Communication system with control frame protection

By employing a multi-basic service set identifier scheme and control message integrity verification between access points and sites, the latency and security issues in communication systems are resolved, enabling efficient data transmission and secure communication.

CN120897193APending Publication Date: 2025-11-04APPLE INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510567382.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-04-16
Filing Date
2025-04-30
Publication Date
2025-11-04

AI Technical Summary

Technical Problem

In communication systems, communication between nodes may suffer from excessive latency, excessive resource consumption, or insufficient data security.

Method used

Access points (APs) and stations (STAs) communicate using the Multiple Basic Service Set Identifier (M-BSSID) scheme, generate Control Message Integrity Check (CMIC), and protect the initial control frame (ICF) using either the Control Frame Integrity Group Temporary Key (CIGTK) or the Beacon Integrity Group Temporary Key (BIGTK).

Benefits of technology

This approach achieves the goal of reducing latency and maximizing data throughput while ensuring data security, thereby improving the performance of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120897193A_ABST
    Figure CN120897193A_ABST
Patent Text Reader

Abstract

The invention relates to a communication system with control frame protection. A communication system is provided in which an access point (AP) communicates with a station (STA). The AP may communicate with the STA according to a multi-basic service set identifier (M-BSSID) scheme. The AP may transmit an initial control frame (ICF) to an STA associated with a different BSSID of the AP. The AP may integrity protect the ICF by generating one or more control message integrity checks (CMICs) and inserting the CMICs into the ICF. The AP may use a BSSID-specific or BSSID-independent Control Frame Integrity Group Temporary Key (CIGTK) to generate a common CMIC that is shared across the BSSID. The CIGTK independent of the BSSID may be a newly defined Beacon Integrity Group Temporary Key (BIGTK), or may be a Beacon Integrity Group Temporary Key (BIGTK). As another example, the AP may generate a different CMIC for each BSSID in the ICF using a different BSSID-specific CIGTK for each BSSID.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to U.S. Patent Application No. 19 / 181,014, filed April 16, 2025, and U.S. Provisional Patent Application No. 63 / 641,000, filed May 1, 2024, which are hereby incorporated by reference in their entirety. TECHNICAL FIELD

[0002] The present disclosure relates generally to wireless communications, including wireless communications by electronic devices. BACKGROUND

[0003] Communication systems and methods are used to convey wireless data between nodes of a communication network. The nodes can include user equipment devices, wireless access points, wireless base stations, or other electronic devices.

[0004] Ensuring that a communication system exhibits a sufficient level of performance can be challenging. If not careful, communications between nodes of a communication network can exhibit excessive latency, can consume excessive resources, or can exhibit insufficient levels of data security. SUMMARY

[0005] A communication system is provided in which an access point (AP) communicates with stations (STAs). The AP can communicate with the STAs in accordance with a communication protocol that implements a multiple basic service set identifier (M-BSSID) scheme. The AP can transmit an initial control frame (ICF) to STAs associated with different basic service set identifiers (BSSIDs) maintained by the AP. The BSSIDs can include a transmitted BSSID for common management signaling, and can include non-transmitted BSSIDs for each virtual network.

[0006] The AP can protect the ICF by generating one or more control message integrity checks (CMICs) and inserting the CMICs into the ICF. As one example, the AP can generate a common CMIC shared across the BSSIDs using a control frame integrity group transient key (CIGTK). The CIGTK can be a BSSID-specific CIGTK for the transmitted BSSID, or can be a BSSID-independent CIGTK shared across the BSSIDs. The BSSID-independent CIGTK can be a newly defined CIGTK, or can be a beacon integrity group transient key (BIGTK). As another example, the AP can generate a different CMIC for each BSSID in the ICF using a different BSSID-specific CIGTK for each BSSID. The AP and the STAs can perform secure communications in accordance with the M-BSSID scheme while minimizing latency and maximizing data throughput.

[0007] One aspect of this disclosure provides a method of operating a station (STA) to communicate with an access point (AP). The method can include receiving, from the AP, a control frame comprising a control message integrity check (CMIC) shared by a plurality of basic service set identifiers (BSSIDs) of the AP. The method can include attempting to verify the CMIC in the control frame using one or more processors. The method can include transmitting, to the AP, an uplink signal using one or more antennas in response to verifying the CMIC in the control frame.

[0008] One aspect of this disclosure provides an electronic device configured to communicate with an access point (AP). The electronic device can include a receiver configured to receive, from the AP, a control frame comprising a first control message integrity check (CMIC) for a first basic service set identifier (BSSID) of the AP and comprising a second CMIC for a second BSSID of the AP, the electronic device being associated with the first BSSID but not with the second BSSID. The electronic device can include one or more processors configured to attempt to verify the first CMIC in the control frame. The electronic device can include a transmitter configured to transmit, to the AP, an uplink signal in response to verifying the first CMIC in the control frame.

[0009] One aspect of this disclosure provides a method of operating an access point (AP) according to a communication protocol that implements a multiple basic service set identifier (M-BSSID) scheme. The method can include generating, using one or more processors, a control message integrity check (CMIC) based on a cryptographic key. The method can include transmitting, using one or more antennas, a control frame to a first station (STA) associated with a first basic service set identifier (BSSID) of the AP and to a second STA associated with a second BSSID of the AP that is different from the first BSSID. A header of the control frame can include the CMIC and a transmitter address (TA). The TA can identify a third BSSID that is different from the first BSSID and the second BSSID. BRIEF DESCRIPTION OF DRAWINGS

[0010] Figure 1 is a diagram of an exemplary wireless communication system according to some embodiments.

[0011] Figure 2 is a diagram of an exemplary wireless station (STA) according to some embodiments.

[0012] Figure 3 is a diagram of an exemplary wireless access point (AP) according to some embodiments.

[0013] Figure 4 is a timing diagram illustrating one example of how an AP and multiple STAs can perform downlink communications according to a multiple basic service set identifier (M-BSSID) scheme, in accordance with some embodiments.

[0014] Figure 5 is a timing diagram illustrating one example of how an AP and multiple STAs can perform uplink communications according to an M-BSSID scheme, in accordance with some embodiments.

[0015] Figure 6 is a diagram illustrating how an exemplary transmitter device can perform integrity protection on a transmitted control frame, in accordance with some embodiments.

[0016] Figure 7 is a diagram illustrating how an exemplary receiver device can perform integrity checking on an integrity-protected control frame received from a transmitting device, in accordance with some embodiments.

[0017] Figure 8 is a timing diagram illustrating one example of integrity-protected communications between an AP and STAs having the same basic service set identifier (BSSID), in accordance with some embodiments.

[0018] Figure 9 is a timing diagram illustrating one example of how an AP can perform integrity protection of an initial control frame (ICF) using different respective control message integrity check (CMIC) for STAs associated with different BSSIDs, in accordance with some embodiments.

[0019] Figure 10 is a timing diagram illustrating one example of how an AP can perform integrity protection of an ICF using a shared CMIC for STAs associated with different BSSIDs, in accordance with some embodiments.

[0020] Figure 11 is a diagram of exemplary group key tables stored on an AP and STAs in an example in which the AP generates a shared CMIC for an integrity-protected ICF using a BSSID-specific control frame integrity group temporal key (CIGTK), in accordance with some embodiments.

[0021] Figure 12 is a diagram of exemplary group key tables stored on an AP and STAs in an example in which the AP generates a shared CMIC for an integrity-protected ICF using a dedicated CIGTK that is shared across BSSIDs, in accordance with some embodiments.

[0022] Figure 13is a diagram of an exemplary group key table stored on an AP and STAs in an example in which the AP reuses the beacon integrity group temporary key (BIGTK) to generate a shared CMIC for an integrity protected ICF according to some embodiments.

[0023] Figure 14 is a diagram of an exemplary group key table stored on an AP and STAs in an example in which separate CIGTKs for different BSSIDs are omitted and in which the AP uses a dedicated CIGTK shared across BSSIDs to generate a shared CMIC for an integrity protected ICF according to some embodiments.

[0024] Figure 15 is a diagram of an exemplary group key table stored on an AP and a set of STAs of the set in an example in which the AP uses a dedicated CIGTK shared across BSSIDs to generate a shared CMIC for an integrity protected ICF and in which one of the different sets of STAs belongs to an opportunistic wireless encryption (OWE) network according to some embodiments.

[0025] Figure 16 is a flowchart illustrating exemplary operations involved in performing wireless communications between an AP configured to communicate according to an M-BSSID scheme and a STA associated with a non-transmit BSSID of the AP according to some embodiments.

[0026] Figure 17 is a timing diagram illustrating an exemplary handshake procedure that can be performed between a STA and an AP according to some embodiments.

[0027] Figure 18 is a diagram illustrating one example of how an AP can include information identifying a cryptographic group key in a handshake message with the AP according to some embodiments.

[0028] Figure 19 is a timing diagram illustrating one example of how an AP can include information identifying a selected cryptographic group key to be used by a STA for integrity checking of an integrity protected ICF transmitted by the AP according to some embodiments. DETAILED DESCRIPTION

[0029] Figure 1 An example of a wireless communication system 108 (sometimes also referred to herein as a wireless communication network 108, a communication network 108, a network 108, or a system 108) is shown. It should be noted that, Figure 1This represents one of many possibilities, and the features of this disclosure can be implemented as needed through any of various systems. For example, the embodiments described herein can be implemented in any type of wireless device. The wireless implementation described below is an example implementation.

[0030] like Figure 1 As shown, an exemplary wireless communication system 108 includes an access point (AP) 104 that communicates with one or more wireless devices 106 (e.g., a first wireless device 106A, a second wireless device 106B, etc.) via a transmission medium. Wireless devices 106A and 106B may be user equipment (e.g., user equipment (UE) devices), such as a station (STA), a non-AP STA, or a wireless local area network (WLAN) device. Wireless device 106 is sometimes referred to herein as STA 106 or client 106.

[0031] STA 106 can be a device with wireless network connectivity, such as a mobile (e.g., cellular) phone, a handheld device, a wearable device (e.g., a wristwatch, a pendant, a ringer, a head-mounted device, such as a virtual, mixed, and / or augmented reality headset, goggles, a helmet, or glasses), a computer (e.g., a desktop computer, a laptop computer, a computer monitor containing an embedded computer, etc.), a tablet computer, a media player, headphones, one or two wireless earbuds, a television, a gaming device or console, a navigation device, an embedded system (such as a system in which electronic equipment with a display is installed in a kiosk or a car), a voice-controlled speaker with wireless internet connectivity, a home entertainment device, a remote control device, a game controller, a user input device, a peripheral device or accessory, an electronic stylus or pen, an unmanned aerial vehicle (UAV), an unmanned control unit (UAC), a car, computing equipment integrated into a vehicle or kiosk, equipment that enables the functionality of two or more of these devices, or virtually any type of wireless device.

[0032] STA 106 may include a processor (processing element) configured to execute program instructions stored in memory. STA 106 may execute any method implementation of the method embodiments described herein by executing such stored instructions. Alternatively or additionally, STA 106 may include any of the following programmable hardware elements: a field-programmable gate array (FPGA), an integrated circuit, and / or various other possible hardware components configured to (e.g., individually or in combination) execute any method implementation of the method embodiments described herein or any portion thereof.

[0033] The wireless communication system 108 can include one or more wireless access points (APs), such as the AP 102. The AP 102 can be a standalone AP or an enterprise AP, and can include hardware capable of enabling wireless communication with STAs 106, such as the STAs 106A and 106B. The AP 102 can also be equipped to communicate with the network 100 (e.g., a WLAN, an enterprise network, and / or another communication network connected to the Internet, among various possible networks). Thus, the AP 102 can facilitate communication between the STAs 106 and / or between the STAs 106 and the network 100. The AP 102 can be configured to provide communication through one or more wireless technologies, such as any of 802.11a, 802.11b, 802.11g, 802.11n, 802.11ac, 802.11ad, 802.11ax, 802.11ay, 802.11be, 802.11bn, and / or other 802.11 versions, or a cellular protocol such as 5G or LTE, including in unlicensed bands (LAA).

[0034] The network 100 can include any desired number of network nodes, terminals, and / or end hosts communicatively coupled together using communication paths that include wired links and / or wireless links. The wired links can include electrical cables (e.g., Ethernet cables, optical fibers or other optical cables that use light to carry signals, telephone cables, radio frequency cables such as coaxial cable or other transmission lines, etc.). The wireless links can include short-range wireless communication links that operate within a few inches, feet, or tens of feet, medium-range wireless communication links that operate within a few hundred feet, thousands of feet, miles, or tens of miles, and / or long-range wireless communication links that operate within a few hundred or thousands of miles.

[0035] The network nodes of the network 100 can be organized into one or more relay networks, mesh networks, local area networks (LANs), wireless local area networks (WLANs), ring networks (e.g., optical rings), cloud networks, virtual / logical networks, the Internet (e.g., can be communicatively coupled to each other over the Internet), combinations of these, and / or using any other desired network topologies. The network nodes, terminals, and / or end hosts of the network 100 can include network switches, network routers, optical add-drop multiplexers, other multiplexers, repeaters, modems, portals, gateways, servers, network cards (line cards), wireless access points, wireless base stations, and / or any other desired network components. The network nodes in the network 100 can include physical components such as electronic devices, servers, computers, network cabinets, line cards, user equipment, etc., and / or can include virtual components that are logically defined in software and distributed across two or more underlying physical devices (over which they are defined) (e.g., in a cloud network configuration).

[0036] The communication area (or coverage area) of AP 102 (or AP 104) may be referred to as the Basic Service Area (BSA) or cell. AP 102 (or AP 104) and STA 106 can be configured to communicate over a transmission medium using any of a variety of Radio Access Technologies (RATs) or wireless communication technologies such as Wi-Fi, LTE, LTE-A Advanced, 5G NR, Ultra Wideband (UWB), etc. A given RAT may, for example, specify the physical method used to implement the corresponding communication protocol (e.g., WLAN protocol, Wireless Personal Area Network (WPAN) protocol, cellular telephone protocols such as 3G, 4G (LTE), 5G (NR), etc., UWB protocol, satellite communication protocol, satellite navigation protocol, device-to-device (D2D) protocol, etc.).

[0037] Therefore, AP 102, AP 104, and other similar access points (not shown) operating according to one or more wireless communication technologies can be configured as a network that can, for example, provide continuous or nearly continuous overlapping services to STA106A and 106B and similar devices within a geographical area via one or more communication technologies. For example, a STA can roam directly from one AP to another, or can switch between APs and cellular network cells.

[0038] It should be noted that, at least in some cases, the STA 106 may be able to communicate using any of a variety of wireless communication technologies. For example, the STA 106 can be configured to communicate using one or more of Wi-F, LTE, LTE-A, 5G NR, Bluetooth, UWB, one or more satellite systems, etc. Other combinations of wireless communication technologies (including more than two wireless communication technologies) are also possible. Similarly, in some cases, the STA 106 can be configured to communicate using only a single wireless communication technology.

[0039] like Figure 1 As shown, the exemplary wireless communication system 108 may also include an access point (AP) 104, which communicates with the wireless device 106B via a transmission medium. AP 104 also provides a communication connection to network 100. Therefore, according to some embodiments, a wireless device may be able to connect to one or both of AP 102 (or a cellular base station (BS)) and AP 104 (or another access point) to access network 100. For example, a STA may roam from AP 102 to AP 104 based on one or more factors such as coverage, interference, and capability. It should be noted that AP 104 may also allow access to networks different from those allowed by AP 102 (e.g., enterprise Wi-Fi networks, home Wi-Fi networks, etc.).

[0040] In some implementations, the STAs 106 (e.g., STAs 106A and 106B) can include handheld devices such as smartphones or tablets, wearable devices such as smartwatches or smartglasses, and / or can include any of various types of devices with wireless communication capabilities. For example, one or more of the STAs 106A and / or 106B can be a wireless device intended for either stationary or nomadic deployment, such as a home appliance, a metering device, a control device, etc.

[0041] The STA 106B can also be configured to communicate with the STA 106A. For example, the STA 106A and the STA 106B can be capable of performing direct device-to-device (D2D) communication. In some embodiments, such direct communication between STAs can also be referred to or alternatively known as peer-to-peer (P2P) communication. The direct communication can be supported by the AP 102 (e.g., the AP 102 can facilitate discovery, as well as various forms of assistance), or can be performed in ways that are not supported by the AP 102. According to various embodiments, such P2P communication can be performed using any of 3GPP-based D2D communication technology, Wi-Fi based P2P communication technology, UWB, Bluetooth (BT), and / or various other direct communication technologies.

[0042] The STAs 106 can include one or more devices or integrated circuits for facilitating wireless communication, including potentially a WLAN (e.g., Wi-Fi) modem, a cellular modem, and / or one or more other wireless modems. The wireless modems can include one or more processors (processor elements) and various hardware components as described herein. The STAs 106 can perform any of the method embodiments described herein (or any portions thereof) by executing instructions onto one or more programmable processors. Alternatively, or in addition, the one or more processors can be one or more programmable hardware elements, such as an FPGA (field programmable gate array) or other circuit that is configured to perform any of the method embodiments described herein, or any portion thereof. The wireless modems described herein can be used in a STA as defined herein, a wireless device as defined herein, or a communication device as defined herein. The wireless modems described herein can also be used in an AP, a base station, a pico cell, a femto cell, or other similar network-side device.

[0043] STA 106 may include one or more antennas for communicating using one or more wireless communication protocols or radio access technologies. In some embodiments, STA 106 may be configured to communicate using a single shared radio component. The shared radio component may be coupled to a single antenna or to multiple antennas (e.g., for multiple-input multiple-output (MIMO)) for performing wireless communication. Alternatively, STA 106 may include two or more radio components, each configured to communicate via a corresponding wireless link. Other configurations are also possible.

[0044] Figure 2 This is a possible block diagram of a STA device (such as STA 106). STA 106 is sometimes also referred to herein as UE 106, UE device 106, device 106, electronic device 106, or client 106. STA 106 may also be referred to herein as a non-AP STA 106, non-AP device 106, or non-AP client 106. Figure 2 As shown, STA 106 may include wireless circuits such as wireless communication circuitry 230, subsystems such as system-on-chip (SOC) 200, displays such as display 260, and one or more interfaces such as connector interface (I / F) 220.

[0045] The SOC 200 may include one or more parts configured for various purposes. For example, such as Figure 2 As shown, the SOC 200 may include one or more processors 202 and display circuitry 204. The processor 202 executes program instructions for the STA 106. The display circuitry 204 performs graphics processing and provides display signals to the display 260. The display 260 may be a touch-sensitive display, a force-sensitive display, or a display without touch or force sensitivity. For example, the display 260 may include one or more arrays of display pixels that emit light containing an image.

[0046] The SOC 200 can also include sensor circuitry, such as motion sensing circuitry 270. The motion sensing circuitry 270 can use, for example, any of a gyroscope, an accelerometer, an inertial measurement unit (IMU), a compass, and / or various other motion sensing components to detect motion of the STA 106. The processor 202 can also be coupled to a memory management unit (MMU) 240 that can be configured to receive addresses from the processor 202 and can translate those addresses to locations in memory or other storage circuits (e.g., memory 206, read-only memory (ROM) 250, flash (NAND) memory 210, etc.). The MMU 240 can be configured to perform memory protection and page table translation or set up. In some embodiments, the MMU 240 can be included as part of the processor 202.

[0047] The SOC 200 can be coupled to various other circuitry in the STA 106. For example, the SOC 200 can be coupled to various types of memory (e.g., flash memory 210), a connector interface 220 (e.g., to couple to a computer system, a docking station, a charging station, etc.), a display 260, and wireless communication circuitry 230 (e.g., to perform wireless communication under LTE, LTE-A, 5G NR, Bluetooth, Wi-Fi, NFC, GPS, UWB, etc.).

[0048] The STA 106 can include at least one antenna 235. If desired, the STA 106 can include multiple antennas 235, such as at least a first antenna 235A and a second antenna 235B. The STA 106 can use the antennas 235 to perform wireless communication with access points, base stations, and / or other devices. For example, the STA 106 can use the antennas 235A and 235B to perform wireless communication with the APs 102 and / or 104. As described above, in some embodiments, the STA 106 can be configured to use multiple wireless communication standards or radio access technologies (RATs) for wireless communication. Figure 1

[0049] The wireless communication circuitry 230 can include one or more modems, such as a WLAN (e.g., Wi-Fi) modem 232, a cellular modem 234, and a Bluetooth modem 236. If desired, the wireless communication circuitry 230 can include additional modems for handling other RATs or wireless communication technologies. The STA 106 can use the WLAN modem 232 (sometimes also referred to herein as the Wi-Fi modem 232) to perform wireless communication with one or more external devices (e.g., APs, base stations, etc.) using the WLAN (e.g., Wi-Fi) communication standard. The STA 106 can use the cellular modem 234 to perform wireless communication with one or more external devices (e.g., APs, base stations, etc.) using the cellular communication standard. The STA 106 can use the Bluetooth modem 236 to perform wireless communication with one or more external devices (e.g., APs, base stations, etc.) using the Bluetooth communication standard. Figure 1 ​Wi-Fi or other WLAN communications (e.g., over an 802.11 network) with the AP 104 and / or 102). The STA 106 can use the Bluetooth modem 236 to perform Bluetooth or other WPAN communications with one or more external devices (e.g., another STA 106). The STA 106 can use the cellular modem 234 to perform cellular communications with one or more wireless base stations in accordance with one or more cellular communication technologies (e.g., in accordance with one or more 3GPP specifications).

[0050] As described herein, the STA 106 can include hardware components and software components for implementing embodiments of the present disclosure. For example, one or more components of the wireless communication circuitry 230 of the STA 106 (e.g., the Wi-Fi modem 232, the cellular modem 234, the BT modem 236) can be configured to implement some or all of the methods described herein, e.g., by one or more processors executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium), configured as an FPGA (field-programmable gate array), and / or using a processor that can include an ASIC (application-specific integrated circuit). The STA 106 can include a support structure, such as a housing. The housing can include conductive and / or dielectric housing walls, layers, and / or other structures.

[0051] The STA 106 can include additional input-output devices (not shown for the sake of clarity), if desired. The input-output devices can be used to allow data to be supplied to and provided from the STA 106 to external devices. The input-output devices can include user interface devices, data port devices (interfaces 220), touch sensors, displays (e.g., display 260), light-emitting components such as displays without touch sensor capabilities, buttons (mechanical, capacitive, optical, etc.), scroll wheels, touchpads, keypads, keyboards, microphones, cameras, buttons, speakers, status indicators, audio jack and other audio port components, digital data port devices, motion sensors (accelerometers, gyroscopes, and / or compasses that detect motion), capacitive sensors, proximity sensors, magnetic sensors, force sensors (e.g., force sensors coupled to a display to detect pressure applied to the display), temperature sensors, and the like. In some configurations, keyboards, headsets, displays, pointing devices such as touchpads, mice, and joysticks, and other input-output devices can be coupled to the STA 106 using wired or wireless connections (e.g., some of the input-output devices can be peripheral devices coupled to a main processing unit or other portion of the STA 106 via wired or wireless links).

[0052] Figure 3 is a STA 106 such as the AP 104 (or equivalently,Figure 1 an example block diagram of an electronic device such as an AP 102. In some cases (e.g., in the context of 802.11 communications), the AP 104 can also be referred to as an AP STA. Note that Figure 3 The AP 104 can include one or more processors 304 that can execute program instructions for the AP 104. The processor 304 can also be coupled to an MMU 340, which can be configured to receive addresses from the processor 304 and translate those addresses to locations in memory (e.g., the memory 360 and the ROM 350), or to other storage circuits, circuits, or devices.

[0053] The AP 104 can include at least one network port 370. The network port 370 can be configured to couple to a network and provide access to the network (e.g., the network 100) for multiple devices such as the STAs 106. The network port 370 (or an additional network port) can also be or alternatively be configured to couple to a cellular network (e.g., a core network (CN) of a cellular service provider). The core network can provide mobility related services and / or other services to multiple UE devices (e.g., the STAs 106). In some cases, the network port 370 can couple to a telephone network via the core network, and / or the core network can provide a telephone network (e.g., between other UE devices served by the cellular service provider). Figure 1

[0054] The AP 104 can include one or more radios 330A-330N, each of which can be coupled to a respective communication chain 332 and at least one antenna 334, and possibly to multiple antennas (e.g., the first radio 330A is coupled to the antenna 334A via the communication chain 332A, the Nth radio 330N is coupled to the antenna 334N via the communication chain 332N, and so on). The radios 330 can be configured to function as wireless transceivers that communicate with the STAs 106 via the communication chains 332 and the antennas 334. The antennas 334A-334N communicate with their respective radios 330A-330N via the communication chains 332A-332N. The communication chains 332 can be receive chains, can be transmit chains, or can include both transmit and receive chains. The radios 330A-330N can be configured to communicate according to a variety of wireless communication standards, including but not limited to LTE, LTE-A, 5G NR, 6G, UWB, WLAN (Wi-Fi), WPAN (BT), and so on. If desired, the AP 104 can be configured to operate on multiple wireless links using one or more radios 330A-330N, with each radio used to operate on a respective wireless link. ​

[0055] The AP 104 can be configured to use one or more wireless communication standards to communicate. In some cases, the AP 104 can include multiple radios that can enable the network entity to communicate according to multiple wireless communication technologies. For example, as one possibility, the AP 104 can include an LTE or 5G radio to perform communications according to LTE or 5G NR and a Wi-Fi radio to perform communications according to Wi-Fi. In this case, the AP 104 can be capable of operating as both a cellular base station and a Wi-Fi access point. As another possibility, the AP 104 can include a multi-mode radio capable of performing communications according to any of a plurality of wireless communication technologies, such as NR and Wi-Fi, NR and LTE, and so on. As another possibility, the AP 104 can be configured to function exclusively as a Wi-Fi access point, e.g., without cellular communication capabilities.

[0056] As described further herein, the AP 104 can include hardware and software components for implementing or supporting implementation of the features described herein. The processor 304 of the AP 104 can be configured to implement or support implementation of some or all of the methods described herein, e.g., by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium). Alternatively, the processor 304 can be configured as a programmable hardware element, such as an FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit) or a combination thereof. Alternatively (or additionally) the processor 304 of the AP 104, along with one or more of the other components 330, 332, 334, 340, 350, 360, 370 can be configured to implement or support implementation of some or all of the features described herein.

[0057] The radio 330 on the AP 104 can use the antenna 334 Figure 3 and the wireless communication circuit 230 on the STA 106 can use the antenna 235 Figure 2 to transmit and / or receive radio frequency signals within different frequency bands (sometimes referred to herein as communication frequency bands or simply “frequency bands”) at radio frequencies. The frequency bands handled by the AP 104 and the STA 106 can include satellite communication frequency bands (e.g., C-band, S-band, L-band, X-band, W-band, V-band, K a -band, K u -band, and so on); wireless local area network (WLAN) frequency bands (e.g., 2.4 GHz, 5 GHz, 60 GHz, and so on); cellular frequency bands (e.g., 700 MHz, 1500 MHz, 2100 MHz, 2600 MHz, and so on); and so on. such as a 2.4 GHz WLAN band (e.g., 2400 MHz to 2480 MHz), a 5 GHz WLAN band (e.g., 5180 MHz to 5825 MHz), a 6E band (e.g., 5925 MHz to 7125 MHz), and / or other bands (e.g., 1875 MHz to 5160 MHz); a wireless personal area network (WPAN) band such as a 2.4 GHz band or other WPAN communication band, a cellular telephone band (e.g., a band of about 600 MHz to about 5 GHz, a 3G band, a 4G LTE band, a 5G New Radio Frequency Range 1 (FR1) band below 10 GHz, a 5G New Radio Frequency Range 2 (FR2) band between 20 GHz and 60 GHz, a 6G band, etc.), other centimeter or millimeter wave bands between 10 GHz and 300 GHz; a near field communication (NFC) band (e.g., 13.56 MHz); a satellite navigation band (e.g., a GPS band of 1565 MHz to 1610 MHz, a GLONASS band, a BeiDou satellite navigation system (BDS) band, etc.); an ultra-wideband (UWB) band operating under IEEE 802.15.4 protocol and / or other ultra-wideband communication protocols; a communication band under the 3GPP wireless communication standards family; a communication band under the IEEE 802.XX standards family; and / or any other desired band of interest.

[0058] Any desired antenna structure can be used to form the antenna 334 Figure 3 and the antenna 235 Figure 2). For example, the antennas can include antennas having resonant elements formed by loop antenna structures, patch antenna structures, inverted-F antenna structures, slot antenna structures, planar inverted-F antenna structures, helical antenna structures, monopole antennas, dipole antennas, hybrids of these designs, etc. If desired, one or more of the antennas can include antenna resonant elements formed by electrically conductive portions of the device housing (e.g., a peripherally extending electrically conductive housing structure that surrounds a display on the STA 106). Filter circuitry, switching circuitry, impedance matching circuitry, and / or other antenna tuning components can be adjusted to adjust the frequency response and wireless performance of the antennas over time. If desired, multiple antennas can be implemented as a phased array antenna (e.g., where each antenna forms a radiator or antenna element of the phased array antenna (sometimes also referred to as a phased antenna array)). In these cases, the phased array antenna can transmit radio frequency signals within a signal beam. The phase and / or amplitude of each radiator in the phased array antenna can be adjusted so that the radio frequency signals of each radiator constructively and destructively interfere to direct or steer the signal beam in a particular pointing direction (e.g., a direction of peak signal gain). The signal beam can be adjusted or steered over time.

[0059] The wireless communication circuitry 230 can transmit radio frequency signals using the antennas 235 Figure 2 ). The radio 330 can transmit radio frequency signals using the antennas 334 Figure 3 ). As used herein, the term “transmit radio frequency signals” means transmission and / or reception of radio frequency signals (e.g., for performing one-way and / or two-way wireless communication with external wireless communication equipment). As used herein, the term “transmit wireless data” means sending and / or receiving wireless data (e.g., as by corresponding radio frequency signals). An antenna can transmit radio frequency signals by radiating the radio frequency signals into free space (or through an intervening device structure such as a dielectric cover layer to free space). Additionally or alternatively, an antenna can receive radio frequency signals from free space (or through an intervening device structure such as a dielectric cover layer). The transmission and reception of radio frequency signals by an antenna each involve excitation or resonance of antenna current on an antenna resonant element in the antenna by radio frequency signals within the operating band of the antenna.

[0060] The wireless communication circuitry 230 can be coupled to the antennas 235 Figure 2 ) by one or more radio frequency transmission lines. The radio 330 can be coupled to the antennas 334 Figure 3 ) by one or more radio frequency transmission lines. The communication link 332 Figure 3A radio frequency (RF) transmission line may be disposed between antenna 334 and radio component 330. The RF transmission line may include coaxial cable, microstrip transmission line, stripline transmission line, edge-coupled microstrip transmission line, edge-coupled stripline transmission line, or a combination of these types of transmission lines. If desired, the RF transmission line may be integrated into a rigid and / or flexible printed circuit board. If desired, one or more RF lines may be shared between radio components or modems. If desired, an RF front-end (RFFE) module may be inserted into one or more RF transmission lines (e.g., in…). Figure 3 Within communication link 332 or in Figure 2 (Within the wireless communication circuit 230). The radio frequency front-end module may include a substrate, integrated circuit, chip, or package separate from the radio components or modem, and may include filter circuitry, switching circuitry, amplifier circuitry, impedance matching circuitry, radio frequency coupling circuitry, and / or any other desired radio frequency circuitry for operating on radio frequency signals transmitted through the radio frequency transmission line.

[0061] Processor 202 ( Figure 2 ) and processor 304 ( Figure 3 Each of these components may include one or more processors, such as microprocessors, microcontrollers, digital signal processors, host processors, baseband processing circuitry (e.g., one or more baseband processors or baseband processor integrated circuits), application-specific integrated circuits (ASICs), FPGAs, central processing units (CPUs), graphics processing units (GPUs), etc. If necessary, radio components 330 ( Figure 3 The STA 106 and / or wireless communication circuitry 230 may also include one or more processors. The baseband circuitry in the STA 106 and / or AP 104 may, for example, access corresponding memory circuitry (e.g., Figure 2 memory 206 or Figure 3 The communication protocol stack on the memory 360 performs user plane functions at the physical (PHY) layer, data link or media access control (MAC) layer, RLC layer, PDCP layer, SDAP layer and / or PDU layer; and / or performs control plane functions at the PHY layer, MAC layer, RLC layer, PDCP layer, RRC layer and / or non-access layer.

[0062] AP 104 (or Figure 1The APs 104 can communicate with the STAs 106 over corresponding wireless communication links. Radio frequency signals can be wirelessly communicated between the radios and antennas on the APs 104 and the STAs 106 to support the wireless communication links. The radio frequency signals can include wireless data modulated onto a carrier frequency of the radio frequency signals (e.g., modulated by a transmitter in the radios 330 of the APs 104 or a modem on the wireless communication circuitry 230 of the STAs 106). The wireless data can be organized, modulated onto, and demodulated from the radio frequency signals in accordance with a corresponding communication protocol or standard (e.g., an IEEE 802.11 protocol or standard) (e.g., by a receiver in the radios 330 of the APs 104 or a modem on the wireless communication circuitry 230 of the STAs 106). The radio frequency signals can be communicated in one or more frequency bands associated with the communication protocol.

[0063] Described herein are implementations in which the APs 104 and the STAs 106 communicate in accordance with an IEEE 802.11 protocol or standard as one example. Under the 802.11 protocol, wireless data is organized into a series of frames or frame streams (e.g., medium access control (MAC) frames) carried by radio frequency signals. The frames, sometimes also referred to as packets, can include management frames, control frames, data frames, beacon frames, association frames, authentication frames, acknowledgement (ACK) frames, block ACK frames, trigger frames, trigger response frames, and / or other types of frames. Each frame can include a frame header, a body (e.g., after the header), and a trailer (e.g., after the body). The header can include, for example, source address (SA) information identifying a transmitter of the frame (sometimes also referred to herein as transmitter address (TA) information, which identifies a corresponding TA), destination address information identifying an intended recipient of some or all of the frame (sometimes also referred to herein as receiver address (RA) information, which identifies a corresponding RA), routing information, identifier information identifying one or more aspects of the frame (e.g., information identifying a type of the frame), an association identifier (AID) field, control information, and / or the like. The body can include, for example, a data payload (e.g., a payload of voice data, video data, web browsing data, application data, and / or the like). The trailer can include check information that helps to verify the frame to a recipient. As an example, the check information can include a frame check sequence (FCS) or cyclic redundancy check (CRC) field. If desired, the header, the body, and / or the trailer can include one or more message integrity check (MIC) fields (e.g., a hash value or other output of a cryptographic function that takes different portions of the frame as input and is used to verify the integrity of the frame when received by a recipient).

[0064] Under a bidirectional communication link between the AP 104 and the STAs 106, frames are communicated from the AP 104 to the STAs 106 and from the STAs 106 to the AP 104. The STAs 106 can send one or more ACK frames or block ACK frames to the AP 104 to acknowledge successful receipt of one or more frames sent by the AP 104. The AP 104 can send one or more ACK frames or block ACK frames to the STAs 106 to acknowledge successful receipt of one or more frames sent by the AP STAs 106.

[0065] Radio frequency signals are transmitted from the AP 104 to the STAs 106 in a downlink (DL) direction. Radio frequency signals transmitted in the DL direction are sometimes also referred to herein as DL signals. The DL signals can carry DL data (e.g., DL frames transmitted by the AP 104 to the STAs 106). Radio frequency signals are transmitted from the STAs 106 to the AP 104 in an uplink (UL) direction. Radio frequency signals transmitted in the UL direction are sometimes also referred to herein as UL signals. The UL signals can carry UL data (e.g., UL frames transmitted by the STAs 106 to the AP 104).

[0066] A given AP 104 can support, maintain, and / or implement a basic service set (BSS) for communicating with at least one STA 106 (e.g., in accordance with a corresponding 802.11 protocol). If desired, a single physical AP 104 can concurrently support, maintain, and / or implement multiple BSSs (e.g., can support wireless communication with different STAs associated with multiple BSSs). An AP can communicate with a first set of one or more STAs 106 utilizing a first BSS, a second set of one or more STAs 106 utilizing a second BSS, and so on. When initiating communication between the AP 104 and a given STA 106, the STA registers with the AP 104 and is subsequently associated with a corresponding BSS of the AP (a process referred to as association). A BSS can include and / or identify corresponding communication / operation parameters, device capabilities, security level information, and / or other information associated with communication services provided by the AP 104 to one or more STAs under the BSS.

[0067] Each BSS can be identified by a corresponding BSS identifier (BSSID). The BSSID can represent or correspond to, for example, a particular network address (e.g., MAC address) and / or wireless network name established, owned, and / or maintained by the AP for wireless communication using the corresponding BSS. If desired, a given AP 104 can sometimes be referred to herein as supporting, implementing, and / or maintaining multiple BSSIDs concurrently or simultaneously in a communication scheme that performs multiple BSSID (M-BSSID) operations or M-BSSID communications. When configured to perform M-BSSID communications, each BSSID maintained by the AP 104 corresponds to a different network address (e.g., MAC address) and wireless network name maintained and operated by the AP.

[0068] Consider an example in which the AP 104 is a Wi-Fi router or hotspot in a university campus and is configured to perform M-BSSID communications. In this example, the AP 104 can concurrently maintain a first BSSID named “Students” for STAs 106 operated by students of the university campus and corresponding to a first MAC address of the AP 104, a second BSSID named “Employees” for STAs 106 operated by employees of the university campus and corresponding to a second MAC address of the AP 104, a third BSSID named “Guests” for STAs 106 operated by visitors of the university campus, and so on. Each BSSID can have different respective operating characteristics, security configurations, and / or settings. When a STA 106 enters the wireless coverage area of the AP, the user of the STA can interact with a user interface of the STA to select one of the BSSIDs of the AP to connect to. The AP can then associate the STA with or to the BSSID (e.g., if the STA satisfies one or more security conditions related to the BSSID, such as being registered with users granted access to the BSSID, providing a correct password to access the BSSID, and so on). Once associated with a given BSSID, the STA and the AP use the BSSID (e.g., the BSS identified by the BSSID) to communicate wireless data. This example is illustrative and non-limiting.

[0069] When configured to perform M-BSSID communication (e.g., according to the M-BSSID communication scheme), the AP 104 transmits a single beacon frame for multiple BSSIDs to minimize signaling overhead. The beacon frame can advertise the different BSSIDs of the AP 104, e.g., using an M-BSSID element of the beacon frame. In some implementations (e.g., previous versions of the 802.11 protocol), the AP is unable to simultaneously serve Enhanced Multi-Link Single Radio (EMLSR) STAs associated with different BSSIDs in a multi-user (MU) manner. In these implementations, only sequential data transmissions can occur (e.g., where data for STAs associated with a first BSSID is transmitted during a first transmission opportunity (TXOP) before data for STAs associated with a second BSSID is transmitted during a second TXOP). This can result in excessive latency and can reduce the data throughput of wireless data transmitted between the STAs and the AP.

[0070] A communication protocol for performing communications between the AP 104 and the STAs 106 can define an M-BSSID control frame to mitigate these latency and throughput issues. The AP 104 can transmit (broadcast) the M-BSSID control frame to multiple STAs 106 with different BSSIDs prior to UL or DL data transmissions. Figure 4 is a timing diagram illustrating one example of how the AP 104 can transmit the M-BSSID control frame to STAs 106 with different BSSIDs prior to transmitting DL data to the STAs.

[0071] In the example of Figure 4 , row 400 illustrates frame transmissions by the AP 104, row 402 illustrates frame transmissions by a first STA 106A (also denoted as STA1), and row 404 illustrates frame transmissions by a second STA 106B (also denoted as STA2). The AP 104 has a dedicated BSSID, such as BSSID0 (e.g., a first MAC address uniquely assigned to the physical device forming the AP 104 during manufacture or assembly of the AP 104). BSSID0 is also sometimes referred to herein as “transmitted BSSID0.” The transmitted BSSID0 uniquely identifies the AP 104 and is not used for common management signaling. The transmitted BSSID0 can be used to refer to or otherwise address the AP 104 during beacon frame transmissions and / or subsequent communications. The AP 104 is configured to perform M-BSSID communication and operates / maintains two or more BSSIDs for associating with one or more STAs 106, which are sometimes also referred to herein as “non-transmitted” BSSIDs.

[0072] In the example of Figure 4In the example, AP 104 concurrently supports at least a first non-transmitting BSSID1 (e.g., a first network name associated with a second MAC address maintained at AP 104) and a second non-transmitting BSSID2 (e.g., a second network name associated with a third MAC address maintained at AP 104). STA 106A may be associated with BSSID1. STA 106A may have a corresponding network address, such as MAC address MSTA1. MAC address MSTA1 may uniquely identify STA 106A. STA 106B may be associated with BSSID2. STA 106B may have a corresponding network address, such as MAC address MSTA2. MAC address MSTA2 may uniquely identify STA 106B.

[0073] like Figure 4 As shown, AP 104 can send M-BSSID control frames, such as Initial Control Frame (ICF) 406, to all STAs associated with the non-transmitting BSSID maintained by AP 104. ICF 406 can be a MU Request Transmission (MU-RTS) frame or another type of ICF that precedes or initiates DL data transmission. ICF 406 may have a header (e.g., a MAC header) in which the receiver address (RA) field is set to "broadcast" (e.g., including one or more bits indicating or identifying a broadcast address, that ICF 406 is a broadcast frame, and / or that ICF 406 is intended to be received by all STAs 106 associated with AP 104). The header may also have a transmitter address (TA) field set to BSSID 0 of AP 104 (e.g., the TA field may include one or more bits indicating or identifying the MAC address of BSSID 0). The transmitter address (TA) is sometimes also referred to as the source address. The receiver address (RA) is sometimes also referred to as the destination address.

[0074] The STAs 106A and 106B can receive the ICF 406. After a short reception and processing period (e.g., in response to receiving the ICF 406 and after at least a short interframe space (SIFS) has passed since the end of the transmission of the ICF 406), the STA 106A can transmit an allow transmit (CTS) frame 408 to the AP 104. The header of the CTS frame 408 can have a RA field set to the transmitted BSSID0 of the AP 104, indicating that the CTS frame 408 is to be received by the AP 104 (e.g., the STA 106A can generate the CTS frame 408 to include the transmitted BSSID0 identified by the TA field of the ICF 406 in its RA field). The STA 106B can concurrently transmit a CTS frame 410. The header of the CTS frame 410 can also have a RA field set to the transmitted BSSID0 of the AP 104, indicating that the CTS frame 410 is to be received by the AP 104 (e.g., the STA 106B can generate the CTS frame 410 to include the transmitted BSSID0 identified by the TA field of the ICF 406 in its RA field). The CTS frames 408 and 410 can indicate to the AP 104 to transmit DL data to the STAs 106A and 106B.

[0075] The AP 104 can receive the CTS frame 408 and the CTS frame 410. In response to receiving the CTS frames and after a short reception and processing time (e.g., after at least a SIFS has passed since the end of the transmission of the CTS frames), the AP 104 can transmit a first data frame 412 to the STA 106A and can transmit a second data frame 414 to the STA 106B (e.g., concurrently with the transmission of the data frame 412). The data frames 412 and 414 can be, for example, MU physical protocol data unit (PPDU) frames.

[0076] The AP 104 can generate the RA field in the header of the data frame 412 to include or identify the MAC address MSTA1 of the STA 106A, to uniquely indicate that the data frame 412 is intended to be received by the STA 106A (e.g., the data frame 412 can have RA = MSTA1). The AP 104 can generate the TA field in the header of the data frame 412 to include or identify the BSSID1 of the STA 106A (e.g., the data frame 412 can have TA = BSSID1, indicating that the data frame 412 is transmitted by the BSSID1 of the AP 104). Similarly, the AP 104 can set the RA field in the header of the data frame 414 to include or identify the MAC address MSTA2 of the STA 106B, to uniquely indicate that the data frame 414 is intended to be received by the STA 106B (e.g., the data frame 414 can have RA = MSTA2). The AP 104 can set the TA field in the header of the data frame 414 to include or identify the BSSID2 of the STA 106B (e.g., the data frame 414 can have TA = BSSID2, indicating that the data frame 414 is transmitted by the BSSID2 of the AP 104).

[0077] The STA 106A can receive the data frame 412. In response to receiving the data frame 412 and after a short reception and processing time (e.g., after at least a SIFS has passed since the end of the transmission of the data frame 412), the STA 106A can transmit an acknowledgement frame, such as a Block Acknowledgement (BA) frame 416, to the AP 104. The STA 106A can include or identify the MAC address MSTA1 of the STA 106A in the TA field of the BA frame 416, to uniquely indicate that the BA frame 416 is transmitted by the STA 106A (e.g., the BA frame 416 can have TA = MSTA1). The STA 106A can include or identify the BSSID1 associated with the STA 106A in the RA field of the BA frame 416, to indicate that the BA frame 416 is intended to be received by the non-transmitting BSSID1 of the AP 104 (e.g., the BA frame 416 can have RA = BSSID1). The BA frame 416 can serve as an acknowledgement to the AP 104 that the STA 106A has successfully received the wireless data payload of the data frame 412, after which the AP 104 can transmit a subsequent DL data frame to the STA 106A, and / or the STA 106A can transmit a subsequent UL data frame to the AP 104.

[0078] Similarly, STA 106B can receive data frame 414 (e.g., concurrently with receiving data frame 412 at STA 106A). In response to receiving data frame 414 and after a short receive and processing time (e.g., after at least a SIFS has passed since the end of transmission of data frame 414), STA 106B can transmit an acknowledgement frame, such as BA frame 418, to AP 104. STA 106B can include or identify the MAC address MSTA2 of STA 106B in the TA field of BA frame 418, thereby uniquely indicating that BA frame 418 is transmitted by STA 106B (e.g., BA frame 418 can have TA = MSTA2). STA 106B can include or identify the BSSID2 associated with STA 106B in the RA field of BA frame 418, thereby indicating that BA frame 418 is intended to be received by BSSID2 of AP 104 (e.g., BA frame 418 can have RA = BSSID2). BA frame 418 can serve as an acknowledgement to AP 104 that STA 106B has successfully received the wireless data payload of data frame 414, after which AP 104 can transmit a subsequent DL data frame to STA 106B, and / or after which STA 106B can transmit a subsequent UL data frame to AP 104. The frame structure of frames 406-418 can be specified by a communication protocol (e.g., an 802.11 protocol) that manages communications between STAs 106 and AP 104.

[0079] Figure 5 is a timing diagram illustrating one example of how AP 104 can transmit control frames to STAs 106 with different BSSIDs before the AP receives UL data from the STAs. In this example, column 500 illustrates frame transmissions by AP 104, column 502 illustrates frame transmissions by STA 106A, and column 504 illustrates frame transmissions by STA 106B. Figure 5

[0080] As shown in column 500, AP 104 can transmit a control frame, such as ICF 506, to all STAs associated with a non-transmitted BSSID maintained by AP 104. ICF 506 can be a trigger frame (TF) that triggers UL data transmission by STAs 106, or another type of ICF that precedes or initiates UL data transmission by STAs 106. AP 104 can set the RA field in the header of ICF 506 to a broadcast address, and can set the TA field in the header of ICF 506 to the transmitted BSSID0 of AP 104. Figure 5

[0081] ​​The STAs 106A and 106B can receive the ICF 506. After a short reception and processing period (e.g., in response to receiving the ICF 506 and after at least a SIFS has passed since the end of the transmission of the ICF 506), the STA 106A can transmit an UL data frame, such as data frame 508 (e.g., the ICF 506 can trigger the transmission of the data frame 508). Similarly, the STA 106B can transmit an UL data frame, such as data frame 510, in response to receiving the ICF 506 (e.g., the ICF 506 can trigger the transmission of the data frame 510). The data frames 508 and 510 can be, for example, Trigger-Based (TB) PPDU frames (e.g., frames that are triggered by receiving a trigger frame and have a data payload carrying UL data for reception at the AP 104).

[0082] The STA 106A can set the TA field in the header of the data frame 508 to include or identify the MAC address MSTA1 of the STA 106A, thereby uniquely indicating that the data frame 508 is transmitted by the STA 106A. The STA 106A can set the RA field in the header of the data frame 508 to include or identify the BSSID (e.g., BSSID1) associated with the STA 106A, thereby indicating that the data frame 508 is intended for reception by the BSSID1 of the AP 104. Similarly, the STA 106B can set the TA field in the header of the data frame 510 to include or identify the MAC address MSTA2 of the STA 106B, thereby uniquely indicating that the data frame 510 is transmitted by the STA 106B. The STA 106B can set the RA field in the header of the data frame 510 to include or identify the BSSID (e.g., BSSID2) associated with the STA 106B, thereby indicating that the data frame 510 is intended for reception by the BSSID2 of the AP 104.

[0083] The AP 104 can receive the data frames 508 and 510. In response to receiving the data frames 508 and 510 and after a short reception and processing time (e.g., after at least a SIFS has passed since the end of the transmission of the data frames 508 and 510), the AP 104 can broadcast an acknowledgement frame, such as a multi-STA block acknowledgement (M-BA) frame 512. The AP 104 may, for example, set the RA field in the header of the M-BA frame 512 to the broadcast address (“broadcast”) and can set the TA field in the header of the M-BA frame 512 to BSSID0, thereby uniquely identifying that the AP 104 transmitted the M-BA frame 512. The M-BA frame 512 can serve as an acknowledgement to the STAs 106A and 106B that the AP 104 successfully received the wireless data payloads of the data frames 508 and 510, after which the STAs 106A and 106B can transmit subsequent data frames to the AP 104 and / or after which the AP 104 can transmit subsequent data frames to the STA 106A and / or the STA 106B. The frame structures of the frames 506-512 can be specified by a communication protocol (e.g., an 802.11 protocol) that governs the communication between the STAs 106 and the AP 104.

[0084] To help optimize the security of the wireless communications of the AP 104, the AP 104 can integrity protect ICFs transmitted to the STAs 106 according to the M-BSSID scheme (e.g., MU-RTS frames as shown in Figure 4 trigger frames as shown in Figure 5 etc.). ICs that have been integrity protected by the AP 104 are sometimes referred to herein as integrity-protected ICs or secured ICs (SICs). Integrity protecting the ICs can help the STAs verify that the ICs and subsequent data frames were actually transmitted by the AP 104 and not by an unauthorized device or a network intruder (e.g., a so-called man-in-the-middle (MITM) attacker).

[0085] To integrity protect the ICs, the AP 104 can generate a control message integrity check (CMIC) for the IC (sometimes also referred to herein as a CMIC field, CMIC information, or CMIC bits). The AP 104 can include the CMIC in the IC transmitted to the STAs 106. Figure 6 is a diagram showing how an illustrative transmitter device 616 can generate an integrity-protected frame for transmission to a corresponding receiver device. In Figure 6In the example, transmitter device 616 could be AP 104, which generates an integrity-protected ICF from an unprotected ICF (such as ICF 602) for transmission to STA 106. This is illustrative and not limiting. In general, transmitter device 616 could be any desired device (e.g., STA 106) that transmits any desired integrity-protected frame to any type of receiver device (e.g., ...). Figure 6 The ICF 602 can be replaced with any frame desired to be protected for integrity.

[0086] like Figure 6 As shown, the transmitter device 616 may include a cryptographic key storage device 600 (e.g., in...). Figure 3 In the memory 360 or ROM 350), the cryptographic function 608 (e.g., using digital and / or analog logic components, Figure 3 (such as processor 304 to implement and / or execute) and wireless transmitters such as transmitter 614 (e.g., Figure 3 The radio component 330 and / or communication link 332. The cryptographic key storage device 600 may include tables, databases, other types of data structures, and / or dedicated storage on the transmitter device 616 (e.g., hard-coded and / or encrypted key storage on AP 104). The cryptographic function 608 may include a hash function / algorithm. As an example, the cryptographic function 608 may be a Galois Message Authentication Code (GMAC) function or algorithm.

[0087] To provide integrity protection for an initial / unprotected ICF such as ICF 602, transmitter device 616 may provide ICF information 606 from ICF 602 as a first input to cryptographic function 608. ICF information 606 may include some or all of one or more fields from ICF 602 (e.g., some or all of the payload of ICF 602, some or all of one or more fields from the header of ICF 602, etc.). Transmitter device 616 may also provide a selected cryptographic key 604 from cryptographic key storage device 600 as a second input to cryptographic function 608. Cryptographic function 608 may generate (e.g., perform operations, calculations, outputs, etc.) CMIC 610 based on the selected cryptographic key 604 and ICF information 606 (e.g., by hashing ICF information 606 using the selected cryptographic key 604 according to the GMAC algorithm or another hash algorithm). Then, transmitter device 616 can insert CMIC 610 into the corresponding field of ICF 602 to generate integrity-protected ICF 612. Transmitter 614 can then send the integrity-protected ICF 612 to the corresponding receiver device.

[0088] Figure 7 This illustrates how the exemplary receiver device 708 can receive data from... Figure 6 A diagram illustrating the transmitter device 616 receiving integrity-protected frames and performing integrity checks on them. Figure 7 In the example, receiver device 708 could be STA 106 performing integrity checks on an integrity-protected ICF 612 received from AP 104. This is illustrative and not limiting. In general, receiver device 708 could be any desired device (e.g., AP 104) receiving any desired integrity-protected frame from any type of transmitter device (e.g., ...). Figure 7 The integrity-protected ICF 612 can be replaced with any desired integrity-protected frame.

[0089] like Figure 7 As shown, receiver device 708 may include cryptographic key storage device 702 (e.g., in...). Figure 2 In the memory 206 or ROM 250), the cryptographic function 608 (e.g., using digital and / or analog logic components, Figure 2 The processor 202, etc., implements and / or executes) and the wireless receiver, such as the receiver 700 (e.g., in...). Figure 2 In the wireless communication circuit 230). The cryptographic key storage device 702 may include tables, databases, other types of data structures, and / or dedicated key storage devices on the transmitter device 616 (e.g., hard-coded and / or encrypted key storage devices on STA 106). The cryptographic function 608 may be generated by the transmitter device 616 ( Figure 6 The same cryptographic function is used to generate ICF 612 with integrity protection.

[0090] Receiver 700 can be connected from transmitter device 616 ( Figure 6 Receiver device 708 receives an integrity-protected ICF 612. Receiver device 708 can extract ICF information 606 from the integrity-protected ICF 612 (e.g., Figure 6 The receiver device 708 can also provide the selected cryptographic key 604 from the cryptographic key storage device 702 as a second input to the cryptographic function 608. The receiver device 708 can also provide the selected cryptographic key 604 from the cryptographic key storage device 702 as a second input to the cryptographic function 608. Figure 6 During the initial registration, association, and / or handshake operation between the transmitter device 616 and the receiver device 708, the receiver device 708 may receive a selected cryptographic key 604 from the transmitter device 616. The receiver device 708 may receive the selected cryptographic key 604 based on one or more fields of an integrity-protected ICF frame 612 and / or from the transmitter device 616. Figure 6) one or more bits in another frame received, receiving information identifying which cryptographic key stored on the cryptographic key storage 702 is to be provided to the cryptographic function 608 (i.e., the selected cryptographic key 604).

[0091] The cryptographic function 608 can generate (e.g., operate on, compute, output, etc.) a candidate CMIC (denoted as CMIC') such as the candidate CMIC 704 based on the selected cryptographic key 604 and the ICF information 606 (e.g., by hashing the ICF information 606 with the selected cryptographic key 604 according to a GMAC algorithm or another hashing algorithm). Since the cryptographic function 608 is the same cryptographic function, and the selected cryptographic key 604 is the same cryptographic key used by the sender device 616 to generate the CMIC 610( Figure 6 ) included in the integrity protected ICF 612 sent by the sender device 616, the candidate CMIC 704 output by the cryptographic function 608 will be the same as the CMIC 610( Figure 6 ) if / when the integrity protected ICF 612 is in fact the integrity protected ICF 612 sent by the sender device 616. On the other hand, the candidate CMIC 704 will not match the CMIC 610 if / when the frame received by the receiver 700 was sent by a different device (e.g., an unauthorized device such as a MITM attacker).

[0092] The receiver device 708 can include a comparison logic component 706 (e.g., implemented / executed using digital and / or analog logic components and / or the processor 202 as using Figure 2 ) included in the integrity protected ICF 612. The comparison logic component 706 can compare the candidate CMIC 704 output by the cryptographic function 608 to the CMIC 610( Figure 6) with the candidate CMIC 704. If / when the comparison logic component 706 determines that the CMIC 610 in the integrity protected ICF 612 matches / is equal to the candidate CMIC 704, the receiver device 708 successfully integrity checks the integrity protected ICF 612 (e.g., verifies that the integrity protected ICF 612 was sent by the intended and authorized sender device 616) and can pass the payload of the integrity protected ICF 612 up the protocol stack for further processing. If desired, the receiver device 708 can also send an acknowledgement frame to the sender device 616 to acknowledge successful receipt of the integrity protected ICF 612 and additional frames (e.g., data frames) can be conveyed between the sender device 616 and the receiver device 708. On the other hand, if / when the comparison logic component 706 determines that the CMIC 610 in the integrity protected ICF 612 is different from the candidate CMIC 704, then the receiver device 708 fails to successfully integrity check the integrity protected ICF 612 (e.g., indicating that the frame can have been sent by a non-intended or unauthorized device) and the integrity protected ICF 612 can be discarded. In this way, the sender device 616 Figure 6 may securely and reliably send control frames to the receiver device 708.

[0093] Figure 8 is a timing diagram illustrating one example of how an AP 104 that is configured with M- BSSIDs can send an integrity protected control frame to STAs 106A and 106B that are associated with the same BSSID. As shown, column 800 illustrates frame transmissions by the AP 104, column 802 illustrates frame transmissions by the STA 106A, and column 804 illustrates frame transmissions by the STA 106B. In the example of Figure 8 , the STA 106A and the STA 106B are both associated with the same non-transmitting BSSID (e.g., BSSID1). Figure 8

[0094] The AP 104 can generate an integrity protected ICF 806. The AP 104 may, for example, generate the integrity protected ICF 806 as the integrity protected ICF 612 of Figure 6 . The integrity protected ICF 806 can have a RA field set to the broadcast address. Since both the STA 106A and the STA 106B belong to BSSID1 in this example, the AP 104 can set the TA field of the integrity protected ICF 806 to BSSID1. The AP 104 can generate a CMIC for the integrity protected ICF 806 (e.g., the CMIC 610 of Figure 6 ​CMIC 610), such as CMIC1. AP 104 can generate CMIC1 using a pairwise key corresponding to and / or specific to BSSID1 (e.g., as selected pairwise key 604). AP 104 can include CMIC1 in a header field or frame body of an integrity protected ICF 806. AP 104 can transmit (broadcast) integrity protected ICF 806. Figure 6

[0095] STA 106A and STA 106B can receive integrity protected ICF 806. STA 106A and STA 106B can perform an integrity check on integrity protected ICF 806 using a pairwise key corresponding to BSSID1 (e.g., as shown). STA 106A and STA 106B can receive the pairwise key corresponding to BSSID1 during or after association with AP 104's BSSID1 during a handshake operation with AP 104. Integrity protected ICF 806 can include information identifying that STA 106A and STA 106B are to perform an integrity check on integrity protected ICF 806 using the pairwise key corresponding to BSSID1. In response to successfully checking the integrity of integrity protected ICF 806, STA 106A can transmit CTS frame 808 with a RA field identifying BSSID1, and STA 106B can transmit CTS frame 812 with a RA field identifying BSSID1. AP 104 can receive CTS frames 808 and 812 at / using BSSID1. Figure 7

[0096] In response to receiving CTS frames, AP 104 can transmit a DL data frame to STA 106A (e.g., a MU PPDU frame with a header of RA = MSTA1 and TA = BSSID1), and can transmit a DL data frame to STA 106B (e.g., a MU PPDU frame with a header of RA = MSTA2 and TA = BSSID1), as shown in block 810. STA 106A can receive the data frame addressed to MAC address MSTA1, and STA 106B can receive the data frame addressed to MAC address MSTA2.

[0097] ​​In response to receiving the DL data frame, STA 106A can send a BA frame 814 to BSSID1 of AP 104. BA frame 814 can have a RA field set to BSSID1 and a TA field set to MAC address MSTA1. If desired, STA 106A can integrity protect BA frame 814 by generating an additional CMIC (such as CMIC2) based on one or more fields of BA frame 814 and inserting CMIC2 into the BA frame (e.g., where STA 106A forms transmitter device 616 and BA frame 814 replaces ICF 602 in FIG. 6B). Figure 6

[0098] Similarly, in response to receiving the DL data frame, STA 106B can send a BA frame 816 to BSSID1 of AP 104. BA frame 816 can have a RA field set to BSSID1 and a TA field set to MAC address MSTA2. If desired, STA 106B can integrity protect BA frame 816 by generating an additional CMIC (such as CMIC3) based on one or more fields of BA frame 816 and inserting CMIC3 into the BA frame (e.g., where STA 106B forms transmitter device 616 and BA frame 816 replaces ICF 602 in FIG. 6B). AP 104 can continue to communicate wireless data with STA 106A and STA 106B. Figure 6 Figure 8 Examples of FIG. 6A illustrate DL data transmission from AP 104 to STA 106A and 106B. Similar integrity protection can apply to UL data transmission from STA 106A and 106B (e.g., as shown in FIG. 6B, where ICF 506 such as a trigger frame can be integrity protected using CMIC1). Figure 5

[0099] Figure 8 Examples of FIG. 6A illustrate DL data transmission from AP 104 to STA 106A and 106B. Similar integrity protection can apply to UL data transmission from STA 106A and 106B (e.g., as shown in FIG. 6B, where ICF 506 such as a trigger frame can be integrity protected using CMIC1). Figure 4 Figure 5 Examples of FIG. 6A illustrate DL data transmission from AP 104 to STA 106A and 106B. Similar integrity protection can apply to UL data transmission from STA 106A and 106B (e.g., as shown in FIG. 6B, where ICF 506 such as a trigger frame can be integrity protected using CMIC1).

[0100] ​​​​In these scenarios, the AP 104 can only transmit integrity-protected ICFs for a single non-transmitting BSSID at a time. For example, during a first TXOP, the AP 104 can transmit an integrity-protected ICF carrying a first CMIC, such as CMIC1 for a STA 106 (e.g., STA 106A) associated with BSSID1. After integrity checking of the integrity-protected ICF carrying CMIC1, data frames can be communicated between BSSID1 of the AP 104 and the STA 106 associated with the non-transmitting BSSID1. Then, during a second TXOP after the first TXOP, the AP 104 can transmit an integrity-protected ICF carrying a second CMIC, such as CMIC2 for a STA 106 (e.g., STA 106B) associated with BSSID2. After integrity checking of the integrity-protected ICF carrying CMIC2, data frames can be communicated between BSSID2 of the AP 104 and the STA 106 associated with BSSID2. This process can continue in respective TXOPs for each non-transmitting BSSID of the AP 104. Forcing STAs associated with different BSSIDs to provide service in different TXOPs in this manner can result in reduced data throughput and excessive latency.

[0101] To maximize throughput and minimize latency when the STA 106A and the STA 106B are associated with different BSSIDs, the AP 104 can use one or more techniques as described herein to generate an integrity-protected ICF (also sometimes referred to herein as a protected ICF (SICF)) for transmission to the STA 106A and 106B. In a first implementation, for example, the SICF can carry a separate CMIC for each non-transmitting BSSID of the AP 104.

[0102] Figure 9 is a timing diagram illustrating a DL data transmission example in which the AP 104 generates a SICF carrying a separate CMIC for each non-transmitting BSSID of the AP 104. As shown, row 900 illustrates frame transmissions by the AP 104, row 902 illustrates frame transmissions by the STA 106A, and row 902 illustrates frame transmissions by the STA 106B. In the example of Figure 9 Figure 9 In the example of FIG. 9, the STA 106A is associated with BSSID1 and the STA 106B is associated with BSSID2.

[0103] ​The AP 104 can generate a SICF 906. The SICF 906 can have a RA field set to “broadcast.” Because the STAs 106A and 106B are associated with different BSSIDs, the AP 104 can set the TA field of the SICF 906 to a unique BSSID, such as BSSID0 that has been transmitted. Using the procedures illustrated in Figure 6 The AP 104 can generate a first CMIC1 using a first BSSID-specific group key (e.g., a first control frame integrity temporary group key) associated with BSSID1 and can generate a second CMIC2 using a second BSSID-specific group key (e.g., a second control frame integrity temporary group key) associated with BSSID2. The AP 104 can insert both CMIC1 and CMIC2 into one or more fields of the SICF 906. In Figure 9 In the DL data transmission scenario illustrated in

[0104] The STAs 106A and 106B can receive the SICF 906. The STA 106A can perform an integrity check of the SICF 906 using CMIC1 included in the SICF 906 and a first group key associated with BSSID1 (e.g., using the procedures illustrated in Figure 7 The STA 106A can receive the first group key associated with BSSID1 during or after association with the BSSID1 of the AP 104 during a handshake operation with the AP 104. The SICF 906 can include information identifying that the STA 106A is to use the first group key associated with BSSID1 to perform an integrity check of the SICF 906. In response to successfully checking the integrity of the integrity protected SICF 906, the STA 106A can transmit a CTS frame 908 with a RA field identifying the BSSID0 of the AP 104. The AP 104 can receive the CTS frame 908 at / using the BSSID0.

[0105] Meanwhile, the STA 106B can perform an integrity check of the SICF 906 using CMIC2 included in the SICF 906 and a second group key associated with BSSID2 (e.g., using the procedures illustrated in Figure 7The STA 106B can receive the second password group key associated with BSSID2 during or after association with the BSSID2 of the AP 104, during a handshake operation with the AP 104. The SICF 906 can include information identifying that the STA 106B is to use the second password group key associated with BSSID2 to integrity check the SICF 906. In response to successfully checking the integrity of the integrity protected SICF 906, the STA 106B can transmit a CTS frame 910 with a RA field identifying BSSID0 of the AP 104. The AP 104 can receive the CTS frame 910 at / using BSSID0. The use of BSSID0 in the RA field of both the CTS frame 908 and the CTS frame 910 can be used, for example, to prevent collisions between the CTS frames, despite the STA 106A and the STA 106B being associated with different BSSIDs.

[0106] In response to receiving the CTS frames, the AP 104 can transmit a DL data frame 912 (e.g., a MU PPDU frame with a header of RA = MSTA1 and TA = BSSID1) to the STA 106A, and can concurrently transmit a DL data frame 914 (e.g., a MU PPDU frame with a header of RA = MSTA2 and TA = BSSID2) to the STA 106B. The STA 106A can receive the DL data frame 912, and the STA 106B can receive the DL data frame 914.

[0107] In response to receiving the DL data frame 912, the STA 106A can transmit an integrity protected BA frame 916 (sometimes also referred to herein as a protected BA frame (SBA)) to BSSID1 of the AP 104 (e.g., with a header of RA = BSSID1 and TA = MSTA1). In response to receiving the DL data frame 914, the STA 106B can transmit a SBA 918 to BSSID2 of the AP 104 (e.g., with a header of RA = BSSID2 and TA = MSTA2). The AP 104 can then continue to communicate wireless data with the STA 106A and the STA 106B. Figure 9 The example of FIG. 9 illustrates DL data transmission from the AP 104 to the STAs 106A and 106B. Similar integrity protection can be applied to UL data transmission from the STAs 106A and 106B (e.g., as shown in Figure 5 The ICF 506 can be integrity protected using the CMIC1 and CMIC2 included in the trigger frame, as shown.

[0108] Although STA 106A and STA 106B belong to different BSSIDs, including both CMIC1 and CMIC2 in SICF 906 can minimize latency and maximize data throughput (e.g., allowing concurrent transmission of DL data frames 912 and 914 instead of transmitting DL data frames in a separate TXOP). However, including a corresponding CMIC for each non-transmitting BSSID increases the size of the control frame and may undesirably increase protocol overhead and implementation complexity. For example, SICF 906 may also need to include a corresponding packet number (PN) and key identifier (KeyID) field for each CMIC included in the SICF (e.g., for each BSSID served by the SICF).

[0109] To minimize the size of the SICF (e.g., to minimize protocol overhead and implementation complexity), the SICF can alternatively consist of only a single CMIC shared by each of the BSSIDs served by AP 104 and STAs. Figure 10 SICF 1000 is an example of an SICF that includes only a single shared CMIC shared by each BSSID across AP 104. (Example) Figure 10 As shown, AP 104 can use the Common Control Message Integrity Check (CCMIC) (sometimes referred to herein as shared or combined CCMIC, CCMIC field, CCMIC information, or CCMIC bit) to protect the integrity of SICF 1000. AP 104 can include the Common Control Message Integrity Check (CCMIC) in the header field or frame body of SICF 1000.

[0110] AP 104 can use the selected cryptographic group key (e.g., using...) Figure 6 The process shown in the diagram is used to generate the Common Control Message Integrity Verification (CCMIC). The selected cipher set key can be used by STAs associated with all or a subset of the non-transmitting BSSIDs of AP 104 to perform integrity verification on SICF 1000. For example, STA 106A can use the selected cipher set key to perform integrity verification on SICF 1000 received from AP 104 (e.g., using...). Figure 7 (The process illustrated in the diagram). The STA106B can also use the selected cryptographic group key to perform integrity verification on SICF 1000 received from AP 104 (e.g., using...). Figure 7(The process illustrated herein) even if STA 106B is associated with a BSSID different from that of STA 106A. STA 106A and STA 106B may receive a selected cipher set key for generating a Common Control Message Integrity Verification (CCMIC) during or after association with AP 104, in the handshake operation with AP 104. If necessary, SICF 1000 may include information identifying the selected cipher set key to be used by STA 106A and 106B for integrity verification of SICF 1000. In response to successful verification of the integrity of the integrity-protected SICF 1000, STA 106A may send a CTS frame 908, and STA 106B may send a CTS frame 910.

[0111] Figure 4 , Figure 5 , Figure 9 and Figure 10 The example illustrates the simplest case where AP 104 has two non-transmitting BSSIDs (e.g., BSSID1 and BSSID2). This is illustrative and not restrictive. In general, AP 104 may have more than two non-transmitting BSSIDs. Figure 5 , Figure 9 and Figure 10 The example illustrates the simplest case where BSSID1 and BSSID2 are each associated with a single STA 106. This is illustrative and not restrictive. In general, any desired number of STAs can be associated with each non-transmitting BSSID of AP 104. In other words, the system and method described herein can be applied to and generalized to any number of STAs 106 associated with any number of non-transmitting BSSIDs of a given AP 104.

[0112] AP 104 can utilize different cipher suite keys to generate a Common Control Message Integrity Verification (CCMIC) for SICF 1000 (e.g., using...). Figure 6 The process), and verify the integrity of SICF 1000 at STA 106 (e.g., using...). Figure 7 (The process). As an example, AP 104 can use a BSSID-specific Control Frame Integrity Group Temporary Key (CIGTK) (sometimes referred to herein as Control Frame Integrity Group Key, Control Integrity Group Key, Control Integrity Temporary Key, or Control Integrity Temporary Group Key) to generate a Common Control Message Integrity Verification (CCMIC).

[0113] Figure 11 It is possible to use AP 104 and a given STA 106 (e.g., Figure 10a diagram of an exemplary group key table maintained at the AP 104 (e.g., by the transmitter device 616 of the AP 104) for integrity protection and verification of the SICF 1000. As shown, the AP 104 can store and maintain an AP group key table 1100. For example, when the AP 104 forms the transmitter device 616 of the SICF (e.g., when the SICF is prior to transmission of a subsequent DL data frame to the STAs 106), the AP 104 can store the AP group key table 1100 in the cryptographic key storage 600 of the transmitter device 616. Figure 11 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 6 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 6 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 7 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 6 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 6 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 7 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 7 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104.

[0114] As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 11 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 11 As shown, the AP group key table 1100 can include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. Figure 11The remaining n columns of the BSSID-specific group key sets shown in the AP group key table 1100 can each be associated with a different respective non-transmitting BSSID (from a first non-transmitting BSSID (e.g., BSSID1) to an nth non-transmitting BSSID (e.g., BSSIDn)) maintained by the AP 104. Each non-transmitting BSSID can have a corresponding group transient key GTK, integrity group transient key IGTK, and control frame integrity group transient key CIGTK (e.g., BSSID1 can have a corresponding GTK (such as GTK1), IGTK (such as IGTK1), and CIGTK (such as CIGTK1), BSSIDn can have a corresponding GTK (such as GTKn), IGTK (such as IGTKn), and CIGTK (such as CIGTKn), etc.).

[0115] The STA group key table 1102 can also include a BSSID-specific group key for a BSSID associated with the STA 106 having the STA group key table 1102 (e.g., BSSIDi, where i is an integer index from 1 to n identifying the BSSID associated with the STA). The BSSID-specific group key can include a corresponding group transient key GTKi (e.g., GTK1 when the STA 106 having the STA group key table 1102 is associated with BSSID1, GTKn when the STA 106 having the STA group key table 1102 is associated with BSSIDn, etc.), a corresponding integrity group transient key IGTKi (e.g., IGTK1 when the STA 106 having the STA group key table 1102 is associated with BSSID1, IGTKn when the STA 106 having the STA group key table 1102 is associated with BSSIDn, etc.), and a corresponding control frame integrity group transient key CIGTKi (e.g., CIGTK1 when the STA 106 having the STA group key table 1102 is associated with BSSID1, CIGTKn when the STA 106 having the STA group key table 1102 is associated with BSSIDn, etc.).

[0116] The AP 104 can use the BSSID-specific group temporal keys GTK1 through GTKn to generate a hash code appended to the end of DL data frames (e.g., DL PPDU frames) associated with a corresponding BSSID sent to the STAs 106 (e.g., by hashing message data from the DL data frames with the corresponding group temporal key GTK). For example, the AP 104 can use the group temporal key GTK1 to encrypt data frames sent to STAs 106 associated with BSSID1, can use the group temporal key GTKn to encrypt data frames sent to STAs 106 associated with BSSIDn, and so on. The STAs 106 can then use their stored group temporal key GTKi to decrypt message data encrypted at the AP 104 using the same group temporal key GTKi.

[0117] The AP 104 can use the integrity group temporal keys IGTK to integrity protect management frames sent to STAs 106 associated with a corresponding BSSID. This can include using the corresponding integrity group temporal key IGTK to generate a CMIC for a management frame, and inserting the generated CMIC into the management frame sent to the STAs 106. The STAs 106 can then use their stored integrity group temporal key IGTKi to generate a CMIC for their associated BSSIDi, and can compare the generated CMIC to the CMIC included with the management frame to verify that the management frame was sent by the intended AP 104.

[0118] The AP 104 can use the control frame integrity group temporal keys CIGTK to integrity protect control frames (e.g., ICFs) addressed to STAs 106 with a single BSSID. This can include using the corresponding control frame integrity group temporal key CIGTK to generate a CMIC for an ICF, inserting the generated CMIC into the ICF, and sending the ICF to the STAs 106 with the corresponding BSSID. The STAs 106 can then use their stored control frame integrity group temporal key CIGTKi to generate a CMIC for their associated BSSIDi, and can compare the generated CMIC to the CMIC included with the ICF to verify that the ICF frame was sent by the intended AP 104.

[0119] AP group key table 1100 and STA group key table 1102 may also store shared group keys independent of BSSID, such as the Beacon Integrity Group Temporary Key (BIGTK). AP 104 can use the BIGTK to perform integrity protection on beacon frames sent to STA 106. Since AP 104 sends a single beacon frame to all STAs and BSSIDs according to the M-BSSID communication scheme, all STAs 106 can use the same BIGTK to perform integrity checksums and / or decryption on the beacon frames, regardless of the BSSIDs of these STAs.

[0120] exist Figure 11 In the example, AP 104 generates SICF 1000 based on its control frame integrity group temporary key CIGTK0, which it has already sent as BSSID0. Figure 10 For example, AP 104 can use the control frame integrity group temporary key CIGTK0 from AP group key table 1100 as provided to cryptographic function 608. Figure 6 The selected cryptographic key 604, the cryptographic function outputs a Common Control Message Integrity Verification (CCMIC) (e.g., as...). Figure 6 (CCMIC 610). AP 104 can then insert the CCMIC into a field of SICF 1000 and can send SICF 1000 to STA 106 (e.g., as a CMIC 610). Figure 6 (The integrity-protected ICF 612). Since the control frame integrity group temporary key CIGTK0 is dedicated to AP 104 but not to any non-transmitting BSSID, the same control frame integrity group temporary key CIGTK0 is particularly suitable for generating SICF 1000 BSSID broadcasts across AP 104.

[0121] As indicated by arrow 1104, STA 106 may also store a control frame integrity group temporary key CIGTK0 associated with the transmitted BSSID0 of AP 104 (e.g., as a BSSID-specific common group key in its BSSID-specific common group keys in STA group key table 1102). For example, STA 106 may receive the control frame integrity group temporary key CIGTK0 from AP 104 during the handshake operation prior to the transmission of SICF 1000 by AP 104. STA 106 may receive SICF 1000 transmitted by AP 104 and perform integrity verification on SICF 1000 based on the control frame integrity group temporary key CIGTK0. For example, STA 106 may use the control frame integrity group temporary key CIGTK0 from STA group key table 1102 as provided to cryptographic function 608 ( Figure 7) of the selected cryptographic key 604 to the cryptographic function 608 (e.g., as the CMIC 610 of the SICF 1000). The AP 104 can then insert the CCMIC into the field of the SICF 1000, and can transmit the SICF 1000 to the STA 106 (e.g., as the integrity-protected ICF 612 of the SICF 1000). Figure 7 The STA 106 can then compare its generated CCMIC with the CCMIC received in the SICF 1000 to verify that the SICF was transmitted by the intended AP 104.

[0122] In the example of FIG. 10, the control frame integrity group transient key CIGTK0 associated with the transmitted BSSID0 of the AP 104 is used to generate the common control message integrity check CCMIC of the SICF 1000. As another example, as shown in FIG. 11, the AP 104 can use a dedicated (e.g., unique or newly defined) control frame integrity group transient key CCIGTK (sometimes also referred to herein as a common control frame integrity group transient key, a control frame integrity transient key, a control integrity group transient key, or a control integrity group key) for generating the common control message integrity check CCMIC of the SICF 1000. The dedicated control frame integrity group transient key CCIGTK is different from the control frame integrity group transient key CIGTK0 associated with the transmitted BSSID0 of the AP 104, and is different from each of the control frame integrity group transient keys CIGTK1 through CIGTKn associated with each of the non-transmitted BSSIDs (e.g., BSSID1 through BSSIDn) of the AP 104. Figure 11 Figure 12 As shown in FIG. 10, the AP group key table 1100 can store the dedicated control frame integrity group transient key CCIGTK as one of its BSSID-independent common group keys. The AP 104 can generate the SICF 1000 (e.g., the SICF 1000 of FIG. 10) based on the dedicated control frame integrity group transient key CCIGTK stored in the AP group key table 1100. For example, the AP 104 can use the dedicated control frame integrity group transient key CCIGTK as the selected cryptographic key 604 provided to the cryptographic function 608 (e.g., as the CMIC 610 of the SICF 1000). The AP 104 can then insert the CCMIC into the field of the SICF 1000, and can transmit the SICF 1000 to the STA 106 (e.g., as the integrity-protected ICF 612 of the SICF 1000).

[0123] As shown in FIG. 11, the AP group key table 1100 can store the dedicated control frame integrity group transient key CCIGTK as one of its BSSID-independent common group keys. The AP 104 can generate the SICF 1000 (e.g., the SICF 1000 of FIG. 11) based on the dedicated control frame integrity group transient key CCIGTK stored in the AP group key table 1100. For example, the AP 104 can use the dedicated control frame integrity group transient key CCIGTK as the selected cryptographic key 604 provided to the cryptographic function 608 (e.g., as the CMIC 610 of the SICF 1000). The AP 104 can then insert the CCMIC into the field of the SICF 1000, and can transmit the SICF 1000 to the STA 106 (e.g., as the integrity-protected ICF 612 of the SICF 1000). Figure 12 Figure 10 As shown in FIG. 10, the AP group key table 1100 can store the dedicated control frame integrity group transient key CCIGTK as one of its BSSID-independent common group keys. The AP 104 can generate the SICF 1000 (e.g., the SICF 1000 of FIG. 10) based on the dedicated control frame integrity group transient key CCIGTK stored in the AP group key table 1100. For example, the AP 104 can use the dedicated control frame integrity group transient key CCIGTK as the selected cryptographic key 604 provided to the cryptographic function 608 (e.g., as the CMIC 610 of the SICF 1000). The AP 104 can then insert the CCMIC into the field of the SICF 1000, and can transmit the SICF 1000 to the STA 106 (e.g., as the integrity-protected ICF 612 of the SICF 1000). Figure 6 Figure 6 As shown in FIG. 10, the AP group key table 1100 can store the dedicated control frame integrity group transient key CCIGTK as one of its BSSID-independent common group keys. The AP 104 can generate the SICF 1000 (e.g., the SICF 1000 of FIG. 10) based on the dedicated control frame integrity group transient key CCIGTK stored in the AP group key table 1100. For example, the AP 104 can use the dedicated control frame integrity group transient key CCIGTK as the selected cryptographic key 604 provided to the cryptographic function 608 (e.g., as the CMIC 610 of the SICF 1000). The AP 104 can then insert the CCMIC into the field of the SICF 1000, and can transmit the SICF 1000 to the STA 106 (e.g., as the integrity-protected ICF 612 of the SICF 1000). Figure 6

[0124] ​​​​As indicated by arrow 1200, STA 106 may also store a private control frame integrity group temporary key (CCIGTK) as a BSSID-independent common group key within its BSSID-independent common group key. For example, STA 106 may receive the private control frame integrity group temporary key (CCIGTK) from AP 104 during the handshake operation prior to the transmission of SICF 1000 by AP 104. STA 106 may receive SICF 1000 transmitted by AP 104 and may use the private control frame integrity group temporary key (CCIGTK) to perform integrity verification on SICF 1000. For example, STA 106 may use the private control frame integrity group temporary key (CCIGTK) stored in STA group key table 1102 as a key provided to cryptographic function 608. Figure 7 The selected cryptographic key 604, the cryptographic function outputs a Common Control Message Integrity Verification (CCMIC) (e.g., as...). Figure 7 (Candidate CMIC704). STA 106 can then compare its generated Common Control Message Integrity Verification (CCMIC) with the CCMIC received in SICF 1000 to verify that the SICF was sent by the intended AP 104. Using the Private Control Frame Integrity Group Temporary Key (CCIGTK) to generate the CCMIC provides the same level of security robustness to all STAs, regardless of their associated BSSID, but may require additional storage at both the AP and STAs to store the Private Control Frame Integrity Group Temporary Key (CCIGTK).

[0125] As another example, such as Figure 13 As shown, AP 104 can reuse the Beacon Integrity Group Temporary Key (BIGTK) stored on AP Group Key Table 1100 to generate the Common Control Message Integrity Verification (CCMIC) for SICF 1000. This can be used to minimize the storage required at AP 104 and STA 106, because AP and STA do not need to store any additional cryptographic keys for integrity protection and verification of SICF 1000.

[0126] For example, AP 104 can use BIGTK as the cryptographic function provided to 608 ( Figure 6 The selected cryptographic key 604, the cryptographic function outputs a Common Control Message Integrity Verification (CCMIC) (e.g., as...). Figure 6 (CCMIC 610). AP 104 can then insert the CCMIC into a field of SICF 1000 and can send SICF 1000 to STA 106 (e.g., as a CMIC 610). Figure 6The integrity-protected ICF 612). STA 106 can use the BIGTK stored in the STA group key table 1102 as the key provided to the cryptographic function 608 ( Figure 7 The selected cryptographic key 604, the cryptographic function outputs a Common Control Message Integrity Verification (CCMIC) (e.g., as...). Figure 7 The candidate CMIC 704 is then used. STA 106 can then compare its generated Common Control Message Integrity Verification (CCMIC) with the CCMIC received in SICF 1000 to verify that the SICF was sent by the intended AP 104. Using BIGTK to generate the CCMIC provides the same level of security robustness to all STAs, regardless of their associated BSSID, and minimizes the storage required in AP group table 1100 and STA group key table 1102. However, STAs may exhibit vulnerability to insider attacks from STAs that know BIGTK but are connected to a less robust network (BSSID) (such as a guest network of the AP).

[0127] As another example, such as Figure 14 As shown, AP 104 and STA 106 across all BSSIDs of AP 104 can use the dedicated control frame integrity group temporary key CCIGTK to perform both integrity protection and integrity verification on SICF 1000 addressed to all STAs across BSSIDs (e.g., with RA="broadcast"), and integrity protection and verification on control frames (e.g., ICF) sent to STAs with a single BSSID (e.g., with RA=BSSIDi). This allows the control frame integrity group temporary key CCIGTK to be omitted from the BSSID-specific group keys in AP group key table 1100 and STA group key table 1102. Figure 11 to Figure 13 This can be used to minimize the storage consumed by AP group table 1100 and STA group key table 1102, but may provide less robust security compared to maintaining a separate control frame integrity group temporary key CCIGTK for each BSSID of AP 104.

[0128] exist Figure 10 to Figure 14In an example, the SICF 1000 is transmitted to STAs 106 associated with all of the BSSIDs of the AP 104 (e.g., RA = “broadcast”). If desired, the SICF 1000 can alternatively be transmitted to STAs 106 associated with a subset (e.g., some but not all) of the BSSIDs of the AP 104. A set of BSSes within the multiple BSSIDs can have the same common control frame integrity group key, no common control frame integrity group key, or no BIGTK. As one example, the AP 104 can support a set of Opportunistic Wireless Encryption (OWE) BSSes that do not authenticate STAs but have a password key set for the BSS. A common CIGTK can not be shared to STAs in OWE because the common CIGTK can allow attacks with a valid integrity checksum. For the same reason, STAs associated with OWE BSSes in the M-BSSID beacon frame are not shared in the BIGTK. Similarly, if the BSS security mode cannot do beacon protection or control frame integrity protection, then no BIGTK or common CIGTK is provided to the STAs. Under this type of implementation, different security level networks can be included in the same M-BSSID beacon frame.

[0129] Figure 15 An example is illustrated in which the AP 104 is associated with STAs 106 that support a first set of BSSIDs (e.g., from BSSID1 to BSSIDm) that support robust security capabilities and a second set of BSSIDs (e.g., BSSIDn) that form an OWE network. A STA group key table 1102 can be stored on the STAs 106 associated with the BSSIDs i in the first set. There can also be a STA group key table 1502 stored on the STAs 106 of the second set and associated with BSSIDn (the OWE network). In this example, when the SICF 1000 Figure 10 ) is addressed to STAs associated with BSSID1 to BSSIDm, the SICF 1000 can include a CMIC that is generated using a dedicated control frame integrity group temporal key CCIGTK stored in the AP group key table 11000 and verified using a dedicated control frame integrity group temporal key CCIGTK stored in the STA group key table 1102. The STAs 106 associated with OWE (BSSIDn) do not store a dedicated control frame integrity group temporal key CCIGTK and the AP group key table 1100 does not use a BSSID-independent common group key for BSSIDn (as shown by the empty region 1500).

[0130] Figure 16This is a flowchart illustrating the exemplary operations involved in performing wireless communication between STA 106 and AP 104 configured according to the M-BSSID scheme. At operation 1600, STA 106 may register with and associate with the corresponding non-transmitting BSSIDi (e.g., BSSID1, BSSID2, etc.) of AP 104. Some or all of operations 1602 may be performed concurrently with operation 1600 if necessary.

[0131] At operation 1602, AP 104 may perform a handshake operation with STA 106. If necessary, AP 104 may send a set of cryptographic group keys to STA 106 during the handshake operation (at operation 1604). The cryptographic group keys sent to STA 106 may include, for example, a shared group key independent of the BSSID (such as those stored in AP group key table 1100). Figure 11 to Figure 15 The BIGTK in ) and / or stored in AP group key table 1100 ( Figure 12 , Figure 14 and Figure 15 The dedicated control frame integrity group temporary key CCIGTK in ) and the control frame integrity group temporary key CIGTK0 for AP 104's sent BSSID0 ( Figure 11 ), and the group temporary key GTK used for BSSIDi associated with STA 106 Figure 11 to Figure 14 ), and the integrity group temporary key IGTKi associated with STA 106 BSSIDi Figure 11 to Figure 14 ) and / or the temporary key CIGTKi for the control frame integrity group associated with STA 106 and BSSIDi. Figure 11 to Figure 13 STA 106 can store the received cipher group key in its STA group key table 1102. Figure 11 to Figure 15 This is used for subsequent communication.

[0132] At operation 1606, AP 104 uses the corresponding CMIC for each BSSIDi supported by that AP to process the transmitted SICF (e.g., Figure 9 In a specific implementation of integrity protection using SICF 906, AP 104 can generate a corresponding CMIC for each BSSIDi supported by the AP. For example, AP 104 can use the corresponding control frame integrity group temporary key CIGTKi associated with each BSSIDi. Figure 11 to Figure 13 To generate a CMIC for that BSSIDi (e.g., using the control frame integrity group temporary key CIGTK1 as...). Figure 6 The selected cryptographic key 604 is used to generate CMIC1 for BSSID1, using the control frame integrity group temporary key CIGTK2 as... Figure 6The chosen cryptographic key 604 is used to generate CMIC2 for BSSID2, and so on.

[0133] AP 104 uses a common control message integrity check (CCMIC) for all BSSIDi supported by the AP to verify the integrity of transmitted SICF messages (e.g., ...). Figure 10 In the specific implementation of integrity protection using the SICF 1000, AP 104 can, for example, use a dedicated control frame integrity group temporary key CCIGTK ( Figure 12 , Figure 14 and Figure 15 To generate a Common Control Message Integrity Verification (CCMIC) (e.g., using the Control Frame Integrity Group Temporary Key CCIGTK as...). Figure 6 The selected cryptographic key 604 is used to generate a Common Control Message Integrity Verification (CCMIC) at cryptographic function 608, or a dedicated BIGTK for AP 104 can be used. Figure 13 To generate a Common Control Message Integrity Verification (CCMIC) (e.g., using BIGTK as...) Figure 6 The selected cryptographic key 604 is used to generate the Common Control Message Integrity Verification (CCMIC) at cryptographic function 608.

[0134] AP 104 can insert the CMIC generated at operation 1606 into the ICF (e.g., MU-RTS frame, trigger frame, etc.) to be sent to STA 106, thereby generating the corresponding SICF (e.g., Figure 9 SICF 906 or Figure 10 (SICF 1000). AP 104 may also insert information (e.g., one or more bits of one or more header fields of the SICF) into the SICF, which identifies or indicates the selected cipher suite key used by AP 104 to generate the CMIC in the SICF. At operation 1608, AP 104 may send the SICF, including the generated CMIC and information identifying the selected cipher suite key, to STA 106.

[0135] At operation 1610, STA 106 receives the SICF. STA 106 can use the selected cryptographic group key identified by the received SICF to perform integrity verification on the SICF (e.g., using...). Figure 7 (The process illustrated in the document). Performing integrity verification on the SICF is sometimes referred to herein as verification or an attempt to verify the SICF's CMIC. For example, STA 106 can use a dedicated control frame integrity group temporary key CCIGTK or BIGTK as... Figure 7The STA 106 can generate a candidate common control message integrity check CCMIC using the selected cryptographic key 604 and can compare the candidate common control message integrity check CCMIC to the common control message integrity check CCMIC included in the SICF. The STA 106 can generate the candidate common control message integrity check CCMIC using the BSSID-specific control frame integrity group transient key CIGTK or the BSSID-independent control frame integrity group transient key CCIGTK as the selected cryptographic key and can compare the candidate common control message integrity check CCMIC to the common control message integrity check CCMIC included in the SICF. If / when the common control message integrity check CCMIC included in the SICF matches the candidate common control message integrity check CCMIC, the STA 106 can pass the integrity check and processing can continue to operation 1612. As another example, the STA 106 can generate a candidate control message integrity check CMIC' using the control frame integrity group transient key CIGTKi for its associated BSSID i and can compare the candidate control message integrity check CMIC' to the control message integrity check CMIC included in the SICF for its associated BSSID i. If / when the control message integrity check CMIC for the STA 106's BSSID i included in the SICF matches the candidate control message integrity check CMIC', the STA 106 can pass the integrity check and processing can continue to operation 1612.

[0136] At operation 1612 (e.g., in response to passing / verifying the integrity check), the STA 106 can send a response (e.g., an ACK frame, a BA frame, an M-BA frame, etc.) to the AP 104. If desired, the STA 106 can integrity protect the response. The AP 104 and the STA 106 can then communicate data frames (e.g., data frames prior to or triggered by the SICF).

[0137] Figure 17 is a timing diagram illustrating an exemplary handshake procedure between the AP 104 and the STA 106 (e.g., as performed at operation 1602 of Figure 16 Figure 17 ​As shown, the handshake process may include sending a first message (MSG1) from AP 104 to STA 106. STA 106 may then acknowledge or respond to the receipt of MSG1 by sending a second message (MSG2) from STA 106 to AP 104. AP 104 may then acknowledge or respond to the receipt of MSG2 by sending a third message (MSG3) from AP 104 to STA 106. STA 106 may then acknowledge or respond to the receipt of MSG3 by sending a fourth message (MSG4) from STA 106 to AP 104. This example is illustrative and not limiting. The handshake process may include additional message sending, or other handshake procedures may be used.

[0138] If needed, AP 104 can include a set of cryptographic group keys in MSG3 (e.g., in...). Figure 16 (See operation 1604). For example, AP 104 may include a set of cipher group keys in one or more key data elements (KDEs) of MSG3. For example, MSG3 may include a different corresponding KDE for each cipher group key sent to STA 106.

[0139] Figure 18 This is a diagram illustrating an exemplary KDE that can be included in MSG3 for sending the corresponding cryptographic group key from AP 104 to STA 106 during the handshake. For example... Figure 18 As shown, the KDE may include a Key Identifier (KeyID) field 1800, a CIPN field 1802, a Reserved field 1804, a Key Type field 1806, a Link Identifier (LinkID) field 1808, and a Key Data field 1810. The Key Data field 1810 may include the cipher group key being sent to STA 106. The KeyID field 1800 identifies the cipher group key included in the Key Data field 1810. The CIPN field 1802 is the block number associated with CIGTK. The Key Type field 1806 indicates whether the cipher group key included in the Key Data field 1810 is a BSSID-specific cipher group key (e.g., CIGTKi) or a BSSID-independent shared group key shared by all BSSIDs (e.g., CCIGTK or BIGTK). Figure 18 The example is illustrative, and in general, other container structures can be used to notify the STA 106 of one or more cryptographic group keys.

[0140] Figure 19 This illustrates how AP 104 can include information identifying / indicating the selected cryptographic group key in the SICF sent to STA 106 (e.g., in...). Figure 19This is an example diagram of operation 1608. This information can be used to inform STA 106 which cipher suite keys among its stored cipher suite keys will be used to verify the integrity of SICF. This information is sometimes also referred to as the KDE selector or KDE selector information.

[0141] like Figure 19 As shown, the SICF may include a header field 1900. Header field 1900 may include a key or KDE identifier / selector field, such as field 1902. Field 1902 may include a key type field 1904 and a key identifier field 1906. Key type field 1904 and key identifier field 1906 together identify which cipher suite key from the stored cipher suite keys STA 106 will use to verify the integrity of the SICF. Key type field 1904 and key identifier field 1906 may be relatively small (e.g., each may be a single-bit field consisting of only a single bit) to minimize the overhead of the SICF.

[0142] For example, when the selected cipher group key is a BSSID-specific key (e.g., when the selected cipher group key is the control frame integrity group temporary key CIGTKi for the STA's BSSID), the key type field 1904 may have a value "1", and when the selected cipher group key is shared by more than one BSSID of the AP (e.g., when the selected cipher group key is the dedicated control frame integrity group temporary key CCIGTK or BIGTK), the key type field may have a value "0". For example, the key identifier field 1906 can be used to resolve ambiguity within the same key type of the key type field 1904, which identifies the selected cipher group key (e.g., it may have a value "1" when the first cipher group key is used for the dedicated control frame integrity group temporary key CCIGTK, and a value "0" when the second cipher group key is used for the dedicated control frame integrity group temporary key CCIGTK). Other frame structures and reporting mechanisms can be used to notify the STA 106 of the selected cipher group key.

[0143] As used herein, the term “concurrent” means at least partially overlapping in time. In other words, a first event and a second event are referred to herein as being “concurrent” with each other if at least some of the first event occurs at the same time as at least some of the second event (e.g., if at least some of the first event occurs during, at the same time as, or when at least some of the second event occurs). A first event and a second event can be concurrent if they are synchronous (e.g., if the entire duration of the first event overlaps in time with the entire duration of the second event), but a first event and a second event can also be concurrent if they are not synchronous (e.g., if the first event starts before or after the second event starts, if the first event ends before or after the second event ends, or if the first event and the second event partially do not overlap in time). As used herein, the term “while” is synonymous with “concurrent.” The term “when” also implies at least some concurrency (e.g., event A occurs “when” event B occurs means that at least some of event A occurs at the same time as at least some of event B).

[0144] The STAs 106 and the APs 102 / 104 Figure 1 may collect and / or use personal identifiable information. It is well understood that the use of personal identifiable information should follow privacy policies and practices that are generally recognized and accepted as meeting or exceeding industry or governmental requirements for maintaining the privacy of users. In particular, personally identifiable information data should be managed and handled in a manner that allows authorized access, while minimizing the risks that have been identified as sophisticated threats or generally results in unauthorized access or disclosure.

[0145] The methods and operations described above Figure 1 to Figure 19 may be performed using software, firmware, and / or hardware (e.g., dedicated circuitry or hardware) by components of the STA and / or the AP. Software code for performing these operations may be stored on a non-transitory computer-readable storage medium (e.g., a tangible computer-readable storage medium) that is stored on one or more of the components of the STA and / or the AP. This software code can sometimes be referred to as software, data, instructions, program instructions, or code. The non-transitory computer-readable storage medium can include a drive, non-volatile memory such as read only memory (ROM), volatile memory, removable storage, or other type of computer- readable storage medium. The software stored on the non-transitory computer-readable storage medium can be executed by processing circuitry on one or more of the components of the STA and / or the AP. The processing circuitry can include a microprocessor, a central processing unit (CPU), a dedicated integrated circuit, or other processing circuitry.

[0146] For one or more aspects, at least one of the components illustrated in one or more of the preceding figures can be configured to perform one or more operations, techniques, processes, or methods as described in the following embodiment section. For example, circuitry associated with the electronic device, authentication server, one or more processors, etc. described above in connection with one or more of the preceding figures can be configured to operate in accordance with one or more of the embodiments illustrated in the following embodiment section.

[0147] EMBODIMENTS

[0148] In the following sections, additional exemplary aspects are provided.

[0149] Example 1 includes a method of operating a station (STA) to communicate with an access point (AP), the method comprising: receiving a control frame from the AP, the control frame including a control message integrity check (CMIC) shared by a plurality of basic service set identifiers (BSSIDs) of the AP; attempting to verify the CMIC in the control frame using one or more processors; and transmitting an uplink signal to the AP using one or more antennas in response to verifying the CMIC in the control frame.

[0150] Example 2 includes the method of example 1 or some other embodiment or combination of embodiments herein, wherein the control frame includes: a receiver address (RA) field including a broadcast address; and a transmitter address (TA) field identifying a BSSID of the AP that is not associated with any STA served by the AP.

[0151] Example 3 includes the method of any of examples 1 or 2 or some other embodiment or combination of embodiments herein, wherein the control frame includes a multi-user request to send (MU-RTS) frame, and the uplink signal includes a clear to send (CTS) frame with an additional RA field including the BSSID of the AP that is not associated with any STA served by the AP.

[0152] Example 4 includes the method of any of examples 1 to 3 or some other embodiment or combination of embodiments herein, wherein the control frame includes a trigger frame, and the uplink signal includes a trigger-based physical protocol data unit (TB PPDU) frame.

[0153] Example 5 includes the method of any of Examples 1-4 or some other embodiment or combination of embodiments herein, wherein attempting to verify the CMIC comprises attempting to verify the CMIC based on a pairwise group key received from the AP.

[0154] Example 6 includes the method of any of Examples 1-5 or some other embodiment or combination of embodiments herein, wherein the pairwise group key comprises a BSSID-specific control frame integrity group transient key (CIGTK) associated with a dedicated BSSID of the AP, and wherein the dedicated BSSID is not associated with any STA served by the AP.

[0155] Example 7 includes the method of any of Examples 1-6 or some other embodiment or combination of embodiments herein, wherein the pairwise group key comprises a BSSID- independent control frame integrity group transient key (CIGTK) shared by the multiple BSSIDs of the AP.

[0156] Example 8 includes the method of any of Examples 1-7 or some other embodiment or combination of embodiments herein, wherein the pairwise group key comprises a beacon integrity group transient key (BIGTK) used by the AP for integrity protection of beacon frames transmitted by the AP.

[0157] Example 9 includes the method of any of Examples 1-8 or some other embodiment or combination of embodiments herein, further comprising receiving a key data element (KDE) in a third message of a handshake procedure between the STA and the AP, wherein the KDE identifies the pairwise group key.

[0158] Example 10 includes the method of any of Examples 1-9 or some other embodiment or combination of embodiments herein, wherein the control frame comprises one or more header fields that identify the pairwise group key.

[0159] Example 11 includes the method of any of Examples 1-10 or some other embodiment or combination of embodiments herein, wherein the one or more header fields comprise a single-bit key type field and a single-bit key identifier field.

[0160] Example 12 includes an electronic device configured to communicate with an access point (AP), the electronic device comprising: a receiver configured to receive, from the AP, a control frame comprising a first control message integrity check (CMIC) for a first basic service set identifier (BSSID) of the AP and comprising a second CMIC for a second BSSID of the AP, the electronic device being associated with the first BSSID but not with the second BSSID; one or more processors configured to attempt to verify the first CMIC in the control frame; and a transmitter configured to transmit, to the AP, an uplink signal in response to verifying the first CMIC in the control frame.

[0161] Example 13 includes the method of example 12 or some other example or combination of examples herein, the one or more processors configured to attempt to verify the first CMIC in the control frame by: generating a candidate CMIC based on a control frame integrity group temporary key (CIGTK) associated with the first BSSID; and comparing the candidate CMIC to the first CMIC in the control frame.

[0162] Example 14 includes the method of any of examples 12, 13 or some other example or combination of examples herein, wherein the control frame comprises a multi-user request to send (MU-RTS) frame, and the uplink signal comprises a clear to send (CTS) frame having a receiver address field, the receiver address field comprising a third BSSID of the AP, the third BSSID being different from the first BSSID and the second BSSID.

[0163] Example 15 includes the method of any of examples 12-14 or some other example or combination of examples herein, wherein the control frame comprises a trigger frame, and the uplink signal comprises a trigger-based physical protocol data unit (TB PPDU) frame.

[0164] Example 16 includes a method of operating an access point (AP) in accordance with a communication protocol implementing a multiple basic service set identifier (M-BSSID) scheme, the method comprising: generating, using one or more processors, a control message integrity check (CMIC) based on a cryptographic key; and transmitting, using one or more antennas, a control frame to a first station (STA) associated with a first basic service set identifier (BSSID) of the AP and a second STA associated with a second BSSID of the AP different from the first BSSID, wherein a header of the control frame includes the CMIC and a transmitter address (TA), and the TA identifies a third BSSID different from the first BSSID and the second BSSID.

[0165] Example 17 includes the method of example 16 or some other example or combination of examples herein, wherein the cryptographic key comprises a BSSID-specific control frame integrity group transient key (CIGTK) associated with the third BSSID.

[0166] Example 18 includes the method of any of examples 16, 17 or some other example or combination of examples herein, wherein the cryptographic key comprises a BSSID-independent control frame integrity group transient key shared by the first BSSID and the second BSSID.

[0167] Example 19 includes the method of any of examples 16-18 or some other example or combination of examples herein, wherein the cryptographic key comprises a beacon integrity group transient key (BIGTK).

[0168] Example 20 includes the method of any of examples 16-19 or some other example or combination of examples herein, wherein the cryptographic key comprises a BSSID-specific control frame integrity group transient key (CIGTK) associated with the first BSSID, the method further comprising: generating, using the one or more processors, an additional CMIC based on an additional CIGTK associated with the second BSSID, wherein the header of the control frame includes the additional CMIC.

[0169] Example 21 can include an apparatus comprising means for performing one or more elements of a method described in or related to any of examples 1-20, or any other method or process described herein, or a combination thereof.

[0170] Example 22 can include one or more non-transitory computer-readable media comprising instructions to cause an electronic device, upon execution of the instructions by one or more processors of the electronic device, to perform one or more elements of a method described in or related to any of examples 1-20, or any other method or process described herein.

[0171] Example 23 can include an apparatus comprising logic, modules, or circuitry to perform one or more elements of a method described in or related to any of examples 1-20, or any other method or process described herein.

[0172] Example 24 can include a method, technique, or process as described in or related to any of examples 1-20, or any portion or part thereof.

[0173] Example 25 can include an apparatus comprising: one or more processors and one or more non-transitory computer-readable storage media comprising instructions to cause the one or more processors to perform a method, technique, or process as described in or related to any of examples 1-20, or portions thereof, when executed by the one or more processors.

[0174] Example 26 can include a signal as described in or related to any of examples 1-20, or portions thereof.

[0175] Example 27 can include a datagram, information element, packet, frame, segment, PDU, or message, or portions thereof, as described in or related to any of examples 1-20, or combinations thereof, or otherwise described in the present disclosure.

[0176] Example 28 can include a signal encoded with data as described in or related to any of examples 1-20, or portions thereof, or otherwise described in the present disclosure.

[0177] Example 29 can include a signal encoded with a datagram, IE, packet, frame, segment, PDU, or message, or portions thereof, as described in or related to any of examples 1-20, or combinations thereof, or otherwise described in the present disclosure.

[0178] Example 30 can include an electromagnetic signal carrying computer-readable instructions, wherein execution of the computer-readable instructions by one or more processors is to cause the one or more processors to perform the method, techniques, or process as described in or related to any of examples 1-20, or portions thereof.

[0179] Example 31 can include a computer program comprising instructions, wherein execution of the program by a processing element is to cause the processing element to perform the method, techniques, or process as described in or related to any of examples 1-20, or portions thereof.

[0180] Example 32 can include a signal in a wireless network as shown and described herein.

[0181] Example 33 can include a method of communicating in a wireless network as shown and described herein.

[0182] Example 34 can include a system for providing wireless communication as shown and described herein.

[0183] Example 35 can include an apparatus for providing wireless communication as shown and described herein.

[0184] According to one implementation, a method of operating a station (STA) to communicate with an access point (AP) includes receiving a control frame from the AP, the control frame including a control message integrity check (CMIC) shared by a plurality of basic service set identifiers (BSSIDs) of the AP, attempting, by the STA, to verify the CMIC in the control frame, and sending, by the STA, an uplink signal to the AP in response to verifying the CMIC in the control frame.

[0185] According to another implementation, the control frame optionally includes a receiver address (RA) field including a broadcast address, and a transmitter address (TA) field optionally indicating a transmitted BSSID of the AP, the transmitted BSSID being used for multi-BSSID management signaling.

[0186] According to another implementation, the control frame optionally includes a multi-user request to send (MU-RTS) frame, and the uplink signal optionally includes an allow to send (CTS) frame with an additional RA field having the transmitted BSSID of the AP, the transmitted BSSID not being associated with any STA served by the AP.

[0187] According to another embodiment, the control frame optionally comprises a trigger frame, and the uplink signal optionally comprises a trigger-based physical protocol data unit (TB PPDU) frame.

[0188] According to another embodiment, attempting to verify the CMIC optionally comprises attempting to verify the CMIC based on a group transient key received from the AP.

[0189] According to another embodiment, the group transient key optionally comprises a BSSID-specific control frame integrity group transient key (CIGTK) associated with a dedicated BSSID of the AP.

[0190] According to another embodiment, the group transient key optionally comprises a BSSID-independent control frame integrity group transient key (CIGTK) shared by at least two BSSIDs of the AP.

[0191] According to another embodiment, the group transient key optionally comprises a beacon integrity group transient key (BIGTK) used for integrity protection of a beacon frame transmitted by the AP.

[0192] According to another embodiment, the method optionally comprises receiving a key data element (KDE) in a third message of a handshake procedure between the STA and the AP, wherein the KDE indicates the group transient key.

[0193] According to another embodiment, the control frame optionally comprises one or more header fields indicating the group transient key.

[0194] According to another embodiment, the one or more header fields optionally comprise a single-bit key type field and a single-bit key identifier field.

[0195] According to one embodiment, an electronic device configured to communicate with an access point (AP) is provided, the electronic device comprising: a receiver configured to receive a control frame from the AP, the control frame comprising a first control message integrity check (CMIC) for a first basic service set identifier (BSSID) of the AP and comprising a second CMIC for a second BSSID of the AP, the electronic device being associated with the first BSSID but not with the second BSSID; one or more processors configured to attempt to verify the first CMIC in the control frame; and a transmitter configured to transmit an uplink signal to the AP when the first CMIC in the control frame has been successfully verified.

[0196] According to another implementation, the one or more processors are optionally configured to attempt to verify the first CMIC in the control frame by: generating a candidate CMIC based on a control frame integrity group transient key (CIGTK) associated with the first BSSID; and comparing the candidate CMIC to the first CMIC in the control frame.

[0197] According to another implementation, the control frame optionally comprises a multi-user request to send (MU-RTS) frame, and the uplink signal comprises a clear to send (CTS) frame having a receiver address field, the receiver address field comprising a third BSSID of the AP, the third BSSID being different from the first BSSID and the second BSSID.

[0198] According to another implementation, the control frame optionally comprises a trigger frame, and the uplink signal optionally comprises a trigger-based physical protocol data unit (TB PPDU) frame.

[0199] According to one implementation, a method of operating an access point (AP) in accordance with a communication protocol that implements a multiple basic service set identifier (M-BSSID) scheme is provided, the method comprising: generating, by the AP, a control message integrity check (CMIC) based on a cryptographic key; and transmitting, by the AP, a control frame to a first station (STA) associated with a first basic service set identifier (BSSID) of the AP and a second STA associated with a second BSSID of the AP that is different from the first BSSID, wherein a header of the control frame comprises the CMIC and a transmitter address (TA), and the TA identifies a third BSSID that is different from the first BSSID and the second BSSID.

[0200] According to another implementation, the cryptographic key optionally comprises a BSSID-specific control frame integrity group transient key (CIGTK) associated with the third BSSID.

[0201] According to another implementation, the cryptographic key optionally comprises a BSSID-independent control frame integrity group transient key that is shared by the first BSSID and the second BSSID.

[0202] According to another implementation, the cryptographic key optionally comprises a beacon integrity group transient key (BIGTK).

[0203] According to another implementation, the cryptographic key optionally includes a BSSID-specific control frame integrity group transient key (CIGTK) associated with the first BSSID, the method optionally includes generating, using the one or more processors, an additional CMIC based on an additional CIGTK associated with the second BSSID, wherein the header of the control frame includes the additional CMIC.

[0204] Unless otherwise explicitly stated, any of the above embodiments can be combined with any other embodiment (or combination of embodiments). The foregoing description of one or more implementations provides functionality and / or technical features to enable one to get a working decision. It is appreciated that not all of the features and / or benefits described above need to be implemented in implementations of the various aspects.

Claims

1. A method of operating a station (STA) to communicate with an access point (AP), the method comprising: receiving a control frame from the AP, the control frame including a control message integrity check (CMIC) shared by a plurality of basic service set identifiers (BSSIDs) of the AP; attempting, by the STA, to verify the CMIC in the control frame; and transmitting, by the STA, an uplink signal to the AP in response to verifying the CMIC in the control frame.

2. The method of claim 1, wherein the control frame includes: a receiver address (RA) field including a broadcast address; and a transmitter address (TA) field indicating a transmitted BSSID of the AP, the transmitted BSSID used for multi-BSSID management signaling.

3. The method of claim 2, wherein the control frame includes a multi-user request to send (MU-RTS) frame and the uplink signal includes a clear to send (CTS) frame with an additional RA field having the transmitted BSSID of the AP, the transmitted BSSID not associated with any STA served by the AP.

4. The method of claim 2, wherein the control frame includes a trigger frame and the uplink signal includes a trigger-based physical protocol data unit (TB PPDU) frame. attempting to verify the CMIC based on a password group key received from the AP.

6. The method of claim 5, wherein the password group key includes a BSSID-specific control frame integrity group transient key (CIGTK) associated with a dedicated BSSID of the AP.

5. The method of claim 1, wherein attempting to authenticate the CMIC comprises:

7. The method of claim 5, wherein the password group key includes a BSSID- independent control frame integrity group transient key (CIGTK) shared by at least two BSSIDs of the AP.

8. The method of claim 5, wherein the password group key includes a beacon integrity group transient key (BIGTK) used to integrity protect a beacon frame transmitted by the AP.

9. The method of claim 5, further comprising: receiving a key data element (KDE) in a third message of a handshake procedure between the STA and the AP, wherein the KDE indicates the password group key.

10. The method of claim 5, wherein the control frame includes one or more header fields indicating the password group key.

11. The method of claim 10, wherein the one or more header fields include a single-bit key type field and a single-bit key identifier field.

12. An electronic device configured to communicate with an access point (AP), the electronic device comprising: ​ ​ a receiver configured to receive, from the AP, a control frame including a first control message integrity check (CMIC) for a first basic service set identifier (BSSID) of the AP and including a second CMIC for a second BSSID of the AP, the electronic device being associated with the first BSSID but not with the second BSSID; one or more processors configured to attempt to verify the first CMIC in the control frame; and a transmitter configured to transmit, to the AP, an uplink signal when the first CMIC in the control frame has been successfully verified.

13. The electronic device of claim 12, the one or more processors configured to attempt to verify the first CMIC in the control frame by: generating a candidate CMIC based on a control frame integrity group transient key (CIGTK) associated with the first BSSID; and comparing the candidate CMIC to the first CMIC in the control frame.

14. The electronic device of claim 12, wherein the control frame comprises a multi-user request to send (MU-RTS) frame and the uplink signal comprises a clear to send (CTS) frame having a receiver address field, the receiver address field including a third BSSID of the AP, the third BSSID being different from the first BSSID and the second BSSID.

15. The electronic device of claim 12, wherein the control frame comprises a trigger frame and the uplink signal comprises a trigger-based physical protocol data unit (TB PPDU) frame.

16. A method of operating an access point (AP) in accordance with a communication protocol that implements a multiple basic service set identifier (M-BSSID) scheme, the method comprising: generating, by the AP, a control message integrity check (CMIC) based on a cryptographic key; and transmitting, by the AP, a control frame to a first station (STA) associated with a first basic service set identifier (BSSID) of the AP and to a second STA associated with a second BSSID of the AP that is different from the first BSSID, wherein a header of the control frame includes the CMIC and a transmitter address (TA), and the TA indicates a third BSSID that is different from the first BSSID and the second BSSID.

17. The method of claim 16, wherein the cryptographic key comprises a BSSID-specific control frame integrity group transient key (CIGTK) associated with the third BSSID.

18. The method of claim 16, wherein the cryptographic key comprises a BSSID-independent control frame integrity group transient key shared by the first BSSID and the second BSSID.

19. The method of claim 16, wherein the cryptographic key comprises a beacon integrity group transient key (BIGTK). ​ ​ 20. The method of claim 16, wherein the cryptographic key comprises a BSSID- specific control frame integrity group transient key (CIGTK) associated with the first BSSID, the method further comprising: generating, using the one or more processors, an additional CMIC based on an additional CIGTK associated with the second BSSID, wherein the header of the control frame comprises the additional CMIC.