Frame protection in wireless communications
By introducing a time-based packet number and MIC field XOR operation into the wireless communication frame, the problem of unprotected frames is solved, the security and reliability of frames are enhanced, blocking, recording and replay attacks are prevented, and the security and throughput of communication are improved.
Patent Information
- Application Number
- CN202480056499.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-09-12
- Filing Date
- 2024-08-23
- Publication Date
- 2026-03-31
AI Technical Summary
In wireless communication, certain fields of data frames (such as the duration/ID field or HT control field) are not protected and are easily exploited by malicious devices, causing the receiving device to take unexpected actions. Furthermore, existing blocking, logging, and replay attacks are difficult to prevent.
By introducing a time-based portion and a counter value group number into the frame, and combining it with an XOR operation of the Message Integrity Check (MIC) field, the receiving device performs replay checks and frame integrity verification to prevent blocking, logging, and replay attacks.
It enhances the security and reliability of frames, prevents blocking, logging, and replay attacks, and improves the security and throughput of communication.
Smart Images

Figure CN121773647A_ABST
Abstract
Description
[0001] Cross-references
[0002] This patent application claims the benefit of U.S. Patent Application No. 18 / 465,962, filed September 12, 2023, entitled “FRAME PROTECTIONIN WIRELESS COMMUNICATIONS,” which has been assigned to the assignee of this patent application. Technical Field
[0003] This disclosure relates to wireless communications, and more specifically to frame protection in wireless communications. Background Technology
[0004] A Wireless Local Area Network (WLAN) can be formed by one or more wireless access points (APs) that provide a shared wireless communication medium for use by multiple client devices (also known as wireless stations (STAs)). The basic building block of a WLAN conforming to the IEEE 802.11 standard family is the Basic Service Set (BSS) managed by the AP. Each BSS is identified by a Basic Service Set Identifier (BSSID) advertised by the AP. The AP periodically broadcasts beacon frames to enable any STA within the AP's wireless range to establish or maintain a communication link with the WLAN.
[0005] In some WLANs, data frames transmitted over the air between STAs or APs wirelessly communicating with another STA or AP include information such as source address, destination address, duration / ID field, or high throughput (HT) control field in the Media Access Control (MAC) header of the data frame. Some fields in the MAC header, such as the duration / ID field or the HT control field, may be unprotected because they may not be encrypted or undergo integrity checks. Malicious devices can exploit such unprotected fields, which could cause the receiving device to take potentially unintended actions. Summary of the Invention
[0006] The systems, methods, and apparatus disclosed herein each have some innovative aspects, and no single aspect is solely responsible for the desired properties disclosed herein.
[0007] A first wireless communication device for wireless communication is described. The first wireless communication device may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the first wireless communication device to: generate a packet number for a frame to be transmitted to a second wireless communication device, the packet number comprising a first subset of bits corresponding to a portion of a timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and transmit the frame to the second wireless communication device, the frame including the portion containing the packet number.
[0008] A second wireless communication device for wireless communication is described. The second wireless communication device may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the second wireless communication device to: receive a frame including a packet number comprising a first subset of bits corresponding to a first timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and process the frame at least in part based on whether a time value indicated by the first subset of bits corresponds to a local time maintained at the second wireless communication device.
[0009] Another first wireless communication device for wireless communication is described. The first wireless communication device may include a processing system comprising processor circuitry and memory circuitry for storing code. The processing system may be configured to cause the first wireless communication device to: generate a Message Integrity Check (MIC) field for a frame to be transmitted to a second wireless communication device; perform an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of a timing synchronization function value associated with the frame; and transmit the frame, including the XORed MIC field, to the second wireless communication device.
[0010] A second wireless communication device for wireless communication is described. This second wireless communication device may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the second wireless communication device to: receive a frame including a Message Integrity Check (MIC) field; perform an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of the timing synchronization function value associated with the reception time of the frame; and process the XORed MIC field to determine the frame integrity of the frame.
[0011] A method for wireless communication by a first wireless communication device is described. The method may include: generating a packet number for a frame to be transmitted to a second wireless communication device, the packet number including a first subset of bits corresponding to a portion of a timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and transmitting the frame to the second wireless communication device, the frame including the portion containing the packet number.
[0012] In some examples of the method and the first wireless communication device, generating a packet number may include operations or instructions for performing the following actions: generating a portion of the timing synchronization function value as a truncated version of the timing synchronization function value; and appending a counter value to that portion of the timing synchronization function value.
[0013] A method for wireless communication by a second wireless communication device is described. The method may include: receiving a frame including a packet number comprising a first subset of bits corresponding to a first timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and processing the frame at least in part based on whether a time value indicated by the first subset of bits corresponds to a local time maintained at the second wireless communication device.
[0014] Some examples of the methods and second wireless communication devices described herein may also include operations or instructions for performing the following actions: generating a second timing synchronization function value as a truncated version of the time value of the timing synchronization function at the second wireless communication device, wherein the local time maintained at the second wireless communication device corresponds to the second timing synchronization function value, and wherein the frame may be processed based on matching the second timing synchronization function value with the first timing synchronization function value.
[0015] Another method for wireless communication by a first wireless communication device is described. The method may include: generating a Message Integrity Check (MIC) field for a frame to be transmitted to a second wireless communication device; performing an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of a timing synchronization function value associated with the frame; and transmitting the frame, including the XORed MIC field, to the second wireless communication device.
[0016] In some examples of the method and the first wireless communication device, this portion of the timing synchronization function value may be a truncated version of the timing synchronization function value at the first wireless communication device.
[0017] Another method for wireless communication by a second wireless communication device is described. The method may include: receiving a frame including a Message Integrity Check (MIC) field; performing an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of the timing synchronization function value associated with the reception time of the frame; and processing the XORed MIC field to determine the frame integrity of the frame.
[0018] In some examples of the method and the second wireless communication device, this portion of the timing synchronization function value may be a truncated version of the timing synchronization function value at the second wireless communication device.
[0019] Details of one or more specific embodiments of the subject matter described in this disclosure are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages will become apparent from the description, drawings, and claims. Note that the relative dimensions in the following drawings may not be drawn to scale. Attached Figure Description
[0020] Figure 1 A schematic diagram of an example wireless communication network is shown.
[0021] Figure 2 An example Protocol Data Unit (PDU) is shown that can be used for communication between a wireless access point (AP) and one or more wireless stations (STA).
[0022] Figure 3 An example physical layer (PHY) protocol data unit (PPDU) capable of being used for communication between a wireless AP and one or more wireless STAs is shown.
[0023] Figure 4 A hierarchical format of an example PPDU that can be used for communication between a wireless AP and one or more wireless STAs is shown.
[0024] Figure 5 An example of time-based packet numbering that supports frame protection in wireless communication is shown.
[0025] Figure 6 An example of a signaling diagram supporting frame protection in wireless communication is shown.
[0026] Figure 7 An example of a process flow that supports frame protection in wireless communication is shown.
[0027] Figure 8 An example of a process flow that supports frame protection in wireless communication is shown.
[0028] Figure 9A block diagram of an example wireless communication device that supports frame protection in wireless communication is shown.
[0029] Figure 10 A block diagram of an example wireless communication device that supports frame protection in wireless communication is shown.
[0030] Figure 11 A flowchart illustrating an example process that can be performed by or at a first wireless communication device that supports frame protection in wireless communication is shown.
[0031] Figure 12 A flowchart illustrating an example process that can be performed by or at a second wireless communication device that supports frame protection in wireless communication is shown.
[0032] Figure 13 A flowchart illustrating an example process that can be performed by or at a first wireless communication device that supports frame protection in wireless communication is shown.
[0033] Figure 14 A flowchart illustrating an example process that can be performed by or at a second wireless communication device that supports frame protection in wireless communication is shown.
[0034] Similar reference numerals and names in the various figures indicate similar elements. Detailed Implementation
[0035] The following description refers to certain specific examples in order to illustrate the innovative aspects of this disclosure. However, those skilled in the art will readily recognize that the teachings herein can be applied in a variety of different ways. Some or all of the examples described can be applied in Bluetooth systems that meet the requirements of the Institute of Electrical and Electronics Engineers (IEEE) 802.11, IEEE 802.15, or Bluetooth as defined by the Bluetooth Special Interest Group (SIG). ®This can be implemented in any device, system, or network that transmits and receives radio frequency (RF) signals according to one or more of the following standards, or those published by the 3rd Generation Partnership Project (3GPP): Long Term Evolution (LTE), 3G, 4G, or 5G (New Radio (NR)). The described examples can be implemented in any device, system, or network capable of transmitting and receiving RF signals according to one or more of the following technologies or techniques: Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Orthogonal Frequency Division Multiplexing (OFDM), Frequency Division Multiple Access (FDMA), Orthogonal FDMA (OFDMA), Single Carrier FDMA (SC-FDMA), Space Division Multiple Access (SDMA), Rate Split Multiple Access (RSMA), Multi-User Shared Access (MUSA), Single-User (SU) Multiple-Input Multiple-Output (MIMO), and Multi-User (MU) MIMO (MU-MIMO). The described examples can also be implemented using other wireless communication protocols or RF signals suitable for use in one or more of the following networks: Wireless Personal Area Network (WPAN), Wireless Local Area Network (WLAN), Wireless Wide Area Network (WWAN), Wireless Metropolitan Area Network (WMAN), or Internet of Things (IoT).
[0036] A WLAN may include one or more access points (APs) and non-AP stations (STAs) that communicate with each other via specific communication links, such as channels within a given frequency band. In some WLANs that support multi-link operation (MLO), a non-AP STA may be attached to a non-AP multi-link device (MLD) that operates on multiple communication links. Similarly, an AP may be attached to (e.g., controlled or managed by) one or more AP MLDs that operate on more than one communication link. As used herein, the term "STA" can refer to any type of wireless STA, such as a non-AP STA, a non-MLD STA, a non-MLD non-AP STA, etc. Similarly, the term "AP" can refer to any type of wireless AP, such as an AP MLD or a non-MLD AP, etc.
[0037] Security in WLAN communications can be provided through mechanisms such as encryption, integrity checks, or both, that protect certain control frames and fields within the Media Access Control (MAC) header. Even with such security mechanisms, attack scenarios can still exist in some implementations where a malicious device can block the reception of a frame while simultaneously recording it. Later, the attacker can replay the unmodified frame, prompting the receiver to take potentially unexpected actions (e.g., the receiver might perceive the transmitter as operating in a different state than it actually is, since the original frame was not successfully received). This type of attack is known as a blocking, recording, and replay attack. In some implementations, protection against blocking, recording, and replay attacks can use sequentially increasing packet numbers (PNs) provided with the frame, where the receiver discards the frame if the received PN is less than or equal to a previously received PN. However, in a blocking, recording, and replay attack, because the receiving device did not receive the original frame, it did not record the PN carried in that frame, potentially allowing an attacker to successfully bypass replay detection logic.
[0038] Various aspects of this disclosure relate generally to frame protection in wireless communications. Some aspects more specifically relate to preventing jamming, recording, and replay attacks by using a PN with a timing component. In some embodiments, a first wireless device (such as an AP or STA) may transmit the PN with each frame having a time-based portion and a counter value. In some embodiments, the time-based portion may include a truncated timing synchronization function (TSF) value indicating the time the frame was transmitted from the first wireless device, and may thus provide a reduced time granularity provided by the TSF. In some embodiments, the counter value may increment for each frame transmitted with the same truncated TSF value. A second wireless device (such as an AP or STA) may receive the frame and perform a replay check by comparing the received truncated TSF value with a currently local truncated TSF value. If the received TSF value is lower than the truncated local TSF value, the frame may be discarded. If the received value is the same as a TSF value received in a previous frame, the received counter value is compared with the previous counter value, and if the received counter value is equal to or less than the previously received counter, the frame is discarded. Otherwise, the packet is further processed. When operating in a multi-link configuration, a separate TSF can be maintained for each link at the wireless device.
[0039] Additionally or alternatively, some implementations provide protection for frames that may not have an unencrypted PN field (e.g., some management or data frames may encrypt the PN field). In some implementations, such frame protection can be provided using a Message Integrity Check (MIC) sent with the frame. The MIC can be XORed with the truncated TSF value of the sending device. The receiving device can XOR the received MIC with its local truncated TSF value to obtain the XORed MIC. The receiving device can decrypt the received frame and derive the MIC value, and compare the XORed MIC with the derived MIC value. If a mismatch exists, the frame can be discarded; otherwise, further processing can be performed.
[0040] Specific aspects of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages. In some specific implementations, using a time component as part of the PN or as the XOR value in an XOR operation allows the receiving device to discard frames that have a delay in reception at the receiving device, thereby helping to prevent blocking, logging, and replay attacks and enhancing security and reliability in communications. Furthermore, the reduced granularity of the time values used when comparing received time values with local time values allows for some clock drift between the transmitter and receiver. Additionally, a counter value provided along with the time values allows multiple frames to be transmitted with the same reduced granularity of time values, thereby improving throughput and network efficiency.
[0041] Figure 1 A schematic diagram of an example wireless communication network 100 is shown. Depending on some aspects, the wireless communication network 100 may be an example of a wireless local area network (WLAN) (such as a Wi-Fi network). For example, the wireless communication network 100 may be a network implementing at least one of the IEEE 802.11 wireless communication protocol standard families (such as those defined by the IEEE 802.11-2020 specification or its revisions, including but not limited to 802.11ay, 802.11ax, 802.11az, 802.11ba, 802.11bd, 802.11be, 802.11bf, and 802.11bn). In some other examples, the wireless communication network 100 may be an example of a cellular radio access network (RAN), such as a 5G RAN or 6G RAN implementing one or more cellular protocols (such as those specified in one or more 3GPP standards). In some other examples, the wireless communication network 100 may include a WLAN that operates in an interoperable or converged manner with one or more cellular RANs to provide greater or enhanced network coverage to wireless communication devices within the wireless communication network 100, or to enable these devices to connect to the core of the cellular network, such as to access network management capabilities and functionality provided by the cellular network core.
[0042] Wireless communication network 100 may include numerous wireless communication devices, such as at least one wireless access point (AP) 102 and any number of wireless stations (STA) 104. Although Figure 1 Only one AP 102 is shown, but the wireless communication network 100 may include multiple APs 102. AP 102 may be or represent various different types of network entities, including but not limited to home networking APs, enterprise APs, single-band APs, dual-band synchronous (DBS) APs, tri-band synchronous (TBS) APs, standalone APs, non-standalone APs, software-enabled APs (software APs), and multi-link APs (also known as AP multi-link devices (MLDs)), as well as cellular (such as 3GPP, 4G LTE, 5G, or 6G) base stations or other cellular network nodes (such as Node B, evolved Node B (eNB), gNB, Transmit Receive Point (TRP)) or another type of equipment or apparatus included in the radio access network (RAN), including open RAN (O-RAN) network entities such as central units (CUs), distributed units (DUs), or radio units (RUs).
[0043] Each STA 104 may also be referred to as a mobile station (MS), mobile device, mobile phone, wireless phone, access terminal (AT), user equipment (UE), subscriber station (SS), or subscriber unit, etc. STA 104 can represent a variety of devices such as mobile phones, other handheld or wearable communication devices, netbooks, laptops, tablets, laptops, Chromebooks, augmented reality (AR), virtual reality (VR), mixed reality (MR), or extended reality (XR) wireless headsets or other peripherals, wireless earbuds, other wearable devices, display devices (e.g., TVs, computer monitors, or video game consoles), video game controllers, navigation systems, music or other audio or stereo devices, remote control devices, printers, kitchen appliances (including smart refrigerators) or other home appliances, remote keys (e.g., for passive keyless entry and start (PKES) systems), Internet of Things (IoT) devices, and vehicles, etc.
[0044] A single AP 102 and its associated set of STA 104s may be referred to as a Basic Service Set (BSS), which is managed by the respective AP 102. Figure 1Additionally, an example coverage area 108 of AP 102 is shown, which may represent the Basic Service Area (BSA) of wireless communication network 100. The BSA can be identified by STA 104 and other devices via a Service Set Identifier (SSID) and a Basic Service Set Identifier (BSSID), which may be the Media Access Control (MAC) address of AP 102. AP 102 may periodically broadcast beacon frames (“beacons”) including the BSSID to enable any STA 104 within the wireless range of AP 102 to “associate” or reassociate with AP 102 to establish or maintain a corresponding communication link 106 (also referred to hereinafter as a “Wi-Fi link”) with AP 102. For example, the beacon may include an identifier or indication of the primary channel used by the corresponding AP 102, and a Timing Synchronization Function (TSF) for establishing or maintaining timing synchronization with AP 102. AP 102 can provide access to external networks to each STA 104 in the wireless communication network 100 via the corresponding communication link 106.
[0045] To establish a communication link 106 with AP 102, each STA 104 is configured to perform passive or active scanning operations (“scanning”) on frequency channels in one or more frequency bands (e.g., 2.4 GHz, 5 GHz, 6 GHz, 45 GHz, or 60 GHz bands). To perform a passive scan, STA 104 listens for beacons transmitted by the corresponding AP 102 at periodic time intervals (referred to as the Target Beacon Transmission Time (TBTT)). To perform an active scan, STA 104 generates probe requests and transmits these requests sequentially on each channel to be scanned, and listens for probe responses from AP 102. Each STA 104 can identify, determine, detect, or select an AP 102 to associate with based on the scanning information obtained through passive or active scanning, and performs authentication and association operations to establish a communication link 106 with the selected AP 102. The selected AP 102 assigns an association identifier (AID) to STA 104 at the end of the association operation, and AP 102 uses the association identifier (AID) to track STA 104.
[0046] As wireless networks become increasingly prevalent, STA 104 may have the opportunity to choose from one of many BSSs within its range or from multiple APs 102 that together form an Extended Service Set (ESS) (comprising multiple connected BSSs). For example, wireless communication network 100 may be connected to a wired or wireless distribution system capable of connecting multiple APs 102 in such an ESS. Therefore, STA 104 may be covered by more than one AP 102 and may be associated with different APs 102 at different times for different transmissions. Additionally, after associating with an AP 102, STA 104 may periodically scan its surroundings to find a more suitable AP 102 to associate with. For example, STA 104 moving relative to its associated AP 102 may perform a “roaming” scan to find another AP 102 with more desirable network characteristics, such as a larger Received Signal Strength Indicator (RSSI) or reduced traffic load.
[0047] In some cases, STA 104 can form a network without AP 102 or other equipment besides STA 104 itself. An example of such a network is an ad hoc network (or wireless ad hoc network). Ad hoc networks may also be referred to as mesh networks or peer-to-peer (P2P) networks. In some cases, ad hoc networks can be implemented within a larger network, such as wireless communication network 100. In such examples, while STA 104 may be able to communicate with each other via communication link 106 through AP 102, STA 104 may also communicate directly with each other via direct wireless communication link 110. Additionally, two STA 104 may communicate via direct communication link 110, regardless of whether the two STA 104 are associated with and served by the same AP 102. In such ad hoc systems, one or more STAs among STA 104 may assume the role played by AP 102 in the BSS. Such STA 104 may be referred to as the group owner (GO) and may coordinate transmissions within the ad hoc network. Examples of direct wireless communication links 110 include Wi-Fi direct connections, connections established by using Wi-Fi Tunneling Direct Link Establishment (TDLS) links, and other P2P group connections.
[0048] In some networks, AP 102 or STA 104, or both, can support applications associated with high throughput or low latency requirements, or provide lossless audio to one or more other devices. For example, AP 102 or STA 104 can support applications and use cases associated with ultra-low latency (ULL), such as ULL gaming, or streaming lossless audio and video to one or more personal audio devices (such as peripherals) or AR / VR / MR / XR headsets. In scenarios where a user uses two or more peripherals, AP 102 or STA 104 can support extended personal audio networks that enable communication with these two or more peripherals. Additionally, AP 102 and STA 104 can support additional ULL applications with ULL and high throughput requirements, such as cloud-based applications (such as VR cloud gaming).
[0049] As indicated above, in some implementations, AP 102 and STA 104 may operate and communicate according to one or more of the IEEE 802.11 wireless communication protocol family of standards (via the corresponding communication link 106). These standards define WLAN radio and baseband protocols for the physical (PHY) layer and MAC layer. AP 102 and STA 104 transmit and receive wireless communications to and from each other in the form of PHY Protocol Data Units (PPDUs) (also referred to below as "Wi-Fi communication" or "wireless packets").
[0050] Each PPDU is a composite structure comprising a PHY preamble and a payload in the form of a PHY Service Data Unit (PSDU). The information provided in the preamble can be used by the receiving device to decode subsequent data in the PSDU. In instances where the PPDU is transmitted on a bound channel or a wideband channel, the preamble field may be copied and transmitted in each of the multiple component channels. The PHY preamble may include both a legacy portion (or "legacy preamble") and a non-legacy portion (or "non-legacy preamble"). The legacy preamble can be used for other purposes such as packet detection, automatic gain control, and channel estimation. The legacy preamble is also typically used to maintain compatibility with legacy equipment. The format, decoding, and information provided in the non-legacy portion of the preamble are associated with the specific IEEE 802.11 wireless communication protocol to be used to transmit the payload.
[0051] AP 102 and STA 104 in the WLAN wireless communication network 100 can transmit PPDUs on unlicensed spectrum, which may be a portion of the spectrum including frequency bands traditionally used by Wi-Fi technologies, such as the 2.4 GHz band, 5 GHz band, 6 GHz band, 45 GHz band, and 60 GHz band. Some examples of AP 102 and STA 104 described herein can also communicate in other frequency bands that can support both licensed and unlicensed communication. For example, AP 102 or STA 104, or both, may also be able to communicate on licensed operating frequency bands, where multiple operators may have corresponding licenses to operate in the same or overlapping frequency ranges. Such licensed operating frequency bands may be specified or associated with frequency ranges mapped to or associated with FR1 (410MHz to 7.125GHz), FR2 (24.25GHz to 52.6GHz), FR3 (7.125GHz to 24.25GHz), FR4a or FR4-1 (52.6GHz to 71GHz), FR4 (52.6GHz to 114.25GHz), and FR5 (114.25GHz to 300GHz).
[0052] Each of these frequency bands may include multiple sub-bands and frequency channels (also referred to as sub-channels). For example, PPDUs conforming to revisions of the IEEE 802.11n, 802.11ac, 802.11ax, 802.11be, and 802.11bn standards may be transmitted on one or more of the 2.4 GHz, 5 GHz, or 6 GHz frequency bands, each of which is divided into multiple 20 MHz channels. Therefore, these PPDUs are transmitted on physical channels with a minimum bandwidth of 20 MHz, but larger channels can be formed through channel bonding. For example, PPDUs may be transmitted on physical channels with bandwidths of 40 MHz, 80 MHz, 160 MHz, 240 MHz, 320 MHz, 480 MHz, or 640 MHz by bonding multiple 20 MHz channels together.
[0053] In some implementations, a first wireless device (such as STA 104 or AP 102) may transmit frames via one or more communication links 106, and each frame's PN may have a time-based portion and a counter value. In some implementations, the time-based portion may include a truncated TSF value indicating the time the frame was transmitted from the first wireless device. In some implementations, the counter value may be incremented for each frame transmitted with the same truncated TSF value and appended to the truncated TSF value. A second wireless device (such as STA 104 or AP 102) may receive the frame and perform a replay check by comparing the truncated TSF with the current local time based on the truncated local TSF. The second wireless device may process or discard the frame based on the replay check. Additionally or alternatively, the first wireless device may use a MIC for frame protection, wherein the MIC may be XORed with the first wireless device's truncated TSF value. The second wireless device may XOR the received MIC with a local truncated TSF value to obtain an XORed MIC. The receiving device can decrypt the received frame and derive the MIC value, and compare the XORed MIC with the derived MIC value. If a mismatch exists, the frame is discarded; otherwise, further processing can be performed.
[0054] Figure 2 An example protocol data unit (PDU) 200 capable of wireless communication between a wireless access point (AP) and one or more wireless STAs is shown. For example, the AP and STA can be reference... Figure 1 Examples of AP 102 and STA 104 are described. PDU 200 can be configured as a PPDU. As shown, PDU 200 includes a PHY preamble 202 and a PHY payload 204. For example, preamble 202 may include a legacy portion, which itself includes a legacy short training field (L-STF) 206 consisting of two symbols, a legacy long training field (L-LTF) 208 consisting of two symbols, and a legacy signal field (L-SIG) 210 consisting of two symbols. The legacy portion of preamble 202 may be configured according to the IEEE 802.11a wireless communication protocol standard. Preamble 202 may also include a non-legacy portion, which includes one or more non-legacy fields 212, for example, conforming to one or more of the IEEE 802.11 wireless communication protocol standard family.
[0055] L-STF 206 generally enables receiving devices (such as AP 102 or STA 104) to perform coarse timing and frequency tracking, as well as automatic gain control (AGC). L-LTF 208 generally enables receiving devices to perform fine timing and frequency tracking, and also to perform initial estimation of the radio channel. L-SIG 210 generally enables receiving devices to determine (e.g., acquire, select, identify, detect, determine, calculate, or compute) the duration of the PDU and use the determined duration to avoid transmission over the PDU. The legacy portion of the preamble can be modulated according to a binary phase shift keying (BPSK) modulation scheme, including L-STF 206, L-LTF 208, and L-SIG 210. The payload 204 can be modulated according to a BPSK modulation scheme, a quadrature BPSK (Q-BPSK) modulation scheme, a quadrature amplitude modulation (QAM) modulation scheme, or another suitable modulation scheme. Payload 204 may include a PSDU containing a data field (DATA) 214, which in turn may carry higher-level data in the form of, for example, MAC Protocol Data Unit (MPDU) or Aggregated MPDU (A-MPDU).
[0056] In some implementations, a first wireless device (such as a STA or AP) may transmit the PN along with each frame, which may have a time-based portion and a counter value. In some implementations, the time-based portion may include a truncated TSF value indicating the time the frame was transmitted from the first wireless device. In some implementations, the counter value may be incremented for each frame transmitted with the same truncated TSF value and appended to the truncated TSF value. A second wireless device (such as a STA or AP) may receive the frame and perform a replay check by comparing the truncated TSF with the current local time based on the truncated local TSF. The second wireless device may process or discard the frame based on the replay check. Additionally or alternatively, the first wireless device may use a MIC for frame protection, wherein the MIC may be XORed with the truncated TSF value of the first wireless device. The second wireless device may XOR the received MIC with the local truncated TSF value to obtain the XORed MIC. The receiving device may decrypt the received frame and derive the value of the MIC, and compare the XORed MIC with the derived MIC value. If a mismatch exists, the frame is discarded; otherwise, further processing may be performed.
[0057] Figure 3 An example physical layer (PHY) protocol data unit (PPDU) 350 capable of being used for communication between a wireless AP and one or more wireless STAs is shown. For example, the AP and STA can be reference... Figure 1Examples of AP 102 and STA 104 are described below. As shown, PPDU 350 includes a PHY preamble (which includes a legacy portion 352 and a non-legacy portion 354) and a payload 356 (which includes a data field 374). The legacy portion 352 of the preamble includes L-STF 358, L-LTF 360, and L-SIG 362. The non-legacy portion 354 of the preamble includes a repetition of L-SIG (RL-SIG) 364 and multiple wireless communication protocol version-related signal fields following RL-SIG 364. For example, the non-legacy portion 354 may include a general signal field 366 (referred to herein as "U-SIG 366") and an EHT signal field 368 (referred to herein as "EHT-SIG 368"). The presence of RL-SIG 364 and U-SIG 366 ensures compatibility with EHT or later versions. STA 104 indicates that PPDU 350 is an EHT PPDU or a PPDU conforming to a new wireless communication protocol (conforming to future IEEE 802.11 wireless communication protocol standards). One or both of U-SIG 366 and EHT-SIG 368 can be constructed as other wireless communication protocol versions above EHT that are associated with a revision of the IEEE standards family and carry version-related information. For example, U-SIG 366 can be used by receiving devices such as AP102 and STA 104 to interpret bits in one or more of EHT-SIG 368 or data field 374. Similar to L-STF 358, L-LTF 360, and L-SIG 362, in instances involving the use of bound channels, the information in U-SIG 366 and EHT-SIG 368 can be repeated and transmitted in each of the component 20MHz channels.
[0058] The non-legacy portion 354 also includes an additional short training field 370 (referred to herein as "EHT-STF 370," though it can also be constructed for other wireless communication protocol versions above EHT and carry version-related information) and one or more additional long training fields 372 (referred to herein as "EHT-LTF 372," though they can also be constructed for other wireless communication protocol versions above EHT and carry version-related information). EHT-STF 370 can be used for timing and frequency tracking as well as AGC, while EHT-LTF 372 can be used for more refined channel estimation.
[0059] EHT-SIG 368 can be used by AP 102 to identify one or more STAs 104 and notify those STAs that AP 102 has scheduled uplink (UL) or downlink (DL) resources for them. EHT-SIG 368 can be decoded by each compatible STA 104 served by AP 102. EHT-SIG 368 can generally be used by the receiving device to interpret the bits in data field 374. For example, EHT-SIG 368 may include resource element (RU) allocation information, spatial flow configuration information, and per-user (e.g., STA-specific) signaling information. Each EHT-SIG 368 may include a common field and at least one user-specific field. In the context of OFDMA, the common field may indicate the RU distribution across multiple STAs 104, indicate RU assignment in the frequency domain, indicate which RUs are allocated for MU-MIMO transmission and which RUs correspond to OFDMA transmission, and the number of users in the allocation, etc. The user-specific field is assigned to a specific STA 104 and carries STA-specific scheduling information, such as user-specific MCS values and user-specific RU allocation information. This information enables the corresponding STA 104 to identify and decode the corresponding RU in the associated data field 374.
[0060] In some implementations, a first wireless device (such as a STA or AP) may transmit the PN along with each frame, which may have a time-based portion and a counter value. In some implementations, the time-based portion may include a truncated TSF value indicating the time the frame was transmitted from the first wireless device. In some implementations, the counter value may be incremented for each frame transmitted with the same truncated TSF value and appended to the truncated TSF value. A second wireless device (such as a STA or AP) may receive the frame and perform a replay check by comparing the truncated TSF with the current local time based on the truncated local TSF. The second wireless device may process or discard the frame based on the replay check. Additionally or alternatively, the first wireless device may use a MIC for frame protection, wherein the MIC may be XORed with the truncated TSF value of the first wireless device. The second wireless device may XOR the received MIC with the local truncated TSF value to obtain the XORed MIC. The receiving device may decrypt the received frame and derive the value of the MIC, and compare the XORed MIC with the derived MIC value. If a mismatch exists, the frame is discarded; otherwise, further processing may be performed.
[0061] Figure 4 A hierarchical format of an example PPDU capable of being used for communication between a wireless AP and one or more wireless STAs is shown. For example, the AP and STA can be references. Figure 1Examples of AP 102 and STA 104 described. As described, each PPDU 400 includes a PHY preamble 402 and a PSDU 404. Each PSDU 404 may represent (or “carry”) one or more MAC Protocol Data Units (MPDUs) 416. For example, each PSDU 404 may carry an aggregated MPDU (A-MPDU) 406, which includes an aggregation of multiple A-MPDU subframes 408. Each A-MPDU subframe 406 may include an MPDU frame 410 that includes a MAC delimiter 412 and a MAC header 414 preceding the accompanying MPDU 416, which includes the data portion (“payload” or “frame body”) of the MPDU frame 410. Each MPDU frame 410 may also include a Frame Check Sequence (FCS) field 418 for error detection (e.g., the FCS field may include Cyclic Redundancy Check (CRC)) and padding bits 420. MPDU 416 may carry one or more MAC Service Data Units (MSDUs) 416. For example, MPDU 416 may carry an aggregated MSDU (A-MSDU) 422, which includes multiple A-MSDU subframes 424. Each A-MSDU subframe 424 contains a corresponding MSDU frame 426, which has an MSDU 430, preceded by a subframe header 428 and, in some cases, followed by padding bits 432.
[0062] Returning to reference MPDU frame 410, MAC delimiter 412 can be used as a marker to indicate the start of associated MPDU 416 and the length of associated MPDU 416. MAC header 414 may include multiple fields containing information defining or indicating the characteristics or attributes of the data encapsulated within frame body 416. MAC header 414 includes a duration field indicating the duration from the end of the PPDU to at least the end of the acknowledgment (ACK) or block ACK (BA) to be sent by the receiving wireless communication device for that PPDU. The use of the duration field is to preserve the wireless medium until the indicated duration and to enable the receiving device to establish its Network Allocation Vector (NAV). MAC header 414 also includes one or more fields indicating the address of the data encapsulated within frame body 416. For example, MAC header 414 may include a combination of source address, transmitter address, receiver address, or destination address. MAC header 414 may also include a frame control field containing control information. The frame control field may specify the frame type, such as a data frame, control frame, or management frame.
[0063] Some wireless communication devices (including both AP and STA, such as reference) Figure 1The described AP 102 and STA 104 are capable of multi-link operation (MLO). In some examples, MLO supports establishing multiple different communication links (such as a first link in the 2.4 GHz band, a second link in the 5 GHz band, and a third link in the 6 GHz band) between STA 104 and AP 102, and concurrently and dynamically exchanging packets on one or more communication links. Each communication link may support one or more sets of channels or logical entities. In some cases, each communication link associated with a given wireless communication device may be associated with a corresponding radio component of the wireless communication device, which may include one or more transmit / receive (Tx / Rx) chains, including or coupled to one or more physical antennas, or including other components such as signal processing components. A device with MLO capability may be referred to as a multi-link device (MLD). An MLD may include a single upper MAC layer and may include, for example, three independent lower MAC layers and three associated independent PHY layers for the corresponding links in the 2.4 GHz, 5 GHz, and 6 GHz bands. This architecture can implement a single association process and security context. AP MLDs may include multiple APs, each configured to communicate with a corresponding STA among a plurality of STAs 104 that are not AP MLDs (also referred to as "STA MLDs") on a respective communication link. STA MLDs may communicate with AP MLDs at a given time via one or more of the multiple communication links. MLDs may independently compete for access on each of the communication links, which reduces latency by allowing the MLD to send its packets on the first communication link that becomes available.
[0064] Another feature of MLO is traffic steering and QoS characterization, which achieves latency reduction and other QoS enhancements by mapping traffic flows with different latency or other requirements to different links. For example, traffic with low latency requirements can be mapped to radio links operating in the 6 GHz band, and more latency-tolerant traffic can be mapped to radio links operating in the 2.4 GHz or 5 GHz bands.
[0065] One type of MLO is Alternating Multiple Link, where an MLD can simultaneously listen to two different high-performance channels. When an MLD has traffic to transmit, it can use the first channel with access opportunities (such as TXOP). Although an MLD may only use one channel for receiving or transmitting at a time, having access opportunities on two different channels provides low latency during network congestion.
[0066] Another type of MLO is Multi-Link Aggregation (MLA), where traffic associated with a single STA 104 is transmitted simultaneously and in parallel across multiple communication links to maximize the utilization of available resources, thereby achieving higher throughput. This is similar to carrier aggregation in cellular space. That is, during at least some time durations, transmission or portions of transmission can occur simultaneously and in parallel through two or more links. In some examples, the parallel wireless communication links can support synchronous transmission. In some other examples, or during some other time durations, transmissions via links can be parallel, but not synchronous or concurrent. In some examples or durations, two or more of these links can be used for communication between wireless communication devices in the same direction (such as all uplinks or all downlinks). In some other examples or time durations, two or more of these links can be used for communication in different directions. For example, one or more links can support uplink communication, and one or more links can support downlink communication. In such examples, at least one of the wireless communication devices operates in full-duplex mode. Generally, full-duplex operation enables bidirectional communication, where at least one of the wireless communication devices can transmit and receive simultaneously.
[0067] MLA can be implemented in several ways. In some examples, MLA can be packet-based. For packet-based aggregation, frames of a single service stream (such as all services associated with a given service identifier (TID)) can be transmitted concurrently across multiple communication links. In some other examples, MLA can be stream-based. For stream-based aggregation, a single available communication link from multiple available communication links can be used to transmit each service stream (such as all services associated with a given TID). As an example, a single STA MLD can access a web browser while streaming video in parallel. Services associated with web browser access can be communicated via a first communication link, while services associated with the video stream can be communicated in parallel via a second communication link (such that at least some of the data can be transmitted concurrently on the first channel with the data transmitted on the second channel).
[0068] In some other examples, MLA can be implemented as a hybrid of flow-based and packet-based aggregation. For example, MLD can employ flow-based aggregation when multiple traffic flows are created, and packet-based aggregation in other cases. The determination of switching between MLA techniques or modes may additionally or alternatively be correlated with other metrics, such as time of day, traffic load within the network, or battery level of wireless communication devices, and other factors or considerations.
[0069] To support MLO technology, the AP MLD and STA MLD can exchange information about supported MLO capabilities (such as supported aggregation types or supported frequency bands, etc.). In some examples, information exchange can occur via beacon signals, probe requests or responses, association request or response frames, dedicated action frames, or Operation Mode Indicators (OMIs), etc. In some examples, the AP MLD can designate a given channel in a given frequency band as an anchor channel (such as a channel on which the AP MLD transmits beacons and other management frames). In such examples, the AP MLD can also transmit beacons (such as beacons containing less information) on other channels for discovery purposes.
[0070] MLO technology can provide several benefits to wireless communication network 100. For example, MLO can improve user-aware throughput (UPT) (e.g., by rapidly refreshing the per-user transmit queue). Similarly, MLO can improve throughput by improving the utilization of available channels and can increase spectrum utilization (e.g., by increasing the bandwidth-time product). Furthermore, MLO can enable smooth transitions between multi-band radio components (e.g., where each radio component can be associated with a given RF band) or implement a framework for separating control and data channels. Other benefits of MLO include reduced modem power-on time, which can benefit wireless communication devices in terms of power consumption. Another benefit of MLO is increased multiplexing opportunities in the case of a single BSS. For example, multi-link aggregation can increase the number of users transmitted per multiplexed segment served by a multi-link AP MLD.
[0071] In some implementations, a first wireless device (such as a STA or AP) may transmit the PN along with each frame, which may have a time-based portion and a counter value. In some implementations, the time-based portion may include a truncated TSF value indicating the time the frame was transmitted from the first wireless device. In some implementations, the counter value may be incremented for each frame transmitted with the same truncated TSF value and appended to the truncated TSF value. A second wireless device (such as a STA or AP) may receive the frame and perform a replay check by comparing the truncated TSF with the current local time based on the truncated local TSF. In some implementations, MLO technology may be used for each link or two or more links at the first or second wireless device, and individual TSFs may be maintained or synchronized. The second wireless device may process or discard the frame based on the replay check. Additionally or alternatively, the first wireless device may use a MIC for frame protection, wherein the MIC may be XORed with the truncated TSF value of the first wireless device. The second wireless device may XOR the received MIC with the local truncated TSF value to obtain the XORed MIC. The receiving device can decrypt the received frame and derive the MIC value, and compare the XORed MIC with the derived MIC value. If a mismatch exists, the frame is discarded; otherwise, further processing can be performed.
[0072] Figure 5 An example of time-based packet number 500 supporting frame protection in wireless communication is shown. The time-based packet number 500 can implement one or more aspects of the wireless communication network 100. For example, the time-based packet number 500 can be provided with frames transmitted by AP 102 or STA 104, as shown in the reference. Figure 1 As shown and described.
[0073] In some implementations, protection against blocking, recording, and replay attacks can be provided by using PN502, which includes a first subset 504 of bits and a second subset 506 of bits. The first subset 504 of bits can be time-dependent bits obtained from the TSF value 508. For example, the first subset of bits can be obtained by truncating the TSF value 508 to remove a certain number of least significant bits (LSBs) 510. Furthermore, in some implementations, one or more most significant bits (MSBs) 512 can be removed from the TSF value 508. The second subset 506 of bits can correspond to a counter value that increments for each frame transmitted with the same first subset 504 of bits.
[0074] In some implementations, a first wireless device (such as an AP or STA) may transmit PN 502 with each frame. A second wireless device (such as an AP or STA) may receive the frame and perform a replay check by comparing the truncated TSF value provided in the first subset 504 of bits with the current local time based on the truncated local TSF. If the received truncated TSF value provided in the first subset 504 of bits is lower than the truncated local TSF value, the frame may be discarded. If the received value is the same as the received TSF value received in a previous frame, the received counter value provided in the second subset 506 of bits is compared with the previous counter value of the previous frame, and if the received counter value is equal to or less than the previous counter value, the frame is discarded. Otherwise, the frame is further processed.
[0075] In some implementations, the truncated TSF value indicates the time frame was transmitted from the first wireless device and can therefore provide a reduced time granularity provided by the full TSF value 508. In some implementations, the number of truncated bits (e.g., the number of bits in LSB 510) can be a specified value or negotiated between the first and second wireless devices based on their capabilities. A counter value of the second subset 506 of bits can be appended to the truncated TSF value of the first subset 504 and can be incremented each time a frame is transmitted with the same truncated TSF value, and reset to zero when the LSB of the truncated TSF is flipped.
[0076] In some implementations, PN 502 can be used to protect frames and assist in replay checks, where a frame is considered to be replayed by the receiving device if the received PN 502 has a first subset 504 of bits whose value is lower than the corresponding value generated at the receiving device based on its local TSF. In some implementations, PN 502 can be included in plaintext within the frame, making the receiving device aware of the PN used for protection (e.g., MIC generation or payload encryption). As discussed herein, in jamming, recording, and replay attacks, a malicious device may attempt to bypass replay detection logic by jamming the original frame and later replaying the unmodified frame. The technique discussed herein, using a truncated TSF value as the first subset 504 of bits, can further prevent such attacks by linking PN 502 to the transmission time, and thus, delayed replay frames will be discarded because the truncated TSF value of the received PN 502 of the frame is less than the truncated TSF value at the receiving device.
[0077] According to the specific implementation discussed herein, truncating the TSF allows clock drift between the transmitting and receiving devices. For example, it allows the receiving device to have extended periods of inactivity or sleep to conserve battery power. In a particular example, the receiving device may have indicated a listen interval (LI) of 10, and thus may be allowed to skip up to 10 beacons. With a target beacon transmission time (TBTT) of 100 ms, a receiving device with an LI of 10 will skip beacons for one second. Furthermore, because the clocks at the transmitting and receiving devices operate independently on each device, clock drift can occur over time. For example, according to some standards, clocks at different devices may have an accuracy of + / -100 ppm. Therefore, in the worst case, the drift between the transmitting and receiving devices could be + / -200 ppm. Thus, in such an example, the receiving device could shut down its local TSF relative to the transmitting device for 200 μs after skipping 10 beacons (1 second). In implementations where TSF has microsecond (μs) granularity, comparing the LSB 510 of TSF value 508 at the receiving device would result in a TSF value mismatch. Therefore, by truncating LSB 510 from TSF value 508, the granularity of the indicated time value is reduced, and clock drift can be hidden. In some implementations, the number of LSBs 510 to be masked can be specified and used by all devices in the network. In other implementations, the number of LSBs 510 to be masked can be negotiated between two devices based on one or more of the following: device capabilities, the LI used at the receiving device, the expected clock drift at the device, traffic flow, or any combination thereof. For example, TSF value 508 can be truncated by 8 bits of a 64-bit TSF value 508, which reduces the timing granularity to 1 / 4 of a time unit (TU), or 256 μs, which may be sufficient to address most clock drift scenarios.
[0078] However, the reduced time granularity can result in multiple packets transmitted within a reduced granularity time window (e.g., within a 256 μs window) having the same truncated TSF value provided in the first subset 504 in bit. The counter value provided in the second subset 506 in bit can be used to distinguish different frames transmitted with the same truncated TSF value.
[0079] In other implementations, protection against replay attacks can be provided by synchronizing the receiving device's TSF with the transmitting device's TSF after transitioning to a wake-up state. This synchronization allows the use of an uncrunted TSF value of 508 as the PN. Furthermore, in cases where the serving AP's clock is slow, the PN in the AP's downlink frames will have a lower TSF, and to avoid this, the client may not indicate a wake-up state to the AP until it has synchronized its TSF. In further implementations, the transmitting and receiving devices can specify or negotiate a time window for acceptable PN (TSF) values. For example, a fixed-size window for TSF values can be provided by a standard, or the two devices can negotiate a window based on their capabilities (e.g., LI and expected clock drift), and the receiving device can accept packets with TSF values within that window.
[0080] Refer again Figure 5 For example, the counter value provided in the second subset 506 of bits can be used to distinguish different frames sent with the same truncated TSF value. In some implementations, the counter value may increment each time a frame is sent with the same TSF value, and the counter value may be reset to zero when the LSB of the truncated TSF provided in the first subset 504 of bits flips. Thus, in such implementations, the total PN 502 is a cascade of partial TSF and an X-bit counter (e.g., where X=8). In some implementations, PN 502 may include 48 bits, and the second subset 506 of bits may correspond to the lower octet and may represent the counter. Thus, PN 502 may include PN[0:7] corresponding to the 8-bit counter, and PN[8:47] corresponding to the truncated TSF value with bits TSF[8:47]. In some implementations, the TSF value 508 may be a 64-bit value, and in this example, the bits TSF[48:63] corresponding to MSB 512 are not signaled.
[0081] In some implementations, at the receiving device, a replay check is performed by comparing a portion of the TSF with the current local time from the local TSF function. If the received value is lower than the portion of the local TSF, the frame can be discarded. If the received portion of the TSF is the same as the TSF received in a previous frame, the receiving device can compare the received counter value with the counter value of the previous frame. If the received counter value is equal to or less than the counter of the previous frame, the frame can be discarded. Otherwise, if the frame is not discarded, further frame processing is performed. For frames that pass the replay check and subsequent checks (e.g., MIC verification), the receiving device can record the received portion of the TSF and the counter value as the last known values for subsequent replay checks. In some implementations, due to clock drift, there is an extreme case where the 9th bit of the TSF (when 8 bits are truncated) may have recently been flipped at the receiving device but has not yet been flipped at the transmitting device. For example, the receiving device bits TSFR[0:8] = 100000001; while the transmitter bits TSFT[0:8] = 011111101, corresponding to a 4μs time difference. In such cases, a tolerance can be implemented to allow for this difference in TSF values. In some specific implementations, this tolerance can be predefined or negotiated between the two devices.
[0082] In some implementations, both devices can perform a key update operation to generate a new security key for encrypted communication when the PN 502 value wraps around. In some implementations, this wraparound will occur after 2^48 μs, or approximately 3258 days, with a TSF[8:47]. In other implementations, seamless roaming and MLO techniques can be used, and one or more PN 502 MIBs can be reserved for signaling the identification of the PN space. In such implementations, if 8 MSBs are used for the PN space ID, then a portion of the TSF[8:39] can be used, corresponding to 2^40 μs, or approximately 13 days. For most scenarios, such timeframes for key update operations specify that TSF / PN wraparound will not be the cause of the key update.
[0083] Figure 6 An example of a signaling diagram 600 supporting frame protection in wireless communication is shown. Signaling diagram 600 can implement one or more aspects of a wireless communication network 100. For example, signaling diagram 600 includes AP 102-a (such as a non-MLD AP) and AP 102-b (such as an MLD AP), AP 102-c, AP 102-d, AP 102-e, and AP 102-f, which can be as shown in the reference. Figure 1Examples of various aspects of AP 102 are shown and described. Similarly, signaling diagram 600 includes STA 104-a (such as a non-AP MLDSTA), STA 104-b, STA 104-c, and STA 104-d (such as a non-MLD non-AP STA), which can be as referenced. Figure 1 Examples of STA 104 shown and described.
[0084] As used herein, the term "AP" encompasses both a non-MLD AP (e.g., an AP operating on a single communication link) and an MLD AP 604 operating on more than one communication link. Similarly, the term "STA" encompasses both a non-MLD non-AP STA (such as an STA operating on a single communication link) and a non-AP MLD STA operating on more than one communication link. Therefore, in the following description of signaling diagram 600, when referring to communication between an STA and an AP, "STA" can be a non-MLD non-AP STA (e.g., a non-AP STA not attached to a non-AP MLD, such as STA 104-d) or a non-AP MLD STA (such as STA 104-c attached to a non-AP MLD 606), and "AP" can be a non-MLD AP (such as AP 102-a) or an MLD AP (such as AP 102-d attached to AP MLD 604-a or AP 102-e attached to AP MLD 604-b). In some implementations, the serving AP (or centralized controller) can provide a security key associated with a specific client / STA to neighboring APs belonging to the same Single Mobility Domain (SMD) MLD 602.
[0085] According to the described technique, in MLO, each affiliated AP (such as AP 102-b, AP 102-c, and AP 102-d) is allowed to have an independent clock. Therefore, the TSF value on each link can be a different value. In some implementations, the PN based on a portion of the TSF can be a per-link PN. In other implementations, affiliated APs such as AP 102-b, AP 102-c, and AP 102-d can have the same clock, and therefore the TSF value can be the same across each associated link. In such implementations, the TSF-based PN can be elevated to the MLD level, such as the AP MLD 604-a level. In such implementations, a second subset of the bits providing the counter value on the PN can be considered for frame transmission across all corresponding links (e.g., links across each of AP 102-b, AP 102-c, and AP 102-d). In some implementations, the number of bits in the second subset of the PN bits can be selected to consider counter values incrementing for each frame across multiple links. Alternatively, the total length of the PN can be increased to allocate more bits for the counter, or extra bits can be used to signal link ID information for seamless roaming.
[0086] Figure 7 An example of a process flow 700 supporting frame protection in wireless communication is shown. Process flow 700 can be implemented as described in the reference. Figure 1 and Figure 6 One or more aspects of the wireless communication network 100 or signaling diagram 600 shown and described. For example, process flow 700 includes a first wireless device 702 (such as an AP or STA) and a second wireless device 704 (such as an AP or STA).
[0087] At 706, optionally, the first wireless device 702 and the second wireless device 704 may exchange capability signaling. Capability signaling may indicate, for example, the capability to perform time-based PN operation, expected clock drift, MLO capability, or any combination thereof.
[0088] At 708, optionally, the first wireless device 702 and the second wireless device 704 may exchange negotiation signaling. The negotiation signaling may include, for example, the requested number of bits to be truncated in the TSF value, which may be based on the expected clock drift at one or both of the first wireless device 702 and the second wireless device 704. Additionally or alternatively, the negotiation may be directed to one or more specific traffic flows. For example, there may be one or more traffic flows for which one or both of the first wireless device 702 and the second wireless device 704 may not care about time-based replay checks, as well as certain other flows that are more critical from a security perspective and require protection based on a time-based PN. In such implementations, time-based PN replay checks may be enabled or disabled on a traffic flow basis based on negotiation, and / or the number of truncation bits in the TSF value may be negotiated on a traffic flow basis. Additionally or alternatively, the negotiated TSF truncation value may be based on the listening interval (LI) for non-AP devices. Furthermore, in some implementations, APs may or may not have different truncation values for different non-APs, depending on their capabilities. For example, for older non-AP STAs, the AP may not use a time-based PN, while for next-generation non-APs, the negotiated value may depend on one or more of the following: support for the feature (i.e., whether the device supports the feature), clock drift, listening interval, traffic flow, etc.
[0089] At 710, the first wireless communication device 702 may generate a PN based on its TSF value and a counter. As discussed herein, the PN may include a first subset of bits comprising a truncated TSF value and a second subset of bits comprising a counter value. For each transmitted frame having the same truncated TSF value in the first subset of bits, the counter value may be incremented. At 712, the first wireless device 702 may transmit a frame including the PN, and the second wireless device 704 may receive the transmitted frame.
[0090] At 714, the second wireless device 704 can compare portions of the PN with locally truncated TSF and counter values. As discussed herein, the second wireless device 704 can maintain an independent TSF providing the local TSF value. The second wireless device 704 can obtain the local TSF value, truncate the local TSF value according to the number of bits to be truncated, and compare the two TSF values. Furthermore, if the two TSF values are the same, the second wireless device 704 can compare the counter values provided in the second subset of bits.
[0091] At 716, the second wireless device 704 can process or discard the frame based on this comparison. For example, if the received truncated TSF value is less than the local truncated TSF value, the second wireless device 704 can discard the frame. Furthermore, if the received truncated TSF value is the same as the local truncated TSF value, the second wireless device 704 can determine whether a previously received frame has the same truncated TSF value. If the previously received frame does not have the same truncated TSF value, the second wireless device 704 can continue further processing of the frame. If the previously received frame does indeed have the same truncated TSF value, the second wireless device 704 can compare the counter value of a second subset of the bits with the previous counter value of the previous frame. If the counter value of the received frame is higher than the previous counter value of the previous frame, further processing of the received frame can be performed; otherwise, the frame can be discarded.
[0092] Figure 8 An example of a process flow 800 supporting frame protection in wireless communication is shown. Process flow 800 can be implemented as described in the reference. Figure 1 and Figure 6 One or more aspects of the wireless communication network 100 or signaling diagram 600 shown and described. For example, process flow 800 includes a first wireless device 802 (such as an AP or STA) and a second wireless device 804 (such as an AP or STA).
[0093] At 806, optionally, the first wireless device 802 and the second wireless device 804 may exchange capability signaling. Capability signaling may indicate, for example, the capability to perform time-based PN operation, to perform XOR MIC checks on data or management frames, to anticipate clock drift, MLO capability, or any combination thereof.
[0094] At 808, optionally, the first wireless device 802 and the second wireless device 804 may exchange negotiation signaling. The negotiation signaling may include, for example, a request for the number of bits to be truncated from the TSF value for XOR operations on the MIC, which may be based on the expected clock drift at one or both of the first wireless device 802 and the second wireless device 804. Additionally or alternatively, the negotiation may be directed to one or more specific traffic flows. For example, there may be one or more traffic flows for which one or both of the first wireless device 802 and the second wireless device 804 may not care about time-based replay checks, as well as certain other flows that are more critical from a security perspective and require protection based on a time-based PN. In such an implementation, the time-based PN replay check may be enabled or disabled on a traffic flow basis based on negotiation, and / or the number of truncation bits for the TSF value may be negotiated on a traffic flow basis. Additionally or alternatively, the negotiated TSF truncation value may be based on the LI used for non-AP devices. Furthermore, in some specific implementations, the AP may or may not have different cutoff values for different non-APs, depending on their capabilities. For example, for legacy non-AP STAs, the AP may not use time-based PN, while for next-generation non-APs, the negotiated value may depend on one or more of the following: support for the feature (i.e., whether the device supports the feature), clock drift, listening interval, traffic flow, etc.
[0095] At 810, the first wireless communication device 802 can generate a MIC field. The MIC field can be generated based on a subset of the MAC header fields according to established techniques, and is generated during the encryption of the MPDU payload. Because the contents of the header fields can change when the MPDU is retried, a new MIC is generated only for the header fields each time the MPDU is retried, and the MPDU payload is not re-encrypted. In some implementations, control frames can also be protected via the MIC.
[0096] At 812, the first wireless device 802 may perform an XOR operation to XOR the MIC field with a truncated TSF value provided by the TSF at the first wireless device 802. As discussed herein, the truncated TSF may have one or more LSBs truncated to accommodate clock drift between the first wireless device 802 and the second wireless device 804. In some embodiments, the number of bits in the truncated TSF corresponds to the number of bits in the MIC, and an XOR operation is performed on each bit in the MIC and the truncated TSF. In other embodiments, the truncated TSF and the MIC may have different numbers of bits, and padding may be used for values with fewer bits. At 814, the first wireless device 802 may transmit a frame including the XORed MIC field, and the second wireless device 804 may receive the frame transmission. In some embodiments, the frame may be a data frame or a management frame.
[0097] At 816, the second wireless device 804 may perform an XOR operation to XOR the received MIC field with a truncated version of the local TSF value to obtain the transmitted MIC field. At 818, the second wireless device 804 may decrypt the received frame according to the encryption process established for communication between the first wireless device 802 and the second wireless device 804. At 818, the second wireless device 804 may generate the received MIC field based on the decrypted frame.
[0098] At 822, the second wireless device 804 can process or discard a received frame based on whether the generated MIC field matches the XORed received MIC field. In some implementations, the second wireless device 804 can process the received frame if both MICs match, and can discard the received frame if there is a mismatch between the two MICs. In some implementations, the XORed MIC value can be different when retransmitting packets because the TSF will change at the first wireless device 802, and the replay check and XOR operation provides the MIC associated with the transmitted frame for MIC checking, which can be performed if the frame has not been discarded. In some implementations, the retransmitted frame can occur on any link in the MLD operation, and the TSF corresponding to that link will be used during the XOR steps at the first wireless device 802 and the second wireless device 804.
[0099] In some other implementations, TSF-based PNs can be used to manage the encryption of frames or data frames to help prevent replay attacks. In such implementations, the payload of a frame can be re-encrypted for frame retransmission. Furthermore, such techniques can specify that associated APs share a common clock and synchronize TSFs.
[0100] Figure 9 A block diagram 900 is shown of a first wireless device 920 supporting frame protection in wireless communication according to one or more aspects of this disclosure. The first wireless device 920 may be as shown in reference... Figures 2 to 8 Examples of various aspects of the described first wireless device. The first wireless device 920 or its various components may be examples of components used to perform various aspects of frame protection in wireless communication as described herein. For example, the first wireless device 920 may include a packet number manager 925, a communication manager 930, a MIC manager 935, an XOR component 940, a TSF manager 945, a counter manager 950, an MLO manager 955, an encryption manager 960, or any combination thereof. Each of these components, or its components or sub-components (e.g., one or more processors, one or more memories), may communicate directly or indirectly with each other (e.g., via one or more buses).
[0101] According to the examples disclosed herein, wireless communication device 920 may support wireless communication. Packet number manager 925 may be configured or configured to generate a packet number for a frame to be sent to the second wireless communication device, the packet number comprising a first subset of bits corresponding to a portion of the frame associated with a timing synchronization function value and a second subset of bits corresponding to a counter value. Communication manager 930 may be configured or configured to send a frame to the second wireless communication device, the frame including a portion containing the packet number. In some examples, the frame includes a header portion, and the packet number is used to protect the contents of the header portion. In some examples, the frame is a control frame, and the packet number is used to protect the contents of the control frame.
[0102] In some examples, to support the generation of group numbers, the TSF manager 945 can be configured or configured to generate this portion of the timed synchronization function value as a truncated version of the timed synchronization function value. In some examples, to support the generation of group numbers, the counter manager 950 can be configured or configured to append a counter value to this portion of the timed synchronization function value. In some examples, the truncated version of the timed synchronization function value can be truncated by removing a certain number of the least significant bits of the timed synchronization function value.
[0103] In some examples, the TSF Manager 945 can be configured or is configured to communicate with a second wireless communication device to negotiate the number of bits to be truncated from the timing synchronization function value. In some examples, the number of bits to be truncated is different for different traffic flows, and the number of bits to be truncated is based on the listening interval of the first wireless communication device, the second wireless communication device, or any combination thereof. In some examples, the truncated version of the timing synchronization function value can be truncated by a certain amount based on the potential clock drift between the first and second wireless communication devices.
[0104] In some examples, the first wireless communication device may be a non-multilink device (MLD) non-access point (AP) STA or a non-AP STA attached to a non-AP MLD, and the second wireless communication device may be a non-MLD AP or an AP attached to an AP MLD; or the first wireless communication device may be a non-MLD AP or an AP attached to an AP MLD, and the second wireless communication device may be a non-AP STA attached to a non-AP MLD or a non-AP STA attached to a non-AP MLD. In some examples, when a non-AP STA transitions to a wake-up state, it may synchronize its timing synchronization function with the corresponding timing synchronization function at the associated AP operating on that link.
[0105] In some examples, this portion of the timing synchronization function value may correspond to a time window of an acceptable timing synchronization function value, which is a specified time window or has a duration negotiated with a second wireless communication device.
[0106] In some examples, the frame may be a first frame having a first portion of a timing synchronization function value and a first counter value, and a second frame sent after the first frame having a first portion of the timing synchronization function value and a second counter value, the second counter value being an increment from the first counter value. In some examples, in response to a change in this portion of the timing synchronization function value, the subsequent counter value of subsequent frames of the second frame is reset to zero.
[0107] In some examples, the TSF manager 945 can be configured or is configured to communicate with a second wireless communication device to negotiate a tolerance between a timing synchronization function value and a corresponding timing synchronization function value at the second wireless communication device, which allows for frame processing at the second wireless communication device.
[0108] In some examples, the encryption manager 960 may be configured or configured to update the encryption key associated with communication between the first and second wireless communication devices in response to a packet number being reset to an initial value. In some examples, the first wireless communication device may be an MLD operating on multiple links, wherein a separate timing synchronization function is maintained at each link. In some examples, the first wireless communication device may be an MLD operating on multiple links, wherein the same timing synchronization function is used to generate timing synchronization function values for each link.
[0109] Additionally or alternatively, the wireless communication device 900 may support wireless communication according to examples disclosed herein. The MIC manager 935 may be configured or configured to generate a Message Integrity Check (MIC) field for a frame to be sent to a second wireless communication device. The XOR component 940 may be configured or configured to perform an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of the timing synchronization function value associated with the frame. In some examples, the communication manager 930 may be configured or configured to send a frame including the XORed MIC field to the second wireless communication device.
[0110] In some examples, the MIC field may be generated during frame encryption. In some examples, this portion of the timing synchronization function value may be a truncated version of the timing synchronization function value at the first wireless communication device. In some examples, the truncated version of the timing synchronization function value may be truncated by removing a certain number of the least significant bits of the timing synchronization function value.
[0111] In some examples, a truncated version of the timing synchronization function value may be truncated by an amount based on potential clock drift between the first wireless communication device and at least the second wireless communication device. In some examples, the truncated version of the timing synchronization function value may be truncated by removing a certain number of the least significant bits of the timing synchronization function value.
[0112] In some examples, the communication manager 930 can be configured or is configured to retransmit data included in a subsequent frame, wherein the subsequent frame includes an XORed MIC field based on an update of the corresponding subsequent timing synchronization function value associated with that subsequent frame. In some examples, the content of the subsequent frame is not re-encrypted when the frame is retransmitted. In some examples, the frame can be a data frame or a management frame.
[0113] Figure 10 A block diagram 1000 of a second wireless device 1020 supporting frame protection in wireless communication according to one or more aspects of this disclosure is shown. The second wireless device 1020 may be as described in reference... Figures 2 to 8 Examples of various aspects of the described second wireless device. The second wireless device 1020 or its various components may be examples of components used to perform various aspects of frame protection in wireless communications as described herein. For example, the second wireless device 1020 may include a packet number manager 1025, a frame processing manager 1030, a MIC manager 1035, an XOR component 1040, a TSF manager 1045, an MLO manager 1050, a counter manager 1055, an encryption manager 1060, or any combination thereof. Each of these components, or its components or sub-components (e.g., one or more processors, one or more memories), may communicate directly or indirectly with each other (e.g., via one or more buses).
[0114] According to the examples disclosed herein, wireless communication device 1020 may support wireless communication. Packet number manager 1025 may be configured or configured to receive frames including a packet number comprising a first subset of bits corresponding to a first timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value. Frame processing manager 1030 may be configured or configured to process the frame at least in part based on whether a time value indicated by the first subset of bits corresponds to local time maintained at the second wireless communication device.
[0115] In some examples, a frame may include a header section, and a group number is used to protect the contents of the header section. In some examples, a frame may be a control frame, and a group number is used to protect the contents of the control frame.
[0116] In some examples, the TSF manager 1045 can be configured or configured to generate a second timing synchronization function value as a truncated version of the time value of the timing synchronization function at the second wireless communication device, wherein the local time maintained at the second wireless communication device corresponds to the second timing synchronization function value, and wherein frames are processed based on the second timing synchronization function value being matched with the first timing synchronization function value.
[0117] In some examples, the TSF manager 1045 may be configured or configured to communicate with a first wireless communication device to negotiate the number of bits to be truncated from the time value of the timing synchronization function, wherein the frame is transmitted by the first wireless communication device. In some examples, the number of bits to be truncated is different for different traffic flows, and the number of bits to be truncated is based on the listening interval of the first wireless communication device or the second wireless communication device or any combination thereof.
[0118] In some examples, truncated versions of the time values for the timing synchronization function allow clock drift between the second wireless communication device and at least the first wireless communication device.
[0119] In some examples, the second wireless communication device may be a non-multilink device (MLD) AP or an AP attached to an AP MLD, and communicates with a first wireless communication device, which is a non-MLD non-AP STA or a non-AP STA attached to a non-AP MLD; or the first wireless communication device is a non-MLD AP or an AP attached to an AP MLD, and the second wireless communication device is a non-AP MLD non-AP STA or a non-AP STA attached to a non-AP MLD. In some examples, when a non-AP STA transitions to a wake-up state, it synchronizes its timing synchronization function with the corresponding timing synchronization function at the associated AP operating on that link.
[0120] In some examples, the first timing synchronization function value may correspond to a time window of an acceptable timing synchronization function value, which is a specified time window or has a duration negotiated with the first wireless communication device. In some examples, the frame may be a first frame having a first timing synchronization function value and a first counter value, and a second frame transmitted after the first frame may have a first timing synchronization function value and a second counter value, the second counter value being a value incremented from the first counter value. In some examples, in response to a change in the first timing synchronization function value, the subsequent counter value of subsequent frames of the second frame may be reset to zero.
[0121] In some examples, the TSF manager 1045 can be configured or is configured to compare a first subset of bits with a third subset of bits, the third subset of bits corresponding to a second timing synchronization function value generated at the second wireless communication device and associated with the time of receiving the frame.
[0122] In some examples, frame processing manager 1030 may be configured or configured to discard the frame in response to a mismatch between a first subset of bits and a third subset of bits. In some examples, frame processing manager 1030 may be configured or configured to determine, in response to a match between the first subset of bits and the third subset of bits, that the frame is an initial received frame with a first timing synchronization function value, or to determine that a counter value exceeds a previous counter value of a previous frame with the first timing synchronization function value. In some examples, frame processing manager 1030 may be configured or configured to process the frame. In some examples, frame processing manager 1030 may be configured or configured to discard the frame in response to a counter value of the frame being equal to or less than a previously received counter value with the first timing synchronization function value.
[0123] In some examples, the TSF manager 1045 may be configured or configured to record a first timing synchronization function value and a counter value for processing subsequent frame headers. In some examples, the TSF manager 1045 may be configured or configured to communicate with a first wireless communication device to negotiate a tolerance between the first timing synchronization function value and a corresponding timing synchronization function value at the first wireless communication device, which allows the frame to be processed at a second wireless communication device.
[0124] In some examples, the encryption manager 1060 can be configured or is configured to update the encryption key associated with communication between the second wireless communication device and the first wireless communication device in response to a packet number being reset to an initial value. In some examples, the second wireless device is a multi-link device (MLD) operating on multiple links, wherein a separate timing synchronization function is maintained at each link.
[0125] Additionally or alternatively, the wireless communication device 1000 may support wireless communication according to examples disclosed herein. The MIC manager 1035 may be configured or configured to receive frames that include a Message Integrity Check (MIC) field. The XOR component 1040 may be configured or configured to perform an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of the timing synchronization function value associated with the reception time of the frame. In some examples, the frame processing manager 1030 may be configured or configured to process the XORed MIC field to determine the frame integrity of the frame.
[0126] In some examples, the TSF manager 1045 can be configured or is configured such that this portion of the timing synchronization function value is a truncated version of the timing synchronization function value at the second wireless communication device. In some examples, the truncated version of the timing synchronization function value can be truncated by an amount based on potential clock drift between the second and first wireless communication devices.
[0127] In some examples, the encryption manager 1060 may be configured or configured to decrypt frames. In some examples, the MIC manager 1035 may be configured or configured to generate a received frame MIC field based on the decrypted frame. In some examples, the frame processing manager 1030 may be configured or configured to discard a frame in response to a mismatch between the received frame MIC field and the XORed MIC field, or to decode a frame in response to a match between the received frame MIC field and the XORed MIC field. In some examples, the second wireless communication device may be an MLD operating on multiple links, wherein a separate timing synchronization function is maintained at each link.
[0128] Figure 11 A flowchart illustrating a method 1100 for supporting frame protection in wireless communication according to one or more aspects of this disclosure is shown. Operation of method 1100 may be implemented by a first wireless device or its components as described herein. For example, operation of method 1100 may be implemented by, as referenced... Figures 2 to 9 The first wireless device described herein performs the function. In some examples, the first wireless device may execute a set of instructions to control the functional elements of the first wireless device to perform the described function. Additionally or alternatively, the first wireless device may use dedicated hardware to perform aspects of the described function.
[0129] At 1105, the method may include generating a packet number for a frame to be transmitted to a second wireless communication device, the packet number comprising a first subset of bits corresponding to a portion of the frame associated with a timing synchronization function value and a second subset of bits corresponding to a counter value. The operation of block 1105 may be based on examples as disclosed herein (such as...). Figure 5 The generation and / or production of PN 502 Figure 7 (The generation of PN at 710) is performed to achieve this. PN may include parameters relative to... Figures 5 to 7 The information described and illustrated herein is similar to other information. In some examples, aspects of the operation of 1105 may be derived from, as referenced... Figure 9 The group number manager 925 described is used to execute this.
[0130] At 1110, the method may include transmitting a frame to a second wireless communication device, the frame including a portion containing a packet number. The operation of block 1110 may be based on examples as disclosed herein (such as...). Figure 4 The transmission of frame 410 and / or Figure 7 This is performed by sending the frame at position 712. The frame may include information relative to... Figures 5 to 7 The information described and illustrated herein is similar to other information. In some examples, aspects of the operation of 1110 may be derived from, as referenced... Figure 9 The described signal manager 930 is used to execute this.
[0131] Figure 12 A flowchart illustrating a method 1200 for supporting frame protection in wireless communication according to one or more aspects of this disclosure is shown. Operation of method 1200 may be implemented by a second wireless device or its components as described herein. For example, operation of method 1200 may be implemented by, as referenced... Figures 2 to 8 and Figure 10 The second wireless device described herein performs the functions. In some examples, the second wireless device may execute a set of instructions to control the functional elements of the second wireless device to perform the described functions. Additionally or alternatively, the second wireless device may use dedicated hardware to perform aspects of the described functions.
[0132] At 1205, the method may include receiving a frame including a group number comprising a first subset of bits corresponding to a first timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value. Operation of block 1205 may be based on examples as disclosed herein (such as...). Figure 4 Received and / or Frame 410 Figure 7 (This is performed by receiving the frame at position 712). The frame may include information relative to... Figures 5 to 7 The information described and illustrated herein is similar to other information. In some examples, aspects of the operation of 1205 may be derived from, as referenced... Figure 10 The group number manager 1025 described is used to execute this.
[0133] At 1210, the method may include processing the frame at least in part based on whether a time value indicated by a first subset of the bits corresponds to a local time maintained at the second wireless communication device. The operation of block 1210 may be based on examples as disclosed herein (such as...). Figure 4 The processing of frame 410 and / or Figure 7 The processing of frames at points 714 and 716 is performed. A frame may include data relative to... Figures 5 to 7 The information described and illustrated herein is similar to other information. In some examples, aspects of the operation of 1210 may be derived from, as referenced... Figure 10 The frame processing manager 1030 described is used to execute this.
[0134] Figure 13 A flowchart illustrating a method 1300 for supporting frame protection in wireless communication according to one or more aspects of this disclosure is shown. Operation of method 1300 may be implemented by a first wireless device or its components as described herein. For example, operation of method 1300 may be implemented by, as referenced... Figures 2 to 9The first wireless device described herein performs the function. In some examples, the first wireless device may execute a set of instructions to control the functional elements of the first wireless device to perform the described function. Additionally or alternatively, the first wireless device may use dedicated hardware to perform aspects of the described function.
[0135] At 1305, the method may include generating a Message Integrity Check (MIC) field for a frame to be sent to a second wireless communication device. The operation of box 1305 may be based on examples as disclosed herein (such as in...). Figure 8 (The MIC is generated at position 810) to perform the operation. The MIC may include components relative to... Figures 5 to 8 The information described and illustrated herein is similar to other information. In some examples, aspects of the operation of 1305 may be derived from, as referenced... Figure 9 The MIC Manager 935 described is used for execution.
[0136] At 1310, the method may include performing an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of the timing synchronization function value associated with the frame. The operation of box 1310 may be based on examples as disclosed herein (such as in...). Figure 8 The XOR operation is performed using the MIC field at position 812. MIC can include values relative to... Figures 5 to 8 The information described and illustrated therein is similar to the information processed in the XOR operation. In some examples, aspects of the operation of 1310 can be derived from, as referenced... Figure 9 The XOR component 940 described is used for execution.
[0137] At 1315, the method may include sending a frame to a second wireless communication device that includes an XORed MIC field. The operation of box 1315 may be based on examples as disclosed herein (such as...). Figure 4 The transmission of frame 410 and / or Figure 8 The transmission of the frame at position 814 is performed to achieve this. The frame may include information relative to... Figures 5 to 8 The information described and illustrated herein is similar to other information. In some examples, aspects of the operation of 1315 may be derived from, as referenced... Figure 9 The described communication manager 930 is used to execute this.
[0138] Figure 14 A flowchart illustrating a method 1400 for supporting frame protection in wireless communication according to one or more aspects of this disclosure is shown. Operation of method 1400 may be implemented by a second wireless device or its components as described herein. For example, operation of method 1400 may be implemented by, as referenced... Figures 2 to 8 and Figure 10The second wireless device described herein performs the functions. In some examples, the second wireless device may execute a set of instructions to control the functional elements of the second wireless device to perform the described functions. Additionally or alternatively, the second wireless device may use dedicated hardware to perform aspects of the described functions.
[0139] At 1405, the method may include receiving a frame that includes a Message Integrity Check (MIC) field. The operation of box 1405 may be based on examples as disclosed herein (such as...). Figure 4 Received and / or Frame 410 Figure 8 (This is performed by receiving the frame at position 814). The frame may include information relative to... Figures 5 to 8 The information described and illustrated herein is similar to other information. In some examples, aspects of the operation of 1405 may be derived from, as referenced... Figure 10 The MIC manager 1035 described is used to execute this.
[0140] At 1410, the method may include performing an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of the timing synchronization function value associated with the reception time of the frame. The operation of block 1410 may be based on examples as disclosed herein (such as in...). Figure 8 The XOR operation is performed using the MIC field at position 816. MIC may include values relative to... Figures 5 to 8 The information described and illustrated therein is similar to the information processed in the XOR operation. In some examples, aspects of the operation of 1410 can be derived from, as referenced... Figure 10 The XOR component 1040 described is used to perform this.
[0141] At 1415, the method may include processing the XORed MIC field to determine the frame integrity of the frame. The operation of box 1415 may be based on examples as disclosed herein (such as...). Figure 8 The processing of the MIC field at points 820 and 822 is performed to achieve this. The MIC field may include information relative to... Figures 5 to 8 The information described and exemplified therein is similar to the information provided. In some examples, aspects of the operation of 1415 may be derived from, as referenced... Figure 10 The frame processing manager 1030 described is used to execute this.
[0142] Specific implementation examples are described in the following numbered clauses: Clause 1: A first wireless communication device, the first wireless communication device comprising: a processing system including processor circuitry and memory circuitry storing code, the processing system being configured to cause the first wireless device to: generate a packet number for a frame to be transmitted to a second wireless communication device, the packet number including a first subset of bits corresponding to a portion of a timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and transmit the frame to the second wireless communication device, the frame including a portion containing the packet number.
[0143] Clause 2: The first wireless communication device according to Clause 1, wherein the frame includes a header portion and the packet number is used to protect the contents of the header portion.
[0144] Clause 3: A first wireless communication device according to any one of Clauses 1 to 2, wherein the frame is a control frame and the packet number is used to protect the content of the control frame.
[0145] Clause 4: A first wireless communication device according to any one of Clauses 1 to 3, wherein the content of the frame is protected by an integrity check or by encryption of the content to be protected, the integrity check generating a MIC across the content so protected.
[0146] Clause 5: A first wireless communication device according to any one of Clauses 1 to 4, wherein, in order to generate the packet number, the processing system is configured to cause the first wireless device to: generate the portion of the timing synchronization function value as a truncated version of the timing synchronization function value; and append the counter value to the portion of the timing synchronization function value.
[0147] Clause 6: The first wireless communication device according to Clause 5, wherein the truncated version of the timing synchronization function value is truncated by removing a certain number of least significant bits of the timing synchronization function value.
[0148] Clause 7: A first wireless communication device according to any one of Clauses 5 to 6, wherein the processing system is further configured to cause the first wireless device to communicate with the second wireless communication device to negotiate the number of bits to be truncated from the timing synchronization function value.
[0149] Clause 8: The first wireless communication device as described in Clause 7, wherein the number of bits to be truncated is different for different traffic flows, and the number of bits to be truncated is at least in part based on the listening interval of the first wireless communication device or the second wireless communication device or any combination thereof.
[0150] Clause 9: A first wireless communication device according to any one of Clauses 5 to 8, wherein the truncated version of the timing synchronization function value is truncated by an amount based at least in part on a potential clock drift between the first wireless communication device and the second wireless communication device.
[0151] Clause 10: A first wireless communication device according to any one of Clauses 1 to 9, wherein the first wireless communication device is a non-MLD non-AP STA or a non-AP STA attached to a non-AP MLD, and the second wireless communication device is a non-MLD AP or an AP attached to an AP MLD, or the first wireless communication device is a non-MLD AP or an AP attached to an AP MLD, and the second wireless communication device is a non-AP MLD non-AP STA or a non-AP STA attached to a non-AP MLD, and when the non-AP STA transitions to a wake-up state, the non-AP STA synchronizes its timing synchronization function with the corresponding timing synchronization function at the associated AP operating on the link.
[0152] Clause 11: A first wireless communication device according to any one of Clauses 1 to 10, wherein the portion of the timing synchronization function value corresponds to a time window of an acceptable timing synchronization function value, the time window being a specified time window or having a duration negotiated with the second wireless communication device.
[0153] Clause 12: A first wireless communication device according to any one of Clauses 1 to 11, wherein the frame is a first frame having a first portion of the timing synchronization function value and a first counter value, and a second frame transmitted after the first frame has the first portion of the timing synchronization function value and a second counter value, the second counter value being a value incremented from the first counter value.
[0154] Clause 13: The first wireless communication device according to Clause 12, wherein in response to a change in said portion of the timing synchronization function value, the subsequent counter value of the subsequent frame of the second frame is reset to zero.
[0155] Clause 14: A first wireless communication device according to any one of Clauses 1 to 13, wherein the processing system is further configured to cause the first wireless device to: communicate with the second wireless communication device to negotiate a tolerance between the timing synchronization function value and a corresponding timing synchronization function value at the second wireless communication device, the tolerance allowing processing of the frame at the second wireless communication device.
[0156] Clause 15: A first wireless communication device according to any one of Clauses 1 to 14, wherein the processing system is further configured to cause the first wireless device to: update the encryption key associated with communication between the first wireless communication device and the second wireless communication device in response to the packet number being reset to an initial value.
[0157] Clause 16: A first wireless communication device according to any one of Clauses 1 to 15, wherein the first wireless communication device is an MLD operating on multiple links, and wherein a separate timing synchronization function is maintained at each link.
[0158] Clause 17: A first wireless communication device according to any one of Clauses 1 to 16, wherein the first wireless communication device is an MLD operating on multiple links, and wherein the same timing synchronization function is used to generate timing synchronization function values for each link.
[0159] Clause 18: A second wireless communication device, the second wireless communication device comprising: a processing system including processor circuitry and memory circuitry storing code, the processing system being configured to cause the second wireless device to: receive a frame including a packet number, the packet number including a first subset of bits corresponding to a first timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and process the frame at least in part based on whether a time value indicated by the first subset of bits corresponds to a local time maintained at the second wireless communication device.
[0160] Clause 19: The second wireless communication device according to Clause 18, wherein the frame includes a header portion and the packet number is used to protect the contents of the header portion.
[0161] Clause 20: A second wireless communication device according to any one of Clauses 18 to 19, wherein the frame is a control frame and the packet number is used to protect the contents of the control frame.
[0162] Clause 21: A second wireless communication device according to any one of Clauses 18 to 20, the second wireless communication device further comprising: generating a second timing synchronization function value as a truncated version of the time value of the timing synchronization function at the second wireless communication device, wherein the local time maintained at the second wireless communication device corresponds to the second timing synchronization function value, and wherein the frame is processed at least in part based on the second timing synchronization function value matching the first timing synchronization function value.
[0163] Clause 22: A second wireless communication device according to Clause 21, wherein the processing system is configured to cause the second wireless device to: communicate with a first wireless communication device to negotiate the number of bits to be truncated from the time value of the timing synchronization function, and wherein the frame is transmitted by the first wireless communication device.
[0164] Clause 23: The second wireless communication device as described in Clause 22, wherein the number of bits to be truncated is different for different traffic flows, and the number of bits to be truncated is at least in part based on the listening interval of the first wireless communication device or the second wireless communication device or any combination thereof.
[0165] Clause 24: A second wireless communication device according to any one of Clauses 21 to 23, wherein the truncated version of the time value of the timing synchronization function allows clock drift between the second wireless communication device and at least the first wireless communication device.
[0166] Clause 25: A second wireless communication device according to any one of Clauses 18 to 24, wherein the second wireless communication device is a non-MLD AP or an AP attached to an AP MLD and communicates with a first wireless communication device, wherein the first wireless communication device is a non-MLD non-AP STA or a non-AP STA attached to a non-AP MLD, or the first wireless communication device is a non-MLD AP or an AP attached to an AP MLD and the second wireless communication device is a non-AP MLD non-AP STA or a non-AP STA attached to a non-AP MLD, and when the non-AP STA transitions to a wake-up state, the non-AP STA synchronizes its timing synchronization function with the corresponding timing synchronization function at the associated AP operating on the link.
[0167] Clause 26: A second wireless communication device according to any one of Clauses 18 to 25, wherein the first timing synchronization function value corresponds to a time window of an acceptable timing synchronization function value, the time window being a specified time window or having a duration negotiated with the first wireless communication device.
[0168] Clause 27: A second wireless communication device according to any one of Clauses 18 to 26, wherein the frame is a first frame having a first timing synchronization function value and a first counter value, and a second frame transmitted after the first frame has the first timing synchronization function value and a second counter value, the second counter value being a value incremented from the first counter value.
[0169] Clause 28: The second wireless communication device according to Clause 27, wherein in response to a change in the value of the first timing synchronization function, the value of the subsequent counter of the subsequent frame of the second frame is reset to zero.
[0170] Clause 29: A second wireless communication device according to any one of Clauses 18 to 28, wherein the processing system is further configured to cause the second wireless device to: compare a first subset of bits with a third subset of bits, the third subset of bits corresponding to a second timing synchronization function value generated at the second wireless communication device and associated with the time of receiving the frame.
[0171] Clause 30: A second wireless communication device according to Clause 29, wherein the processing system is configured to cause the second wireless device to discard the frame in response to a mismatch between the first subset of bits and the third subset of bits.
[0172] Clause 31: A second wireless communication device according to any one of Clauses 29 to 30, wherein the processing system is further configured to cause the second wireless device to: determine, in response to a match between the first subset of bits and the third subset of bits, that the frame is a received initial frame having the first timing synchronization function value, or determine that the counter value exceeds a previous counter value of a previous frame having the first timing synchronization function value; and process the frame.
[0173] Clause 32: A second wireless communication device according to any one of Clauses 29 to 31, wherein the processing system is further configured to cause the second wireless device to discard the frame in response to the counter value of the frame being equal to or less than a previously received counter value having the first timing synchronization function value.
[0174] Clause 33: A second wireless communication device according to any one of Clauses 18 to 32, wherein the processing system is further configured to cause the second wireless device to: record the first timing synchronization function value and the counter value for processing subsequent frame headers.
[0175] Clause 34: A second wireless communication device according to any one of Clauses 18 to 33, the second wireless communication device further comprising: communicating with a first wireless communication device to negotiate a tolerance between the first timing synchronization function value and a corresponding timing synchronization function value at the first wireless communication device, the tolerance allowing processing of the frame at the second wireless communication device.
[0176] Clause 35: A second wireless communication device according to any one of Clauses 18 to 34, wherein the processing system is further configured to cause the second wireless device to: update the encryption key associated with communication between the second wireless communication device and the first wireless communication device in response to the packet number being reset to an initial value.
[0177] Clause 36: A second wireless communication device according to any one of Clauses 18 to 35, wherein the second wireless device is an MLD operating on multiple links, and wherein a separate timing synchronization function is maintained at each link.
[0178] Clause 37: A second wireless communication device pursuant to any one of Clauses 18 to 36, wherein the first wireless communication device is an MLD operating on multiple links, and wherein the same timing synchronization function is used to generate timing synchronization function values for each link.
[0179] Clause 38: A first wireless communication device, the first wireless communication device comprising: a processing system including processor circuitry and memory circuitry storing code, the processing system being configured to cause the first wireless device to: generate a MIC field for a frame to be transmitted to a second wireless communication device; perform an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of a timing synchronization function value associated with the frame; and transmit the frame including the XORed MIC field to the second wireless communication device.
[0180] Clause 39: The first wireless communication device according to Clause 38, wherein the MIC field is generated during the encryption of the frame.
[0181] Clause 40: A first wireless communication device pursuant to any one of Clauses 38 to 39, wherein the portion of the timing synchronization function value is a truncated version of the timing synchronization function value at the first wireless communication device.
[0182] Clause 41: The first wireless communication device according to Clause 40, wherein the truncated version of the timing synchronization function value is truncated by removing a certain number of least significant bits of the timing synchronization function value.
[0183] Clause 42: A first wireless communication device according to any one of Clauses 40 to 41, wherein the truncated version of the timing synchronization function value is truncated by an amount based at least in part on a potential clock drift between the first wireless communication device and at least the second wireless communication device.
[0184] Clause 43: The first wireless communication device according to any one of Clauses 40 to 42, wherein the truncated version of the timing synchronization function value is truncated by removing a certain number of least significant bits of the timing synchronization function value.
[0185] Clause 44: A first wireless communication device according to any one of Clauses 38 to 43, wherein the processing system is further configured to cause the first wireless device to: retransmit data included in a subsequent frame in a subsequent frame, wherein the subsequent frame includes an XORed MIC field based on an updated value of a corresponding subsequent timing synchronization function associated with the subsequent frame.
[0186] Clause 45: The first wireless communication device according to Clause 44, wherein when the frame is retransmitted, the content of the subsequent frame is not re-encrypted.
[0187] Clause 46: A first wireless communication device pursuant to any one of Clauses 38 to 45, wherein the frame is a data frame or a management frame.
[0188] Clause 47: A second wireless communication device, the second wireless communication device comprising: a processing system including processor circuitry and memory circuitry storing code, the processing system being configured to cause the second wireless device to: receive a frame including a MIC field; perform an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of a timing synchronization function value associated with the reception time of the frame; and process the XORed MIC field to determine the frame integrity of the frame.
[0189] Clause 48: The second wireless communication device according to Clause 47, wherein the portion of the timing synchronization function value is a truncated version of the timing synchronization function value at the second wireless communication device.
[0190] Clause 49: The second wireless communication device according to Clause 48, wherein the truncated version of the timing synchronization function value is truncated by an amount at least in part based on a potential clock drift between the second wireless communication device and the first wireless communication device.
[0191] Clause 50: A second wireless communication device according to any one of Clauses 47 to 49, the second wireless communication device further comprising: decrypting the frame; generating a received frame MIC field based on the decrypted frame; and discarding the frame in response to a mismatch between the received frame MIC field and the XORed MIC field, or decoding the frame in response to a match between the received frame MIC field and the XORed MIC field.
[0192] Clause 51: A second wireless communication device according to any one of Clauses 47 to 50, wherein the second wireless communication device is an MLD operating on multiple links, and wherein a separate timing synchronization function is maintained at each link.
[0193] Clause 52: A second wireless communication device pursuant to any one of Clauses 47 to 51, wherein the first wireless communication device is an MLD operating on multiple links, and wherein the same timing synchronization function is used to generate timing synchronization function values for each link.
[0194] Aspect 53: A method for performing wireless communication at a first wireless communication device, the method comprising: generating a packet number for a frame to be transmitted to a second wireless communication device, the packet number comprising a first subset of bits corresponding to a portion of a timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and transmitting the frame to the second wireless communication device, the frame comprising a portion containing the packet number.
[0195] Aspect 54: According to the method of aspect 53, the frame includes a header portion, and the group number is used to protect the contents of the header portion.
[0196] Aspect 55: The method according to any one of Aspects 53 to 54, wherein the frame is a control frame and the group number is used to protect the content of the control frame.
[0197] Aspect 56: The method according to any one of Aspects 53 to 55, wherein the content of the frame is protected by an integrity check or by encryption of the content to be protected, the integrity check generating a message integrity check (MIC) across the content so protected.
[0198] Aspect 57: The method according to any one of Aspects 53 to 56, wherein generating the group number comprises: generating the portion of the timing synchronization function value as a truncated version of the timing synchronization function value; and appending the counter value to the portion of the timing synchronization function value.
[0199] Aspect 58: According to the method of aspect 57, the truncated version of the timing synchronization function value is truncated by removing a certain number of least significant bits of the timing synchronization function value.
[0200] Aspect 59: The method according to any one of Aspects 57 to 58, the method further comprising: communicating with the second wireless communication device to negotiate the number of bits to be truncated from the timing synchronization function value.
[0201] Aspect 60: The method according to aspect 59, wherein the number of bits to be truncated is different for different traffic flows, and the number of bits to be truncated is based at least in part on the listening interval of the first wireless communication device or the second wireless communication device or any combination thereof.
[0202] Aspect 61: The method according to any one of Aspects 57 to 60, wherein the truncated version of the timing synchronization function value is truncated by an amount, the amount being at least partially based on a potential clock drift between the first wireless communication device and the second wireless communication device.
[0203] Aspect 62: The method according to any one of Aspects 53 to 61, wherein the first wireless communication device is a non-multilink device (MLD) non-access point (AP) STA or a non-AP STA attached to a non-AP MLD, and the second wireless communication device is a non-MLD AP or an AP attached to an AP MLD, or the first wireless communication device is a non-MLD AP or an AP attached to an AP MLD, and the second wireless communication device is a non-AP MLD non-AP STA or a non-AP STA attached to a non-AP MLD, and when the non-AP STA transitions to a wake-up state, the non-AP STA synchronizes its timing synchronization function with the corresponding timing synchronization function at the associated AP operating on the link.
[0204] Aspect 63: The method according to any one of aspects 53 to 62, wherein the portion of the timing synchronization function value corresponds to a time window of an acceptable timing synchronization function value, the time window being a specified time window or having a duration negotiated with the second wireless communication device.
[0205] Aspect 64: The method according to any one of Aspects 53 to 63, wherein the frame is a first frame having a first portion of the timing synchronization function value and a first counter value, and a second frame transmitted after the first frame has the first portion of the timing synchronization function value and a second counter value, the second counter value being a value incremented from the first counter value.
[0206] Aspect 65: According to the method of aspect 64, wherein in response to a change in the portion of the timing synchronization function value, the subsequent counter value of the subsequent frame of the second frame is reset to zero.
[0207] Aspect 66: The method according to any one of aspects 53 to 65, the method further comprising: communicating with the second wireless communication device to negotiate a tolerance between the timing synchronization function value and a corresponding timing synchronization function value at the second wireless communication device, the tolerance allowing the frame to be processed at the second wireless communication device.
[0208] Aspect 67: The method according to any one of aspects 53 to 66, the method further comprising: updating the encryption key associated with communication between the first wireless communication device and the second wireless communication device in response to the packet number being reset to an initial value.
[0209] Aspect 68: The method according to any one of aspects 53 to 67, wherein the first wireless communication device is a multi-link device (MLD) operating on multiple links, and wherein a separate timing synchronization function is maintained at each link.
[0210] Aspect 69: The method according to any one of Aspects 53 to 68, wherein the first wireless communication device is a multi-link device (MLD) operating on multiple links, and wherein the same timing synchronization function is used to generate timing synchronization function values for each link.
[0211] Aspect 70: A method for performing wireless communication at a second wireless communication device, the method comprising: receiving a frame including a packet number, the packet number including a first subset of bits corresponding to a first timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and processing the frame at least in part based on whether a time value indicated by the first subset of bits corresponds to a local time maintained at the second wireless communication device.
[0212] Aspect 71: According to the method of aspect 70, the frame includes a header portion, and the group number is used to protect the contents of the header portion.
[0213] Aspect 72: The method according to any one of Aspects 70 to 71, wherein the frame is a control frame and the group number is used to protect the content of the control frame.
[0214] Aspect 73: The method according to any one of aspects 70 to 72, the method further comprising: generating a second timing synchronization function value as a truncated version of the time value of the timing synchronization function at the second wireless communication device, wherein the local time maintained at the second wireless communication device corresponds to the second timing synchronization function value, and wherein the frame is processed at least in part based on the second timing synchronization function value matching the first timing synchronization function value.
[0215] Aspect 74: The method according to aspect 73, the method further comprising: communicating with a first wireless communication device to negotiate the number of bits to be truncated from the time value of the timing synchronization function, wherein the frame is transmitted by the first wireless communication device.
[0216] Aspect 75: The method according to aspect 74, wherein the number of bits to be truncated is different for different traffic flows, and the number of bits to be truncated is based at least in part on the listening interval of the first wireless communication device or the second wireless communication device or any combination thereof.
[0217] Aspect 76: The method according to any one of aspects 73 to 75, wherein the truncated version of the time value of the timing synchronization function allows clock drift between the second wireless communication device and at least the first wireless communication device.
[0218] Aspect 77: The method according to any one of Aspects 70 to 76, wherein the second wireless communication device is a non-multilink device (MLD) AP or an AP attached to an AP MLD and communicates with a first wireless communication device, the first wireless communication device being a non-MLD non-AP STA or a non-AP STA attached to a non-AP MLD, or the first wireless communication device being a non-MLD AP or an AP attached to an AP MLD, and the second wireless communication device being a non-AP MLD non-AP STA or a non-AP STA attached to a non-AP MLD, and when the non-AP STA transitions to a wake-up state, the non-AP STA synchronizes its timing synchronization function with the corresponding timing synchronization function at the associated AP operating on the link.
[0219] Aspect 78: The method according to any one of aspects 70 to 77, wherein the first timing synchronization function value corresponds to a time window of an acceptable timing synchronization function value, the time window being a specified time window or having a duration negotiated with the first wireless communication device.
[0220] Aspect 79: The method according to any one of Aspects 70 to 78, wherein the frame is a first frame having a first timing synchronization function value and a first counter value, and a second frame transmitted after the first frame has the first timing synchronization function value and a second counter value, the second counter value being a value incremented from the first counter value.
[0221] Aspect 80: According to the method of aspect 79, wherein in response to a change in the value of the first timing synchronization function, the value of the subsequent counter of the subsequent frame of the second frame is reset to zero.
[0222] Aspect 81: The method according to any one of aspects 70 to 80, the method further comprising: comparing a first subset of bits with a third subset of bits, the third subset of bits corresponding to a second timing synchronization function value generated at the second wireless communication device and associated with the time of receiving the frame.
[0223] Aspect 82: According to the method of aspect 81, the method further includes: discarding the frame in response to a mismatch between the first subset of bits and the third subset of bits.
[0224] Aspect 83: The method according to any one of aspects 81 to 82, the method further comprising: determining, in response to a match between the first subset of bits and the third subset of bits, that the frame is a received initial frame having the first timing synchronization function value, or determining that the counter value exceeds a previous counter value of a previous frame having the first timing synchronization function value; and processing the frame.
[0225] Aspect 84: The method according to any one of aspects 81 to 83, the method further comprising: discarding the frame in response to the counter value of the frame being equal to or less than a previously received counter value having the first timing synchronization function value.
[0226] Aspect 85: The method according to any one of aspects 70 to 84, the method further comprising: recording the first timing synchronization function value and the counter value for processing subsequent frame headers.
[0227] Aspect 86: The method according to any one of Aspects 70 to 85, the method further comprising: communicating with a first wireless communication device to negotiate a tolerance between the first timing synchronization function value and a corresponding timing synchronization function value at the first wireless communication device, the tolerance allowing the frame to be processed at the second wireless communication device.
[0228] Aspect 87: The method according to any one of aspects 70 to 86, the method further comprising: updating the encryption key associated with communication between the second wireless communication device and the first wireless communication device in response to the packet number being reset to an initial value.
[0229] Aspect 88: The method according to any one of Aspects 70 to 87, wherein the second wireless device is a multi-link device (MLD) operating on multiple links, and wherein a separate timing synchronization function is maintained at each link.
[0230] Aspect 89: The method according to any one of Aspects 70 to 88, wherein the first wireless communication device is a multi-link device (MLD) operating on multiple links, and wherein the same timing synchronization function is used to generate timing synchronization function values for each link.
[0231] Aspect 90: A method for performing wireless communication at a first wireless communication device, the method comprising: generating a message integrity check (MIC) field for a frame to be transmitted to a second wireless communication device; performing an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of a timing synchronization function value associated with the frame; and transmitting the frame including the XORed MIC field to the second wireless communication device.
[0232] Aspect 91: According to the method of aspect 90, wherein the MIC field is generated during the encryption of the frame.
[0233] Aspect 92: The method according to any one of aspects 90 to 91, wherein the portion of the timing synchronization function value is a truncated version of the timing synchronization function value at the first wireless communication device.
[0234] Aspect 93: According to the method of aspect 92, the truncated version of the timing synchronization function value is truncated by removing a certain number of least significant bits of the timing synchronization function value.
[0235] Aspect 94: The method according to any one of Aspects 92 to 93, wherein the truncated version of the timing synchronization function value is truncated by an amount, the amount being at least partially based on a potential clock drift between the first wireless communication device and at least the second wireless communication device.
[0236] Aspect 95: The method according to any one of Aspects 92 to 94, wherein the truncated version of the timing synchronization function value is truncated by removing a certain number of least significant bits of the timing synchronization function value.
[0237] Aspect 96: The method according to any one of aspects 90 to 95, the method further comprising: retransmitting data included in the frame in a subsequent frame, wherein the subsequent frame includes an XORed MIC field based on an updated value of a corresponding subsequent timing synchronization function associated with the subsequent frame.
[0238] Aspect 97: The method according to aspect 96, wherein when the frame is retransmitted, the content of the subsequent frame is not re-encrypted.
[0239] Aspect 98: The method according to any one of aspects 90 to 97, wherein the frame is a data frame or a management frame.
[0240] Aspect 99: A method for performing wireless communication at a second wireless communication device, the method comprising: receiving a frame including a Message Integrity Check (MIC) field; performing an XOR function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of a timing synchronization function value associated with a reception time of the frame; and processing the XORed MIC field to determine the frame integrity of the frame.
[0241] Aspect 100: According to the method of aspect 99, the portion of the timing synchronization function value is a truncated version of the timing synchronization function value at the second wireless communication device.
[0242] Aspect 101: According to the method of aspect 100, the truncated version of the timing synchronization function value is truncated by an amount, the amount being at least partially based on a potential clock drift between the second wireless communication device and the first wireless communication device.
[0243] Aspect 102: The method according to any one of aspects 99 to 101, the method further comprising: decrypting the frame; generating a received frame MIC field based on the decrypted frame; and discarding the frame in response to a mismatch between the received frame MIC field and the XORed MIC field, or decoding the frame in response to a match between the received frame MIC field and the XORed MIC field.
[0244] Aspect 103: The method according to any one of aspects 99 to 102, wherein the second wireless communication device is a multi-link device (MLD) operating on multiple links, and wherein a separate timing synchronization function is maintained at each link.
[0245] Aspect 104: The method according to any one of aspects 99 to 103, wherein the first wireless communication device is a multi-link device (MLD) operating on multiple links, and wherein the same timing synchronization function is used to generate timing synchronization function values for each link.
[0246] As used herein, the term "determine" encompasses a wide variety of actions, and therefore, "determine" can include calculation, computation, processing, derivation, estimation, investigation, searching (such as by searching in a table, database, or other data structure), reasoning, probing, or measurement, among other possibilities. Furthermore, "determine" can include receiving (such as receiving information), accessing (such as accessing data stored in memory), or sending (such as sending information), among other possibilities. Additionally, "determine" can include parsing, selecting, obtaining, choosing, building, and other similar actions.
[0247] As used herein, the phrase “at least one of” or “one or more of” refers to any combination of these items, including a single member. For example, “at least one of a, b, or c” is intended to cover: a, b, c, ab, ac, bc, and abc. As used herein, “or” is intended to be interpreted as inclusive unless otherwise explicitly stated. For example, “a or b” could include only a, only b, or a combination of a and b. Furthermore, as used herein, the phrase referring to “one” element means one or more of such elements that act individually or collectively to perform the stated function. Additionally, “set” refers to one or more items, and “subset” refers to less than the entire set, but not empty.
[0248] As used herein, unless otherwise expressly indicated, “based on” is intended to be interpreted in an inclusive sense. For example, unless otherwise explicitly indicated, “based on” may be used interchangeably with “at least partially based on,” “associated with,” “associated with,” or “according to.” Specifically, unless the phrase in the context means “based on only one” or an equivalent, whether it is “based on one” or “at least partially based on one”, it may be based solely on “one” or based on a combination of “one” and one or more other factors, conditions, or information.
[0249] The various exemplary components, logic units, logic blocks, modules, circuits, operations, and algorithmic processes described in conjunction with the examples disclosed herein can be implemented as electronic hardware, firmware, software, or a combination of hardware, firmware, or software, including the structures disclosed in this specification and their structural equivalents. This interchangeability of hardware, firmware, and software has been generally described in terms of its functionality and exemplified in the various exemplary components, blocks, modules, circuits, and processes described above. Whether this functionality is implemented in hardware, firmware, or software depends on the specific application and the design constraints imposed on the overall system.
[0250] Various modifications to the examples described herein will be apparent to those skilled in the art, and the general principles defined herein may be applied to other examples without departing from the spirit or scope of this disclosure. Therefore, the claims are not intended to be limited to the examples shown herein, but are to be granted the widest scope consistent with this disclosure, the principles disclosed herein, and the novel features.
[0251] Furthermore, the various features described in the context of individual examples in this specification may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple examples. Thus, although features may be described above as functioning in a particular combination, and even initially claimed in this way, one or more features from the claimed combination may be removed from the combination in some cases, and the claimed combination may involve sub-combinations or variations of sub-combinations.
[0252] Similarly, although operations are depicted in a specific order in the diagrams, this should not be construed as requiring such operations to be performed in the specific order shown or in sequential order, or to perform all illustrated operations to achieve the desired result. Furthermore, the accompanying figures may schematically depict one or more example processes in the form of flowcharts or flow diagrams. However, other operations not depicted may be incorporated into the schematically illustrated example processes. For example, one or more additional operations may be performed before, after, simultaneously with, or between any of the illustrated operations. In some environments, multitasking and parallel processing may be advantageous. Moreover, the separation of various system components in the examples described above should not be construed as requiring such separation in all examples, but rather should be understood as meaning that the described program components and systems can generally be integrated together in a single software product or encapsulated in multiple software products.
Claims
1. A first wireless communication device, the first wireless communication device comprising: a processing system comprising a processor circuit and a memory circuit storing code, the processing system configured to cause the first wireless communication device to: generate a packet number for a frame to be transmitted to a second wireless communication device, the packet number comprising a first subset of bits of a portion associated with the frame corresponding to a timing synchronization function value and a second subset of bits corresponding to a counter value; and transmit the frame to the second wireless communication device, the frame comprising a portion containing the packet number.
2. The first wireless communication device of claim 1, wherein the frame comprises a header portion and the packet number is used to protect contents of the header portion.
3. The first wireless communication device of claim 1, wherein the frame is a control frame and the packet number is used to protect contents of the control frame.
4. The first wireless communication device of claim 1, wherein to generate the packet number, the processing system is configured to cause the first wireless communication device to: generate the portion of the timing synchronization function value as a truncated version of the timing synchronization function value; and append the counter value to the portion of timing synchronization function value.
5. The first wireless communication device of claim 4, wherein the truncated version of the timing synchronization function value is truncated by removing a number of least significant bits of the timing synchronization function value.
6. The first wireless communication device of claim 4, wherein the processing system is further configured to cause the first wireless communication device to: communicate with the second wireless communication device to negotiate a number of bits to truncate from the timing synchronization function value.
7. The first wireless communication device of claim 6, wherein the number of bits to truncate is different for different traffic streams, the number of bits to truncate based at least in part on a listen interval of the first wireless communication device or the second wireless communication device or any combination thereof.
8. The first wireless communication device of claim 4, wherein the truncated version of the timing synchronization function value is truncated by an amount based at least in part on a potential clock drift between the first wireless communication device and the second wireless communication device.
9. The first wireless communication device of claim 1, wherein: the first wireless communication device is a non-multi-link device (MLD) non-access point (AP) station (STA) or a non-AP STA affiliated with a non-AP MLD and the second wireless communication device is a non-MLD AP or an AP affiliated with an AP MLD, or the first wireless communication device is a non-MLD AP or an AP affiliated with an AP MLD and the second wireless communication device is a non-AP MLD non-AP STA or a non-AP STA affiliated with a non-AP MLD, and upon the non-AP STA transitioning to an awake state, the non-AP STA synchronizes its timing synchronization function with a corresponding timing synchronization function at an associated AP operating on the link.
10. The first wireless communication device of claim 1, wherein the portion of the timing synchronization function value corresponds to a window of time of acceptable timing synchronization function values, the window of time being a designated window of time or having a duration negotiated with the second wireless communication device.
11. The first wireless communication device of claim 1, wherein the frame is a first frame having a first portion of the timing synchronization function value and a first counter value, and a second frame transmitted after the first frame has the first portion of the timing synchronization function value and a second counter value, the second counter value being a value incremented from the first counter value.
12. The first wireless communication device of claim 11, wherein responsive to a change in the portion of the timing synchronization function value, a subsequent counter value of a subsequent frame of the second frame is reset to zero.
13. The first wireless communication device of claim 1, wherein the processing system is further configured to cause the first wireless communication device to: communicate with the second wireless communication device to negotiate a tolerance between the timing synchronization function value and a corresponding timing synchronization function value at the second wireless communication device, the tolerance allowing the frame to be processed at the second wireless communication device.
14. The first wireless communication device of claim 1, wherein the processing system is further configured to cause the first wireless communication device to: responsive to the packet number being reset to an initial value, perform a key update of an encryption key associated with communications between the first wireless communication device and the second wireless communication device.
15. The first wireless communication device of claim 1, wherein the first wireless communication device is a multi-link device (MLD) operating on multiple links, and wherein a separate timing synchronization function is maintained at each link.
16. The first wireless communication device of claim 1, wherein the first wireless communication device is a multi-link device (MLD) operating on multiple links, and wherein a same timing synchronization function is used to generate a timing synchronization function value for each link.
17. A second wireless communication device, the second wireless communication device comprising: a processing system comprising a processor circuit and a memory circuit storing code, the processing system configured to cause the second wireless communication device to: receive a frame comprising a packet number, the packet number including a first subset of bits corresponding to a first timing synchronization function value associated with the frame and a second subset of bits corresponding to a counter value; and process the frame based at least in part on whether a time value indicated by the first subset of bits corresponds to a local time maintained at the second wireless communication device.
18. The second wireless communication device of claim 17, wherein the processing system is further configured to cause the second wireless communication device to: generating a second timing synchronization function value as a truncated version of a time value of a timing synchronization function at the second wireless communication device, wherein the local time maintained at the second wireless communication device corresponds to the second timing synchronization function value, and wherein the frame is processed based at least in part on the second timing synchronization function value matching the first timing synchronization function value.
19. The second wireless communication device of claim 17, wherein the processing system is further configured to cause the second wireless communication device to: compare the first subset of bits to a third subset of bits, the third subset of bits corresponding to a second timing synchronization function value generated at the second wireless communication device and associated with a time of receiving the frame.
20. The second wireless communication device of claim 19, wherein the processing system is further configured to cause the second wireless communication device to: discard the frame in response to a mismatch between the first subset of bits and the third subset of bits.
21. The second wireless communication device of claim 19, wherein the processing system is further configured to cause the second wireless communication device to: determine, in response to a match between the first subset of bits and the third subset of bits, that the frame is a received initial frame having the first timing synchronization function value or that the counter value exceeds a previous counter value of a previous frame having the first timing synchronization function value; and process the frame.
22. The second wireless communication device of claim 19, wherein the processing system is further configured to cause the second wireless communication device to: discard the frame in response to the counter value of the frame being equal to or less than a previously received counter value having the first timing synchronization function value.
23. A first wireless communication device, the first wireless communication device comprising: a processing system comprising a processor circuit and a memory circuit storing code, the processing system configured to cause the first wireless communication device to: generate a message integrity check (MIC) field for a frame to be transmitted to a second wireless communication device; perform an exclusive OR (XOR) function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of a timing synchronization function value associated with the frame; and transmit the frame including the XORed MIC field to the second wireless communication device.
24. The first wireless communication device of claim 23, wherein the MIC field is generated during encryption of the frame.
25. The first wireless communication device of claim 23, wherein the portion of the timing synchronization function value is a truncated version of the timing synchronization function value at the first wireless communication device.
26. The first wireless communication device of claim 23, wherein the processing system is further configured to cause the first wireless communication device to: to retransmit data included in the frame in a subsequent frame, wherein the subsequent frame includes an updated XORed MIC field based on a corresponding subsequent timing synchronization function value associated with the subsequent frame.
27. The first wireless communication device of claim 26, wherein when the frame is retransmitted, contents of the subsequent frame are not re-encrypted.
28. The first wireless communication device of claim 23, wherein the frame is a data frame or a management frame.
29. A second wireless communication device, the second wireless communication device comprising: a processing system including a processor circuit and a memory circuit storing code, the processing system configured to cause the second wireless communication device to: receive a frame including a message integrity check (MIC) field; perform an exclusive OR (XOR) function on the MIC field to generate an XORed MIC field, wherein bits of the MIC field are XORed with a set of bits corresponding to a portion of a timing synchronization function value associated with a time of receipt of the frame; and process the XORed MIC field to determine frame integrity of the frame.
30. The second wireless communication device of claim 29, wherein the processing system is further configured to cause the second wireless communication device to: decrypt the frame; generate a received frame MIC field based on the decrypted frame; and discard the frame in response to a mismatch between the received frame MIC field and the XORed MIC field, or decode the frame in response to a match between the received frame MIC field and the XORed MIC field.