Security control frame in wireless communication
By using a two-part Control Message Integrity Check (CMF) field to verify control frames in wireless communication, the problem of wireless communication caused by malicious attacks is solved, achieving more efficient security and resource utilization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- QUALCOMM INC
- Filing Date
- 2024-12-20
- Publication Date
- 2026-08-04
AI Technical Summary
In wireless communication, malicious attackers may attack control information frames, leading to denial of service, UE power consumption, and waste of radio frequency resources. Existing technologies are insufficient to effectively protect the security of control frames.
The Control Message Integrity Check (CMF) field is divided into two parts. The first part includes the ID of the security key, and the second part includes a truncated integrity check. The validity of the control frame is verified by comparing the truncated integrity check, and the verification is performed in combination with the partial block number (PN) and the security key.
It improves the security of control frames, avoids the waste of power and radio frequency resources caused by invalid frames, improves frame verification efficiency, and reduces memory usage and processing time.
Smart Images

Figure CN122514929A_ABST
Abstract
Description
[0001] Cross-references
[0002] This patent application claims priority to Indian Patent Application No. 202441002125, filed on January 11, 2024, entitled “SECURECONTROL FRAMES IN WIRELESS COMMUNICATIONS”, which is assigned to the assignee of this application and is expressly incorporated herein by reference. Technical Field
[0003] This disclosure relates in general to wireless communications, and more specifically to the security of control frames in wireless communications. Background Technology
[0004] A Wireless Local Area Network (WLAN) can be formed by one or more wireless access points (APs) that provide a shared wireless communication medium for use by multiple client devices (also known as wireless stations (STAs)). The basic building block of a WLAN conforming to the IEEE 802.11 family of standards is the Basic Service Set (BSS) managed by the AP. Each BSS is identified by a Basic Service Set Identifier (BSSID) advertised by the AP. The AP periodically broadcasts beacon frames to enable any STA within the AP's wireless range to establish or maintain a communication link with the WLAN.
[0005] In some WLANs, APs and STAs can participate in reliable (such as Ultra-High Reliability (UHR)) communication. UHR communication relies on the transmission of control information for various purposes, such as acknowledgment, Network Assignment Vector (NAV) setting, probing, triggering, and cross-link control signaling. In some cases, malicious actors can attack wireless communications by targeting frames containing control information. Such attacks can lead to denial of service, power consumption at the UE, reduced communication reliability, and wasted radio frequency resources. Summary of the Invention
[0006] The systems, methods, and apparatus disclosed herein each have some innovative aspects, and no single aspect is solely responsible for the desired properties disclosed herein.
[0007] One innovative aspect of the subject matter described in this disclosure can be implemented by an apparatus in a method for wireless communication. The method may include: obtaining a control frame including a first portion of a control message integrity check field (CMF) and a second portion of the CMF, the first portion of the CMF including an identifier (ID) of a security key, and the second portion of the CMF including a truncated first integrity check; and verifying the validity of the control frame based on a comparison of the truncated first integrity check and the second integrity check, wherein the second integrity check is based at least on the security key, a partial block number (PN) associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.
[0008] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the apparatus to: obtain a control frame comprising a first portion and a second portion of a CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated first integrity check; and verify the validity of the control frame based on a comparison of the truncated first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.
[0009] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include: components for obtaining a control frame including a first portion of a security function (CMF) and a second portion of the CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated first integrity check; and components for verifying the validity of the control frame based on a comparison of the truncated first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.
[0010] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communication. The code may include instructions executable by one or more processors to: obtain a control frame comprising a first portion and a second portion of a CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated first integrity check; and verify the validity of the control frame based on a comparison of the truncated first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.
[0011] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the CMF includes the partial PN, and the partial PN included in the CMF may be combined with the basic PN associated with the control frame to obtain the complete PN associated with the control frame, wherein the second integrity check may be based on the complete PN.
[0012] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the second integrity check may be truncated to include a subset of bits of the authentication code output, which may be based at least on the security key, the portion PN, and one or more portions of the control frame.
[0013] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the first portion of the CMF includes the portion PN. In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the first portion of the CMF may be provided at a first deterministic location within the control information portion of the control frame, the first deterministic location being prior to one or more fields protected by the truncated first integrity check, and the second portion of the CMF may be provided at a second deterministic location within the control information portion of the control frame, the second deterministic location being subsequent to the one or more fields protected by the truncated first integrity check.
[0014] In some examples of the methods, apparatuses and nontransitory computer-readable media described herein, the number of padding bits following the second portion of the CMF may be a fixed value that can be announced via one or more management frames, or it may be a value that can be signaled before the first portion of the CMF.
[0015] Another innovative aspect of the subject matter described in this disclosure can be implemented by an apparatus in a method for wireless communication. The method may include: obtaining a frame including a CMF (Media Access Control File), the CMF including an Associated Identifier (AID), an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from a Media Access Control address associated with the frame; and verifying the validity of the frame based on a comparison of the first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key associated with the AID and the PN indication.
[0016] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the apparatus to: acquire a frame including a CMF (Content Management Function), the CMF including an AID, an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame; and verify the validity of the frame based on a comparison of the first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key associated with the AID and the PN indication.
[0017] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include: components for acquiring a frame including a CMF (Media Access Control File), the CMF including an AID, an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame; and components for verifying the validity of the frame based on a comparison of the first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key associated with the AID and the PN indication.
[0018] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communication. The code may include instructions executable by one or more processors to: obtain a frame including a CMF (Media Access Control File), the CMF including an AID, an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame; and verify the validity of the frame based on a comparison of the first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key associated with the AID and the PN indication.
[0019] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the AID may be provided in one or more Media Access Control (MAC) Protocol Data Units (MPDUs) having a secure MAC header that solicits protected control frames.
[0020] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the one or more frames soliciting protected control frames include an indication requesting protected control frames.
[0021] Another innovative aspect of the subject matter described in this disclosure can be implemented by an apparatus in a method for wireless communication. The method may include: obtaining an indication that one of a Group Temporary Key (GTK) mode or a Paired Temporary Key (PTK) mode is configured for controlling frame security; generating a control frame including a CMF (Security Key File), the CMF including a security key ID, a PN (Programmable Node) indication, and a first integrity check, wherein the first integrity check is calculated based on the indication for the GTK mode or the PTK mode using GTK or PTK; and outputting the control frame for transmission.
[0022] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the apparatus to: obtain an indication that one of a GTK mode or a PTK mode is configured for controlling frame security; generate a control frame including a CMF (Content Management Function), the CMF including a security key ID, a PN (Programmable Node) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication of the GTK mode or PTK mode; and output the control frame for transmission.
[0023] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include: components for obtaining an indication of either a GTK mode or a PTK mode configured for controlling frame security; components for generating a control frame including a CMF (Content Management Function), the CMF including a security key ID, a PN (Programmable Node) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication of the GTK mode or PTK mode; and components for outputting the control frame for transmission.
[0024] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communication. The code may include instructions executable by one or more processors to: obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security; generate a control frame including a CMF (Content Management Function), the CMF including a security key ID, a PN (Passive Indicator) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication for the GTK mode or the PTK mode; and output the control frame for transmission.
[0025] In some examples of the methods, apparatuses and nontransitory computer-readable media described herein, the control frame may be a group control frame or a single control frame, wherein the group control frame may be protected by the GTK according to the GTK mode or the PTK mode, and the single control frame may be protected by the PTK according to the PTK mode or by the GTK according to the GTK mode.
[0026] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the indication for controlling frame security, either the GTK mode or the PTK mode, may be a dynamic indication that provides dynamic switching between the GTK mode and the PTK mode.
[0027] Another innovative aspect of the subject matter described in this disclosure can be implemented by an apparatus in a method for wireless communication. The method may include: obtaining a control frame comprising a set of multiple padding bits preceding a CMF and an end-of-frame field, wherein the number of the set of multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on a security type associated with the control frame; and decoding the control frame according to the number of the set of multiple padding bits.
[0028] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the apparatus to: obtain a control frame comprising a set of multiple padding bits preceding a CMF and an end-of-frame field, wherein the number of the set of multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on a security type associated with the control frame; and decode the control frame according to the number of the set of multiple padding bits.
[0029] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include: means for obtaining a control frame including a set of multiple padding bits preceding a CMF and a frame end field, wherein the number of the set of multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on a security type associated with the control frame; and means for decoding the control frame according to the number of the set of multiple padding bits.
[0030] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communication. The code may include instructions executable by one or more processors to: obtain a control frame comprising a set of multiple padding bits preceding a CMF and an end-of-frame field, wherein the number of the set of multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on a security type associated with the control frame; and decode the control frame according to the number of the set of multiple padding bits.
[0031] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, an unprotected control frame includes a first number of padding bits, which is less than a second number of padding bits associated with a protected control frame.
[0032] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the unencrypted protected control frame includes the second number of padding bits, and wherein the second number of padding bits is less than the third number of padding bits associated with the encrypted protected control frame.
[0033] Another innovative aspect of the subject matter described in this disclosure can be implemented by an apparatus in a method for wireless communication. The method may include: generating a control frame comprising a first portion of a security key (CMF) and a second portion of the CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame; and outputting the control frame for transmission.
[0034] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the apparatus to: generate a control frame including a first portion and a second portion of a CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame; and output the control frame for transmission.
[0035] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include: components for generating a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame; and components for outputting the control frame for transmission.
[0036] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communication. The code may include instructions executable by one or more processors to: generate a control frame including a first portion and a second portion of a CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame; and output the control frame for transmission.
[0037] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the CMF includes the partial PN, and the partial PN included in the CMF can be combined with the basic PN associated with the control frame to provide the complete PN associated with the control frame, wherein the truncated integrity check includes a subset of bits of a full integrity check based on the complete PN.
[0038] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the first portion of the CMF includes the portion PN. In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the first portion of the CMF may be provided at a first deterministic location within the control information portion of the control frame, the first deterministic location being prior to one or more fields that may be protected by the truncated integrity check, and the second portion of the CMF may be provided at a second deterministic location within the control information portion of the control frame, the second deterministic location being subsequent to the one or more fields that may be protected by the truncated integrity check.
[0039] In some examples of the methods, apparatuses and nontransitory computer-readable media described herein, the number of padding bits following the second portion of the CMF may be a fixed value announced via one or more management frames, or it may be a value signaled before the first portion of the CMF.
[0040] Another innovative aspect of the subject matter described in this disclosure can be implemented by an apparatus in a method for wireless communication. The method may include: generating a frame including a CMF (Media Access Control Format), the CMF including an AID, an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from a Media Access Control address associated with the frame, and wherein the first integrity check is based at least on the security key associated with the AID and the PN indication; and outputting the frame for transmission.
[0041] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the apparatus to: generate a frame including a CMF (Content Management Function), the CMF including an AID, an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame, and wherein the first integrity check is based at least on the security key associated with the AID and the PN indication; and output the frame for transmission.
[0042] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include: components for generating a frame including a CMF (Media Access Control File), the CMF including an AID, an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from a Media Access Control address associated with the frame, and wherein the first integrity check is based at least on the security key associated with the AID and the PN indication; and components for outputting the frame for transmission.
[0043] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communication. The code may include instructions executable by one or more processors to: generate a frame including a CMF (Media Access Control Format), the CMF including an AID, an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame, and wherein the first integrity check is based at least on the security key associated with the AID and the PN indication; and output the frame for transmission.
[0044] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the AID may be provided in one or more MPDUs having a secure MAC header that solicits protected control frames.
[0045] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the one or more frames soliciting protected control frames include an indication requesting protected control frames.
[0046] Another innovative aspect of the subject matter described in this disclosure can be implemented by an apparatus in a method for wireless communication. The method may include: obtaining an indication that one of a GTK mode or a PTK mode is configured for control frame security; generating a control frame including a CMF (Security Key Function), the CMF including a security key ID, a PN (Programmable Node) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication for the GTK mode or the PTK mode; and outputting the control frame for transmission.
[0047] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the apparatus to: obtain an indication that one of a GTK mode or a PTK mode is configured for controlling frame security; generate a control frame including a CMF (Content Management Function), the CMF including a security key ID, a PN (Programmable Node) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication of the GTK mode or PTK mode; and output the control frame for transmission.
[0048] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include: components for obtaining an indication of either a GTK mode or a PTK mode configured for controlling frame security; components for generating a control frame including a CMF (Content Management Function), the CMF including a security key ID, a PN (Programmable Node) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication of the GTK mode or PTK mode; and components for outputting the control frame for transmission.
[0049] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communication. The code may include instructions executable by one or more processors to: obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security; generate a control frame including a CMF (Content Management Function), the CMF including a security key ID, a PN (Passive Indicator) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication for the GTK mode or the PTK mode; and output the control frame for transmission.
[0050] In some examples of the methods, apparatuses and nontransitory computer-readable media described herein, the control frame may be a group control frame or a single control frame, wherein the group control frame utilizes the GTK according to the GTK mode or the PTK mode for protection, and the single control frame utilizes the PTK according to the PTK mode or utilizes the GTK according to the GTK mode for protection.
[0051] In some examples of the methods, apparatuses, and nontransitory computer-readable media described herein, the indication configured for control frame security of either the GTK mode or the PTK mode may be a dynamic indication that provides dynamic switching between the GTK mode and the PTK mode.
[0052] Another innovative aspect of the subject matter described in this disclosure can be implemented by an apparatus in a method for wireless communication. The method may include: generating a control frame including a set of multiple padding bits preceding a CMF and a frame end field, wherein the number of the multiple padding bits in the set is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on a security type associated with the secure control frame; and outputting the control frame for transmission.
[0053] Another inventive aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include a processing system comprising processor circuitry and memory circuitry storing code. The processing system may be configured to cause the apparatus to: generate a control frame including a set of padding bits preceding a CMF and a frame end field, wherein the number of the set of padding bits is based on whether the control frame is a secure control frame, and, when the control frame is a secure control frame, based on a security type associated with the control frame; and output the control frame for transmission.
[0054] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The apparatus may include: components for generating a control frame including a CMF and a set of multiple padding bits preceding a frame end field, wherein the number of the multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on a security type associated with the control frame; and components for outputting the control frame for transmission.
[0055] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communication. The code may include instructions executable by one or more processors to: generate a control frame including a set of multiple padding bits preceding a CMF and a frame end field, wherein the number of such multiple padding bits is based on whether the control frame is a secure control frame, and, when the control frame is a secure control frame, based on a security type associated with the control frame; and output the control frame for transmission.
[0056] Details of one or more specific embodiments of the subject matter described in this disclosure are set forth in the accompanying drawings and the following description. Other features, aspects, and advantages will become apparent from the description, drawings, and claims. Note that the relative dimensions in the following drawings may not be drawn to scale. Attached Figure Description
[0057] Figure 1 A schematic diagram of an example wireless communication network is shown.
[0058] Figure 2 An example Protocol Data Unit (PDU) is shown that can be used for communication between a wireless access point (AP) and one or more wireless stations (STA).
[0059] Figure 3 An example physical layer (PHY) protocol data unit (PPDU) capable of being used for communication between a wireless AP and one or more wireless STAs is shown.
[0060] Figure 4A hierarchical format of an example PPDU that can be used for communication between a wireless AP and one or more wireless STAs is shown.
[0061] Figure 5 An example signaling diagram supporting secure control frames in wireless communication is shown.
[0062] Figure 6 An example is shown that supports the Control Message Integrity Check (CMF) field in a secure control frame for wireless communication.
[0063] Figure 7 An example CMF location supporting security control frames in wireless communication is shown.
[0064] Figure 8 An example of security control frame padding supporting security control frames in wireless communication is shown.
[0065] Figure 9 An example of the process flow supporting security control frames in wireless communication is shown.
[0066] Figure 10 An example of the process flow supporting security control frames in wireless communication is shown.
[0067] Figure 11 A block diagram of an example wireless communication device that supports security control frames in wireless communication is shown.
[0068] Figure 12 A block diagram of an example wireless communication device that supports security control frames in wireless communication is shown.
[0069] Figures 13 to 20 A flowchart illustrating an example process that can be performed by or at a device that supports security control frames in wireless communication is shown.
[0070] The same reference numerals and names in different figures denote the same elements. Detailed Implementation
[0071] The following description refers to certain specific examples in order to illustrate the innovative aspects of this disclosure. However, those skilled in the art will readily recognize that the teachings herein can be applied in a variety of different ways. Some or all of the examples described can be applied in accordance with the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, the IEEE 802.15 standard, or Bluetooth as defined by the Bluetooth Special Interest Group (SIG). ®It is implemented in any device, system, or network that transmits and receives radio frequency (RF) signals using one or more of the standards such as Long Term Evolution (LTE), 3G, 4G, 5G (New Radio (NR)), or 6G standards published by the 3rd Generation Partnership Project (3GPP).
[0072] The described examples can be implemented in any suitable device, component, system, or network capable of transmitting and receiving RF signals according to one or more of the following technologies or techniques: Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Orthogonal Frequency Division Multiplexing (OFDM), Frequency Division Multiple Access (FDMA), Orthogonal FDMA (OFDMA), Single Carrier FDMA (SC-FDMA), Space Division Multiple Access (SDMA), Rate Split Multiple Access (RSMA), Multi-User Shared Access (MUSA), Single-User (SU) Multiple-Input Multiple-Output (MIMO), and Multi-User (MU)-MIMO (MU-MIMO). The described examples can also be implemented using other wireless communication protocols or RF signals suitable for use in one or more of Wireless Personal Area Networks (WPANs), Wireless Local Area Networks (WLANs), Wireless Wide Area Networks (WWANs), Wireless Metropolitan Area Networks (WMANs), Non-Terrestrial Networks (NTNs), or Internet of Things (IoT) networks.
[0073] Various aspects collectively involve protecting frames between access points (APs) and stations (STAs), such as frames including control information. In some examples, the frame is sent along with a Control Message Integrity Check (CMF) field, which includes an identifier (ID) of the security key, at least a portion of the packet number (PN), and at least a portion of the integrity check, calculated based on one or more portions of the frame including control information and the security key. In some examples, the CMF may be sent as separate parts (such as a first part and a second part). The first part of the CMF and the second part of the CMF may include different subsets of the security key's ID, a portion of the PN, and at least a truncated portion of the integrity check. For example, the first part of the CMF may include at least a portion of the security key's ID and PN, and the second part of the CMF may include at least a truncated portion of the integrity check. The first part of the CMF may be sent relatively early in the frame (e.g., before one or more fields to be protected), and the second part of the CMF may be sent after one or more fields to be protected. In some examples, a partial PN may be sent in the first part of the CMF, which may be combined with the basic PN to generate a complete PN used for integrity checks, encryption, or both. Additionally or alternatively, an Association Identifier (AID) may be used instead of a Media Access Control (MAC) address to associate one or more security keys for each STA.
[0074] In some examples, additionally or alternatively, the padding provided in the control frame may be based on whether the frame is protected, and if so, on whether the protection is provided using integrity checks, encryption, or both. In some examples, the security key may be a group temporary key (GTK) or a pairwise temporary key (PTK). Such security keys may be shared between the AP and the authenticated STAs during or after authentication. In some implementations, the GTK or PTK used to encrypt the frame may be selected based on the number of STAs being served by the AP, and the switching between PTK and GTK may be dynamic. A receiver receiving such a frame can verify the frame by calculating an integrity check against the frame using the security key identified by the ID included in the frame and comparing the calculated integrity check with the integrity check included in the frame. Furthermore, a receiver receiving such a frame can verify that the frame is not a replay of a frame already received by the receiver by checking that the PN of the frame is the expected PN (such as the next PN in a sequence).
[0075] Specific aspects of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages. In some examples, by verifying control frames, the UE can avoid wasting power and radio frequency resources when the UE receives invalid control frames from an attacker. Furthermore, the described techniques can be used to efficiently verify control frames, thereby allowing the device to respond to control frames efficiently, in contrast to some techniques in which a large portion of the frame is encrypted, which may cause the device to spend significant time and processing resources to decrypt those portions of the frame. Moreover, by providing CMF information in a separate section, the described techniques allow the CMF to be provided according to existing frame structures in which the PN and the ID of the security key can be part of a security header, while the integrity check is provided later in the frame. By providing a partial PN, overhead within the CMF (such as within the first section of the CMF) can be reduced, and by providing a truncated integrity check, overhead within the CMF (such as within the second section of the CMF) can be reduced. Furthermore, in examples where AID can be used instead of MAC address to associate one or more security keys for each STA, such techniques can provide reduced memory usage compared to specific implementations where MAC address can be stored together with one or more security keys for each STA.
[0076] Additionally, in examples providing switching between GTK and PTK, such techniques can be used to efficiently manage the tracking of security keys for multiple STAs at the AP. If the number of STAs served by the AP is less than a first number, a separate PTK can be maintained for each STA; otherwise, the GTK can be associated with multiple STAs, allowing for more efficient processing at the AP. Furthermore, in examples where padding is based on whether the frame is protected, and if so, on whether the protection is provided using integrity checks, encryption, or both, sufficient processing time can be provided to process control frames while reducing overhead in cases where less processing time is used (such as cases where no frame protection is provided or where integrity checks are used for unencrypted frames, which require less processing time than encrypted frames).
[0077] Figure 1 A schematic diagram of an example wireless communication network 100 is shown. Depending on some aspects, the wireless communication network 100 may be an example of a wireless local area network (WLAN) (such as a Wi-Fi network). For example, the wireless communication network 100 may be a network implementing at least one of the IEEE 802.11 wireless communication protocol standard families (such as those defined by the IEEE 802.11-2020 specification or its revisions, including but not limited to 802.11ay, 802.11ax, 802.11az, 802.11ba, 802.11bc, 802.11bd, 802.11be, 802.11bf, and 802.11bn). In some other examples, the wireless communication network 100 may be an example of a cellular radio access network (RAN), such as a 5G RAN or 6G RAN implementing one or more cellular protocols (such as those specified in one or more 3GPP standards). In some other examples, the wireless communication network 100 may include a WLAN that operates in a manner interoperable with or converged with one or more cellular RANs to provide greater or enhanced network coverage to wireless communication devices within the wireless communication network 100, or to enable these devices to connect to the core of the cellular network, such as accessing network management capabilities and functionality provided by the cellular network core. In some other examples, the wireless communication network 100 may include a WLAN that operates in a manner interoperable with or converged with one or more personal area networks (such as networks implementing Bluetooth or other wireless technologies) to provide greater or enhanced network coverage or to provide or implement other capabilities, functionality, applications, or services.
[0078] The wireless communication network 100 may include numerous wireless communication devices, including at least one wireless access point (AP) 102 and any number of wireless stations (STAs) 104. Although Figure 1Only one AP 102 is shown, but the wireless communication network 100 may include multiple APs 102. AP 102 may be or represent various different types of network entities, including but not limited to home networking APs, enterprise APs, single-band APs, dual-band synchronous (DBS) APs, tri-band synchronous (TBS) APs, standalone APs, non-standalone APs, software-enabled APs (software APs), and multi-link APs (also known as AP multi-link devices (MLDs)), as well as cellular (such as 3GPP, 4G LTE, 5G, or 6G) base stations or other cellular network nodes (such as Node B, evolved Node B (eNB), gNB, Transmit Receive Point (TRP)) or another type of equipment or apparatus included in the radio access network (RAN), including open RAN (O-RAN) network entities such as central units (CUs), distributed units (DUs), or radio units (RUs).
[0079] Each STA 104 may also be referred to as a mobile station (MS), mobile device, mobile phone, wireless phone, access terminal (AT), user equipment (UE), subscriber station (SS), or subscriber unit, etc. STA 104 can represent a variety of devices such as mobile phones, other handheld or wearable communication devices, netbooks, laptops, tablets, laptops, Chromebooks, augmented reality (AR), virtual reality (VR), mixed reality (MR), or extended reality (XR) wireless headsets or other peripherals, wireless earbuds, other wearable devices, display devices (e.g., televisions, computer monitors, or video game consoles), video game controllers, navigation systems, music or other audio or stereo devices, remote control devices, printers, kitchen appliances (including smart refrigerators) or other household appliances, remote keys (e.g., for passive keyless entry and start (PKES) systems), Internet of Things (IoT) devices, vehicles, etc.
[0080] A single AP 102 and its associated set of STA 104s may be referred to as a Basic Service Set (BSS), which is managed by the respective AP 102. Figure 1Additionally, an example coverage area 108 of AP 102 is shown, which may represent the Basic Service Area (BSA) of wireless communication network 100. The BSA can be identified by STA 104 and other devices via a Service Set Identifier (SSID) and a Basic Service Set Identifier (BSSID), which may be the Media Access Control (MAC) address of AP 102. AP 102 may periodically broadcast beacon frames (“beacons”) including the BSSID to enable any STA 104 within the wireless range of AP 102 to “associate” or reassociate with AP 102 to establish or maintain a corresponding communication link 106 (also referred to hereinafter as a “Wi-Fi link”) with AP 102. For example, the beacon may include an identifier or indication of the primary channel used by the corresponding AP 102, and a Timing Synchronization Function (TSF) for establishing or maintaining timing synchronization with AP 102. AP 102 can provide access to external networks to each STA 104 in the wireless communication network 100 via the corresponding communication link 106.
[0081] To establish a communication link 106 with AP 102, each STA 104 is configured to perform a passive or active scanning operation (“scan”) on frequency channels in one or more frequency bands (e.g., 2.4 GHz, 5 GHz, 6 GHz, 45 GHz, or 60 GHz bands). To perform a passive scan, STA 104 listens for beacons transmitted by the corresponding AP 102 at periodic time intervals (referred to as the Target Beacon Transmission Time (TBTT)). To perform an active scan, STA 104 generates probe requests and transmits these requests sequentially on each channel to be scanned, and listens for probe responses from AP 102. Each STA 104 can identify, determine, detect, or select an AP 102 to associate with based on the scanning information obtained through the passive or active scan, and performs authentication and association operations to establish a communication link 106 with the selected AP 102. The selected AP 102 assigns an AID to STA 104 at the end of the association operation, and AP 102 uses this AID to track STA 104.
[0082] As wireless networks become increasingly prevalent, STA 104 may have the opportunity to choose from one of many BSSs within its range or from multiple APs 102 that together form an Extended Service Set (ESS) (comprising multiple connected BSSs). For example, wireless communication network 100 may be connected to a wired or wireless distribution system capable of connecting multiple APs 102 in such an ESS. Therefore, STA 104 may be covered by more than one AP 102 and may be associated with different APs 102 at different times for different transmissions. Additionally, after associating with an AP 102, STA 104 may periodically scan its surroundings to find a more suitable AP 102 to associate with. For example, STA 104 moving relative to its associated AP 102 may perform a “roaming” scan to find another AP 102 with more desirable network characteristics, such as a larger Received Signal Strength Indicator (RSSI) or reduced traffic load.
[0083] In some examples, STA 104 can form a network without AP 102 or any other equipment besides STA 104 itself. An example of such a network is an ad hoc network (or wireless ad hoc network). Ad hoc networks may also be referred to as mesh networks or peer-to-peer (P2P) networks. In some examples, ad hoc networks can be implemented within a larger network, such as wireless communication network 100. In such examples, while STA 104 may be able to communicate with each other via communication link 106 through AP 102, STA 104 can also communicate directly with each other via direct wireless communication link 110. Additionally, two STA 104 can communicate via direct wireless communication link 110, regardless of whether the two STA 104 are associated with and served by the same AP 102. In such ad hoc systems, one or more STAs among STA 104 can assume the role played by AP 102 in the BSS. Such STA 104 can be referred to as the group owner (GO) and can coordinate transmissions within the ad hoc network. Examples of direct wireless communication links 110 include Wi-Fi direct connections, connections established by using Wi-Fi Tunneling Direct Link Establishment (TDLS) links, and other P2P group connections.
[0084] In some networks, AP 102 or STA 104, or both, can support applications associated with high throughput or low latency requirements, or provide lossless audio to one or more other devices. For example, AP 102 or STA 104 can support applications and use cases associated with ultra-low latency (ULL), such as ULL gaming, or streaming lossless audio and video to one or more personal audio devices (such as peripherals) or AR / VR / MR / XR headsets. In scenarios where a user uses two or more peripherals, AP 102 or STA 104 can support extended personal audio networks that enable communication with these two or more peripherals. Additionally, AP 102 and STA 104 can support additional ULL applications with ULL and high throughput requirements, such as cloud-based applications (such as VR cloud gaming).
[0085] As indicated above, in some implementations, AP 102 and STA 104 may operate and communicate according to one or more of the IEEE 802.11 wireless communication protocol family of standards (via the corresponding communication link 106). These standards define WLAN radio and baseband protocols for the physical (PHY) layer and MAC layer. AP 102 and STA 104 transmit and receive wireless communications to and from each other in the form of PHY Protocol Data Units (PPDUs) (also referred to below as "Wi-Fi communication" or "wireless packets").
[0086] Each PPDU is a composite structure comprising a PHY preamble and a payload in the form of a PHY Service Data Unit (PSDU). The information provided in the preamble can be used by the receiving device to decode subsequent data in the PSDU. In instances where the PPDU is transmitted on a bound channel or a wideband channel, the preamble field may be repeated and transmitted in each of the multiple component channels. The PHY preamble may include both a legacy portion (or "legacy preamble") and a non-legacy portion (or "non-legacy preamble"). The legacy preamble can be used for other purposes such as packet detection, automatic gain control, and channel estimation. The legacy preamble is also typically used to maintain compatibility with legacy equipment. The format, decoding, and information provided in the non-legacy portion of the preamble are associated with the specific IEEE 802.11 wireless communication protocol to be used to transmit the payload.
[0087] AP 102 and STA 104 in wireless communication network 100 can transmit PPDUs on unlicensed spectrum, which may be a portion of the spectrum including frequency bands traditionally used by Wi-Fi technologies, such as the 2.4 GHz, 5 GHz, 6 GHz, 45 GHz, and 60 GHz bands. Some examples of AP 102 and STA 104 described herein can also communicate in other frequency bands that can support both licensed and unlicensed communication. For example, AP 102 or STA 104, or both, may also be able to communicate on licensed operating frequency bands, where multiple operators may have corresponding licenses to operate in the same or overlapping frequency ranges. Such licensed operating bands may be mapped to or associated with the following frequency ranges: FR1 (410MHz–7.125GHz), FR2 (24.25GHz–52.6GHz), FR3 (7.125GHz–24.25GHz), FR4a or FR4–1 (52.6GHz–71GHz), FR4 (52.6GHz–114.25GHz), and FR5 (114.25GHz–300GHz).
[0088] Each of these frequency bands may include multiple sub-bands and frequency channels (also referred to as sub-channels). The terms "channel" and "sub-channel" are used interchangeably herein, as each can refer to a portion of the spectrum within the frequency band (e.g., a 20MHz, 40MHz, 80MHz, or 160MHz portion of the spectrum) through which communication between two or more wireless communication devices can occur. For example, PPDUs conforming to revisions of the IEEE 802.11n, 802.11ac, 802.11ax, 802.11be, and 802.11bn standards may be transmitted on one or more of the 2.4GHz, 5GHz, or 6GHz frequency bands, each of which is divided into multiple 20MHz channels. Thus, these PPDUs are transmitted on physical channels with a minimum bandwidth of 20MHz, but larger channels can be formed through channel bonding. For example, a PPDU can be transmitted on a physical channel with bandwidths of 40MHz, 80MHz, 160MHz, 240MHz, 320MHz, 480MHz, or 640MHz by bundling multiple 20MHz channels together.
[0089] AP 102 can determine or select the operating bandwidth or operational bandwidth for STA 104 in its BSS, and select a series of channels within the band to provide that operating bandwidth. For example, AP 102 can select sixteen 20MHz channels that collectively span a 320MHz operating bandwidth. Within the operating bandwidth, AP 102 can typically select a single primary 20MHz channel on which AP 102 and STA 104 in its BSS monitor contention-based access schemes. In some examples, AP 102 or STA 104 may be able to monitor only a single primary 20MHz channel for packet detection (e.g., for detecting preambles of PPDUs). Under normal circumstances, any transmission made by AP 102 or STA 104 within the BSS must involve a transmission on the primary 20MHz channel. Therefore, in a conventional system, the transmitting device must compete for and win a transmission opportunity (TXOP) on the primary channel in order to make any transmission. However, some AP 102 and STA104 devices supporting Ultra-High Reliability (UHR) communication or communication according to the IEEE 802.11bn standard amendment can be configured to operate, monitor, compete for, and communicate using multiple primary 20MHz channels. Such monitoring of multiple primary 20MHz channels can be sequential, such that in response to determining, identifying, or detecting that a first primary 20MHz channel is unavailable, the wireless communication device can switch to using a second primary 20MHz channel for monitoring and competition.
[0090] Additionally or alternatively, wireless communication devices may be configured to monitor multiple primary 20MHz channels in parallel. In some examples, a first primary 20MHz channel may be referred to as the main primary (M-primary) channel, and one or more additional secondary primary channels may each be referred to as the opportunistic primary (O-primary) channel. For example, if the wireless communication device measures, identifies, determines, detects, or otherwise determines that the M-primary channel is busy or occupied (e.g., due to overlapping BSS (OBSS) transmissions), the wireless communication device may switch to monitoring and competing on the O-primary channel. In some examples, the M-primary channel may be used for beacon transmission and serving legacy client equipment, and the O-primary channel may be dedicated by non-legacy (e.g., UHR or IEEE 802.11bn compatible) equipment for opportunistic access to spectrum that may otherwise be underutilized.
[0091] Figure 2 An example protocol data unit (PDU) 200 capable of wireless communication between a wireless access point (AP) and one or more wireless STAs is shown. For example, the AP and STA can be reference... Figure 1Examples of AP 102 and STA 104 are described. PDU 200 can be configured as a PPDU. As shown, PDU 200 includes a PHY preamble 202 and a PHY payload 204. For example, preamble 202 may include a legacy portion, which itself includes a legacy short training field (L-STF) 206 consisting of two symbols, a legacy long training field (L-LTF) 208 consisting of two symbols, and a legacy signal field (L-SIG) 210 consisting of two symbols. The legacy portion of preamble 202 may be configured according to the IEEE 802.11a wireless communication protocol standard. Preamble 202 may also include a non-legacy portion, which includes one or more non-legacy fields 212, for example, conforming to one or more of the IEEE 802.11 wireless communication protocol standard family.
[0092] L-STF 206 generally enables receiving devices (such as AP 102 or STA 104) to perform coarse timing and frequency tracking, as well as automatic gain control (AGC). L-LTF 208 generally enables receiving devices to perform fine timing and frequency tracking, and also to perform initial estimation of the radio channel. L-SIG 210 generally enables receiving devices to determine (e.g., acquire, select, identify, detect, determine, calculate, or compute) the duration of the PDU and use the determined duration to avoid transmission over the PDU. The legacy portion of the preamble can be modulated according to a binary phase shift keying (BPSK) modulation scheme, including L-STF 206, L-LTF 208, and L-SIG 210. The payload 204 can be modulated according to a BPSK modulation scheme, a quadrature BPSK (Q-BPSK) modulation scheme, a quadrature amplitude modulation (QAM) modulation scheme, or another suitable modulation scheme. Payload 204 may include a PSDU containing a data field (DATA) 214, which in turn may carry higher-level data in the form of, for example, MAC Protocol Data Unit (MPDU) or Aggregated MPDU (A-MPDU).
[0093] Figure 3 An example physical layer (PHY) protocol data unit (PPDU) 350 capable of being used for communication between a wireless AP and one or more wireless STAs is shown. For example, the AP and STA can be reference... Figure 1Examples of AP 102 and STA 104 are described below. As shown, PPDU 350 includes a PHY preamble (which includes a legacy portion 352 and a non-legacy portion 354) and a payload 356 (which includes a data field 374). The legacy portion 352 of the preamble includes L-STF 358, L-LTF 360, and L-SIG 362. The non-legacy portion 354 of the preamble includes a repetition of L-SIG (RL-SIG) 364 and multiple wireless communication protocol version-related signal fields following RL-SIG 364. For example, the non-legacy portion 354 may include a general signal field (referred to herein as "U-SIG 366") and an EHT signal field (referred to herein as "EHT-SIG 368"). The presence of RL-SIG 364 and U-SIG 366 indicates to an EHT-compliant or later version STA 104 that PPDU 350 is an EHT PPDU or any later (post-EHT) version PPDU conforming to a new wireless communication protocol (conforming to the future IEEE 802.11 wireless communication protocol standard). One or both of U-SIG 366 and EHT-SIG 368 can be constructed as other wireless communication protocol versions above EHT that are associated with a revision of the IEEE standards family and carry version-related information for those protocol versions. For example, U-SIG 366 can be used by a receiving device (such as AP 102 or STA 104) to interpret bits in one or more of EHT-SIG 368 or data field 374. Similar to L-STF 358, L-LTF 360, and L-SIG 362, in instances involving the use of bound channels, the information in U-SIG366 and EHT-SIG 368 can be repeated and transmitted in each of the component 20MHz channels.
[0094] The non-legacy portion 354 also includes additional short training fields (referred to herein as "EHT-STF 370," but which can be constructed for other wireless communication protocol versions above EHT and carry version-specific information for those versions) and one or more additional long training fields (referred to herein as "EHT-LTF 372," but which can be constructed for other wireless communication protocol versions above EHT and carry version-specific information for those versions). EHT-STF 370 can be used for timing and frequency tracking as well as AGC, and EHT-LTF 372 can be used for more refined channel estimation.
[0095] EHT-SIG 368 can be used by AP 102 to identify one or more STAs 104 and notify those STAs that AP 102 has scheduled uplink (UL) or downlink (DL) resources for them. EHT-SIG 368 can be decoded by each compatible STA 104 served by AP 102. EHT-SIG 368 can generally be used by the receiving device to interpret the bits in data field 374. For example, EHT-SIG 368 may include resource element (RU) allocation information, spatial flow configuration information, and per-user (e.g., STA-specific) signaling information. Each EHT-SIG 368 may include a common field and at least one user-specific field. In the context of OFDMA, the common field may indicate the RU distribution across multiple STAs 104, indicate RU assignment in the frequency domain, indicate which RUs are allocated for MU-MIMO transmission and which RUs correspond to OFDMA transmission, and the number of users in the allocation, etc. The user-specific field is assigned to a specific STA 104 and carries STA-specific scheduling information, such as user-specific MCS values and user-specific RU allocation information. This information enables the corresponding STA 104 to identify and decode the corresponding RU in the associated data field 374.
[0096] Figure 4 A hierarchical format of an example PPDU capable of being used for communication between a wireless AP and one or more wireless STAs is shown. For example, the AP and STA can be references. Figure 1Examples of AP 102 and STA 104 described. As described, each PPDU 400 includes a PHY preamble 402 and a PSDU 404. Each PSDU 404 may represent (or “carry”) one or more MAC Protocol Data Units (MPDUs) 416. For example, each PSDU 404 may carry an aggregated MPDU (A-MPDU) 406, which includes an aggregation of multiple A-MPDU subframes 408. Each A-MPDU subframe 408 may include an MPDU frame 410, which includes a MAC delimiter 412 and a MAC header 414 preceding an accompanying MPDU 416, which includes the data portion (“payload” or “frame body”) of the MPDU frame 410. Each MPDU frame 410 may also include a Frame Check Sequence (FCS) field 418 for error detection (e.g., the FCS field 418 may include a Cyclic Redundancy Check (CRC)) and padding bits 420. MPDU 416 may carry one or more MAC Service Data Units (MSDUs) 430. For example, MPDU 416 may carry an aggregated MSDU (A-MSDU) 422, which comprises multiple A-MSDU subframes 424. Each A-MSDU subframe 424 may be associated with an MSDU frame 426 and may contain a corresponding MSDU 430, preceded by a subframe header 428, and in some examples, followed by padding bits 432.
[0097] Returning to reference MPDU frame 410, MAC delimiter 412 can be used as a marker for the start of associated MPDU 416 and to indicate the length of associated MPDU 416. MAC header 414 may include multiple fields containing information defining or indicating the characteristics or attributes of the data encapsulated within the frame body. MAC header 414 includes a duration field indicating the duration from the end of the PPDU to at least the end of an acknowledgment (ACK) or block ACK (BA) to be sent by the receiving wireless communication device to the PPDU. The use of the duration field is to preserve the wireless medium for the indicated duration and to enable the receiving device to establish its Network Allocation Vector (NAV). MAC header 414 also includes one or more fields indicating the address of the data encapsulated within the frame body. For example, MAC header 414 may include a combination of source address, transmitter address, receiver address, or destination address. MAC header 414 may also include a frame control field containing control information. The frame control field may specify the frame type, such as a data frame, control frame, or management frame.
[0098] In some wireless communication systems, the wireless communication between AP 102 and its associated STA 104 can be protected. For example, AP 102 or STA 104 can establish a security key to protect its wireless communication with another device, and the security key can be used to encrypt the contents of data frames and management frames. In some examples, fields, or both, within the MAC header of control frames and data or management frames can also be protected via encryption or integrity checks (e.g., by generating MICs for one or more relevant fields).
[0099] Figure 5 An example signaling diagram 500 is shown to support a security control frame in wireless communication between a first wireless device (such as a wireless AP) and one or more second wireless devices (such as one or more wireless STAs). Signaling diagram 500 may be implemented or be implemented to implement one or more aspects of wireless communication network 100. For example, signaling diagram 500 illustrates communication 505 between AP 510 and one or more STAs (such as STA 515-a and STA 515-b), which may be provided by… Figure 1 Examples of corresponding devices described with reference to this figure are illustrated. In some specific implementations, communication 505 may be an example of one or more types of communication between AP 510 and STA 515-a and 515-b, which may include one or more control frames 520.
[0100] In some implementations, a first wireless device (such as AP 510) may communicate with a second wireless device (such as STA 515-a), and either AP 510 or STA 515-a may send control frame 520. Control frame 520 may be any of a variety of different types of control frames, such as trigger frames, ready-to-transmit frames, request-to-transmit (RTS) frames, block acknowledgment request (BAR) frames, block acknowledgment (BA) frames, etc. In some implementations, the wireless device may send control frame 520 in response to an initiating control frame (such as in a trigger-based PPDU format). In some implementations, the wireless device may send a control response frame (CRF) indicating feedback on data to another wireless device, such as a BA frame (which may be a CRF transmitted in response to a solicitation frame that is not a control frame). In some examples, the solicitation frame may be an RTS frame, a trigger frame (and any variant of a trigger frame), a BAR frame, etc.
[0101] exist Figure 5In the example, control frame 520 may include a frame control field 525 (two octets in this example), a duration or identifier field 530 (two octets in this example), a receiver address (RA) field 535 (six octets in this example), a transmitter address (TA) field 540 (six octets in this example), one or more control information fields 545 (such as a common information field, a user information list, CMF, and padding, which may have variable lengths), and a frame check sequence (FCS) field 550 (four octets in this example). In some implementations, these fields may include one or more subfields. In some implementations, the CMF may be provided within the control information field 545, which may include two or more parts of the CMF, such as a first part 555 and a second part 560 of the CMF. In some examples, the padding field 565 may be provided before the FCS field 550. In some examples, the first part 555 of the CMF may be provided relatively early within one or more control information fields 545. For example, a security trigger frame may include a first portion 555 of the CMF following a common information field. In some examples, a second portion 560 of the CMF may be provided later within one or more control information fields 545, such as after a user information list and before padding bits in a padding field 565. Alternatively, the second portion 560 of the CMF may be included within padding bits in a padding field 565.
[0102] In some examples, the second part 560 of the CMF may include an integrity check, which may be calculated against all or some fields in the MAC header (such as the duration or identifier field 530, the RA field 535, and the TA field 540) and control information fields 545 (such as the common information field, the user information list field, the security key indication, and the PN). In some specific implementations, STAs 515-a and 515-b with access to the security key and AP 510 may verify control frame 520 by calculating an integrity check value based on the receive fields of control frame 520 and comparing the calculated integrity check with the integrity check value provided in the second part 560 of the CMF. If STAs 515-a and 515-b or AP 510 cannot verify control frame 520 because the calculated integrity check does not match the integrity check provided in control frame 520, STAs 515-a and 515-b or AP 510 may discard control frame 520. Other STAs capable of performing security checks (such as non-UHR STAs, such as high-efficiency (HE) or extremely high-throughput (EHT) STAs) can ignore the first part 555 and the second part 560 of the CMF while processing the rest of the control frame 520.
[0103] In some implementations, control frame 520 may contain variable data or information to support the communication of control information and other information (such as information related to TXOP). The control frame may be transmitted as a single MPDU (such as the initial frame of TXOP) or during TXOP. In some implementations, control frame 520 may solicit a response with control feedback, which may be indicated by bits in control frame 520 or reserved values of TXOP sharing modes. For example, a bit value "1" in control frame 520 (such as a multi-user RTS (MU-RTS)) may indicate that control frame 520 is soliciting a response frame (such as a multi-STA block acknowledgment (M-BA) frame, or a transmit-allowed (CTS) frame with control feedback, or a trigger frame variant with control feedback). In some examples, control frame 520 may only contain control feedback in which a response is not requested (such as CTS, trigger-based PPDUs, etc.).
[0104] Figure 6 An example of a CMF 600 capable of being used for communication between wireless devices, such as a wireless AP and one or more wireless STAs, is shown. The example CMF 600 may include a security key ID field 610 or a packet number 615 (such as an Integrity Group Temporary Key Packet Number (IPN) or a Beacon Integrity Group Temporary Key Packet Number (BIPN)) in a first portion 620 of the CMF. The security key ID field includes a first number of octets (such as two octets), and the packet number includes a second number of octets (such as six octets). The example CMF 600 may also include a second portion 630 of the CMF, which includes a MIC value 625, which includes a third number of octets (such as eight or sixteen octets). It can be noted that the example CMF 600 has a structure similar to that of a Management MIC Information Element (IE) that can be used to protect beacon frames. However, this disclosure is not limited to this. Figure 6 The illustrated structure, and includes CMFs with other structures.
[0105] For example, the ID described herein may be transmitted in a field of less than two octets, or as a bit included in other fields of the frame. In another example, the complete PN described herein may be split into a partial PN and a basic PN, and the PN field of the CMF described herein may transmit the partial PN instead of the complete PN. The wireless device described herein may occasionally (e.g., periodically, in response to a request, or in response to a triggering event) exchange the basic PN and store the basic PN for use (e.g., when calculating, transmitting, or verifying received packets). In yet another example, the wireless device described herein may include only a portion of the MIC (e.g., a truncated integrity check) in the second part 630 of the CMF.
[0106] In some examples, the truncated integrity check can be a truncated portion of the Galois Message Authentication Code (GMAC) output (such as 28 or 32 least significant bits of the GMAC output, or 56 or 62 least significant bits of the GMAC output), which reduces the MIC value 625 to four or eight octets, thus reducing overhead compared to sending the full GMAC output. The receiving device can compare the truncated integrity check with the corresponding four or eight octets of an integrity check calculated at the receiving device based at least on the security key and other parts of the packet. In such examples, one or more portions of the CMF605 can be provided in the user information field of a five-octet-long trigger frame, although the same approach can be used for other control frames.
[0107] Figure 7 An example CMF location 700 is shown that supports a security control frame in wireless communication between wireless devices, such as a wireless AP and one or more wireless STAs. In this example, similarly, as discussed above, the control frame 705 may include a frame control field 710, a duration or identifier field 715, an RA field 720, a TA field 725, one or more control information fields 730, and an FCS field 735. The control information field 730 may include multiple fields, including optional first control information subfield 740-a, second control information subfield 740-b, a first portion 745 of the CMF, a second portion 750 of the CMF, and a padding field 755. See reference... Figure 5 The locations of the first part 745 and the second part 750 of the CMF discussed can be provided in different areas within the control information.
[0108] exist Figure 7In the example, the first portion 745 of the CMF can be placed relatively early in the control information field 730. For example, the first portion 745 of the CMF can be placed before one or more fields to be protected, although in some frames, due to the frame definition format, the first portion 745 of the CMF can be placed after one or more control information fields. For example, in a trigger frame, the common information field can be located at the beginning of the control information, and in such cases, the first portion 745 of the CMF can be placed after the common information field. Placing the first portion 745 of the CMF relatively early in the control information allows the receiving device to determine its position earlier according to the control frame. For example, if the control frame 705 is a protected trigger frame, the first portion 745 of the CMF can be CMF1 immediately following the common information field, or if the control frame includes a special user information field, the first portion 745 of the CMF can be placed immediately following the special user information field. In some examples, if the protected control frame 705 is a BAR or BA frame, the first portion 745 of the CMF can be placed immediately following the BAR or BA control information.
[0109] exist Figure 7 In some examples, the second portion 750 of the CMF may follow one or more protected fields in the protected control frame 705. In some examples, the second portion 750 of the CMF may immediately precede the padding field 755 (such as when the second portion 750 of the CMF is included as a user information field). In some other examples, the second portion 750 of the CMF may be included as part of the padding field 755. For example, the padding field 755 may include an initial set of bits with defined values (such as the first 12 bits being set to all 1s), and the second portion 750 of the CMF may follow such an initial set of bits.
[0110] In some examples, the receiving device may be able to determine the positions of the first portion 745 and the second portion 750 of the CMF relatively early. In some examples, the position of the second portion 750 of the CMF may be indicated in or before the first portion 745 of the CMF. In some examples, the padding duration after the second portion 750 of the CMF remains constant (or changes slowly) and is announced via a management frame (such as in a UHR operating element); or it may be signaled in or before the first portion 745 of the CMF. Such positions of the CMF may allow the control frame to be decoded at a receiving device that does not support the security of such frames by preserving the control frame structure in which the PN and encryption key ID may be part of a secure header and the MIC may be located at the end of the control information field 730.
[0111] Furthermore, in some examples, the AID of a STA at the AP can be associated with an encryption key and a PN. In some implementations, various calculations can be based on the MAC address (such as random number calculations and Attached Authentication Data (AAD)). On the STA side, using the MAC address may not consume significant memory or processing resources because the STA may only be associated with one AP, and obtaining the key (such as the PTK) for that MAC address may be relatively efficient with relatively low memory usage (only one MAC address, only one PTK, and PN for the AP). However, on the AP side, since there are potentially many STAs associated with the AP, obtaining the key (such as the PTK) for each STA and associating it with each STA's MAC address, PTK, and PN can consume significant memory and processing resources. This applies to reception and transmission at the AP, especially to control frames generated during Short Interframe Spaces (SIFS).
[0112] In some examples, the STA's AID instead of its MAC address can be used in these steps. In this way, the AP can use the AID instead of the MAC address to retrieve relevant data, and because the AID has fewer bits (12 bits instead of 48 bits), it saves memory and processing resources at the AP. In some examples, to provide support for the use of the AID, the AID can be carried in the protected control frame. Providing the AID can be supported for trigger frames and M-BA (downlink) frames. In some examples, one or more fields of other frame types can be modified to provide the AID. For example, uplink M-BA frames, compressed block acknowledgment (C-BA) frames, multi-service identifier (TID) BAR frames, and compressed BAR (C-BAR) frames can be modified to provide an AID indication. For frames that solicit protected control frames, in some examples, the AID field can be provided as part of an MPDU with a secure MAC header. In some examples, the MPDU requesting a protected control frame may be carried only in the UHR PPDU, where the PHY header of the UHR PPDU is expected to contain the transmitter ID from U-SIG / SIG-A. Furthermore, not all frames may require an indication of the AID; only frames generated by non-AP STAs and requesting a protected response may require an AID indication. In some examples, the requesting frame may contain bits indicating a request for a protected control frame.
[0113] When performing encryption on protected control frames, either PTK or GTK can be used, as discussed herein. For example, GTK can be used for group-addressed control frames, and PTK can be used for individual control frames to provide additional security. However, if a relatively large number of STAs are being served, the AP using PTK may consume significant processing resources. In some examples, PTK can be used for secure control frames when a limited number of STAs are actively communicating with the AP, and GTK can be used when the number of STAs exceeds a threshold. For example, the AP can use PTK to communicate with STAs when there are 10 or fewer STAs, and GTK to communicate when more than 10 STAs are communicating. In some examples, the AP can determine whether all protected control frames are protected using GTK (i.e., both group control frames and individual control frames are protected using GTK), or whether all protected group control frames are protected using GTK while individual control frames are protected using PTK. In some examples, the AP can dynamically switch between two modes, and when the AP switches from one mode to another, it can use protected control frames to signal (such as in UHR operating elements) that a PTK and GTK switch has occurred. In some examples, when the number of STAs exceeds a threshold, the AP can continue to use PTK for some STAs and GTK for others. For example, if nine STAs communicate with the AP using PTK mode, additional STAs can be instructed to use GTK mode, allowing the AP to manage only a total of 10 encryption keys.
[0114] Figure 8 An example of secure control frame padding 800 supporting secure control frames in wireless communication is shown. In some implementations, these control frames may include padding before or after the FCS, which can give the receiver additional time to process the decryption and integrity checks of the protected control frame. The padding field may be a variable field that contains information bits that are part of the PPDU carrying the control frame but do not contain information useful to the receiver (these information bits may alternatively provide the receiver with additional time to process information, prepare response messages, adjust one or more subsequent frame exchanges to take into account updated parameters indicated by control feedback, or any combination thereof).
[0115] In some implementations, the amount of padding in a frame (such as a control frame) soliciting a control frame may be based on whether the solicitation frame solicits a protected control frame, and if a protected control frame is solicited, then based on the protection type used for the protected control frame. For example, a first frame soliciting an unprotected control frame may include a first number of padding bits (such as padding for one OFDM symbol), which is less than a second number of padding bits included in a second frame soliciting a protected control frame (such as padding for two OFDM symbols). In other words, if no security control frame is solicited, the solicitation frame may include padding for one OFDM symbol. Otherwise, two OFDM symbols may be included in the solicitation PPDU.
[0116] exist Figure 8 In the example, control frame 805 may include a first portion 810 of the CMF, a control information field 815, a second portion 820 of the CMF, a padding field 825, and an FCS field 830. In this example, the padding field 825 for an unprotected control frame 835 may include a first number of padding bits 840 (such as the number of bits corresponding to one OFDM symbol). The padding field 825 for an unencrypted MIC-protected control frame 845 may include a second number of padding bits 850 (such as the number of bits corresponding to two OFDM symbols), the second number of padding bits being greater than the first number of padding bits 840. The padding field 825 for an encrypted MIC-protected control frame 855 may include a third number of padding bits 860 (such as the number of bits corresponding to three OFDM symbols), the third number of padding bits being greater than the second number of padding bits 850. The pre-frame padding for secure control frames may account for the additional time required for the receiving device to obtain the PN, PTK / GTK, and perform security procedures such as MIC verification and decryption.
[0117] Figure 9 An example of process flow 900 supporting security control frames in wireless communication between a first wireless device (such as an AP) and a second wireless device (such as a STA) is shown. Process flow 900 can be implemented as described in the reference. Figure 1 – Figure 8 The described wireless communication system using security control frames refers to one or more aspects of, or is implemented by, these aspects. For example, process flow 900 illustrates communication between a first wireless device 905 and a second wireless device 910, where the first and second wireless devices may be references. Figure 1 – Figure 8 An example of an AP or STA is described. Process flow 900 supports security control frames and can be executed across any number of wireless devices.
[0118] In the following description of process flow 900, operations (such as reporting or providing) may be performed in a different order than those shown, or operations performed by the example device may be performed in a different order or at different times. For example, specific operations may be omitted from process flow 900, or other operations may be added to process flow 900. Furthermore, although some operations or signaling are shown to occur at different times for discussion purposes, these operations may actually occur simultaneously. It should be noted that although the illustrated example involves an AP communicating with one or more STAs, the sequence may support other device configurations, such as STAs indicating control feedback to one or more APs, STAs indicating control feedback to one or more other STAs, a first wireless device communicating with a second wireless device, or any combination of devices with different functionalities.
[0119] At 915, the first wireless device 905 and the second wireless device 910 may schedule an initial frame. The initial frame may be a data message. In some implementations, scheduling the initial frame may include conveying a control frame. For example, the first wireless device 905 and the second wireless device 910 may convey one or more control frames (such as BA frames) after the initial frame.
[0120] At 920, the first wireless device 905 can receive an initial frame from the second wireless device 910. In some specific implementations, the initial frame may be a data frame scheduled by the first wireless device 905 and the second wireless device 910.
[0121] At 925, the first wireless device 905 may send a first control frame in response to receiving a data message. In some implementations, the first control frame may be a first BA control frame and may be protected according to the techniques discussed herein. The first BA control frame may include, for example, a CMF to be used for verifying the first BA control frame.
[0122] At 930, the second wireless device 910 may verify the frame validity of the first control frame. In some specific implementations, the second wireless device 910 may generate an integrity check on one or more fields of the first control frame and compare at least a portion of the generated integrity check with the corresponding MIC (or a portion of the MIC) provided in the CMF within the first control frame. If the compared integrity checks match, the first control frame is further processed; otherwise, the first control frame is discarded.
[0123] At 935, the first wireless device 905 may receive a second control frame from the second wireless device 910. In some embodiments, the second control frame may be a second BA control frame. The second control frame may include second control information (such as second BA control information) indicating a request (solicitation response) based on a first control feedback field. In some embodiments, the second control frame may be protected according to the techniques discussed herein. The second BA control frame may include, for example, a CMF to be used for verifying the second BA control frame.
[0124] At 940, the first wireless device 905 may verify the frame validity of the second control frame. In some specific implementations, the first wireless device 905 may generate an integrity check on one or more fields of the second control frame and compare at least a portion of the generated integrity check with the corresponding MIC (or a portion of the MIC) provided in the CMF within the second control frame. If the compared integrity checks match, the second control frame may be further processed; otherwise, the second control frame may be discarded.
[0125] Figure 10 An example of a process flow 1000 supporting a security control frame in wireless communication between a first wireless device and a second wireless device is shown. Process flow 1000 can be implemented as described in the reference. Figure 1 – Figure 8 The described wireless communication system using security control frames refers to one or more aspects of, or is implemented by, these aspects. For example, process flow 1000 illustrates communication between a first wireless device 1005 and a second wireless device 1010, where the first and second wireless devices may be references. Figure 1 – Figure 8 An example of an AP or STA is described. Process flow 1000 supports security control frames and can be executed across any number of wireless devices.
[0126] In the following description of process flow 1000, operations (such as reporting or providing) may be performed in a different order than those shown, or operations performed by the example device may be performed in a different order or at different times. For example, specific operations may be omitted from process flow 1000, or other operations may be added to process flow 1000. Furthermore, although some operations or signaling are shown to occur at different times for discussion purposes, these operations may actually occur simultaneously. It should be noted that although the illustrated example involves an AP communicating with one or more STAs, the sequence may support other device configurations, such as STAs indicating control feedback to one or more APs, STAs indicating control feedback to one or more other STAs, a first wireless device communicating with a second wireless device, or any combination of devices with different functionalities.
[0127] At point 1015, the first wireless device 1005 may send a first control frame to the second wireless device 1010. In some implementations, the first control frame may be a trigger frame and may be protected according to the techniques discussed herein. The first control frame may include, for example, a CMF to be used for verifying the first control frame.
[0128] At 1020, the second wireless device 1010 may verify the frame validity of the first control frame. In some specific implementations, the second wireless device 1010 may generate an integrity check on one or more fields of the first control frame and compare at least a portion of the generated integrity check with the corresponding MIC (or a portion of the MIC) provided in the CMF within the first control frame. If the compared integrity checks match, the first control frame may be further processed; otherwise, the first control frame may be discarded.
[0129] At 1025, the first wireless device 1005 may receive a second control frame from the second wireless device 1010, such as a response frame in response to the first control frame. The second control frame may be generated based on a request for the first wireless device 1005 to respond with a second control frame indicating whether the first control frame was successfully received. Alternatively, if the first control frame does not solicit a response from the second wireless device 1010, the second control frame may not be sent. In some implementations, the second control frame may be protected according to the techniques discussed herein. The second control frame may include, for example, a CMF (Content Validation Model) for verifying the first control frame.
[0130] At 1030, the first wireless device 1005 may verify the frame validity of the second control frame. In some specific implementations, the first wireless device 1005 may generate an integrity check on one or more fields of the second control frame and compare at least a portion of the generated integrity check with the corresponding MIC (or a portion of the MIC) provided in the CMF within the second control frame. If the compared integrity checks match, the second control frame may be further processed; otherwise, the second control frame may be discarded.
[0131] At 1035, the first wireless device 1005 can send a data frame to the second wireless device 1010 based on the received response frame.
[0132] Figure 11 A block diagram of an example wireless communication device 1100 supporting security control frames in wireless communication is shown. In some examples, the wireless communication device 1100 is configured to perform respective references Figure 13 , Figure 14 , Figure 16 , Figure 17 , Figure 18 and Figure 20The processes described are 1300, 1400, 1600, 1700, 1800, and 2000. Wireless communication device 1100 may include one or more chips, SoCs, chipsets, packages, components, or devices that individually or collectively constitute or include a processing system. The processing system may interface with other components of wireless communication device 1100 and typically processes information (such as inputs or signals) received from and outputs information (such as outputs or signals) to such other components. In some aspects, an example chip may include a processing system, a first interface for outputting or transmitting information, and a second interface for receiving or acquiring information. For example, the first interface may refer to an interface between the chip's processing system and a transmitting component, enabling wireless communication device 1100 to transmit information output from the chip. In such examples, the second interface may refer to an interface between the chip's processing system and a receiving component, enabling wireless communication device 1100 to receive information that is passed to the processing system. In some such examples, the first interface may also, for example, acquire information from the transmitting component, and the second interface may also, for example, output information to the receiving component.
[0133] The processing system of the wireless communication device 1100 includes processor (or “processing”) circuitry in the form of one or more processors, microprocessors, processing units (such as a central processing unit (CPU), graphics processing unit (GPU), neural processing unit (NPU) (also referred to as a neural network processor or deep learning processor (DLP)) or digital signal processor (DSP)), processing blocks, application-specific integrated circuits (ASICs), programmable logic devices (PLDs) (such as field-programmable gate arrays (FPGAs)), or other discrete gate or transistor logic components or circuits (all of which are generally referred to herein individually as “processors” or collectively as “processors” or “processor circuitry”). One or more of these processors may be individually or collectively configured to perform the various functions or operations described herein.
[0134] The processing system may also include memory circuitry in the form of one or more memory devices, memory blocks, memory elements, or other discrete gate or transistor logic components or circuits, each of which may include tangible storage media such as random access memory (RAM) or read-only memory (ROM) or combinations thereof (all of which are generally referred to herein individually as "memory" or collectively as "memory" or "memory circuitry"). One or more of these memories may be coupled to one or more processors in the processor and may store processor-executable code, individually or collectively, that, when executed by one or more processors in the processor, configures one or more processors in the processor to perform the various functions or operations described herein. Additionally or alternatively, in some examples, one or more processors in the processor may be pre-configured to perform the various functions or operations described herein without requiring software configuration. The processing system may also include or be coupled to one or more modems (such as a Wi-Fi (e.g., IEEE compliant) modem or a cellular (e.g., 3GPP 4G LTE, 5G, or 6G compliant) modem). In some specific embodiments, one or more processors of the processing system include or implement one or more modems in the modem. The processing system may also include, or be coupled to, multiple radio components (collectively, “radio components”), multiple RF chains, or multiple transceivers, each of which may in turn be coupled to one or more of a plurality of antennas. In some embodiments, one or more processors of the processing system include or implement one or more of the radio components, RF chains, or transceivers.
[0135] In some examples, the wireless communication device 1100 may be configured to be used for or configured to be used in an AP (such as a reference). Figure 1The described AP 102 is used. In some other examples, the wireless communication device 1100 may be an AP that includes such a processing system as well as other components including multiple antennas. The wireless communication device 1100 is capable of transmitting and receiving wireless communications, for example, in the form of wireless packets. For example, the wireless communication device 1100 may be configured to transmit and receive packets in the form of physical layer PPDUs and MPDUs conforming to one or more of the IEEE 802.11 series of wireless communication protocol standards. In some other examples, the wireless communication device 1100 may be configured to transmit and receive signals and communications conforming to one or more 3GPP specifications, including those for 5G NR or 6G. In some examples, the wireless communication device 1100 also includes one or more application processors or may be coupled to one or more application processors, which may also be coupled to one or more other memories. In some examples, the wireless communication device 1100 also includes at least one external network interface coupled to the processing system, which enables communication with a core network or backhaul network that allows the wireless communication device 1100 to access external networks, including the Internet.
[0136] Wireless communication device 1100 includes a CMF component 1125, a verification component 1130, and a frame manager 1135. A portion of one or more of the CMF component 1125, the verification component 1130, and the frame manager 1135 may be implemented at least partially in hardware or firmware. For example, one or more of the CMF component 1125, the verification component 1130, and the frame manager 1135 may be implemented at least partially by at least a processor or a modem. In some examples, a portion of one or more of the CMF component 1125, the verification component 1130, and the frame manager 1135 may be implemented at least partially by a processor and software in the form of processor-executable code stored in memory.
[0137] Wireless communication device 1100 can support wireless communication according to the examples disclosed herein. CMF component 1125 can be configured to or be configured to receive a control frame including a first portion and a second portion of a CMF, the first portion of the CMF including an ID of a security key and a partial PN, and the second portion of the CMF including a truncated first integrity check. Verification component 1130 can be configured to or be configured to verify the validity of the control frame based on a comparison of the truncated first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key, the partial PN, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.
[0138] In some examples, the partial PN included in the CMF is combined with the basic PN associated with the control frame to obtain the complete PN associated with the control frame, and the second integrity check is based on the complete PN. In some examples, the number of bits in the partial PN is based on the frame type of the control frame.
[0139] In some examples, the second integrity check is truncated to include a subset of bits of the authentication code output, which is based at least on the security key, a partial PN, and one or more portions of the control frame. In some examples, the validity of each of several different types of control frames is verified based on a partial PN and the truncated first integrity check.
[0140] In some examples, a first portion of the CMF is provided at a first deterministic location within the control information portion of the control frame, the first deterministic location preceding one or more fields protected by a truncated first integrity check, and a second portion of the CMF is provided at a second deterministic location within the control information portion of the control frame, the second deterministic location following one or more fields protected by a truncated first integrity check.
[0141] In some examples, the first part of the CMF is placed before or after one or more information fields within the control information section, based on the frame type of the control frame. In some examples, the second part of the CMF is included within the control information section as a user information field, preceding a set of multiple padding bits at the end of the control information section, or the second part of the CMF is included within that set of padding bits. In some examples, the second part of the CMF is included within the control information section at a specified position, either together with the first part of the CMF or preceding the first part of the CMF. In some examples, the number of padding bits following the second part of the CMF is a fixed value announced via one or more management frames, or a value signaled before the first part of the CMF.
[0142] Additionally or alternatively, the wireless communication device 1100 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1125 can be configured to or be configured to acquire a frame including a CMF, the CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, wherein the AID is different from the media access control address associated with the frame. In some examples, the verification component 1130 can be configured to or be configured to verify the validity of the frame based on a comparison of a first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key associated with the AID and the PN indication.
[0143] In some examples, the frame is a trigger frame, a block acknowledgment frame, or a block acknowledgment request frame. In some examples, the AID is provided in one or more MPDUs, which have a secure MAC header requesting a protected control frame.
[0144] In some examples, the MPDU requesting a protected control frame is carried in the UHR PPDU. In some examples, the AID is provided in one or more frames generated by the non-access point station requesting the protected control frame. In some examples, one or more frames requesting the protected control frame include an indication requesting the protected control frame.
[0145] Additionally or alternatively, the wireless communication device 1100 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1125 can be configured to or be configured to receive a control frame that includes a set of multiple padding bits preceding the CMF and the end-of-frame field, wherein the number of such multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on the security type associated with the control frame. In some examples, the verification component 1130 can be configured to or be configured to decode the control frame based on the number of such multiple padding bits.
[0146] In some examples, the verification component 1130 can be configured to verify the validity of a control frame based on a comparison of a second integrity check and a first integrity check included in the CMF, wherein the second integrity check is based at least on the security key indicated in the CMF, the PN indicated in the CMF, and one or more portions of the control frame. In some examples, the unprotected control frame includes a first number of padding bits, which is less than a second number of padding bits associated with a secure control frame. In some examples, the unencrypted protected control frame includes a second number of padding bits, wherein the second number of padding bits is less than a third number of padding bits associated with an encrypted protected control frame.
[0147] Additionally or alternatively, the wireless communication device 1100 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1125 can be configured to generate a control frame including a first portion and a second portion of the CMF, the first portion of the CMF including an ID of a security key and a portion PN associated with the control frame, and the second portion of the CMF including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, the portion PN, and one or more portions of the control frame. The frame manager 1135 can be configured to output control frames for transmission.
[0148] In some examples, the partial PN included in the CMF is combined with the basic PN associated with the control frame to provide the complete PN associated with the control frame, and the truncated integrity check includes a subset of bits from the full integrity check based on the complete PN. In some examples, the number of bits in the partial PN is based on the frame type of the control frame.
[0149] In some examples, the truncated integrity check includes a subset of bits of the authentication code output, which is based at least on the security key, a partial PN, and one or more portions of the control frame. In some examples, the validity of each of several different types of control frames is verified based on the partial PN and the truncated first integrity check. In some examples, a first portion of the CMF is provided at a first deterministic position within the control information portion of the control frame, preceding one or more fields protected by the truncated integrity check, and a second portion of the CMF is provided at a second deterministic position within the control information portion of the control frame, following one or more fields protected by the truncated integrity check.
[0150] In some examples, the first part of the CMF is placed before or after one or more information fields within the control information section, based on the frame type of the control frame. In some examples, the second part of the CMF is included within the control information section as a user information field, preceding a set of multiple padding bits at the end of the control information section, or the second part of the CMF is included within that set of padding bits. In some examples, the second part of the CMF is included within the control information section at a specified position, either together with the first part of the CMF or preceding the first part of the CMF. In some examples, the number of padding bits following the second part of the CMF is a fixed value announced via one or more management frames, or a value signaled before the first part of the CMF.
[0151] Additionally or alternatively, the wireless communication device 1100 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1125 can be configured to generate frames including a CMF, the CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame, and wherein the first integrity check is based at least on the security key associated with the AID and the PN indication. In some examples, the frame manager 1135 can be configured to output frames for transmission.
[0152] In some examples, the frame is a trigger frame, a block acknowledgment frame, or a block acknowledgment request frame. In some examples, the AID is provided in one or more MPDUs that have a secure MAC header requesting a protected control frame. In some examples, the MPDU requesting a protected control frame is carried in a UHR PPDU. In some examples, the AID is provided in one or more frames generated by a non-access point station requesting a protected control frame. In some examples, the one or more frames requesting a protected control frame include an indication requesting a protected control frame.
[0153] Additionally or alternatively, the wireless communication device 1100 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1125 can be configured to generate a control frame that includes a set of multiple padding bits preceding the CMF and a frame end field, wherein the number of such multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on the security type associated with the control frame. In some examples, the frame manager 1135 can be configured to output control frames for transmission.
[0154] In some examples, the CMF field includes an integrity check based at least on the security key indicated in the CMF, the PN indicated in the CMF, and one or more portions of the control frame. In some examples, the unprotected control frame includes a first number of padding bits, which is less than a second number of padding bits associated with the secure control frame. In some examples, the unencrypted protected control frame includes a second number of padding bits, where the second number of padding bits is less than a third number of padding bits associated with the encrypted protected control frame.
[0155] Figure 12 A block diagram of an example wireless communication device 1200 supporting security control frames in wireless communication is shown. In some examples, the wireless communication device 1200 is configured to perform respective references Figure 13 , Figure 14 , Figure 15 , Figure 16 , Figure 17 , Figure 18 , Figure 19 and Figure 20The processes described are 1300, 1400, 1500, 1600, 1700, 1800, 1900, and 2000. Wireless communication device 1200 may include one or more chips, SoCs, chipsets, packages, components, or devices that individually or collectively constitute or include a processing system. The processing system may interface with other components of wireless communication device 1200 and generally processes information (such as inputs or signals) received from and outputs information (such as outputs or signals) to such other components. In some aspects, an example chip may include a processing system, a first interface for outputting or transmitting information, and a second interface for receiving or acquiring information. For example, the first interface may refer to an interface between the chip's processing system and a transmitting component, enabling wireless communication device 1200 to transmit information output from the chip. In such examples, the second interface may refer to an interface between the chip's processing system and a receiving component, enabling wireless communication device 1200 to receive information that is passed to the processing system. In some such examples, the first interface may also acquire information, for example, from the transmitting component, and the second interface may also output information, for example, to the receiving component.
[0156] The processing system of the wireless communication device 1200 includes processor (or “processing”) circuitry in the form of one or more processors, microprocessors, processing units (such as CPUs, GPUs, NPUs (also known as neural network processors or DLPs) or DSPs), processing blocks, ASICs, PLDs (such as FPGAs), or other discrete gate or transistor logic components or circuits (all of which are generally referred to herein individually as “processors” or collectively as “processors” or “processor circuitry”). One or more of these processors may be individually or collectively configured to perform the various functions or operations described herein.
[0157] The processing system may also include memory circuitry in the form of one or more memory devices, memory blocks, memory elements, or other discrete gate or transistor logic components or circuits, each of which may include tangible storage media such as RAM or ROM or combinations thereof (all of which are generally referred to herein individually as "memory" or collectively as "memory" or "memory circuitry"). One or more of these memories may be coupled to one or more processors in the processor and may store processor-executable code, individually or collectively, that, when executed by one or more processors, configures one or more processors in the processor to perform the various functions or operations described herein. Additionally or alternatively, in some examples, one or more processors in the processor may be pre-configured to perform the various functions or operations described herein without requiring software configuration. The processing system may also include or be coupled to one or more modems (such as Wi-Fi (e.g., IEEE compliant) modems or cellular (e.g., 3GPP 4G LTE, 5G, or 6G compliant) modems). In some embodiments, one or more processors of the processing system include or implement one or more modems in the modems. The processing system may also include, or be coupled to, multiple radio components (collectively, “radio components”), multiple RF chains, or multiple transceivers, each of which may in turn be coupled to one or more of a plurality of antennas. In some embodiments, one or more processors of the processing system include or implement one or more of the radio components, RF chains, or transceivers.
[0158] In some examples, the wireless communication device 1200 may be configured to be used for or configured to be used in STA (such as reference STA). Figure 1The described STA 104 is used. In some other examples, the wireless communication device 1200 may be an STA that includes such a processing system and other components including multiple antennas. The wireless communication device 1200 is capable of transmitting and receiving wireless communications, for example, in the form of wireless packets. For example, the wireless communication device 1200 may be configured to transmit and receive packets in the form of physical layer PPDUs and MPDUs conforming to one or more of the IEEE 802.11 series of wireless communication protocol standards. In some other examples, the wireless communication device 1200 may be configured to transmit and receive signals and communications conforming to one or more 3GPP specifications, including those for 5G NR or 6G. In some examples, the wireless communication device 1200 also includes one or more application processors or may be coupled to one or more application processors, which may also be coupled to one or more other memories. In some examples, the wireless communication device 1200 also includes a user interface (UI) (such as a touchscreen or keypad) and a display that may be integrated with the UI to form a touchscreen display coupled to the processing system. In some examples, the wireless communication device 1200 may also include one or more sensors, such as one or more inertial sensors, accelerometers, temperature sensors, pressure sensors, or altitude sensors coupled to the processing system.
[0159] Wireless communication device 1200 includes a CMF component 1225, a verification component 1230, and a frame manager 1235. A portion of one or more of the CMF component 1225, the verification component 1230, and the frame manager 1235 may be implemented at least partially in hardware or firmware. For example, one or more of the CMF component 1225, the verification component 1230, and the frame manager 1235 may be implemented at least partially by at least a processor or a modem. In some examples, a portion of one or more of the CMF component 1225, the verification component 1230, and the frame manager 1235 may be implemented at least partially by a processor and software in the form of processor-executable code stored in memory.
[0160] Wireless communication device 1200 can support wireless communication according to the examples disclosed herein. CMF component 1225 can be configured to or be configured to receive a control frame including a first portion and a second portion of a CMF, the first portion of the CMF including an ID of a security key and a partial PN, and the second portion of the CMF including a truncated first integrity check. Verification component 1230 can be configured to or be configured to verify the validity of the control frame based on a comparison of the truncated first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key, the partial PN, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.
[0161] In some examples, the partial PN included in the CMF is combined with the basic PN associated with the control frame to obtain the complete PN associated with the control frame, and the second integrity check is based on the complete PN. In some examples, the number of bits in the partial PN is based on the frame type of the control frame.
[0162] In some examples, the second integrity check is truncated to include a subset of bits of the authentication code output, which is based at least on the security key, a partial PN, and one or more portions of the control frame. In some examples, the validity of each of several different types of control frames is verified based on a partial PN and the truncated first integrity check.
[0163] In some examples, a first portion of the CMF is provided at a first deterministic location within the control information portion of the control frame, the first deterministic location preceding one or more fields protected by a truncated first integrity check, and a second portion of the CMF is provided at a second deterministic location within the control information portion of the control frame, the second deterministic location following one or more fields protected by a truncated first integrity check.
[0164] In some examples, the first part of the CMF is placed before or after one or more information fields within the control information section, based on the frame type of the control frame. In some examples, the second part of the CMF is included within the control information section as a user information field, preceding a set of multiple padding bits at the end of the control information section, or the second part of the CMF is included within that set of multiple padding bits. In some examples, the second part of the CMF is included within the control information section at a specified location, either together with the first part of the CMF or before the first part of the CMF.
[0165] In some examples, the number of padding bits after the second part of the CMF is a fixed value announced via one or more management frames, or a value signaled before the first part of the CMF.
[0166] Additionally or alternatively, the wireless communication device 1200 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1225 can be configured to or be configured to acquire a frame including a CMF, the CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, wherein the AID is different from the media access control address associated with the frame. In some examples, the verification component 1230 can be configured to or be configured to verify the validity of the frame based on a comparison of a first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key and PN indication associated with the AID.
[0167] In some examples, the frame is a trigger frame, a block acknowledgment frame, or a block acknowledgment request frame. In some examples, the AID is provided in one or more MPDUs that have a secure MAC header requesting a protected control frame. In some examples, the MPDU requesting a protected control frame is carried in a UHR PPDU. In some examples, the AID is provided in one or more frames generated by a non-access point station requesting a protected control frame. In some examples, the one or more frames requesting a protected control frame include an indication requesting a protected control frame.
[0168] Additionally or alternatively, the wireless communication device 1200 may support wireless communication according to the examples disclosed herein. In some examples, the verification component 1230 may be configured to obtain an indication of either a GTK mode or a PTK mode configured for control frame security. In some examples, the CMF component 1225 may be configured to generate a control frame including a CMF, which includes a security key ID, a PN indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication of the GTK mode or PTK mode. In some examples, the CMF component 1225 may be configured to output a control frame for transmission.
[0169] In some examples, control frames are group control frames or individual control frames, wherein group control frames are protected using GTK according to GTK mode or PTK mode, and individual control frames are protected using PTK according to PTK mode or GTK according to GTK mode. In some examples, the indication configured for control frame security in either GTK mode or PTK mode is a dynamic indication that provides dynamic switching between GTK mode and PTK mode. In some examples, the indication configured for control frame security in either GTK mode or PTK mode is obtained from a UHR operation element.
[0170] Additionally or alternatively, the wireless communication device 1200 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1225 can be configured to or be configured to receive a control frame that includes a set of multiple padding bits preceding the CMF and the end-of-frame field, wherein the number of such a set of multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on the security type associated with the control frame. In some examples, the verification component 1230 can be configured to or be configured to decode the control frame based on the number of such a set of multiple padding bits.
[0171] In some examples, the verification component 1230 can be configured to verify the validity of a control frame based on a comparison of a second integrity check and a first integrity check included in the CMF, wherein the second integrity check is based at least on the security key indicated in the CMF, the PN indicated in the CMF, and one or more portions of the control frame. In some examples, the unprotected control frame includes a first number of padding bits, which is less than a second number of padding bits associated with a secure control frame. In some examples, the unencrypted protected control frame includes a second number of padding bits, wherein the second number of padding bits is less than a third number of padding bits associated with an encrypted protected control frame.
[0172] Additionally or alternatively, the wireless communication device 1200 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1225 can be configured to generate a control frame including a first portion and a second portion of the CMF, the first portion of the CMF including an ID of a security key and a portion PN associated with the control frame, and the second portion of the CMF including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, the portion PN, and one or more portions of the control frame. The frame manager 1235 can be configured to output control frames for transmission.
[0173] In some examples, the partial PN included in the CMF is combined with the basic PN associated with the control frame to provide the complete PN associated with the control frame, and the truncated integrity check includes a subset of bits from a full integrity check based on the complete PN. In some examples, the number of bits in the partial PN is based on the frame type of the control frame. In some examples, the truncated integrity check includes a subset of bits from the authentication code output, which is based at least on the security key, the partial PN, and one or more parts of the control frame. In some examples, the validity of each of several different types of control frames is verified based on the partial PN and the truncated first integrity check. In some examples, a first part of the CMF is provided at a first deterministic position within the control information portion of the control frame, preceding one or more fields protected by the truncated integrity check, and a second part of the CMF is provided at a second deterministic position within the control information portion of the control frame, following one or more fields protected by the truncated integrity check.
[0174] In some examples, the first part of the CMF is placed before or after one or more information fields within the control information section, based on the frame type of the control frame. In some examples, the second part of the CMF is included within the control information section as a user information field, preceding a set of multiple padding bits at the end of the control information section, or the second part of the CMF is included within that set of multiple padding bits. In some examples, the second part of the CMF is included within the control information section at a specified location, either together with the first part of the CMF or before the first part of the CMF.
[0175] In some examples, the number of padding bits after the second part of the CMF is a fixed value announced via one or more management frames, or a value signaled before the first part of the CMF.
[0176] Additionally or alternatively, the wireless communication device 1200 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1225 can be configured to generate frames including a CMF, the CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame, and wherein the first integrity check is based at least on the security key associated with the AID and the PN indication. In some examples, the frame manager 1235 can be configured to output frames for transmission.
[0177] In some examples, the frame is a trigger frame, a block acknowledgment frame, or a block acknowledgment request frame. In some examples, the AID is provided in one or more MPDUs that have a secure MAC header requesting a protected control frame. In some examples, the MPDU requesting a protected control frame is carried in a UHR PPDU. In some examples, the AID is provided in one or more frames generated by a non-access point station requesting a protected control frame. In some examples, the one or more frames requesting a protected control frame include an indication requesting a protected control frame.
[0178] Additionally or alternatively, the wireless communication device 1200 may support wireless communication according to the examples disclosed herein. In some examples, the verification component 1230 may be configured to obtain an indication of either a GTK mode or a PTK mode configured for controlling frame security. In some examples, the CMF component 1225 may be configured to generate a control frame including a CMF, which includes a security key ID, a PN indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication of the GTK mode or PTK mode. In some examples, the frame manager 1235 may be configured to output control frames for transmission.
[0179] In some examples, control frames are group control frames or individual control frames, wherein group control frames are protected using GTK according to GTK mode or PTK mode, and individual control frames are protected using PTK according to PTK mode or GTK according to GTK mode. In some examples, the indication configured for control frame security in either GTK mode or PTK mode is a dynamic indication that provides dynamic switching between GTK mode and PTK mode. In some examples, the indication configured for control frame security in either GTK mode or PTK mode is obtained from a UHR operation element.
[0180] Additionally or alternatively, the wireless communication device 1200 may support wireless communication according to the examples disclosed herein. In some examples, the CMF component 1225 can be configured to generate a control frame that includes a set of multiple padding bits preceding the CMF and a frame end field, wherein the number of such multiple padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on the security type associated with the control frame. In some examples, the frame manager 1235 can be configured to output control frames for transmission.
[0181] In some examples, the CMF field includes an integrity check based at least on the security key indicated in the CMF, the PN indicated in the CMF, and one or more portions of the control frame. In some examples, the unprotected control frame includes a first number of padding bits, which is less than a second number of padding bits associated with the secure control frame. In some examples, the unencrypted protected control frame includes a second number of padding bits, where the second number of padding bits is less than a third number of padding bits associated with the encrypted protected control frame.
[0182] Figure 13A flowchart illustrating an example process 1300 that can be executed by or at a device supporting security control frames in wireless communication is shown. Operation of process 1300 can be implemented by a device or its components as described herein. For example, process 1300 can be implemented by a wireless communication device (such as reference 1300) operating as a wireless access point (AP) or wireless STA, or within a wireless AP or wireless STA. Figure 11 The described wireless communication device 1100) performs the procedure. In some examples, the procedure 1300 may be performed by a wireless AP or a wireless STA (such as reference 1100). Figure 1 (either AP 102 or STA 104 as described) to perform.
[0183] In some examples, in block 1305, the device may receive a control frame including a first portion and a second portion of a CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated first integrity check. Operation of block 1305 may be performed according to examples as disclosed herein. In some specific implementations, aspects of the operation of block 1305 may be provided by reference to [reference needed]. Figure 11 and Figure 12 The described CMF component 1125 or CMF component 1225 is used to perform this.
[0184] In some examples, in block 1310, the apparatus may verify the validity of a control frame based on a comparison of a truncated first integrity check and a second integrity check, wherein the second integrity check is based at least on a security key, a portion of the control frame (PN) associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check. The operation of block 1310 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 1310 may be provided by reference to [reference needed]. Figure 11 and Figure 12 The verification component 1130 or verification component 1230 described herein shall be used to perform the verification.
[0185] Figure 14 A flowchart illustrating an example process 1400 that can be executed by or at a device supporting security control frames in wireless communication is shown. Operation of process 1400 can be implemented by a device or its components as described herein. For example, process 1400 can be performed by a wireless communication device (such as reference 1400) operating as a wireless AP or wireless STA, or within a wireless AP or wireless STA. Figure 11 The described wireless communication device 1100) performs the procedure. In some examples, the process 1400 may be performed by a wireless AP or a wireless STA (such as reference 1100). Figure 1 (either AP 102 or STA 104 as described) to perform.
[0186] In some examples, in block 1405, the device may receive a frame including a CMF (Media Access Control File), which includes an AID (Answer ID), an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from the Media Access Control address associated with the frame. Operation of block 1405 may be performed according to examples as disclosed herein. In some specific implementations, aspects of the operation of block 1405 may be provided by reference to [reference needed]. Figure 11 and Figure 12 The described CMF component 1125 or CMF component 1225 is used to perform this.
[0187] In some examples, in block 1410, the device may verify the validity of a frame based on a comparison of a first integrity check and a second integrity check, wherein the second integrity check is based at least on a security key associated with the AID and a PN indication. The operation of block 1410 may be performed according to examples as disclosed herein. In some specific implementations, aspects of the operation of block 1410 may be provided by reference to [reference needed]. Figure 11 and Figure 12 The verification component 1130 or verification component 1230 described herein shall be used to perform the verification.
[0188] Figure 15 A flowchart illustrating an example process 1500 that can be executed by or at a device supporting security control frames in wireless communication is shown. Operation of process 1500 can be implemented by a device or its components as described herein. For example, process 1500 can be implemented by a wireless communication device (such as reference 1500) operating as a wireless STA or within a wireless AP. Figure 12 The process 1500 is performed by the described wireless communication device 1200. In some examples, the process 1500 may be performed by a wireless STA (such as reference STA). Figure 1 The STA described in STA 104 is used to perform this action.
[0189] In some examples, in block 1505, the device may receive an indication that either GTK mode or PTK mode is configured to control frame security. Operation of block 1505 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 1505 may be provided by reference to [reference needed]. Figure 12 The described verification component 1230 is used to perform this.
[0190] In some examples, in block 1510, the device may generate a control frame including a CMF (Security Key Function), which includes a security key ID, a PN (Programmable Node Indicator) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to an indication of GTK mode or PTK mode. Operation of block 1510 may be performed according to examples as disclosed herein. In some specific implementations, aspects of the operation of block 1510 may be provided by reference to [reference needed]. Figure 12The described CMF component 1225 is used to perform this.
[0191] In some examples, in block 1515, the device may output a control frame for transmission. The operation of block 1515 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 1515 may be determined by reference to [reference needed]. Figure 12 The described CMF component 1225 is used to perform this.
[0192] Figure 16 A flowchart illustrating an example process 1600 that can be executed by or at a device supporting security control frames in wireless communication is shown. Operation of process 1600 can be implemented by a device or its components as described herein. For example, process 1600 can be implemented by a wireless communication device (such as reference 1600) operating as a wireless AP or wireless STA, or within a wireless AP or wireless STA. Figure 11 The described wireless communication device 1100) performs the procedure. In some examples, the procedure 1600 may be performed by a wireless AP or a wireless STA (such as reference 1100). Figure 1 (either AP 102 or STA 104 as described) to perform.
[0193] In some examples, in block 1605, the device may obtain a control frame that includes a set of multiple padding bits preceding a CMF and a frame end field, wherein the number of such multiple padding bits is based on whether the control frame is a security control frame, and when the control frame is a security control frame, based on the security type associated with the control frame. Operation of block 1605 may be performed according to examples as disclosed herein. In some specific implementations, aspects of the operation of block 1605 may be provided by reference to [reference]. Figure 11 and Figure 12 The described CMF component 1125 or CMF component 1225 is used to perform this.
[0194] In some examples, in block 1610, the apparatus may decode the control frame according to the number of such sets of multiple padding bits. The operation of block 1610 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 1610 may be as described in the references... Figure 11 and Figure 12 The verification component 1130 or verification component 1230 described herein shall be used to perform the verification.
[0195] Figure 17 A flowchart illustrating an example process 1700 that can be executed by or at a device supporting security control frames in wireless communication is shown. Operation of process 1700 can be implemented by a device or its components as described herein. For example, process 1700 can be implemented by a wireless communication device (such as reference 1700) operating as a wireless AP or wireless STA, or within a wireless AP or wireless STA. Figure 11 The described wireless communication device 1100) performs this operation. In some examples, process 1700 may be performed by a wireless AP or a wireless STA (such as reference 1100). Figure 1 (either AP 102 or STA 104 as described) to perform.
[0196] In some examples, in block 1705, the apparatus may generate a control frame comprising a first portion and a second portion of a CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame. Operation of block 1705 may be performed according to examples as disclosed herein. In some specific implementations, aspects of the operation of block 1705 may be provided by reference to [reference needed]. Figure 11 and Figure 12 The described CMF component 1125 or CMF component 1225 is used to perform this.
[0197] In some examples, in block 1710, the device may output a control frame for transmission. The operation of block 1710 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 1710 may be as described in the references... Figure 11 and Figure 12 The frame manager 1135 or frame manager 1235 described herein shall be used to execute this.
[0198] Figure 18 A flowchart illustrating an example process 1800 that can be executed by or at a device supporting security control frames in wireless communication is shown. Operation of process 1800 can be implemented by a device or its components as described herein. For example, process 1800 can be performed by a wireless communication device (such as reference 1800) operating as a wireless AP or wireless STA, or within a wireless AP or wireless STA. Figure 11 The described wireless communication device 1100) performs the procedure. In some examples, the procedure 1800 may be performed by a wireless AP or a wireless STA (such as reference 1100). Figure 1 (either AP 102 or STA 104 as described) to perform.
[0199] In some examples, in block 1805, the apparatus may generate a frame including a CMF (Media Access Control File), which includes an AID, an ID of a security key, a PN (Programmable Node) indication, and a first integrity check, wherein the AID is different from the Media Access Control address associated with the frame, and wherein the first integrity check is based at least on the security key associated with the AID and the PN indication. Operation of block 1805 may be performed according to examples as disclosed herein. In some specific implementations, aspects of the operation of block 1805 may be derived from references... Figure 11 and Figure 12 The described CMF component 1125 or CMF component 1225 is used to perform this.
[0200] In some examples, in block 1810, the device may output a frame for transmission. The operation of block 1810 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 1810 may be as described in the references... Figure 11 and Figure 12 The frame manager 1135 or frame manager 1235 described herein shall be used to execute this.
[0201] Figure 19 A flowchart illustrating an example process 1900 that can be executed by or at a device supporting security control frames in wireless communication is shown. Operation of process 1900 can be implemented by a device or its components as described herein. For example, process 1900 can be implemented by a wireless communication device (such as reference _____) operating as a wireless STA or within a wireless AP. Figure 12 The described wireless communication device 1200) performs the procedure. In some examples, the procedure 1900 may be performed by a wireless STA (such as reference STA). Figure 1 The STA described in STA 104 is used to perform this action.
[0202] In some examples, in block 1905, the device may receive an indication that either GTK mode or PTK mode is configured to control frame security. Operation of block 1905 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 1905 may be provided by reference to [reference needed]. Figure 12 The described verification component 1230 is used to perform this.
[0203] In some examples, in block 1910, the device may generate a control frame including a CMF (Security Key Function), which includes a security key ID, a PN (Programmable Node Indicator) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to an indication of GTK mode or PTK mode. Operation of block 1910 may be performed according to examples as disclosed herein. In some specific implementations, aspects of the operation of block 1910 may be provided by reference to [reference needed]. Figure 12 The described CMF component 1225 is used to perform this.
[0204] In some examples, in block 1915, the device may output a control frame for transmission. The operation of block 1915 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 1915 may be as described in the references... Figure 12 The frame manager 1235 described is used to execute this.
[0205] Figure 20A flowchart illustrating an example process 2000 that can be executed by or at a device supporting security control frames in wireless communication is shown. Operation of process 2000 can be implemented by a device or its components as described herein. For example, process 2000 can be implemented by a wireless communication device (such as reference 2000) operating as a wireless AP or wireless STA, or within a wireless AP or wireless STA. Figure 11 The described wireless communication device 1100) performs the operation. In some examples, process 2000 may be performed by a wireless AP or a wireless STA (such as reference 1100). Figure 1 (either AP 102 or STA 104 as described) to perform.
[0206] In some examples, in block 2005, the apparatus may generate a control frame that includes a set of multiple padding bits preceding a CMF and a frame end field, wherein the number of such multiple padding bits is based on whether the control frame is a security control frame, and when the control frame is a security control frame, based on the security type associated with the control frame. The operation of block 2005 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 2005 may be as described in the references... Figure 11 and Figure 12 The described CMF component 1125 or CMF component 1225 is used to perform this.
[0207] In some examples, in block 2010, the device may output a control frame for transmission. The operation of block 2010 may be performed according to the examples disclosed herein. In some specific implementations, aspects of the operation of block 2010 may be provided by reference to [reference needed]. Figure 11 and Figure 12 The frame manager 1135 or frame manager 1235 described herein shall be used to execute this.
[0208] Specific implementation examples are described in the following numbered clauses: Clause 1: A method for wireless communication, the method comprising: obtaining a control frame, the control frame including a first portion of a security key (CMF) and a second portion of the CMF, the first portion of the CMF including an ID of a security key, and the second portion of the CMF including a truncated first integrity check; and verifying the validity of the control frame based on a comparison of the truncated first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key, a portion PN associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.
[0209] Clause 2: The method according to Clause 1, wherein the CMF includes the partial PN, wherein the partial PN included in the CMF is combined with the basic PN associated with the control frame to obtain the complete PN associated with the control frame, and wherein the second integrity check is based on the complete PN.
[0210] Clause 3: The method according to any one of Clauses 1 to 2, wherein the number of bits in the portion of the PN is based on the frame type of the control frame.
[0211] Clause 4: The method according to any one of Clauses 1 to 3, wherein the second integrity check is truncated to include a subset of bits of the authentication code output, the authentication code output being based at least on the security key, the partial PN, and one or more portions of the control frame.
[0212] Clause 5: The method according to any one of Clauses 1 to 4, wherein the validity of each of the various types of control frames is verified based on a partial PN and a first integrity check of the truncated portion.
[0213] Clause 6: The method according to any one of Clauses 1 to 5, wherein the first portion of the CMF includes the portion PN; and wherein the first portion of the CMF is provided at a first deterministic position within the control information portion of the control frame, the first deterministic position being prior to one or more fields protected by the truncated first integrity check, and the second portion of the CMF is provided at a second deterministic position within the control information portion of the control frame, the second deterministic position being subsequent to the one or more fields protected by the truncated first integrity check.
[0214] Clause 7: The method described in Clause 6, wherein the first portion of the CMF is placed before or after one or more information fields within the control information portion based on the frame type of the control frame.
[0215] Clause 8: The method according to any one of Clauses 6 to 7, wherein the second part of the CMF is included as a user information field within the control information portion, the user information field being located before a plurality of padding bits being located at the end of the control information portion, or the second part of the CMF is included within the plurality of padding bits.
[0216] Clause 9: The method according to any one of Clauses 6 to 8, wherein the second portion of the CMF is included within the control information portion at a location specified together with or before the first portion of the CMF.
[0217] Clause 10: The method according to any one of Clauses 6 to 9, wherein the number of padding bits after the second portion of the CMF is a fixed value announced via one or more management frames, or a value signaled before the first portion of the CMF.
[0218] Clause 11: A method for wireless communication, the method comprising: obtaining a frame including a CMF, the CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame; and verifying the validity of the frame based on a comparison of the first integrity check and a second integrity check, wherein the second integrity check is based at least on the security key associated with the AID and the PN indication.
[0219] Clause 12: The method described in Clause 11, wherein the frame is a trigger frame, a block acknowledgment frame, or a block acknowledgment request frame.
[0220] Clause 13: The method according to any one of Clauses 11 to 12, wherein the AID is provided in one or more MPDUs having a secure MAC header that solicits a protected control frame.
[0221] Clause 14: The method according to Clause 13, wherein the MPDU requesting the protected control frame is carried in a UHRPPDU.
[0222] Clause 15: The method according to any one of Clauses 11 to 14, wherein the AID is provided in one or more frames generated by a non-access point station soliciting a protected control frame.
[0223] Clause 16: The method according to Clause 15, wherein the one or more frames soliciting protected control frames include an indication to request protected control frames.
[0224] Clause 17: A method for wireless communication, the method comprising: obtaining an indication that one of a GTK mode or a PTK mode is configured for control frame security; generating a control frame including a CMF, the CMF including a security key ID, a PN indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication for the GTK mode or the PTK mode; and outputting the control frame for transmission.
[0225] Clause 18: The method according to Clause 17, wherein the control frame is a group control frame or a single control frame, and wherein the group control frame is protected by the GTK according to the GTK mode or the PTK mode, and the single control frame is protected by the PTK according to the PTK mode or by the GTK according to the GTK mode.
[0226] Clause 19: In the method according to any one of Clauses 17 to 18, the indication in which one of the GTK mode or the PTK mode is configured for the security of the control frame is a dynamic indication that provides dynamic switching between the GTK mode and the PTK mode.
[0227] Clause 20: The method described in Clause 19, wherein the indication that one of the GTK mode or the PTK mode is configured for the security of the control frame is obtained from the UHR operation element.
[0228] Clause 21: A method for wireless communication, the method comprising: obtaining a control frame including a CMF and a plurality of padding bits preceding a frame end field, wherein the number of the plurality of padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on a security type associated with the control frame; and decoding the control frame according to the number of the plurality of padding bits.
[0229] Clause 22: The method according to Clause 21 further comprises: outputting a frame that solicits the control frame, wherein the frame includes a second plurality of padding bits, and wherein the number of the second plurality of padding bits is based on whether the control frame solicited by the frame is the security control frame, and when the control frame is the security control frame, based on the security type associated with the control frame.
[0230] Clause 23: The method according to Clause 22, wherein the first frame soliciting an unprotected control frame includes a first number of padding bits, the first number of padding bits being less than the second number of padding bits included in the second frame soliciting a protected control frame.
[0231] Clause 24: The method according to Clauses 21 to 23 further comprises: verifying the validity of the control frame based on a comparison of a second integrity check and a first integrity check included in the CMF, wherein the second integrity check is based at least on a security key indicated in the CMF, a PN indicated in the CMF, and one or more portions of the control frame.
[0232] Clause 25: The method according to any one of Clauses 21 to 24, wherein the unprotected control frame includes a first number of padding bits, the first number of padding bits being less than a second number of padding bits associated with the protected control frame.
[0233] Clause 26: The method according to Clause 25, wherein the unencrypted protected control frame includes the second number of padding bits, and wherein the second number of padding bits is less than the third number of padding bits associated with the encrypted protected control frame.
[0234] Clause 27: A method for wireless communication, the method comprising: generating a control frame, the control frame including a first portion of a security key and a second portion of the security key and the second portion of the security key and the control frame including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, a portion of the control frame (PN) associated with the control frame, and one or more portions of the control frame; and outputting the control frame for transmission.
[0235] Clause 28: The method according to Clause 27, wherein the CMF includes the partial PN, wherein the partial PN included in the CMF is combined with the basic PN associated with the control frame to provide the complete PN associated with the control frame, and wherein the truncated integrity check includes a subset of bits of a full integrity check based on the complete PN.
[0236] Clause 29: The method according to any one of Clauses 27 to 28, wherein the number of bits in the portion PN is based on the frame type of the control frame.
[0237] Clause 30: The method according to any one of Clauses 27 to 29, wherein the integrity check of the truncated portion includes a subset of bits of the authentication code output, the authentication code output being based at least on the security key, the partial PN, and one or more portions of the control frame.
[0238] Clause 31: The method according to any one of Clauses 27 to 30, wherein the validity of each of the various types of control frames is verified based on a partial PN and a first integrity check of the truncated portion.
[0239] Clause 32: The method according to any one of Clauses 27 to 31, wherein the first portion of the CMF includes the portion PN; and wherein the first portion of the CMF is provided at a first deterministic position within the control information portion of the control frame, the first deterministic position being prior to one or more fields protected by the truncated integrity check, and the second portion of the CMF is provided at a second deterministic position within the control information portion of the control frame, the second deterministic position being subsequent to the one or more fields protected by the truncated integrity check.
[0240] Clause 33: The method according to Clause 32, wherein the first portion of the CMF is placed before or after one or more information fields within the control information portion based on the frame type of the control frame.
[0241] Clause 34: The method according to any one of Clauses 32 to 33, wherein the second portion of the CMF is included as a user information field within the control information portion, the user information field being located before a plurality of padding bits being located at the end of the control information portion, or the second portion of the CMF being included within the plurality of padding bits.
[0242] Clause 35: The method according to any one of Clauses 32 to 34, wherein the second portion of the CMF is included within the control information portion at a location specified together with or before the first portion of the CMF.
[0243] Clause 36: The method according to any one of Clauses 32 to 35, wherein the number of padding bits after the second portion of the CMF is a fixed value announced via one or more management frames, or a value signaled before the first portion of the CMF.
[0244] Clause 37: A method for wireless communication, the method comprising: generating a frame including a CMF, the CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, wherein the AID is different from a media access control address associated with the frame, and wherein the first integrity check is based at least on the security key associated with the AID and the PN indication; and outputting the frame for transmission.
[0245] Clause 38: The method described in Clause 37, wherein the frame is a trigger frame, a block acknowledgment frame, or a block acknowledgment request frame.
[0246] Clause 39: The method according to any one of Clauses 37 to 38, wherein the AID is provided in one or more MPDUs having a secure MAC header that solicits protected control frames.
[0247] Clause 40: The method according to Clause 39, wherein the MPDU requesting the protected control frame is carried in a UHRPPDU.
[0248] Clause 41: The method according to any one of Clauses 37 to 40, wherein the AID is provided in one or more frames generated by a non-access point station soliciting a protected control frame.
[0249] Clause 42: The method according to Clause 41, wherein the one or more frames soliciting protected control frames include an indication to request protected control frames.
[0250] Clause 43: A method for wireless communication, the method comprising: obtaining an indication that one of a GTK mode or a PTK mode is configured for control frame security; generating a control frame including a CMF, the CMF including a security key ID, a PN indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication for the GTK mode or the PTK mode; and outputting the control frame for transmission.
[0251] Clause 44: The method according to Clause 43, wherein the control frame is a group control frame or a single control frame, and wherein the group control frame is protected by the GTK according to the GTK mode or the PTK mode, and the single control frame is protected by the PTK according to the PTK mode or by the GTK according to the GTK mode.
[0252] Clause 45: In the method according to any one of Clauses 43 to 44, the indication in which one of the GTK mode or the PTK mode is configured for the security of the control frame is a dynamic indication that provides dynamic switching between the GTK mode and the PTK mode.
[0253] Clause 46: The method according to Clause 45, wherein the indication that one of the GTK mode or the PTK mode is configured for the security of the control frame is obtained from the UHR operation element.
[0254] Clause 47: A method for wireless communication, the method comprising: generating a control frame including a CMF and a plurality of padding bits preceding a frame end field, wherein the number of the plurality of padding bits is based on whether the control frame is a secure control frame, and when the control frame is a secure control frame, based on a security type associated with the control frame; and outputting the control frame for transmission.
[0255] Clause 48: The method according to Clause 47 further comprises: obtaining a frame that solicits the control frame, wherein the frame includes a second plurality of padding bits, and wherein the number of the second plurality of padding bits is based on whether the control frame solicited by the frame is the security control frame, and when the control frame is the security control frame, based on the security type associated with the control frame.
[0256] Clause 49: The method according to Clause 48, wherein the first frame soliciting an unprotected control frame includes a first number of padding bits, the first number of padding bits being less than the second number of padding bits included in the second frame soliciting a protected control frame.
[0257] Clause 50: The method according to Clauses 47 to 49, wherein the CMF field includes an integrity check based at least on the security key indicated in the CMF, the PN indicated in the CMF, and one or more portions of the control frame.
[0258] Clause 51: The method according to any one of Clauses 47 to 50, wherein the unprotected control frame includes a first number of padding bits, the first number of padding bits being less than a second number of padding bits associated with the protected control frame.
[0259] Clause 52: The method according to Clause 51, wherein the unencrypted protected control frame includes the second number of padding bits, and wherein the second number of padding bits is less than the third number of padding bits associated with the encrypted protected control frame.
[0260] Clause 53: An apparatus for wireless communication, the apparatus comprising: a processing system including processor circuitry and memory circuitry, the memory circuitry storing code, the processing system being configured to cause the apparatus to perform a method according to any one of Clauses 1 to 10.
[0261] Clause 54: An apparatus for wireless communication, the apparatus comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, so that the apparatus performs a method according to any one of Clauses 1 to 10.
[0262] Clause 55: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to any one of Clauses 1 to 10.
[0263] Clause 56: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform the method according to any one of Clauses 1 to 10.
[0264] Clause 57: An apparatus for wireless communication, the apparatus comprising: a processing system including processor circuitry and memory circuitry, the memory circuitry storing code, the processing system being configured to cause the apparatus to perform a method according to any one of Clauses 11 to 16.
[0265] Clause 58: An apparatus for wireless communication, the apparatus comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, so that the apparatus performs a method according to any one of Clauses 11 to 16.
[0266] Clause 59: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to any one of Clauses 11 to 16.
[0267] Clause 60: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform a method according to any one of Clauses 11 to 16.
[0268] Clause 61: An apparatus for wireless communication, the apparatus comprising: a processing system including processor circuitry and memory circuitry, the memory circuitry storing code, the processing system being configured to cause the apparatus to perform a method according to any one of Clauses 17 to 20.
[0269] Clause 62: An apparatus for wireless communication, the apparatus comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, so that the apparatus performs a method according to any one of Clauses 17 to 20.
[0270] Clause 63: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to any one of Clauses 17 to 20.
[0271] Clause 64: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform a method according to any one of Clauses 17 to 20.
[0272] Clause 65: An apparatus for wireless communication, the apparatus comprising: a processing system including processor circuitry and memory circuitry, the memory circuitry storing code, the processing system being configured to cause the apparatus to perform a method according to any one of Clauses 21 to 26.
[0273] Clause 66: An apparatus for wireless communication, the apparatus comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, so that the apparatus performs a method according to any one of Clauses 21 to 26.
[0274] Clause 67: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to any one of Clauses 21 to 26.
[0275] Clause 68: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform a method according to any one of Clauses 21 to 26.
[0276] Clause 69: An apparatus for wireless communication, the apparatus comprising: a processing system including processor circuitry and memory circuitry, the memory circuitry storing code, the processing system being configured to cause the apparatus to perform a method according to any one of Clauses 27 to 36.
[0277] Clause 70: An apparatus for wireless communication, the apparatus comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, so that the apparatus performs a method according to any one of Clauses 27 to 36.
[0278] Clause 71: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to any one of Clauses 27 to 36.
[0279] Clause 72: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform a method according to any one of Clauses 27 to 36.
[0280] Clause 73: An apparatus for wireless communication, the apparatus comprising: a processing system including processor circuitry and memory circuitry, the memory circuitry storing code, the processing system being configured to cause the apparatus to perform a method according to any one of Clauses 37 to 42.
[0281] Clause 74: An apparatus for wireless communication, the apparatus comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, so that the apparatus performs a method according to any one of Clauses 37 to 42.
[0282] Clause 75: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to any one of Clauses 37 to 42.
[0283] Clause 76: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform a method according to any one of Clauses 37 to 42.
[0284] Clause 77: An apparatus for wireless communication, the apparatus comprising: a processing system including processor circuitry and memory circuitry, the memory circuitry storing code, the processing system being configured to cause the apparatus to perform a method according to any one of Clauses 43 to 46.
[0285] Clause 78: An apparatus for wireless communication, the apparatus comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, so that the apparatus performs a method according to any one of Clauses 43 to 46.
[0286] Clause 79: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to any one of Clauses 43 to 46.
[0287] Clause 80: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform a method according to any one of Clauses 43 to 46.
[0288] Clause 81: An apparatus for wireless communication, the apparatus comprising: a processing system including processor circuitry and memory circuitry, the memory circuitry storing code, the processing system being configured to cause the apparatus to perform a method according to any one of Clauses 47 to 52.
[0289] Clause 82: An apparatus for wireless communication, the apparatus comprising: one or more memories storing processor-executable code; and one or more processors coupled to the one or more memories and capable of operating individually or jointly to execute the code, so that the apparatus performs a method according to any one of Clauses 47 to 52.
[0290] Clause 83: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to any one of Clauses 47 to 52.
[0291] Clause 84: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform a method according to any one of Clauses 47 to 52.
[0292] As used herein, the term "determine" encompasses a wide variety of actions, and therefore, "determine" can include calculation, computation, processing, derivation, estimation, investigation, searching (such as by searching in a table, database, or other data structure), reasoning, probing, or measurement, among other possibilities. Furthermore, "determine" can include receiving (such as receiving information), accessing (such as accessing data stored in memory), or sending (such as sending information), among other possibilities. Additionally, "determine" can include parsing, selecting, obtaining, choosing, building, and other similar actions.
[0293] As used herein, the phrase “at least one of” or “one or more of” refers to any combination of these items, including a single member. For example, “at least one of a, b, or c” is intended to cover: a, b, c, ab, ac, bc, and abc. As used herein, “or” is intended to be interpreted in an inclusive sense unless otherwise expressly indicated. For example, “a or b” may include only a, only b, or a combination of a and b. Furthermore, as used herein, the phrase referring to “a” element means one or more of such elements that act individually or collectively to perform the stated function. Additionally, “set” means one or more items, and “subset” means less than the entire set, but not empty.
[0294] As used herein, unless otherwise expressly indicated, “based on” is intended to be interpreted in an inclusive sense. For example, unless otherwise explicitly indicated, “based on” may be used interchangeably with “at least partially based on,” “associated with,” “associated with,” or “according to.” Specifically, unless the phrase in the context means “based on only one” or an equivalent, whether it is “based on one” or “at least partially based on one”, it may be based solely on “one” or based on a combination of “one” and one or more other factors, conditions, or information.
[0295] The various exemplary components, logic units, logic blocks, modules, circuits, operations, and algorithmic processes described in conjunction with the examples disclosed herein can be implemented as electronic hardware, firmware, software, or a combination of hardware, firmware, or software, including the structures disclosed in this specification and their structural equivalents. This interchangeability of hardware, firmware, and software has been generally described in terms of its functionality and exemplified in the various exemplary components, blocks, modules, circuits, and processes described above. Whether this functionality is implemented in hardware, firmware, or software depends on the specific application and the design constraints imposed on the overall system.
[0296] Various modifications to the examples described in this disclosure will be apparent to those skilled in the art, and the general principles defined herein may be applied to other examples without departing from the spirit or scope of this disclosure. Therefore, the claims are not intended to be limited to the examples shown herein, but are to be granted the widest scope consistent with this disclosure, the principles disclosed herein, and the novel features.
[0297] Additionally, the various features described in this specification in the context of individual examples may also be implemented in combination in a single specific embodiment. Conversely, the various features described in the context of a single specific embodiment may also be implemented individually or in any suitable sub-combination in multiple examples. Thus, although features may be described above as functioning in a particular combination, and even initially claimed in this way, one or more features from the claimed combination may be removed from the combination in some cases, and the claimed combination may involve sub-combinations or variations of sub-combinations.
[0298] Similarly, although operations are depicted in a specific order in the diagrams, this should not be construed as requiring such operations to be performed in the specific order shown or in sequential order, or to perform all illustrated operations to achieve the desired result. Furthermore, the accompanying figures may schematically depict one or more example processes in the form of flowcharts or flow diagrams. However, other operations not depicted may be incorporated into the schematically illustrated example processes. For example, one or more additional operations may be performed before, after, simultaneously with, or between any of the illustrated operations. In some environments, multitasking and parallel processing may be advantageous. Moreover, the separation of various system components in the examples described above should not be construed as requiring such separation in all examples, but rather should be understood as meaning that the described program components and systems can generally be integrated together in a single software product or encapsulated in multiple software products.
Claims
1. An apparatus, the apparatus comprising: A processing system, comprising processor circuitry and memory circuitry, wherein the memory circuitry stores code, and the processing system is configured to cause the device to: A control frame is obtained, the control frame including a first part of a control message integrity check field (CMF) and a second part of the CMF, the first part of the CMF including an identifier (ID) of a security key, and the second part of the CMF including a truncated first integrity check; as well as The validity of the control frame is verified by comparing the first integrity check and the second integrity check, wherein the second integrity check is based at least on the security key, the partial block number (PN) associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated in correspondence with the first integrity check.
2. The apparatus of claim 1, wherein the CMF includes the partial PN, wherein the partial PN included in the CMF is combined with a basic PN associated with the control frame to obtain a complete PN associated with the control frame, and wherein the second integrity check is based on the complete PN.
3. The apparatus of claim 1, wherein the number of bits in the portion of the PN is based on the frame type of the control frame.
4. The apparatus of claim 1, wherein the second integrity check is truncated to include a subset of bits of the authentication code output, the authentication code output being based at least on the security key, the portion of the PN, and one or more portions of the control frame.
5. The apparatus according to claim 1, wherein: The validity of each of the many different types of control frames is verified based on a partial PN and a truncated first integrity check.
6. The apparatus according to claim 1, wherein: The first portion of the CMF includes the portion PN; and The first portion of the CMF is provided at a first deterministic position within the control information portion of the control frame, the first deterministic position being located before one or more fields protected by the truncated first integrity check, and the second portion of the CMF is provided at a second deterministic position within the control information portion of the control frame, the second deterministic position being located after the one or more fields protected by the truncated first integrity check.
7. The apparatus of claim 6, wherein the first portion of the CMF is placed before or after one or more information fields within the control information portion based on the frame type of the control frame.
8. The apparatus of claim 6, wherein the second portion of the CMF is included as a user information field within the control information portion, the user information field preceding a plurality of padding bits, the plurality of padding bits being located at the end of the control information portion, or the second portion of the CMF is included within the plurality of padding bits.
9. The apparatus of claim 6, wherein the second portion of the CMF is included within the control information portion at a location specified together with or before the first portion of the CMF.
10. The apparatus of claim 6, wherein the number of padding bits following the second portion of the CMF is a fixed value announced via one or more management frames, or a value signaled before the first portion of the CMF.
11. An apparatus comprising: A processing system, comprising processor circuitry and memory circuitry, wherein the memory circuitry stores code, and the processing system is configured to cause the device to: A control frame is obtained, the control frame including a control message integrity check field (CMF) and a plurality of padding bits before a frame end field, wherein the number of the plurality of padding bits is based on whether the control frame is a security control frame, and when the control frame is a security control frame, based on the security type associated with the control frame; as well as The control frame is decoded according to the number of the plurality of padding bits.
12. The apparatus of claim 11, wherein the processing system is further configured to cause the apparatus to: An output frame, the frame soliciting the control frame, wherein the frame includes a second plurality of padding bits, and wherein the number of the second plurality of padding bits is based on whether the control frame solicited by the frame is the security control frame, and when the control frame is the security control frame, based on the security type associated with the control frame.
13. The apparatus of claim 12, wherein the first frame soliciting an unprotected control frame includes a first number of padding bits, the first number of padding bits being less than the second number of padding bits included in the second frame soliciting a protected control frame.
14. The apparatus of claim 11, wherein the processing system is further configured to cause the apparatus to: The validity of the control frame is verified by comparing a second integrity check with a first integrity check included in the CMF, wherein the second integrity check is based at least on the security key indicated in the CMF, the block number indicated in the CMF, and one or more portions of the control frame.
15. The apparatus of claim 11, wherein the unprotected control frame includes a first number of padding bits, the first number of padding bits being less than a second number of padding bits associated with the protected control frame.
16. The apparatus of claim 15, wherein the unencrypted protected control frame includes the second number of padding bits, and wherein the second number of padding bits is less than the third number of padding bits associated with the encrypted protected control frame.
17. An apparatus comprising: A processing system, comprising processor circuitry and memory circuitry, wherein the memory circuitry stores code, and the processing system is configured to cause the device to: An indication is obtained that either Group Temporary Key (GTK) mode or Paired Temporary Key (PTK) mode is configured to control frame security; Generate a control frame, the control frame including a Control Message Integrity Check (CMF) field, the Control Message Integrity Check (CMF) including a Security Key Identifier (ID), a Block Number (PN) indication, and a first integrity check, wherein the first integrity check is calculated based on GTK or PTK according to the indication for the GTK mode or the PTK mode; and The control frame is output for transmission.
18. The apparatus of claim 17, wherein the control frame is a group control frame or a single control frame, and wherein the group control frame is protected by the GTK according to the GTK mode or the PTK mode, and the single control frame is protected by the PTK according to the PTK mode or by the GTK according to the GTK mode.
19. The apparatus of claim 17, wherein the indication configured for control frame security, wherein one of the GTK mode or the PTK mode, is a dynamic indication that provides dynamic switching between the GTK mode and the PTK mode.
20. The apparatus of claim 19, wherein the indication for the control frame security, which is configured to be one of the GTK mode or the PTK mode, is obtained from an Ultra-High Reliability (UHR) operating element.
21. An apparatus comprising: A processing system, comprising processor circuitry and memory circuitry, wherein the memory circuitry stores code, and the processing system is configured to cause the device to: A control frame is generated, the control frame including a first part of a control message integrity check field (CMF) and a second part of the CMF, the first part of the CMF including an identifier (ID) of a security key, and the second part of the CMF including a truncated integrity check, wherein the truncated integrity check is based at least on the security key, a partial block number (PN) associated with the control frame, and one or more parts of the control frame; as well as The control frame is output for transmission.
22. The apparatus of claim 21, wherein the CMF includes the partial PN, wherein the partial PN included in the CMF is combined with a basic PN associated with the control frame to provide a complete PN associated with the control frame, and wherein the truncated integrity check includes a subset of bits of a full integrity check based on the complete PN.
23. The apparatus of claim 21, wherein the number of bits in the portion of the PN is based on the frame type of the control frame.
24. The apparatus of claim 21, wherein the truncated integrity check comprises a subset of bits of the authentication code output, the authentication code output being based at least on the security key, the partial PN, and one or more portions of the control frame.
25. The apparatus according to claim 21, wherein: The validity of each of the many different types of control frames is verified based on a partial PN and a truncated first integrity check.
26. The apparatus according to claim 21, wherein: The first portion of the CMF includes the portion PN; and The first portion of the CMF is provided at a first deterministic position within the control information portion of the control frame, the first deterministic position being located before one or more fields protected by the truncated integrity check, and the second portion of the CMF is provided at a second deterministic position within the control information portion of the control frame, the second deterministic position being located after the one or more fields protected by the truncated integrity check.
27. The apparatus of claim 26, wherein the first portion of the CMF is placed before or after one or more information fields within the control information portion based on the frame type of the control frame.
28. The apparatus of claim 26, wherein the second portion of the CMF is included as a user information field within the control information portion, the user information field preceding a plurality of padding bits, the plurality of padding bits being located at the end of the control information portion, or the second portion of the CMF is included within the plurality of padding bits.
29. The apparatus of claim 26, wherein the second portion of the CMF is included within the control information portion at a location specified together with or before the first portion of the CMF.
30. The apparatus of claim 26, wherein the number of padding bits following the second portion of the CMF is a fixed value announced via one or more management frames, or a value signaled before the first portion of the CMF.