLAN network 100 may also include multiple APs 102 . Figure 1 The illustrated AP 102 may represent various types of APs, including but not limited to enterprise-class APs, single-band APs, dual-band APs, standalone APs, software-enabled APs (soft APs), and multi-link APs. The coverage area and capacity of cellular networks (such as LTE, 5G NR, etc.) can be further improved by small cells supported by APs acting as micro base stations. In addition, small cells can also be used to establish private cellular networks over wireless area networks.

[0047] Each STA 104 may also be referred to as a mobile station (MS), a mobile device, a mobile phone, a wireless phone, an access terminal (AT), a user equipment (UE), a subscriber station (SS), or a subscriber unit, etc. STA 104 may represent a variety of devices, such as mobile phones, personal digital assistants (PDAs), other handheld devices, netbooks, notebook computers, tablet computers, laptop computers, Chromebooks, extended reality (XR) headsets, wearable devices, display devices (e.g., TVs (including smart TVs), computer monitors, navigation systems, etc.), music or other audio or stereo equipment, remote control devices (“remote controls”), printers, kitchen appliances (including smart refrigerators) or other home appliances, key fobs (e.g., for passive keyless entry and start (PKES) systems), Internet of Things (IoT) devices, vehicles, etc. The various STAs 104 in the network can communicate with each other via the AP 102.

[0048] A single AP 102 and the associated set of STAs 104 may be referred to as a basic service set (BSS), which is managed by the corresponding AP 102 . Figure 1Additionally shown is an example coverage area 108 of the AP 102, which may represent a basic service area (BSA) of the WLAN 100. A BSS may be identified or indicated to a user by a service set identifier (SSID) and may also be identified to other devices by a basic service set identifier (BSSID), which may be the media access control (MAC) address of the AP 102. The AP 102 may periodically broadcast a beacon frame ("beacon") including the BSSID to enable any STA 104 within wireless range of the AP 102 to "associate" or re-associate with the AP 102 to establish or maintain a corresponding communication link 106 (hereinafter also referred to as a "Wi-Fi link") with the AP 102. For example, the beacon may include an identification or indication of a primary channel used by the corresponding AP 102 and a timing synchronization function for establishing or maintaining timing synchronization with the AP 102. The AP 102 may provide access to external networks to the various STAs 104 in the WLAN via respective communication links 106 .

[0049] To establish a communication link 106 with the AP 102, each of the STAs 104 is configured to perform passive or active scanning operations ("scans") on frequency channels in one or more frequency bands (eg, the 2.4 GHz, 5 GHz, 6 GHz, or 60 GHz bands). To perform passive scanning, the STA 104 listens for beacons transmitted by the corresponding AP 102 at periodic time intervals, referred to as target beacon transmit times (TBTTs), measured in time units (TUs), where one TU may be equal to 1024 microseconds (μs). To perform active scanning, the STA 104 generates probe requests and sequentially transmits these probe requests on each channel to be scanned, and listens for probe responses from the AP 102. Each STA 104 may identify, determine, detect, or select an AP 102 with which to associate based on the scanning information obtained through passive or active scanning, and perform authentication and association operations to establish a communication link 106 with the selected AP 102. The AP 102 assigns an association identifier (AID) to the STA 104 at the end of the association operation, and the AP 102 uses the association identifier (AID) to track the STA 104.

[0050] As wireless networks become increasingly common, a STA 104 may have the opportunity to select one of many BSSs within range of the STA or multiple APs 102 that together form an extended service set (ESS) (including multiple connected BSSs). Extended network stations associated with a WLAN 100 can connect to a wired or wireless distribution system that allows multiple APs 102 to connect in such an ESS. Thus, a STA 104 may be covered by more than one AP 102 and may associate with different APs 102 at different times for different transmissions. In addition, after associating with an AP 102, the STA 104 may also periodically scan its surroundings to find a more suitable AP 102 with which to associate. For example, a STA 104 that is moving relative to its associated AP 102 may perform a "roaming" scan to find another AP 102 with more desirable network characteristics, such as a greater received signal strength indicator (RSSI) or reduced traffic load.

[0051] In some cases, STAs 104 may form a network without APs 102 or other equipment other than the STAs 104 themselves. One example of such a network is an ad hoc network (or wireless ad hoc network). An ad hoc network may alternatively be referred to as a mesh network or a peer-to-peer (P2P) network. In some cases, an ad hoc network may be implemented within a larger wireless network, such as WLAN 100. In such an example, while STAs 104 may be able to communicate with each other through AP 102 using communication link 106, STAs 104 may also communicate directly with each other via direct wireless communication link 110. Additionally, two STAs 104 may communicate via direct wireless link 110 regardless of whether they are associated with and served by the same AP 102. In such an ad hoc system, one or more of the STAs 104 may assume the role played by AP 102 in a BSS. Such STAs 104 may be referred to as group owners (GOs) and may coordinate transmissions within the ad hoc network. Examples of direct wireless communication links 110 include Wi-Fi direct connections, connections established by using a Wi-Fi Tunneled Direct Link Setup (TDLS) link, and other P2P group connections.

[0052] The AP 102 and the STA 104 may operate and communicate in accordance with one or more of the IEEE 802.11 family of wireless communication protocol standards (via corresponding communication links 106). These standards define WLAN radio and baseband protocols for the PHY and MAC layers. The AP 102 and the STA 104 send and receive wireless communications (hereinafter also referred to as "Wi-Fi communications" or "wireless packets") to and from each other in the form of PHY protocol data units (PPDUs). The AP 102 and the STA 104 in the WLAN 100 may send PPDUs over an unlicensed spectrum, which may be a portion of the spectrum that includes frequency bands traditionally used by Wi-Fi technology, such as the 2.4 GHz band, the 5 GHz band, the 60 GHz band, the 3.6 GHz band, and the 900 MHz band. Some examples of the AP 102 and the STA 104 described herein may also communicate in other frequency bands that may support both licensed and unlicensed communications, such as the 5.9 GHz band and the 6 GHz band. The AP 102 and STAs 104 may also communicate on other frequency bands, such as shared licensed frequency bands, where multiple operators may have licenses to operate in one or more of the same or overlapping frequency bands.

[0053] Each frequency band may include multiple sub-bands or frequency channels. For example, PPDUs compliant with IEEE 802.11n, 802.11ac, 802.11ax, and 802.11be standard revisions may be transmitted in the 2.4 GHz, 5 GHz, or 6 GHz frequency bands, each of which is divided into multiple 20 MHz channels. Thus, these PPDUs are transmitted on physical channels with a minimum bandwidth of 20 MHz, but larger channels may be formed through channel bonding. For example, a PPDU may be transmitted on a physical channel with a bandwidth of 40 MHz, 80 MHz, 160 MHz, or 320 MHz by bonding multiple 20 MHz channels together.

[0054] Each PPDU is a composite structure that includes a PHY preamble and a payload in the form of a PHY service data unit (PSDU). The information provided in the preamble can be used by the receiving device to decode subsequent data in the PSDU. In instances where the PPDU is transmitted on a bonded channel, the preamble field may be replicated and transmitted in each of the multiple component channels. The PHY preamble may include both a legacy portion (or "legacy preamble") and a non-legacy portion (or "non-legacy preamble"). Legacy preambles may be used for other purposes such as packet detection, automatic gain control, and channel estimation. Legacy preambles are also typically used to maintain compatibility with legacy devices. The format, decoding, and information provided in the non-legacy portion of the preamble are associated with the specific IEEE 802.11 protocol to be used to transmit the payload.

[0055] The AP 102 and the STAs 104 may support multi-user (MU) communications; that is, concurrent transmissions from one device to each of multiple devices (e.g., multiple simultaneous downlink (DL) communications from the AP 102 to the corresponding STAs 104), or concurrent transmissions from multiple devices to a single device (e.g., multiple simultaneous uplink (UL) transmissions from the corresponding STAs 104 to the AP 102). To support MU transmissions, the AP 102 and the STAs 104 may utilize multi-user multiple-input multiple-output (MU-MIMO) and multi-user orthogonal frequency-division multiple access (MU-OFDMA) techniques.

[0056] In the MU-OFDMA scheme, the available spectrum of a wireless channel can be divided into multiple resource units (RUs), each of which includes multiple frequency subcarriers (also known as "tones"). Different RUs can be allocated or assigned to different STAs 104 by the AP 102 at a specific time. The size and distribution of the RUs can be referred to as RU allocation. In some examples, RUs can be allocated in 2 MHz intervals, and thus, the smallest RU can include 26 tones consisting of 24 data tones and 2 pilot tones. Therefore, in a 20 MHz channel, up to 9 RUs (such as 2 MHz, 26-tone RUs) can be allocated (because some tones are reserved for other purposes). Similarly, in a 160 MHz channel, up to 74 RUs can be allocated. Larger 52-tone, 106-tone, 242-tone, 484-tone, and 996-tone RUs can also be allocated. Adjacent RUs can be separated by null subcarriers (such as DC subcarriers), for example to reduce interference between adjacent RUs, reduce receiver DC offset, and avoid transmit center frequency leakage.

[0057] For UL MU transmissions, the AP 102 may send a trigger frame to initiate and synchronize UL MU-OFDMA or UL MU-MIMO transmissions from multiple STAs 104 to the AP 102. Such a trigger frame may thereby enable multiple STAs 104 to transmit UL traffic concurrently in time to the AP 102. The trigger frame may address one or more STAs 104 by corresponding association identifiers (AIDs) and may assign one or more RUs to each AID (and thus each STA 104) that may be used to transmit UL traffic to the AP 102. The AP may also specify one or more random access (RA) RUs that unscheduled STAs 104 may contend for.

[0058] Figure 2AA trigger frame 200 according to aspects of the present disclosure is illustrated in block form. As shown, the trigger frame 200 may include a frame control field, a duration field, a receiver address (RA) field, a transmitter address (TA) field, a common information field, a user information list, padding, and a frame check sequence (FCS) field.

[0059] Figure 2B A collection 250 of trigger-based communications according to various aspects of the present disclosure is illustrated. As shown, an AP (such as the one described above with reference to FIG. Figure 1 The AP 102 described above may send a trigger frame 252, which may be a trigger frame 252 as described above. Figure 2A An example of a trigger frame 200 is described. Upon receiving the trigger frame 252, one or more UEs (such as those described above with reference to Figure 1 The UE 104 depicted may transmit an UL frame 254 in response to the trigger frame 252. In response to the UL frame 254, the AP may transmit a multi-station block acknowledgement (M-BA) frame 256 to the UE. The M-BA frame may indicate successful reception of one or more of the UL frames 254 while also indicating that one or more other UL frames 254 were not received by the AP.

[0060] Figure 3A An example control message integrity check (MIC) field (CMF) 300 is illustrated in accordance with aspects of the present disclosure. The example CMF 300 includes a security key ID field 302 comprising two octets, an integrity group transient key (IGTK) group number or an integrity pairwise transient key (IPTK) group number 304 comprising six octets, and a message integrity check (MIC) field 306 (also referred to herein as a message integrity code field) comprising eight or sixteen octets. It may be noted that the example CMF 300 has a structure similar to a management MIC information element (IE) that may be used to protect beacon frames. However, the present disclosure is not limited thereto. Figure 3A, and includes CMFs with other structures. For example, the ID described herein may be conveyed in a field smaller than two octets, or as bits included in other fields of the frame. In another example, the full packet number (PN) described herein may be split into a partial packet number (PPN) and a base packet number, and the PN field of the CMF described herein may convey the PPN instead of the full packet number. The wireless nodes described herein may occasionally (e.g., periodically, in response to a request, or in response to a triggering event) exchange base packet numbers and store the base packet numbers for use (e.g., when calculating, sending, or verifying received packets). In yet another example, the wireless nodes described herein may include only a portion of the MIC in a packet (e.g., in a CMF in the packet). The wireless nodes described herein may send four octets of the MIC (e.g., the four least significant octets of the MIC), and a node receiving a packet including the four octets of the MIC may compare the four octets with the corresponding four octets of an integrity check calculated based on at least a security key and other portions of the packet.

[0061] Figure 3B An example CMF 350 is illustrated in accordance with aspects of the present disclosure. The example CMF 350 includes a MIC control field 352, a PN field 354, and a MIC field 356. As shown, the MIC control field 352 may include two octets, which may include one or more bits that convey a key ID and / or other bits that indicate the combined length of the MIC control field and the PN field. The PN field 354 may include two octets and may convey a PPN, which may be, for example, the two least significant octets of the packet number. The MIC field 356 may include four octets that convey a portion of the MIC for the packet (e.g., the four least significant octets).

[0062] Figure 4An example security trigger frame 400 according to various aspects of the present disclosure is illustrated. As shown, the security trigger frame 400 includes a CMF 402 after the user information list and may include padding 404 after the CMF. Alternatively, the CMF may be included in the padding of the security trigger frame 400. The MIC of the CMF may be calculated over all or part of the fields of the MAC header (e.g., duration, TA, RA, etc.), and the trigger frame body includes a common information field, a user information list field, a security key corresponding to the ID field, and a PN field. UHR STAs associated with the AP and unassociated UHR STAs with access rights to the IGTK may verify the trigger frame. If those STAs cannot verify the trigger frame because the calculated MIC does not match the MIC in the trigger frame, the STA discards the trigger frame and avoids generating a trigger-based (TB) PPDU, thereby saving power. Other STAs that are not UHR STAs (such as HE or EHT STAs) may ignore the CMF 402 when processing the rest of the trigger frame 400. Although the illustrated CMF 402 is similar to Figure 3A The CMF 300 is shown, but the present disclosure is not so limited, and the CMF in the security trigger frame may have other structures, such as Figure 3B The structure of the example CMF 350 is illustrated.

[0063] Figure 5 5. The present disclosure illustrates a method of converting a CMF 510 (which may be a CMF 510 as described above) into a CMF according to various aspects of the present disclosure. Figure 3A and Figure 3B The examples of CMF 300 or 350 described above) incorporate a trigger frame (such as trigger frame 400 (described above with reference to Figure 4 1 . Example 500 of a user information list field 501 of a MIC (e.g., a MIC) is shown. Three user information list fields 501a, 501b, and 501e are illustrated, each comprising five octets. The five octets of each user information list field include: a twelve-bit association ID field 502; a four-bit first field 504; and a twenty-four-bit second field 506. As shown, bits of a CMF 510 may be included in first fields 504a, 504b, 504c, etc., and second fields 506a, 506b, 506c, etc., of the user information list field, which includes association ID fields 502a, 502b, 502c, etc. set to a reserved value (such as 2023). When the MIC comprises eight octets, a CMF having the structure of CMF 300 may be included in five user information list fields, each comprising five octets. When the MIC includes sixteen octets, the CMF having the structure of the CMF 300 may be included in seven user information list fields each having five octets.

[0064] In aspects of the present disclosure, one or more reserved values ​​of the association ID may indicate the presence of a MIC in a field of the security trigger frame.

[0065] According to aspects of the present disclosure, the CMF may be included in the padding field of the trigger frame, following a sequence of sixteen ones in the first two octets of padding that signals to the receiver that padding has begun. The CMF may be included in the next eight, sixteen, twenty-four, or another number of octets of the padding field, and the additional bits following the CMF may be considered padding.

[0066] According to aspects of the present disclosure, a bit in a trigger frame, such as a protected bit in a frame control field, may be used to indicate the presence of a CMF in the trigger frame.

[0067] In aspects of the present disclosure, bits in the trigger frame (such as bits in the padding field) may indicate the length of the CMF present in the trigger frame (such as sixteen octets or twenty-four octets).

[0068] According to aspects of the present disclosure, a UHR STA may validate a frame based on the CMF and start processing the frame before the UHR has checked the FCS, because validating the PN in the CMF is an alternative to checking the FCS of the frame.

[0069] Figure 6 An example secure null data packet (NDP) announcement frame 600 is shown in accordance with aspects of the present disclosure. As shown, the secure NDP announcement frame 600 includes a CMF 602 following the STA information list and may include padding 604 following the CMF. Alternatively, the CMF may be included in the padding of the secure NDP announcement frame 600. The MIC of the CMF may be calculated on the NDP announcement frame body, which includes a probe dialogue token, a STA information list field, a security key ID field, and a PN field. UHR STAs associated with the AP may verify the secure NDP announcement frame 600. If those STAs cannot verify the trigger frame because the calculated MIC does not match the MIC in the trigger frame, the STA discards the NDP announcement frame. Other STAs that are not UHR STAs, such as HE or EHT STAs, may ignore the CMF 602 when processing the rest of the NDP announcement frame 600. Although the illustrated CMF 602 is similar to Figure 3A The CMF 300 is shown, but the present disclosure is not so limited, and the CMF in the secure NDP announcement frame may have other structures, such as Figure 3B The structure of the example CMF 350 is illustrated.

[0070] Figure 77. The present disclosure illustrates a method of converting a CMF 710 (which may be a CMF 710 as described above) into a CMF according to various aspects of the present disclosure. Figure 3A and Figure 3B The example of the CMF 300 or 350 described above) incorporates an NDP announcement frame (such as the NDP announcement frame 600 (described above with reference to Figure 6 1 . An example 700 of the STA information list field 701 of FIG. 2 is shown. Two STA information list fields 701a and 701g are illustrated, and each STA information list field includes four octets. The four octets of each STA information list field in the STA information list field include: an association ID field 702 including eleven bits, a first field 704 including sixteen bits, a disambiguation field 706 including one bit, and a second field 708 including four bits. As shown in the figure, bits of the CMF 710 may be included in the first fields 704a, 704b, 704c, etc. and the second fields 708a, 708b, 708c, etc. in the STA information list fields 701a, 701b, 701c, etc., including the association ID fields 702a, 702b, 702c, etc. set to a reserved value (such as 2023). When the MIC includes eight octets, the CMF having the structure of CMF 300 may be included in seven STA Information List fields, each having four octets. When the MIC includes sixteen octets, the CMF having the structure of CMF 300 may be included in ten STA Information List fields, each having four octets.

[0071] In aspects of the present disclosure, one or more reserved values ​​of the Association ID may indicate the presence of a MIC in a field of the Secure NDP Announcement frame.

[0072] According to aspects of the present disclosure, the CMF may be included in the padding field of the secure NDP announcement frame, following a sequence of sixteen ones in the first two octets of the padding to signal to the receiver that padding has begun. The CMF may be included in the next eight or sixteen octets of the padding field, and the additional bits after the CMF may be considered padding.

[0073] Figure 8An example secure M-BA frame 800 according to aspects of the present disclosure is illustrated. As shown, the secure M-BA frame 800 includes a CMF 802 in a block acknowledgement information list and may include padding 804 following the CMF 802. Alternatively, the CMF 802 may be included in the padding of the secure M-BA frame 800. The MIC of the CMF may be calculated on the M-BA frame body, which includes a BA control field and a previous per-AID traffic identifier (TID) information field. The UHR STAs associated with the AP may verify the secure M-BA frame. If those STAs cannot verify the secure M-BA frame because the calculated MIC does not match the MIC in the trigger frame, the STA discards the secure M-BA frame and avoids losing packets indicated as acknowledged by the invalid secure M-BA frame. Other STAs that are not UHR STAs, such as HE or EHT STAs, may ignore the CMF 802 when processing the rest of the secure M-BA frame 800. The structure of the illustrated CMF 802 may be similar to Figure 3A and Figure 3B The structure or the other structure of one of the CMFs 300 or 350 shown in FIG.

[0074] Figure 9 exemplifies the method of converting a CMF 930 (which may be the CMF of the embodiment of the present disclosure) into a CMF 930 according to various aspects of the present disclosure. Figure 3A and Figure 3B The example of the CMF 300 or 350 described above) incorporates a secure M-BA frame (such as the secure M-BA frame 800 (described above with reference to Figure 8 900 is an example of a per-AID TID information field 902 in a block acknowledgement information field (CMF) of FIG. Two per-AID TID information fields 902a and 902n are illustrated, and the per-AID TID information field 902n configured to convey a CMF 930 may include 18 to 36 octets, including: an AID TID information field 910 including two octets, a block acknowledgement start sequence control field 920 including zero or two octets, and a CMF 930 including sixteen or thirty-two octets. As shown, the AID TID information field 910 may include an AID field 912, which includes eleven bits and may be set to a reserved value (such as 2023) to indicate the presence of a CMF in the per-AID TID information field 902n. When the MIC includes eight octets, the CMF 930 having the structure of the CMF 300 may include sixteen octets, and when the MIC includes sixteen octets, the CMF 930 having the structure of the CMF 300 may include 32 octets. The FN subfield of the Block Ack Start Sequence Control field 920 may indicate the CMF field length.

[0075] In aspects of the present disclosure, one or more reserved values ​​of the Association ID may indicate the presence of a CMF in the Per-AID TID Information field of a Secure M-BA frame.

[0076] According to aspects of the present disclosure, a CMF may be included in a secure Compressed Block Ack (C-BA) frame in a manner similar to that described for a secure M-BA frame.

[0077] Figure 10 An example secure multi-service identifier (multi-TID) block acknowledgement request (BAR) frame 1000 is illustrated, in accordance with aspects of the present disclosure. As shown, secure multi-TID BAR frame 1000 includes a CMF 1002 following the last useful BAR information list and may include padding following CMF 1002. Alternatively, the CMF may be included in the padding of secure multi-TID BAR frame 1000. A MIC for the CMF may be calculated over the secure multi-TID BAR frame body, which includes a BAR control field, a BAR information field, a security key ID field, and a PN field. UHR STAs associated with an AP may validate the secure multi-TID BAR frame. If those STAs are unable to validate the secure multi-TID BAR frame due to a mismatch between the calculated MIC and the MIC in the secure multi-TID BAR frame, the STAs discard the secure multi-TID BAR frame. Other STAs that are not UHR STAs (such as HE or EHT STAs) may ignore the CMF 1002 when processing the rest of the secure multi-TID BAR frame 1000. As shown, the CMF 1002 may be included in the BAR information field, which has the first bit in the per-TID information field set (which is generally considered to be a set of twelve bits reserved) set to indicate the presence of the CMF. The bits of the CMF 1002 may be included in the Block Ack Start Sequence Control field and other fields of the BAR information field. A sequence of ones may be used to indicate padding after the CMF. Although the illustrated CMF 1002 is similar to Figure 3A The CMF 300 is shown, but the present disclosure is not so limited, and the CMF in the secure multi-TID BAR frame may have other structures, such as Figure 3B The structure of the example CMF 350 is illustrated.

[0078] Figure 11 Illustrated is an example MPDU 1100 in accordance with certain aspects of the present disclosure. An additional control field (eg, a High Efficiency (HE) Control field) may be added to the MAC header of the MPDU 1100 in order to provide certain control information.

[0079] Figure 12An example algorithm 1200 for encrypting data in an MPDU is illustrated. As shown in example algorithm 1200, the MAC header 1208 is not encrypted in the Galois / Counter Mode (GCM) encryption block, and therefore the unencrypted MAC header is sent along with the encrypted data. In example algorithm 1200, portions of some fields in the MAC header of MPDU 1100 are protected from alteration by being included in the Additional Authentication Data (AAD) of the MPDU. If an attacker attempts to alter portions of fields included in the AAD of a transmitted MPDU or when sending duplicates of the MPDU (e.g., an attack frame), the recipient can detect these alterations and reject (e.g., discard) the attack frame. Some bits of the Frame Control (FC) field of example MPDU 1100 are not protected by AAD. AAD does not protect the three least significant bits of the Subtype subfield of the FC field (i.e., bits 4, 5, and 6 of the FC field), the Retry subfield (i.e., bit 11 of the FC field), the Power Management subfield (i.e., bit 12 of the FC field), and the More Data subfield (i.e., bit 13 of the FC field). Furthermore, AAD does not protect the +HTC subfield (i.e., bit 15 of the FC field) that contains the QoS Control field in a data frame. AAD also does not protect the Sequence Number subfield (i.e., bits 4 through 15) of the Sequence Control (SC) field. AAD also does not protect the QoS Control field, except for the TID subfield within the QoS Control field. Furthermore, AAD does not protect the Duration / ID and HT Control fields.

[0080] Because some algorithms do not encrypt some MPDU header fields, those header fields can be used to track the activity of a node (e.g., a STA or AP). For example, a STA participating in a video call over a Wi-Fi network can be tracked, and other activities of the same STA can also be linked to that STA. Therefore, it is desirable to develop methods and apparatus for encrypting one or more subfields and fields of the MAC header of an MPDU. Such encryption can improve user privacy for users of the node.

[0081] Figure 13An example algorithm 1300 is illustrated for encrypting MAC header fields and protecting those fields for individually addressed QoS data frames or management frames ((M)MPDUs). As shown in the example algorithm 1300, an encryption key (TK') 1302, a key ID 1304 (Key ID') for the encryption key, and a packet number (PN') 1306 for a MAC header 1308 are provided to a header protection block 1310. The encryption key (TK') 1302, PN' 1306, and Key ID' 1304 provided to the header protection block 1310 may be different from the encryption key (TK) 1322, PN 1326, and Key ID 1324 used by the GCM encryption block 1330 to encrypt the data of the MPDU and determine the MIC used to protect the data. The encryption key 1302 is used to encrypt one or more portions of the MAC header, the MIC of the MAC header is calculated, and an indication of the PN' 1306, an indication of the key ID' 1304, and an indication of the HDR MIC are placed by the header protection block 1310 in the header protection field of the individually addressed QoS data frame or management frame ((M)MPDU) (see Figure 15 )middle.

[0082] Figure 14 An example algorithm 1400 is illustrated for encrypting MAC header fields and protecting those fields for QoS Null frames, Retried QoS Data frames, or Retried Management frames ((M)MPDUs). Figure 13 Items in the described example algorithm 1400 are not described further. Because the QoS Null frame does not include data, there is no GCM encryption block 1330 ( Figure 13 ). Because the retried QoS data frame or retried (M)MPDU each transports the same encrypted data as the original QoS data frame or original (M)MPDU (i.e., the original QoS data frame or original (M)MPDU being retried / retransmitted, and note that the Retry subfield of the FC field is not protected by AAD, as described above), there is also no GCM cipher block for those types of frames in the example algorithm 1400. As described above with reference to Figure 13 As described, the indication of PN' 1306, the indication of Key ID' 1304 and the indication of HDR MIC are placed by the Header Protection Block 1310 in the Header Protection field of the QoS Null Frame, the Retried QoS Data Frame or the Retried (M)MPDU (see Figure 15 )middle.

[0083] Figure 15An example of incorporating a Header Protection (HDR PRO) field 1502 into an MPDU 1500 is illustrated. As shown, the HDR PRO field 1502 may be included before or after the Galois / Counter Mode Protocol (GCMP) header 1504 of the MPDU. The HDR PRO field may include an indication of a packet number (PN) associated with the MAC header. This indication may be a shortened version of the PN associated with the MAC header. The HDR PRO may also include an indication of a key ID for a key used to encrypt the encrypted portion of the MAC header. The HDR PRO may also include an indication of a MIC for the MAC header. This indication of a MIC may be a shortened version of a MIC calculated for the MAC header.

[0084] Because the group address frame may be received by legacy STAs that are unable to decrypt the encrypted MAC header, it is desirable to protect the MAC header of the group address frame without encrypting the MAC header of the group address frame.

[0085] In various aspects of the present disclosure, the MAC header of a group address frame can be protected by subsequent frames without encrypting the MAC header of the group address frame. A transmitter (e.g., a STA or an AP) that sends a group address frame can send the group address frame according to previously known techniques and then send subsequent frames one SIFS later than the group address frame. The transmitter can include an indication of the PN, key ID, and MIC for the header of the group address frame in the subsequent frame. Legacy STAs that are unable to decrypt the subsequent frame ignore the subsequent frame. A STA that is an embodiment of the present disclosure can receive the subsequent frame and verify the previous group address frame using the PN, key ID, and MIC indicated in the subsequent frame.

[0086] Figure 1616 is an example call flow 1600 illustrating communications between an AP 1602, a UHR STA 1604a, a non-UHR STA 1604b, and an attacker device 1650. At 1610, AP 1602 sends a frame including a security key ID, a PN, and an IC. At 1612, UHR STA 1604a validates the frame by comparing the PN with the expected PN for the frame and by comparing the IC received with the frame with another IC calculated for the frame based on at least the security key indicated by the ID. At 1620, UHR STA 1604a accepts the validated frame and acts accordingly. At 1614, non-UHR STA 1604b accepts the frame without validating it and acts accordingly. At 1616, attacker device 1650 receives the frame, potentially recording or analyzing it. At 1652, attacker device 1650 transmits an attack frame (such as a replay of frame 1610 or a defective block confirmation frame). At 1654, UHR STA 1604a fails to validate the attack frame, and at 1660, UHR STA 1604a discards the unvalidated attack frame. Similarly, at 1656, AP 1602 fails to validate the attack frame, and at 1662, AP 1602 discards the unvalidated attack frame. At 1658, non-UHR STA 1604b accepts the attack frame (without validating it) and acts according to the attack frame.

[0087] Figure 17 A flow chart illustrating an example process 1700 that can be performed at a wireless transmitter supporting security protection of frames according to some aspects of the present disclosure is shown. The operations of process 1700 may be implemented by a wireless AP or UE, or components of a wireless AP or UE, as described herein. For example, process 1700 may be performed by a wireless communication device operating as a wireless AP or UE, or within a wireless AP or UE, such as a wireless communication device (such as a wireless communication device) Figure 20 In some examples, process 1700 may be performed by a wireless AP (such as a wireless AP described in reference Figure 1 In some examples, process 1700 may be performed by a wireless STA (such as one of the APs 102 described herein). Figure 1 One of the STAs 104 described herein) performs.

[0088] In some examples, in box 1702, the wireless transmitter generates a frame that includes an identifier (ID) of a security key, a packet number (PN), and an integrity check, wherein: the integrity check is based on one or more parts of the frame, and the generating includes calculating the integrity check based on at least the security key.

[0089] In block 1704, the wireless transmitter outputs a frame for transmission.

[0090] Figure 18 A flow chart illustrating an example process 1800 that can be performed at a wireless receiver that supports security protection of frames according to some aspects of the present disclosure is shown. The operations of process 1800 may be implemented by a wireless STA or AP or a component of a wireless STA or AP as described herein. For example, process 1800 may be performed by a wireless communication device operating as or within a wireless STA or AP (such as a wireless communication device described in reference to FIG. Figure 21 In some examples, process 1800 may be performed by a wireless STA (such as a wireless STA 2100 described in the referenced embodiment). Figure 1 In some examples, process 1800 may be performed by a wireless AP (such as one of the STAs 104 described herein). Figure 1 102) is performed.

[0091] In some examples, in block 1802, a wireless receiver obtains a frame including an identifier (ID) of a security key, a packet number (PN), and an integrity check.

[0092] In block 1804, the wireless receiver verifies the validity of the frame based on a comparison of the integrity check to another integrity check based on at least the security key and one or more portions of the frame.

[0093] Figure 19 A block diagram illustrating an AP 102 and two wireless STAs 104m and 104x in a MIMO / MLO system, such as the wireless communication network 100, according to certain aspects of the present disclosure is shown. In certain aspects, the AP 102 and / or the wireless STAs 104m and 104x may perform various techniques to secure frames, particularly frames including control information.

[0094] AP 102 is equipped with N ap The wireless STA 104m is equipped with N antennas 1924a to 1924ap. sta,m antennas 1952ma to 1952mu, and the wireless STA 104x is equipped with N sta,x Antennas 1952xa to 1952xu. AP 102 is a transmitting entity for DL ​​and a receiving entity for UL. Each wireless STA 104 is a transmitting entity for UL and a receiving entity for DL. As used herein, a "transmitting entity" is an independently operated device or equipment capable of transmitting data via a wireless channel, and a "receiving entity" is an independently operated device or equipment capable of receiving data via a wireless channel. The term communication generally refers to transmission, reception, or both. In the following description, the subscript "DL" indicates downlink, the subscript "UL" indicates uplink, and N ULWireless STAs are selected for simultaneous transmission on the uplink, N DL Wireless STAs are selected for simultaneous transmission on the downlink, N UL May or may not be equal to N DL , and N UL and N DL It may be a static value, or it may be changed for each scheduling interval.Beam steering, beam forming, or some other spatial processing technique may be used at the access point and wireless stations.

[0095] On the UL, at each wireless STA 104 selected for UL transmission, a transmit (TX) data processor 1988 receives traffic data from a data source 1986 and control data from a controller 1980. The TX data processor 1988 processes (e.g., encodes, interleaves, and modulates) the traffic data for the wireless station based on a coding and modulation scheme associated with the rate selected for the wireless STA and provides a data symbol stream. The TX spatial processor 1990 performs spatial processing on the data symbol stream and transmits the data symbol stream to the N STA. sta,m The antennas provide N sta,m Each transceiver (TMTR) 1954 receives and processes (eg, converts to analog, amplifies, filters, and frequency upconverts) a corresponding transmit symbol stream to generate an uplink signal. N sta,m 1954 transceivers provide N sta,m UL signal for N sta,m The antennas 1952 transmit to the AP 102. The memory 1982 may store data and program codes for the user terminal 104 and may interact with the controller 1980.

[0096] Schedulable N UL Each of these wireless STAs performs spatial processing on its data symbol stream and sends its set of transmit symbol streams to AP 102 on the UL.

[0097] At AP 102, N ap Antennas 1924a to 1924ap are connected to all N UL Each wireless STA receives the UL signal transmitted on the UL. Each antenna 1924 provides a received signal to a corresponding transceiver (RCVR) 1922. Each transceiver 1922 performs processing complementary to that performed by transceiver 1954 and provides a received symbol stream. The receive (RX) spatial processor 1940 processes the signals from the N ap N of 1922 transceivers ap The receiver performs spatial processing on the received symbol streams and provides N ULReceiver spatial processing is performed based on channel correlation matrix inversion (CCMI), minimum mean square error (MMSE), soft interference cancellation (SIC), or some other technique. Each recovered UL data symbol stream is an estimate of the data symbol stream sent by the corresponding wireless station. RX data processor 1942 processes (e.g., demodulates, deinterleaves, and decodes) each recovered uplink data symbol stream based on the rate used for that stream to obtain decoded data. The decoded data for each wireless STA may be provided to a data sink 1944 (e.g., data sink 1972 corresponding to UT 104) for storage and / or to a controller 1930 for further processing.

[0098] On the DL, at the AP 102, the TX data processor 1910 receives N data packets scheduled for downlink transmission from a data source 1908. DL The TX data processor 1910 processes (e.g., encodes, interleaves, and modulates) the traffic data of each wireless station based on the rate selected for that wireless station. The TX data processor 1910 processes (e.g., encodes, interleaves, and modulates) the traffic data of each wireless station based on the rate selected for that wireless station. DL Wireless stations provide N DL DL data symbol streams. TX spatial processor 1920 performs N DL The DL data symbol streams are spatially processed (such as precoding or beamforming as described in this disclosure) and are N ap The antennas provide N ap Each transceiver 1922 receives and processes a corresponding transmit symbol stream to generate a DL signal. ap 1922 transceivers provide N ap DL signals for N ap The antennas 1924 transmit to the wireless STAs. The memory 1932 may store data and program codes for the access point 102 and may interact with the controller 1930.

[0099] At each wireless STA 104, N sta,m Antenna 1952 receives N signals from access point 102 ap Each transceiver 1954 processes the received signal from an associated antenna 1952 and provides a received symbol stream. The RX spatial processor 1960 processes the received signal from N sta,m N of transceivers 1954 sta,mThe RX data processor 1970 performs receiver spatial processing on the received symbol streams and provides a recovered DL data symbol stream to the wireless station. The receiver spatial processing is performed based on CCMI, MMSE, or some other technique. The RX data processor 1970 processes (e.g., demodulates, deinterleaves, and decodes) the recovered DL data symbol stream to obtain decoded data for the wireless station.

[0100] At each wireless STA 104, a channel estimator 1978 estimates the DL channel response and provides a DL channel estimate, which may include a channel gain estimate, an SNR estimate, a noise variance, etc. Similarly, a channel estimator 1928 estimates the UL channel response and provides a UL channel estimate. The controller 1980 of each wireless STA is typically based on the wireless station's downlink channel response matrix H dn,m The controller 1930 derives the spatial filter matrix for the wireless station based on the effective UL channel response matrix H up,eff To derive the spatial filter matrix for the AP. The controller 1980 of each wireless STA can transmit feedback information (e.g., downlink and / or uplink eigenvectors, eigenvalues, SNR estimates, etc.) to the AP. Controllers 1930 and 1980 also control the operation of various processing units at AP 102 and wireless STA 104, respectively.

[0101] Example device

[0102] Figure 20 Examples may include processes operable, configured, or adapted to perform operations for the techniques disclosed herein (such as Figure 17 2. The communication device 2000 may include various components (such as corresponding means plus function components) for the operations illustrated in FIG.

[0103] The communication device 2000 includes a processing system 2002 coupled to a transceiver 2008 (such as a transmitter or receiver). The transceiver 2008 is configured to transmit and receive signals for the communication device 2000, such as the various signals described herein, via an antenna 2010. The processing system 2002 can be configured to perform processing functions for the communication device 2000, including processing signals received by or to be transmitted by the communication device 2000.

[0104] The processing system 2002 includes a processor 2004 coupled to a computer-readable medium / memory 2012 via a bus 2006. In some aspects, the computer-readable medium / memory 2012 is configured to store instructions (such as computer-executable code) that, when executed by the processor 2004, cause the processor 2004 to perform Figure 17 or other operations for performing the various techniques discussed herein.

[0105] In some aspects, the computer-readable medium / memory 2012 stores code for generating 2014 (such as an example of a component for generating); code for computing 2015 (such as an example of a component for computing); code for outputting 2016 (such as an example of a component for outputting); code for placing 2017 (such as an example of a component for placing); code for setting 2018 (such as an example of a component for setting); code for including 2019 (such as an example of a component for including), code for obtaining 2020, code for determining 2021, and code for encrypting 2022.

[0106] In certain aspects, the processor 2004 has circuitry configured to implement code stored in the computer-readable medium / memory 2012. The processor 2004 includes circuitry 2032 for generating (such as an example of means for generating), circuitry 2033 for computing (such as an example of means for computing), circuitry 2034 for outputting (such as an example of means for outputting), circuitry 2035 for placing (such as an example of means for placing), circuitry 2036 for setting (such as an example of means for setting), circuitry 2037 for including (such as an example of means for including), circuitry 2038 for obtaining (such as an example of means for obtaining), circuitry 2039 for determining (such as an example of means for determining), and circuitry 2040 for encrypting (such as an example of means for encrypting).

[0107] The transceiver 2008 may provide a means for receiving information such as packets, user data, or control information associated with various information channels such as control channels, data channels, etc. The information may be passed to other components of the device 2000. The transceiver 2008 may be a reference Figure 19 Examples of various aspects of the transceiver 1954 are described. Antenna 2010 may correspond to a single antenna or a collection of antennas. Transceiver 2008 may provide means for transmitting signals generated by other components of device 2000.

[0108] In some cases, a device may have an interface (a component for outputting) for outputting frames for transmission, rather than actually sending the frames. For example, a processor may output frames to a radio frequency (RF) front end via a bus interface for transmission. Similarly, a device may have an interface (a component for obtaining) for obtaining frames received from another device, rather than actually receiving the frames. For example, a processor may obtain (or receive) frames from an RF front end for reception via a bus interface. In some cases, the interface for outputting frames for transmission and the interface for obtaining frames (which may be referred to herein as a first interface and a second interface) may be the same interface.

[0109] The means for generating, the means for calculating, the means for placing, the means for setting, the means for including, the means for determining, and / or the means for encrypting may include Figure 19 or Figure 20 Any of the various processors and / or memories shown in . The means for obtaining and / or the means for outputting may include Figure 19 or Figure 20 Any of the various processors, memories, and / or transceivers shown in .

[0110] Figure 21 Examples may include processes operable, configured, or adapted to perform operations for the techniques disclosed herein (such as Figure 18 21. The communication device 2100 may include various components (such as corresponding means plus function components) for the operations illustrated in FIG.

[0111] The communication device 2100 includes a processing system 2102 coupled to a transceiver 2108 (such as a transmitter or receiver). The transceiver 2108 is configured to transmit and receive signals for the communication device 2100, such as the various signals described herein, via an antenna 2110. The processing system 2102 can be configured to perform processing functions for the communication device 2100, including processing signals received by or to be transmitted by the communication device 2100.

[0112] The processing system 2102 includes a processor 2104 coupled to a computer-readable medium / memory 2112 via a bus 2106. In some aspects, the computer-readable medium / memory 2112 is configured to store instructions (such as computer-executable code) that, when executed by the processor 2104, cause the processor 2104 to perform Figure 18 or other operations for performing the various techniques discussed herein.

[0113] In some aspects, the computer-readable medium / memory 2112 stores code 2114 for obtaining (such as an example of a component for obtaining); code 2115 for responding (such as an example of a component for responding); code 2116 for discarding (such as an example of a component for discarding); code 2117 for action (such as an example of a component for action); code 2118 for computing (such as an example of a component for computing); code 2119 for requesting (such as an example of a component for requesting), code 2120 for verifying, code 2121 for decoding, and code 2122 for outputting.

[0114] In certain aspects, the processor 2104 has circuitry configured to implement code stored in the computer-readable medium / memory 2112. The processor 2104 includes circuitry 2132 for obtaining (such as an example of means for obtaining), circuitry 2133 for responding (such as an example of means for responding), circuitry 2134 for discarding (such as an example of means for discarding), circuitry 2135 for acting (such as an example of means for acting), circuitry 2136 for computing (such as an example of means for computing), circuitry 2137 for requesting (such as an example of means for requesting), circuitry 2138 for verifying (such as an example of means for verifying), circuitry 2139 for encrypting (such as an example of means for encrypting), and circuitry 2140 for outputting (such as an example of means for outputting).

[0115] The transceiver 2108 may provide a means for receiving information such as packets, user data, or control information associated with various information channels such as control channels, data channels, etc. The information may be passed to other components of the device 2100. The transceiver 2108 may be a reference Figure 19 Examples of various aspects of the transceiver 1954 are described. Antenna 2110 may correspond to a single antenna or a collection of antennas. Transceiver 2108 may provide means for transmitting signals generated by other components of device 2100.

[0116] In some cases, a device may have an interface (a component for outputting) for outputting a frame for transmission, rather than actually sending the frame. For example, a processor may output a frame to a radio frequency (RF) front end via a bus interface for transmission. Similarly, a device may have an interface (a component for obtaining) for obtaining a frame received from another device, rather than actually receiving the frame. For example, a processor may obtain (or receive) a frame from an RF front end for reception via a bus interface. The device that obtains the frame may obtain the values ​​of the various fields of the frame as part of the acquisition, or additionally or alternatively, the device may obtain the frame and obtain the values ​​of the various fields of the frame in a later step such as a decryption step. In some cases, the interface for outputting the frame for transmission and the interface for obtaining the frame (which may be referred to as the first interface and the second interface in this article) may be the same interface.

[0117] The means for responding, the means for discarding, the means for acting, the means for computing, the means for requesting, the means for verifying, and / or the means for decrypting may include Figure 19 or Figure 21 Any of the various processors and / or memories shown in . The means for obtaining and / or the means for outputting may include Figure 19 or Figure 21Any of the various processors, memories, and / or transceivers shown in .

[0118] Sample Clauses

[0119] Specific implementation examples are described in the following numbered clauses:

[0120] Clause 1: A method for wireless communication at a wireless node, the method comprising: generating a frame comprising an identifier (ID) of a security key, a packet number (PN), and an integrity check, wherein: the integrity check is based on one or more portions of the frame and the generating comprises calculating the integrity check based at least on the security key; and outputting the frame for transmission.

[0121] Clause 2: The method of clause 1, wherein the PN comprises at least one of an integrity group transient key (IGTK) block number or an integrity pairwise transient key (IPTK) block number.

[0122] Clause 3: A method according to clause 1, wherein the PN comprises only a portion of the complete packet number of the frame; another portion of the complete packet number is stored locally; and the method further comprises: updating the stored portion of the complete packet number based on the exchange of security management frames.

[0123] Clause 4: A method according to clause 3, wherein: the complete packet number includes a global timestamp maintained by the wireless node or access point (AP) that is the intended recipient of the frame; when the global timestamp is maintained by the AP, the method further includes: obtaining one or more protected beacon frames in which the global timestamp is indicated; and when the global timestamp is maintained by the wireless node, the method further includes: outputting one or more protected beacon frames indicating the global timestamp for transmission.

[0124] Clause 5: The method of any of clauses 1 to 4, wherein the security key comprises at least one of: an Integrity Group Temporal Key (IGTK), a Pairwise Temporal Key (PTK), or a Control Integrity Temporal Key (CIGTK).

[0125] Clause 6: A method according to any one of clauses 1 to 5, wherein: the frame includes a trigger frame, the trigger frame includes a user information list; and the method further includes: placing the ID, the PN and the integrity check after the user information list in the trigger frame.

[0126] Clause 7: A method according to any one of clauses 1 to 5, wherein: the frame includes a trigger frame, the trigger frame includes a user information list, the user information list includes a user information field; and the method further includes: placing the ID, the PN and the integrity check in a subset of the user information field.

[0127] Clause 8: The method of clause 7, wherein: each of the user information fields in the subset includes an association identifier (AID) field; and the method further comprises: setting the AID field of each user information field in the subset to a reserved value indicating the presence of the integrity check.

[0128] Clause 9: The method of clause 7, wherein: the integrity check is conveyed via eight octets or sixteen octets; when the integrity check is conveyed via eight octets, the subset consists of five user information fields; and when the integrity check is conveyed via sixteen octets, the subset consists of seven user information fields.

[0129] Clause 10: A method according to any one of clauses 1 to 9, wherein at least one of the following conditions exists: the integrity check is part of a complete integrity check for the frame; or the complete integrity check includes the integrity check and a portion of the complete integrity check that is known by another wireless node that is the intended recipient of the frame.

[0130] Clause 11: A method according to any one of clauses 1 to 10, wherein: the frame includes a Null Data Packet (NDP) announcement frame, the Null Data Packet (NDP) announcement frame includes a Station (STA) Information field; and the method further includes: placing the ID, the PN and the integrity check after the STA Information field in the NDP announcement frame.

[0131] Clause 12: A method according to any one of clauses 1 to 11, wherein: the frame includes a Null Data Packet (NDP) announcement frame, the Null Data Packet (NDP) announcement frame includes a Station (STA) Information field; and the method further includes: placing the ID, the PN and the integrity check in a subset of the STA Information field.

[0132] Clause 13: The method of clause 12, wherein: each STA information field includes an association identifier (AID) field; and the method further comprises: setting the AID field of each STA information field in the subset to a reserved value indicating the presence of the integrity check.

[0133] Clause 14: The method of clause 12, wherein: the integrity check is conveyed via eight octets or sixteen octets; when the integrity check is conveyed via eight octets, the subset consists of seven STA information fields; and when the integrity check is conveyed via sixteen octets, the subset consists of ten STA information fields.

[0134] Clause 15: The method of any of clauses 1 to 14, wherein: the frame comprises a Multi-Station Block Acknowledgement (M-BA) frame, the Multi-Station Block Acknowledgement (M-BA) frame comprising an Association Identifier (AID) Traffic Identifier (TID) information field; and the method further comprises: placing the ID, the PN, and the integrity check in a subset of the AID TID information field.

[0135] Clause 16: The method of clause 15, wherein: each of the AID TID information fields in the subset comprises an AID field; and the method further comprises: setting the AID field of each AID TID information field in the subset to a reserved value indicating the presence of the integrity check.

[0136] Clause 17: The method of clause 15, further comprising including padding in the frame after the subset, wherein an amount of the padding is based on a number of symbols between the subset and an end of the frame.

[0137] Clause 18: The method of clause 17, further comprising: obtaining an indication of a request period between the subset and the end of the frame; and determining the number of symbols based on the request period.

[0138] Clause 19: A method according to any one of clauses 1 to 18, wherein: the frame comprises a block acknowledgement request (BAR) frame, the block acknowledgement request (BAR) frame includes a BAR information field; and the method further comprises: placing the ID, the PN and the integrity check in a subset of the BAR information field.

[0139] Clause 20: The method of clause 19, wherein the BAR frame comprises a multi-traffic identifier (multi-TID) BAR frame or a compressed BAR frame.

[0140] Clause 21: The method of clause 19, wherein: each of the BAR information fields in the subset comprises a per-traffic identifier (TID) information field; and the method further comprises: setting a first bit of each per-TID information field.

[0141] Clause 22: A method as recited in any one of clauses 1 to 21, wherein the integrity check comprises a message integrity code (MIC).

[0142] Clause 23: A method according to any one of clauses 1 to 22, wherein generating the frame includes: encrypting one or more bits included in a media access control (MAC) header of the frame, and wherein outputting the frame includes: outputting the MAC header including the encrypted one or more bits.

[0143] Clause 24: A method according to clause 23, wherein at least one of the following conditions exists: the PN is a first PN associated with a MAC protocol data unit (MPDU) of the frame; or the encryption of the one or more bits is based on a second security key and a second PN associated with the MAC header.

[0144] Clause 25: The method of clause 24, wherein the frame further comprises a header protection field, the header protection field comprising: an indication of the second PN; an ID of the second security key; and another integrity check based on the MAC header.

[0145] Clause 26: The method of any of clauses 23 to 25, further comprising obtaining an indication that another wireless node supports MAC header encryption, wherein the MAC header indicates a receiver address (RA) of the other wireless node.

[0146] Clause 27: The method of any of clauses 23 to 26, further comprising outputting for transmission an indication that the wireless node supports MAC header encryption.

[0147] Clause 28: A method of wireless communication at a wireless node, the method comprising: obtaining a frame including an identifier (ID) of a security key, a packet number (PN), and an integrity check; and verifying the validity of the frame based on a comparison of the integrity check with another integrity check, wherein the other integrity check is based on at least the security key and one or more portions of the frame.

[0148] Clause 29: The method of clause 28, further comprising responding to the frame based on verifying the validity of the frame.

[0149] Clause 30: A method according to any one of clauses 28 to 29, wherein: the PN comprises only a portion of the complete packet number of the frame; another portion of the complete packet number is stored locally; and the method further comprises: updating the stored portion of the complete packet number based on the exchange of security management frames.

[0150] Clause 31: A method according to clause 30, wherein: the complete packet number includes a global timestamp maintained by the wireless node or access point (AP); when the global timestamp is maintained by the AP, the method further includes: obtaining the global timestamp from one or more protected beacon frames; and when the global timestamp is maintained by the wireless node, the method further includes: outputting one or more protected beacon frames indicating the global timestamp for transmission.

[0151] Clause 32: The method of any of clauses 28 to 31, wherein the security key comprises at least one of: an Integrity Group Temporal Key (IGTK), a Pairwise Temporal Key (PTK), or a Control Integrity Temporal Key (CIGTK).

[0152] Clause 33: The method of any of clauses 28 to 32, further comprising discarding the frame when the PN does not match an expected PN for the frame.

[0153] Clause 34: The method of any of clauses 28 to 33, further comprising: computing the further integrity check.

[0154] Clause 35: The method of any of clauses 28 to 34, wherein the PN comprises at least one of an Integrity Group Temporal Key (IGTK) block number or an Integrity Pairwise Temporal Key (IPTK) block number.

[0155] Clause 36: A method according to any one of clauses 28 to 35, wherein: the frame comprises a trigger frame, the trigger frame comprising a user information list and the ID, the PN and the integrity check following the user information list in the trigger frame.

[0156] Clause 37: A method according to any one of clauses 28 to 36, wherein: the frame comprises a trigger frame, the trigger frame comprises a user information list, the user information list comprises a user information field and the ID, the PN and the integrity check in a subset of the user information field.

[0157] Clause 38: A method according to clause 37, wherein: each user information field in the user information field in the subset includes an association identifier (AID) field having a reserved value associated with the integrity check; and the method further comprises: obtaining the ID, the PN and the integrity check from the user information field of the subset.

[0158] Clause 39: A method according to clause 37, wherein: the integrity check is conveyed via eight octets or sixteen octets; when the integrity check is conveyed via eight octets, the subset consists of five user information fields; and when the integrity check is conveyed via sixteen octets, the subset consists of seven user information fields.

[0159] Clause 40: The method of any of clauses 28 to 39, wherein the integrity check is part of a full integrity check for the frame; and another part of the full integrity check is known to the wireless node.

[0160] Clause 41: A method according to any one of clauses 28 to 40, wherein: the frame includes a Null Data Packet (NDP) announcement frame, the Null Data Packet (NDP) announcement frame including a station (STA) information field and the ID, the PN and the integrity check following the STA information field.

[0161] Clause 42: A method according to any one of clauses 28 to 41, wherein: the frame includes a Null Data Packet (NDP) announcement frame, the Null Data Packet (NDP) announcement frame includes a station (STA) information field and the ID, the PN and the integrity check in a subset of the STA information field; and the method further includes: obtaining the ID, the PN and the integrity check from the STA information field of the subset.

[0162] Clause 43: A method according to clause 42, wherein: each STA information field of the subset includes an association identifier (AID) field having a reserved value associated with the integrity check; and the method further comprises: obtaining the ID, the PN and the integrity check from the STA information field of the subset.

[0163] Clause 44: A method according to clause 42, wherein: the integrity check is conveyed via eight octets or sixteen octets; when the integrity check is conveyed via eight octets, the subset consists of seven STA information fields; and when the integrity check is conveyed via sixteen octets, the subset consists of ten STA information fields.

[0164] Clause 45: A method according to any of clauses 28 to 44, wherein: the frame comprises a multi-station block acknowledgement (M-BA) frame, the multi-station block acknowledgement (M-BA) frame comprising an association identifier (AID) traffic identifier (TID) information field and the ID, the PN and the integrity check in a subset of the AID TID information field; and the method further comprises: obtaining the ID, the PN and the integrity check from the AID TID information field in the subset.

[0165] Clause 46: The method of clause 45, wherein: each of the AID TID information fields in the subset comprises an AID field having a reserved value associated with the integrity check.

[0166] Clause 47: The method of clause 45, wherein: the frame includes padding after the subset; and an amount of the padding is based on a number of symbols between the subset and an end of the frame.

[0167] Clause 48: The method of clause 47, wherein the number of symbols is based on a period between the subset and an end of the frame; and the method further comprises: requesting the period between the subset and an end of the frame.

[0168] Clause 49: A method according to any one of clauses 28 to 48, wherein: the frame comprises a block acknowledgement request (BAR) frame, the block acknowledgement request (BAR) frame comprising a BAR information field and the ID, the PN and the integrity check in a subset of the BAR information field; and the method further comprises: obtaining the ID, the PN and the integrity check from the BAR information field of the subset.

[0169] Clause 50: The method of clause 49, wherein the BAR frame comprises a multi-traffic identifier (multi-TID) BAR frame or a compressed BAR frame.

[0170] Clause 51: The method of clause 49, wherein: each of the BAR information fields in the subset comprises a per-transaction identifier (TID) information field having a first bit set.

[0171] Clause 52: A method as recited in any one of clauses 28 to 51, wherein the integrity check comprises a message integrity code (MIC).

[0172] Clause 53: A method according to any one of clauses 28 to 52, wherein verifying the validity of the frame includes: decrypting one or more bits included in a media access control (MAC) header of the frame, wherein verifying the validity of the frame includes: verifying the validity of the MAC header based on the decrypted one or more bits.

[0173] Clause 54: A method according to clause 53, wherein at least one of the following conditions exists: the PN is a first PN associated with a MAC protocol data unit (MPDU) of the frame; or decrypting the one or more bits is based on a second security key and a second PN associated with the MAC header.

[0174] Clause 55: The method of clause 54, wherein the frame further comprises a header protection field, the header protection field comprising: an indication of the second PN; an ID of the second security key; and another integrity check based on the MAC header.

[0175] Clause 56: The method of any of clauses 53 to 55, further comprising outputting for transmission an indication that the wireless node supports MAC header encryption.

[0176] Clause 57: The method of any of clauses 53 to 56, further comprising obtaining an indication that another wireless node supports MAC header encryption, wherein the MAC header indicates a receiver address (RA) of the other wireless node.

[0177] Clause 58: An apparatus comprising: a memory comprising executable instructions; and a processor configured to execute the executable instructions and cause the apparatus to perform the method of any one of clauses 1 to 57.

[0178] Clause 59: An apparatus comprising means for performing the method of any one of clauses 1 to 57.

[0179] Clause 60: A non-transitory computer-readable medium comprising executable instructions that, when executed by a processor of an apparatus, cause the apparatus to perform the method of any one of clauses 1 to 57.

[0180] Clause 61: A computer program product embodied on a computer-readable storage medium, the computer-readable storage medium comprising code for performing the method according to any of clauses 1 to 57.

[0181] Clause 62: A wireless node comprising: at least one transceiver; a memory comprising instructions; and one or more processors configured to execute the instructions and cause the wireless node to: generate a frame comprising an identifier (ID) of a security key, a packet number (PN), and an integrity check, wherein: the integrity check is based on one or more portions of the frame and the generating comprises calculating the integrity check based at least on the security key; and transmit the frame via the at least one transceiver.

[0182] Clause 63: A wireless node comprising: at least one transceiver; a memory comprising instructions; and one or more processors configured to execute the instructions and cause the wireless node to: receive, via the at least one transceiver, a frame comprising an identifier (ID) of a security key, a packet number (PN), and an integrity check; and verify the validity of the frame based on a comparison of the integrity check with another integrity check, wherein the other integrity check is based at least on the security key and one or more portions of the frame.

[0183] As used herein, the term "determining" encompasses a wide variety of actions, and thus, "determining" may include calculating, computing, processing, deriving, investigating, searching (such as via searching in a table, database, or other data structure), inferring, ascertaining, and the like. Additionally, "determining" may include receiving (such as receiving information), accessing (such as accessing data stored in a memory), sending (such as sending information), etc. Additionally, "determining" may include resolving, selecting, obtaining, choosing, establishing, and other such similar actions.

[0184] As used herein, a phrase referring to "at least one of" a list of items refers to any combination of those items (including single members). For example, "at least one of a, b, or c" is intended to encompass: a, b, c, ab, ac, bc, and abc. As used herein, unless expressly indicated otherwise, "or" is intended to be interpreted in an inclusive sense. For example, "a or b" can include only a, only b, or a combination of a and b.

[0185] As used herein, unless expressly indicated otherwise, the phrase "based on" is intended to be interpreted in an inclusive sense. For example, unless expressly indicated otherwise, "based on" may be used interchangeably with "based at least in part on," "associated with," or "in accordance with." Specifically, unless the context indicates "based only on 'one'" or an equivalent, whether "based on 'one'" or "based at least in part on 'one'" can be based on 'one' alone or on a combination of 'one' and one or more other factors, conditions, or information.

[0186] As used herein, "processor," "at least one processor," or "one or more processors" generally refers to a single processor configured to perform one or more operations or multiple processors configured to collectively perform one or more operations. In the case of multiple processors, execution of one or more operations may be divided among different processors, but a processor may perform multiple operations, and multiple processors may collectively perform a single operation. Similarly, "memory," "at least one memory," or "one or more memories" generally refers to a single memory configured to store data and / or instructions or multiple memories configured to collectively store data and / or instructions.

[0187] The various illustrative components, logical elements, logic blocks, modules, circuits, operations, and algorithmic processes described in conjunction with the examples disclosed herein may be implemented as electronic hardware, firmware, software, or a combination of hardware, firmware, or software, including the structures disclosed in this specification and their structural equivalents. This interchangeability of hardware, firmware, and software has been generally described in terms of their functionality and exemplified in the various illustrative components, blocks, modules, circuits, and processes described above. Whether such functionality is implemented in hardware, firmware, or software depends on the specific application and the design constraints imposed on the overall system.

[0188] Various modifications to the examples described in this disclosure will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other examples without departing from the scope of this disclosure. Therefore, the claims are not intended to be limited to the examples shown herein, but should be accorded the widest scope consistent with this disclosure, the principles, and the novel features disclosed herein.

[0189] Additionally, various features described in this specification in the context of separate examples may also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation may also be implemented in multiple examples individually or in any suitable subcombination. Thus, although features may be described above as functioning in a particular combination and even initially claimed as such, one or more features from a claimed combination may in some cases be deleted from the combination, and a claimed combination may involve subcombinations or variations of subcombinations.

[0190] Similarly, although operations are depicted in a particular order in the accompanying drawings, this should not be understood as requiring such operations to be performed in the particular order shown or in a sequential order, or to perform all illustrated operations to achieve the desired result. In addition, the accompanying drawings may schematically depict one or more example processes in the form of a flow chart or a flow diagram. However, other operations not depicted may be incorporated into the example processes schematically illustrated. For example, one or more additional operations may be performed before, after, simultaneously, or between any of the illustrated operations. In some environments, multitasking and parallel processing may be advantageous. In addition, the separation of the various system components in the examples described above should not be understood as requiring such separation in all examples, but it should be understood that the program components and systems described can usually be integrated together in a single software product, or be packaged into multiple software products.

Claims

1. A device for wireless communication, the device comprising: at least one memory, the at least one memory comprising instructions; and one or more processors configured to execute the instructions and cause the apparatus to: Generate a frame including a security key identifier (ID), a packet number (PN), and an integrity check, where: The integrity check is based on one or more portions of the frame, and The generating comprises computing the integrity check based on at least the security key; and The frame is output for transmission.

2. The apparatus of claim 1 , wherein at least one of the following conditions exists: The PN includes at least one of: an integrity group transient key (IGTK) group number or an integrity pairwise transient key (IPTK) group number; The security key comprises at least one of: an IGTK, a pairwise transient key (PTK), or a control integrity transient key (CIGTK); or The PN includes only a portion of a complete packet number of the frame, another portion of the complete packet number is stored locally, and the one or more processors are configured to execute the instructions and cause the device to update the stored portion of the complete packet number based on the exchange of security management frames.

3. The device according to claim 1, wherein: The frame includes a trigger frame, the trigger frame includes a user information list, the user information list includes a user information field; and The one or more processors are configured to execute the instructions and cause the apparatus to: The ID, the PN and the integrity check are placed after the user information list or in a subset of the user information field in the trigger frame.

4. The device according to claim 3, wherein: Each of the user information fields in the subset includes an association identifier (AID) field; and The one or more processors are configured to execute the instructions and cause the apparatus to: placing the ID, the PN, and the integrity check in the subset of the user information field; as well as The AID field of each user information field in the subset is set to a reserved value indicating the presence of the integrity check.

5. The apparatus according to claim 1, wherein: The frame comprises a Null Data Packet (NDP) announcement frame, the Null Data Packet (NDP) announcement frame comprising a Station (STA) Information field; and The one or more processors are configured to execute the instructions and cause the apparatus to: Place the ID, the PN, and the integrity check in either: After the STA information field in the NDP announcement frame, or In a subset of the STA information field.

6. The device according to claim 5, wherein: Each STA Information field includes an Association Identifier (AID) field; and The one or more processors are configured to execute the instructions and cause the apparatus to: placing the ID, the PN, and the integrity check in the subset of the STA information field; as well as The AID field of each STA information field in the subset is set to a reserved value indicating the presence of the integrity check.

7. The apparatus according to claim 1, wherein: The frame comprises a multi-station block acknowledgement (M-BA) frame including an association identifier (AID) traffic identifier (TID) information field; and The one or more processors are configured to execute the instructions and cause the apparatus to: The ID, the PN and the integrity check are placed in a subset of the AID TID information field.

8. The apparatus according to claim 7, wherein: Each of the AID TID information fields in the subset includes an AID field; and The one or more processors are configured to execute the instructions and cause the apparatus to: The AID field of each AID TID information field in the subset is set to a reserved value indicating the presence of the integrity check.

9. The apparatus of claim 7, wherein the one or more processors are configured to execute the instructions and further cause the apparatus to: Padding is included in the frame after the subset, wherein an amount of the padding is based on a number of symbols between the subset and an end of the frame.

10. The apparatus of claim 9, wherein the one or more processors are configured to execute the instructions and further cause the apparatus to: obtaining an indication of a request period between the subset and the end of the frame; and The number of symbols is determined based on the request period.

11. The apparatus according to claim 1 , wherein: The frame comprises a block acknowledgement request (BAR) frame, the block acknowledgement request (BAR) frame comprising a BAR information field; and The one or more processors are configured to execute the instructions and cause the apparatus to: The ID, the PN and the integrity check are placed in a subset of the BAR information field.

12. The apparatus according to claim 11, wherein: each of the BAR information fields in the subset includes a per-traffic identifier (TID) information field; and The one or more processors are configured to execute the instructions and cause the apparatus to: Sets the first bit of each per-TID information field.

13. The apparatus of claim 1 , wherein the one or more processors being configured to cause the apparatus to generate the frame comprises the one or more processors being configured to cause the apparatus to: Encrypting one or more bits included in a media access control (MAC) header of the frame, wherein the one or more processors are configured to cause the device to output the frame includes the one or more processors being configured to cause the device to output the MAC header including the encrypted one or more bits.

14. The apparatus of claim 13, wherein at least one of the following conditions exists: The PN is a first PN associated with a MAC protocol data unit (MPDU) of the frame; or The one or more processors being configured to cause the apparatus to encrypt the one or more bits includes the one or more processors being configured to cause the apparatus to encrypt the one or more bits based on a second security key and a second PN associated with the MAC header.

15. The apparatus according to claim 14, wherein: The one or more processors being configured to cause the apparatus to encrypt the one or more bits includes the one or more processors being configured to cause the apparatus to encrypt the one or more bits based on the second security key and the second PN associated with the MAC header; and The frame further includes a header protection field, the header protection field including: an indication of the second PN; the ID of the second security key; and Another integrity check based on the MAC header.

16. The apparatus according to claim 1, further comprising: at least one transceiver configured to transmit the frame, wherein the apparatus is configured as a wireless node.

17. An apparatus for wireless communication, the apparatus comprising: at least one memory, the at least one memory comprising instructions; and one or more processors configured to execute the instructions and cause the apparatus to: Obtaining a frame including an identifier (ID) of a security key, a packet number (PN), and an integrity check; as well as The validity of the frame is verified based on a comparison of the integrity check with another integrity check, where the other integrity check is based on at least the security key and one or more portions of the frame.

18. The apparatus according to claim 17, wherein: The PN comprises only a portion of the complete packet number of the frame; Another portion of the complete packet number is stored locally; and The one or more processors are configured to execute the instructions and cause the apparatus to: The stored portion of the complete packet number is updated based on an exchange of security management frames.

19. The apparatus of claim 17, wherein at least one of the following conditions exists: The security key comprises at least one of: an integrity group transient key (IGTK), a pairwise transient key (PTK), or a control integrity transient key (CIGTK); or The PN includes at least one of: an IGTK block number or an Integrity Pairwise Temporal Key (IPTK) block number.

20. The apparatus of claim 17, wherein: The frame includes a Null Data Packet (NDP) announcement frame, the Null Data Packet (NDP) announcement frame including a Station (STA) Information field and the ID, the PN, and the integrity check; and The ID, the PN and the integrity check are located at: After the STA information field, or In a subset of the STA information field; and The one or more processors are configured to execute the instructions and cause the apparatus to: The ID, the PN, and the integrity check are obtained from the NDP announcement frame.

21. The apparatus of claim 17, wherein: The frame comprises a Multi-Station Block Acknowledgement (M-BA) frame, the Multi-Station Block Acknowledgement (M-BA) frame comprising an Association Identifier (AID) Traffic Identifier (TID) information field and the ID, the PN, and the integrity check in a subset of the AID TID information field; and The one or more processors are configured to execute the instructions and cause the apparatus to: The ID, the PN, and the integrity check are obtained from the AID TID information field in the subset.

22. The apparatus of claim 21, wherein: Each of the AID TID information fields in the subset includes an AID field having a reserved value associated with the integrity check.

23. The apparatus of claim 21, wherein: The frame includes padding following the subset; and The amount of padding is based on the number of symbols between the subset and the end of the frame.

24. The apparatus of claim 23, wherein: The number of symbols is based on a period between the subset and the end of the frame; and The one or more processors are configured to execute the instructions and further cause the apparatus to: The period between requesting the subset and the end of the frame.

25. The apparatus of claim 17, wherein: The frame comprises a block acknowledgement request (BAR) frame, the block acknowledgement request (BAR) frame comprising a BAR information field and the ID, the PN, and the integrity check in a subset of the BAR information field; and The one or more processors are configured to execute the instructions and cause the apparatus to: The ID, the PN, and the integrity check are obtained from the BAR information field in the subset.

26. The apparatus of claim 17, wherein the one or more processors being configured to cause the apparatus to verify the validity of the frame comprises the one or more processors being configured to cause the apparatus to: decrypting one or more bits included in a medium access control (MAC) header of the frame, wherein the one or more processors are configured to cause the device to verify the validity of the frame includes the one or more processors being configured to cause the device to verify the validity of the MAC header based on the decrypted one or more bits.

27. The apparatus of claim 26, wherein at least one of the following conditions exists: The PN is a first PN associated with a MAC protocol data unit (MPDU) of the frame; or The one or more processors being configured to cause the apparatus to decrypt the one or more bits includes the one or more processors being configured to cause the apparatus to decrypt the one or more bits based on a second security key and a second PN associated with the MAC header.

28. The apparatus of claim 27, wherein: The one or more processors being configured to cause the apparatus to decrypt the one or more bits includes the one or more processors being configured to cause the apparatus to decrypt the one or more bits based on the second security key and the second PN associated with the MAC header; and The frame further includes a header protection field, the header protection field including: an indication of the second PN; the ID of the second security key; and Another integrity check based on the MAC header.

29. The apparatus according to claim 17, further comprising: At least one transceiver is configured to receive the frame, wherein the apparatus is configured as a wireless node.

30. A method for wireless communication at a wireless node, the method comprising: Obtaining a frame including an identifier (ID) of a security key, a packet number (PN), and an integrity check; as well as The validity of the frame is verified based on a comparison of the integrity check with another integrity check, where the other integrity check is based on at least the security key and one or more portions of the frame.