Envelope circuit for providing replay and integrity protection using an encryption algorithm
Patent Information
- Application Number
- DE102025107718
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-07
- Filing Date
- 2025-02-28
- Publication Date
- 2025-09-11
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to U.S. Provisional Application No. 63 / 563,049, filed March 8, 2024, the contents of which are hereby incorporated by reference in their entirety. TECHNICAL FIELD
[0002] The present disclosure relates generally to communications using the Wi-Fi™ protocol, and more particularly to implementing both data encryption and management frame authentication using data encryption circuitry. BACKGROUND
[0003] Wireless communication devices may include transceivers configured to transmit / receive data using any of a variety of communication protocols. For example, a transceiver may transmit / receive signals using the Wi-Fi protocol, which specifies a variety of features, including those related to data encryption / security. The Wi-Fi protocol provides authenticated data encryption using the 128-bit Advanced Encryption Standard (AES). The Wi-Fi protocol supports AES in a variety of modes, such as Counter with Cipher Block Chaining Message Authentication Code (CCM) mode and Galois / Counter mode (GCM).
[0004] Management frames, such as authentication, deauthentication, association, dissociation, beacons, and probes, are used by wireless clients to establish and tear down sessions for network services. Unlike data traffic, which can be encrypted to provide a level of confidentiality, management frames must be heard and understood by all clients and must therefore be sent unencrypted. Although these frames cannot be encrypted, they must be protected against forgery to prevent attacks on the wireless medium. For example, an attacker can forge management frames from an access point to attack a client associated with the access point.
[0005] Thus, the Wi-Fi protocol also provides robust management frame protection using the 128-bit Broadcast / Multicast Integrity Protocol (BIP) Galois Message Authentication Code (GMAC). BIP-GMAC is a method for providing replay and integrity protection for group-addressed management frames. Integrity protection and replay protection are important aspects in a robust network to prevent attacks that use management frames that are critical to stable network operation but can be easily forged and injected, such as beacon frames. BIP is used to calculate a Message Integrity Code (MIC) based on the payload of the group-addressed management frames (e.g., Management Media Access Control (MAC) Protocol Data Unit (MMPDU)) and an Additional Authentication Data (AAD) unit. The MIC is used to authenticate management frames sent from a sender device to a receiver device.In this way, AES and BIP-GMAC together can provide data encryption and management frame protection.
[0006] Regarding data encryption and authentication, the Wi-Fi protocol currently requires communication devices to be capable of operating in two modes. The first mode is a "data encryption and authentication" mode of operation, in which both data encryption and management frame protection functions are performed. The second mode is an "authentication-only" mode of operation, in which only the management frame protection function is performed. SHORT DESCRIPTION OF THE CHARACTERS
[0007] The present embodiments are illustrated by way of example and not limitation in the figures of the accompanying drawings. Fig. 1 is a block diagram illustrating transmitter and receiver devices that can communicate using the Wi-Fi protocol, according to some embodiments of the present disclosure. Fig. Figure 2A is a block diagram showing an encryption unit of the transmitter of Fig. 1, which implements techniques to enable an authenticated encryption algorithm to operate in both a data encryption and authentication and an authentication-only mode of operation, according to some embodiments of the present disclosure. Fig. 2B and Fig. 2C are block diagrams showing an encryption unit of the receiver of Fig. 1 that implements techniques to enable an authenticated encryption algorithm to operate in both a data encryption and authentication and an authentication-only mode of operation, according to some embodiments of the present disclosure. Fig. Figure 3A is a block diagram showing an encryption unit of the transmitter of Fig. 1, which implements techniques to enable an authenticated encryption algorithm to operate in both a data encryption and authentication and an authentication-only mode of operation, according to some embodiments of the present disclosure. Fig. Figure 3B is a block diagram illustrating an encryption unit of the receiver of Fig. 1, which implements techniques to enable an authenticated encryption algorithm to operate in both a data encryption and authentication and an authentication-only mode of operation, according to some embodiments of the present disclosure. Fig. Figure 3C is a block diagram showing an encryption unit of the receiver of Fig. 1, which implements techniques to enable an authenticated encryption algorithm to operate in both a data encryption and authentication and an authentication-only mode of operation, according to some embodiments of the present disclosure. Fig. 4 is a flow diagram of a method for enabling an authenticated encryption algorithm to operate in both a data encryption and authentication and an authentication-only mode of operation, according to some embodiments of the present disclosure. Fig. 5 is a flow diagram of a method for enabling an authenticated encryption algorithm to operate in both a data encryption and authentication and an authentication-only mode of operation, according to some embodiments of the present disclosure. Fig. 6 is a detailed block diagram of the transmitter of Fig. 1 according to some embodiments of the present disclosure. Fig. 7 illustrates a communication device according to some embodiments of the present disclosure. DETAILED DESCRIPTION
[0008] In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the present embodiments. However, it will be apparent to one skilled in the art that the present embodiments may be practiced without these specific details. In other instances, well-known circuits, structures, and techniques are not shown in detail, but rather in block diagram form to avoid unnecessarily obscuring an understanding of this description.
[0009] Reference in the specification to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment. The phrase "in one embodiment" appears in various places throughout this specification and does not necessarily refer to the same embodiment.
[0010] Although AES can provide data encryption, there are algorithms that can provide authenticated encryption (i.e., both data encryption and authentication / management frame protection functionality). An example of such an algorithm is ASCON, which also provides a symmetric 128-bit cipher. Such algorithms could replace the current symmetric 128-bit cipher provided by AES.However, because the Wi-Fi protocol requires the provision of a data encryption and authentication mode as well as an authentication-only mode, replacing AES requires additional functionality to allow an authenticated encryption algorithm to output original data with a MIC (as would be the case in an authentication-only mode) as well as encrypted data with a MIC (as would be the case in a data encryption and authentication mode).
[0011] The embodiments described herein are directed to circuits implementing an authenticated encryption algorithm and operable in both a data encryption and authentication mode of operation and an authentication-only mode of operation. The circuits may operate based on an authentication control flag having one of two values. When the authentication control flag has a first value (e.g., "1"), it may operate in an "authentication-only" mode. In particular, a first circuit, part of a transmitter device, may copy plaintext data block by block, encrypt the plaintext data to generate encrypted data, and generate a first authentication tag based on the encryption. The first circuit may output the copied plaintext data and the first authentication tag for transmission as part of a MAC protocol data unit (MPDU).A receiving device may receive the MPDU, and a second circuit, part of the receiving device, may receive the copied plaintext data and the first authentication tag from the MPDU. The second circuit may encrypt the copied plaintext data and generate a second authentication tag based on the encryption. The second circuit may verify that management frames associated with the MPDU are valid / have not been tampered with if the first authentication tag and the second authentication tag match.
[0012] If the authentication control flag has a second value (e.g., "0"), it may operate in a "data encryption and authentication" mode. Specifically, the first circuit may copy plaintext data block by block, encrypt the plaintext data, and generate a first authentication tag based on the encryption. The first circuit may output the encrypted data and the first authentication tag for transmission as part of a MAC protocol data unit (MPDU). The receiving device may receive the MPDU, and the second circuit may receive the encrypted data and the first authentication tag from the MPDU. The second circuit may decrypt the encrypted data and generate a second authentication tag based on the decryption.The second circuit can verify that management frames associated with the MPDU are valid / not tampered with if the first authentication tag and the second authentication tag match.
[0013] In other embodiments, the first circuit may concatenate the underlying data of the plaintext data with an AAD to generate an extended AAD and set a data length of the plaintext data to zero. The first circuit may encrypt the plaintext data (zero data length) and generate a first authentication tag based on the encryption. The first circuit may output the extended AAD and the first authentication tag for transmission as part of a MAC protocol data unit (MPDU). The receiving device may receive the MPDU, and the second circuit may receive the plaintext data (via the extended AAD) and the first authentication tag from the MPDU. The second circuit may concatenate the underlying data of the plaintext data with an AAD to generate a second extended AAD and set a data length of the plaintext data to zero.The second circuit can decrypt the plaintext data and generate a second authentication tag based on the decryption. The second circuit can verify that management frames associated with the MPDU are valid / have not been tampered with if the first authentication tag and the second authentication tag match.
[0014] Embodiments of the present disclosure may be implemented in any suitable version of the Wi-Fi protocol. For example, embodiments of the present disclosure may be implemented in Wi-Fi 802.11bn, where the ability to reuse the same hardware / circuitry for a data encryption and authentication mode of operation as well as an authentication-only mode of operation may benefit Wi-Fi 802.11bn's emphasis on low-power / power-efficient operation.
[0015] Fig. 1 is a block diagram illustrating a transmitter device 100 (also referred to herein as transmitter 100), which may be an access point (or any other suitable device) in a Wi-Fi network. In the example of Fig. 1, the transmitter 100 may include a WLAN transceiver 115, which may include transmit and receive chains (not shown), each of which may consist of signal processing components such as a low-noise amplifier, a mixer, a variable-gain amplifier, a low-pass filter, a digital-to-analog converter (DAC), an analog-to-digital converter (ADC), a demodulator, and a detector. The transmit and receive chains may be selectively coupled to an antenna 130, e.g., using a T / R switch (not shown).
[0016] As in Fig. 1, the transmitter 100 further includes a media access control (MAC) layer processing circuit 120 (also referred to herein as MAC circuit 120). The MAC layer controls access to the physical medium, such as a network cable or wireless channel. The MAC circuit 120 may provide MAC layer encryption, which may help prevent unauthorized access to the network by encrypting data sent over the physical medium. The MAC circuit 120 may use symmetric key encryption, in which the same key is used for encryption and decryption, or asymmetric key encryption, in which different keys are used for encryption and decryption.
[0017] Fig. 1 also illustrates a receiver device 150 (also referred to herein as receiver 150), which may be a station (or any other suitable device) in the Wi-Fi network. In the example of Fig. 1, the receiver 150 may include an antenna 135 via which it may receive signals transmitted, for example, by the transmitter 100. The receiver 150 may also include a WLAN transceiver 165, which may have similar components / structures as the WLAN transceiver 115. Each of the WLAN transceiver 115 and the WLAN transceiver 165 may include hardware such as a processing device 105 and a memory 110 (which may include storage devices such as hard disk drives (HDDs), solid state drives (SSDs), random access memory (RAM), other non-volatile memories, etc.). The processing device 105 may perform any suitable signal processing functions, including, in some embodiments, certain functions of the MAC circuit 120. In other embodiments, the MAC circuit 120 may include its own dedicated processing device.It should be noted that although referred to as transmitter 100 and receiver 150, this is for convenience of description only and both transmitter 100 and receiver 150 can function / be capable of functioning as either a transmitter or a receiver.
[0018] Fig. 2A illustrates the MAC circuit 120 according to some embodiments of the present disclosure. As in Fig. 2A, the MAC circuit 120 may include an encryption unit 205 that includes an encryption circuit 210 and a switching circuit 215. The encryption circuit 210 may be circuitry implementing any suitable algorithm for authenticated encryption, such as the ASCON algorithm. The MAC circuit 120 may receive a plaintext MAC protocol data unit (MPDU) to be transmitted by the transmitter 100 and may parse from the plaintext MPDU a MAC header, a MAC address (shown as A2 in the FIGS.), and a data payload of the MPDU. The MAC circuit 120 may generate an Additional Authentication Data (AAD) unit based on information in the MAC header, including the MPDU Frame Control (FC) field and a number of MPDU address fields, as is known in the art. The MAC circuit 120 may also generate a nonce based on the MAC address and the current value of the packet number (in FIGS.The packet number may be a value that is incremented each time a nonce needs to be generated, so that each generated nonce is unique, thereby providing replay protection. The MAC circuitry 120 may also receive an encryption key (shown as TK in the figures) that may be used in encrypting data, as discussed in more detail herein. The MAC circuitry 120 may also use the current value of the packet number and a key ID of the encryption key to generate an encryption header indicating the key ID.
[0019] The encryption circuit 210 may receive the AAD, the nonce, the data payload, and the encryption key, and may encrypt the data payload using the encryption key and the nonce to generate an encrypted data payload. The encryption circuit 210 may also include an authentication tag (described herein and in the Fig. 2A-2C as Authentication Tag 1) that includes a Message Integrity Code (MIC) that encryption circuitry 210 can calculate based on the AAD and the encryption of the data payload. More specifically, as encryption circuitry 210 performs encryption operations on the data payload, its internal state (i.e., the internal state of the encryption and hashing algorithm implemented by encryption circuitry 210) changes as data encryption proceeds block by block through the data payload. The internal state of encryption circuitry 210 during encryption of the last block of the data payload is used by encryption circuitry 210, along with the AAD, to generate Authentication Tag 1.More specifically, the internal state of the encryption circuit 210 may include a bit sequence whose initial value is based on the nonce and the encryption key. The encryption circuit 210 encrypts the data payload block by block and may use the initial value of the internal state to encrypt the first block. Whenever a block of the data payload is encrypted, the internal state used in the next block is updated using permutation operations on the previous internal state and the previously encrypted data block. When the last block of the data payload is encrypted, the encryption circuit 210 may generate the authentication tag 1 based on the internal state of the encryption circuit 210 during the encryption of the last block of the data payload and the AAD.
[0020] The encryption circuit 210 may output the authentication tag 1 to the MPDU construction logic 250 and may output the encrypted data payload to the switching circuit 215. The switching circuit 215 may also receive the data payload, as shown in Fig. 2A. In particular, the MAC circuit 120 may copy the data payload block by block and provide the copied data payload to the switching circuit 215.
[0021] The encryption unit 205 may also include an authentication control flag that can be set to a first value (e.g., 1) or a second value (e.g., 0). When the authentication control flag is set to a value of 1, the encryption unit 205 may operate in an authentication-only mode, in which it may use the authentication tag 1 generated by the encryption circuit 210 to provide replay and integrity protection for management frames (but does not provide / transmit encrypted data), as discussed in more detail herein. In the authentication-only mode, the encryption circuit 210 may generate the encrypted data payload and the authentication tag 1 as described above and may output the authentication tag 1 to the MPDU construction logic 250 and output the encrypted data payload to the switching circuit 215.Since the encryption unit 205 is in authentication-only mode, the switching circuit 215 can output the copied data payload (not the encrypted data payload) since the encrypted data is not needed.
[0022] MPDU construction logic 250 may generate a plaintext MPDU using the MAC header, Authentication Tag 1, the copied data payload, and the Galois / Counter-Mode Protocol (GCMP) header. MAC circuitry 120 may output the plaintext MPDU to transmitter 100, which may transmit the plaintext MPDU to receiver 150.
[0023] If the authentication control flag is set to a value of 0, the encryption unit 205 may operate in a data encryption and authentication mode, in which it may encrypt the data payload and use the authentication tag 1 generated by the encryption circuit 210 to provide replay and integrity protection for management frames. Specifically, the encryption circuit 210 may generate the encrypted data payload and the authentication tag 1 as described hereinabove and may output the authentication tag 1 to the MPDU construction logic 250 and output the encrypted data payload to the switching circuit 215.Since the encryption unit 205 is in the "data encryption and authentication" mode, the switching circuit 215 can output the encrypted data payload (not the copied data payload) to the MPDU construction logic 250 since the encrypted data is to be sent.
[0024] The MPDU construction logic 250 may generate an encrypted MPDU using the MAC header, the authentication tag 1, the encrypted data payload, and the GCMP header, and the MAC circuit 120 may output the encrypted MPDU to the transmitter 100, which may send the encrypted MPDU to the receiver 150.
[0025] Fig. Figure 2B illustrates the MAC circuit 170 of the receiver 150. Similar to the MAC circuit 120, the MAC circuit 170 may include an encryption / decryption unit 230, which includes an encryption / decryption circuit 235 and a switching circuit 240. The encryption / decryption circuit 235 may be similar to the Fig. 2A and may be a circuit implementing any suitable algorithm for authenticated encryption, such as the ASCON algorithm. Encryption / decryption unit 230 may also include an authentication control flag that can be set to a first value (e.g., 1) or a second value (e.g., 0).
[0026] In some embodiments, the encryption / decryption unit 230 may set the value of its authentication control flag based on the data received from the transmitter 100. If the encryption / decryption unit 230 receives a plaintext MPDU, it may determine that the encryption circuit 210 is operating in authentication-only mode and accordingly set the value of its authentication control flag to 1. If the encryption / decryption unit 230 receives an encrypted MPDU, it may determine that the encryption circuit 210 is operating in data encryption and authentication mode and accordingly set the value of its authentication control flag to 0.
[0027] Thus, if the authentication control flag of the encryption unit 205 is set to a value of 1, the authentication control flag of the encryption / decryption unit 230 may also be set to a value of 1. Similarly, if the authentication control flag of the encryption unit 205 is set to a value of 0, the authentication control flag of the encryption / decryption unit 230 may also be set to a value of 0. When the authentication control flag is set to a value of 1, the encryption / decryption unit 230 may operate in an authentication-only mode in which it may use an authentication tag generated by the encryption / decryption circuit 235 (hereinafter referred to as authentication tag 2) and the received authentication tag 1 to provide replay and integrity protection to management frames, as discussed in more detail herein.When the authentication control flag is set to a value of 0, the encryption unit 205 may operate in a "data encryption and authentication" mode in which it may decrypt the encrypted data payload parsed from the encrypted MPDU and use the authentication tag 2 generated by the encryption / decryption circuit 235 and the received authentication tag 1 to provide replay and integrity protection to management frames.
[0028] Fig. Figure 2B illustrates the encryption / decryption unit 230 when the authentication control flag of the encryption / decryption unit 230 (and thus the authentication control flag of the encryption unit 205) is set to a value of 1 (i.e., the encryption unit 205 and the encryption / decryption unit 230 are both operating in "authentication" mode). The MAC circuitry 170 may receive the plaintext MPDU transmitted by the transmitter 100 and may parse the MAC header, the MAC address (shown as A2 in the figures), and the data payload of the plaintext MPDU from the plaintext MPDU. The MAC circuit 170 may generate an Additional Authentication Data (AAD) unit (similar to the AAD generated by the MAC circuit 120) based on information in the MAC header, including the MPDU Frame Control (FC) field and a number of MPDU address fields, as is known in the art.The MAC circuit 170 may also generate a nonce based on the MAC address and the current value of the packet number (shown as PN in the FIGS.), as described with respect to FIG. Fig. 2A. The MAC circuit 170 may further parse from the plaintext MPDU the authentication tag 1 (which includes the MIC) generated by the encryption circuit 210 and the encryption key (from the encryption header).
[0029] Encryption / decryption circuitry 235 may receive the AAD, the nonce, the data payload, and the encryption key. Since the authentication control flag is set to a value of 1, encryption / decryption circuitry 235 may encrypt the data payload using the encryption key and the nonce to generate an encrypted data payload. Encryption / decryption circuitry 235 may also generate authentication tag 2, which includes a message integrity code (MIC) that encryption / decryption circuitry 235 may calculate based on the AAD and the encryption of the data payload, as discussed with respect to authentication tag 1 generated by encryption circuitry 210.The encryption / decryption circuit 235 may output the authentication tag 2 to the encryption / decryption unit 230 and output the encrypted data payload to the switching circuit 240. The switching circuit 240 may also receive the data payload, as shown in FIG. Fig. 2B. In particular, the encryption / decryption unit 230 may copy the data payload block by block and provide the copied data payload to the switching circuit 240. Because the encryption / decryption unit 230 is in "authentication" mode, the switching circuit 240 may output the copied data payload (not the encrypted data payload) since the encrypted data is not needed.
[0030] The encryption / decryption unit 230 may compare the authentication tag 2 with the received authentication tag 1 to determine if they match. If the authentication tag 2 and the authentication tag 1 match, the encryption / decryption unit 230 may confirm that the management frames of the plaintext MPDU received from the transmitter 100 have not been tampered with. If the authentication tag 2 and the authentication tag 1 do not match, the encryption / decryption unit 230 may determine that the management frames of the plaintext MPDU received from the transmitter 100 have been tampered with and indicate an error / discard the data payload.
[0031] Fig. 2C illustrates the encryption / decryption unit 230 when the authentication control flag of the encryption / decryption unit 230 (and thus the authentication control flag of the encryption unit 205) is set to a value of 0 (i.e., the encryption unit 205 and the encryption / decryption unit 230 both operate in the "data encryption and authentication" mode). In the "data encryption and authentication" mode, the encryption / decryption circuit 235 may operate in a decryption mode, although the encryption circuit 210 may operate in an encryption mode. The MAC circuit 170 may receive the encrypted MPDU transmitted by the transmitter 100 and may parse from the encrypted MPDU the MAC header, the MAC address (shown as A2 in FIGS.), and the encrypted data payload of the encrypted MPDU.MAC circuitry 170 may generate an Additional Authentication Data (AAD) unit (similar to the AAD generated by MAC circuitry 120) based on information in the MAC header, including the MPDU Frame Control (FC) field and a number of MPDU address fields, as is known in the art. MAC circuitry 170 may also generate a nonce based on the MAC address and the current value of the packet number (shown as PN in the figures), as described with respect to FIG. Fig. 2A. MAC circuitry 170 may also receive the encryption key used by encryption circuitry 210 (shown as TK in the FIGS.) transmitted by transmitter 100. MAC circuitry 170 may further parse from the encrypted MPDU the authentication tag 1 (which includes the MIC) generated by encryption circuitry 210 and the encryption key (from the encryption header). MAC circuitry 170 may also use the current value of the packet number and a key ID of the encryption key to generate an encryption header indicating the key ID.
[0032] The encryption / decryption circuit 235 may receive the AAD, the nonce, the encrypted data payload, and the encryption key, and may decrypt the encrypted data payload using the encryption key and the nonce to generate the data payload. The encryption / decryption circuit 235 may also generate an authentication tag that includes a message integrity code (MIC), which the encryption / decryption circuit 235 may calculate based on the AAD and the decryption of the encrypted data payload. More specifically, when the encryption / decryption circuit 235 performs decryption operations on the data payload, its internal state (i.e.,The internal state of the encryption and hashing algorithm implemented by encryption / decryption circuitry 235 as data decryption proceeds block by block through the encrypted data payload. The internal state of encryption / decryption circuitry 235 during decryption of the last block of the encrypted data payload is used by encryption / decryption circuitry 235, along with the AAD, to generate authentication tag 2. Encryption / decryption circuitry 235 may output authentication tag 2 and may output the (decrypted) data payload to switching circuitry 215. Switching circuitry 240 may also receive the encrypted data payload, as shown in FIG. Fig. 2C. In particular, the encryption / decryption unit 230 may copy the encrypted data payload block by block and provide the copied encrypted data payload to the switching circuit 240.
[0033] The encryption / decryption circuit 235 may output the authentication tag 2 to the encryption / decryption unit 230 and output the data payload to the switching circuit 240. Since the encryption / decryption unit 230 is in the "data encryption and authentication" mode, the switching circuit 240 may output the data payload (not the copied encrypted data payload).
[0034] The encryption / decryption unit 230 may compare the authentication tag 2 with the received authentication tag 1 to determine if they match. If the authentication tag 2 and the authentication tag 1 match, the encryption / decryption unit 230 may confirm that the management frames of the encrypted MPDU received from the transmitter 100 have not been tampered with and may provide the data payload to the MPDU construction logic 280, which may generate a plaintext MPDU using the MAC header, the data payload, and the GCMP header. The MAC circuitry 170 may output the plaintext MPDU for further processing by the receiver 150 (e.g., once the MAC circuitry 170 has verified the plaintext MPDU using a replay check).If the authentication tag 2 and the authentication tag 1 do not match, the encryption / decryption unit 230 may determine that the management frames of the encrypted MPDU received from the transmitter 100 have been tampered with and indicate an error / discard the data payload.
[0035] In some embodiments, instead of having the encryption circuitry 210 operate directly on the data payload from the plaintext MPDU, the encryption unit 205 may concatenate the AAD with the data payload to generate an enhanced AAD. The encryption circuitry 210 may operate on the enhanced AAD, as discussed in more detail herein. Fig. 3A illustrates the MAC circuit 120 in an exemplary embodiment in which the encryption unit 205 may use an enhanced AAD.
[0036] If the authentication control flag of MAC circuit 120 is 0 (i.e., encryption unit 205 and encryption / decryption unit 230 are both operating in "data encryption and authentication" mode), switching circuit 215 may receive the AAD and data payload and forward the AAD and data payload to encryption circuit 210, which may generate an encrypted data payload and authentication tag 1. Encryption circuit 210 may output authentication tag 1 and the encrypted data payload to MPDU construction logic 250. The MPDU construction logic 250 may generate an encrypted MPDU using the MAC header, the authentication tag 1, the encrypted data payload, and the GCMP header, and the MAC circuit 120 may output the encrypted MPDU to the transmitter 100, which may send the encrypted MPDU to the receiver 150.
[0037] If the authentication control flag of MAC circuit 120 is 1 (i.e., encryption unit 205 and encryption / decryption unit 230 are both operating in "authentication" mode), switching circuit 215 may receive the AAD and the data payload and may concatenate the AAD with the data from the data payload to generate an extended AAD that includes the data from the data payload. Switching circuit 215 may also set the length of the data payload to zero (since its data is now part of the extended AAD) and output both the extended AAD and the data payload (which now has a data length of zero) to encryption circuit 210. Since the data payload length is zero, encryption circuit 210 performs no encryption and instead generates only authentication tag 1 for the extended AAD.Encryption circuitry 210 may output authentication tag 1 along with the extended AAD to MPDU construction logic 250. MPDU construction logic 250 may generate a plaintext MPDU using the MAC header, the extended AAD, authentication tag 1, and the GCMP header. MAC circuitry 120 may output the plaintext MPDU to transmitter 100, which may transmit the plaintext MPDU and the encryption key to receiver 150.
[0038] Fig. Figure 3B illustrates MAC circuitry 170 when the authentication control flag of encryption / decryption unit 230 (and thus the authentication control flag of encryption unit 205) is set to a value of 1 (i.e., encryption unit 205 and encryption / decryption unit 230 are both operating in "authentication" mode). In response to receiving the plaintext MPDU from transmitter 100, MAC circuitry 170 may parse the MAC header, MAC address (shown as A2 in the figures), data payload (from the extended AAD), and authentication tag 1 from the plaintext MPDU. MAC circuitry 170 may generate an AAD and a nonce based on the MAC address and the current value of the packet number (shown as PN in the figures).
[0039] Switching circuit 240 may receive the AAD and the data payload and may concatenate the AAD with the data from the data payload to generate an extended AAD that includes the data from the data payload. Switching circuit 240 may set the length of the data payload to zero (since its data is now part of the extended AAD) and output both the extended AAD and the data payload (which now has a data length of zero).
[0040] Encryption / decryption circuitry 235 may receive the extended AAD, the data payload (zero data length), the encryption key, and the nonce. Because the data payload length has been set to zero, encryption / decryption circuitry 235 may not perform decryption on the data payload and instead generate only an authentication tag 2.
[0041] The encryption / decryption unit 230 may compare the authentication tag 2 with the received authentication tag 1 to determine if they match. If the authentication tag 2 and the authentication tag 1 match, the encryption / decryption unit 230 may confirm that the management frames of the plaintext MPDU received from the transmitter 100 have not been tampered with. If the authentication tag 2 and the authentication tag 1 do not match, the encryption / decryption unit 230 may determine that the management frames of the encrypted MPDU received from the transmitter 100 have been tampered with and indicate an error / discard the encrypted data payload.
[0042] Fig. 3C illustrates MAC circuitry 170 when the authentication control flag of encryption / decryption unit 230 (and thus the authentication control flag of encryption unit 205) is set to a value of 0 (i.e., encryption unit 205 and encryption / decryption unit 230 are both operating in "data encryption and authentication" mode). In response to receiving the encrypted MPDU from transmitter 100, MAC circuitry 170 may parse the MAC header, MAC address (shown as A2 in FIGS.), encrypted data payload (from the extended AAD), and authentication tag 1 from the encrypted MPDU. MAC circuitry 170 may generate an AAD and a nonce based on the MAC address and the current value of the packet number (shown as PN in FIGS.).
[0043] Switching circuitry 240 may receive the AAD and the encrypted data payload and may forward the AAD and the encrypted data payload to encryption / decryption circuitry 235, which may decrypt the encrypted data payload and generate an authentication tag 2, as discussed hereinabove. Encryption / decryption unit 230 may compare authentication tag 2 with the received authentication tag 1 to determine if they match. If authentication tag 2 and authentication tag 1 match, encryption / decryption unit 230 may confirm that the encrypted MPDU management frames received from transmitter 100 have not been tampered with.If the authentication tag 2 and the authentication tag 1 do not match, the encryption / decryption unit 230 may determine that the management frames of the encrypted MPDU received from the transmitter 100 have been tampered with and indicate an error / discard the encrypted data payload.
[0044] Embodiments of the present disclosure enable a circuit implementing an authenticated encryption algorithm to operate in both a data encryption and authentication mode of operation and an authentication-only mode of operation, thereby meeting the requirements of the Wi-Fi protocol.
[0045] Fig. 4 is a flow diagram of a method 400 for implementing an authenticated encryption algorithm to operate in both a data encryption and authentication mode of operation and an authentication-only mode of operation, according to some embodiments of the present disclosure. The method 400 may be performed by processing logic that may include hardware (e.g., circuitry, dedicated logic, programmable logic, a processor, a processing device, a central processing unit (CPU), a system-on-chip (SoC), etc.), software (e.g., instructions executing on a processing device), firmware (e.g., microcode), or a combination thereof. For example, the method 400 may be performed by the MAC circuits 120 and 170.
[0046] Also with reference to the Fig. 2A-2C, the encryption circuit 210 may receive the AAD, the nonce, the data payload, and the encryption key, and at block 405, may encrypt the data payload using the encryption key and the nonce to generate an encrypted data payload. At block 410, the encryption circuit 210 may also receive an authentication tag (described herein and in the Fig. 2A-2C as Authentication Tag 1) that includes a Message Integrity Code (MIC) that encryption circuitry 210 can calculate based on the AAD and the encryption of the data payload. More specifically, as encryption circuitry 210 performs encryption operations on the data payload, its internal state (i.e., the internal state of the encryption and hashing algorithm implemented by encryption circuitry 210) changes as data encryption proceeds block by block through the data payload. The internal state of encryption circuitry 210 during encryption of the last block of the data payload is used by encryption circuitry 210, along with the AAD, to generate Authentication Tag 1.The encryption circuit 210 may output the authentication tag 1 to the MPDU construction logic 250 and may output the encrypted data payload to the switching circuit 215. The switching circuit 215 may also receive the data payload, as shown in FIG. Fig. 2A. In particular, the MAC circuit 120 may copy the data payload block by block and provide the copied data payload to the switching circuit 215.
[0047] The encryption unit 205 may also include an authentication control flag that can be set to a first value (1) or a second value (0). At block 415, if the authentication control flag is set to a value of 1, the encryption unit 205 may operate in an authentication-only mode, in which it may use the authentication tag 1 generated by the encryption circuit 210 to provide replay and integrity protection for management frames (but does not provide / transmit encrypted data), as discussed in more detail herein. In the authentication-only mode, the encryption circuit 210 may generate the encrypted data payload and the authentication tag 1 as described hereinabove and may output the authentication tag 1 to the MPDU construction logic 250 and output the encrypted data payload to the switching circuit 215.Since the encryption unit 205 is in authentication-only mode, the switching circuit 215 can output the copied data payload (not the encrypted data payload) since the encrypted data is not needed.
[0048] MPDU construction logic 250 may generate a cleartext MPDU using the MAC header, Authentication Tag 1, the copied data payload, and the GCMP header. MAC circuitry 120 may output the cleartext MPDU to transmitter 100, which may transmit the cleartext MPDU to receiver 150.
[0049] At block 420, if the authentication control flag is set to a value of 0, the encryption unit 205 may operate in a data encryption and authentication mode, in which it may encrypt the data payload and use the authentication tag 1 generated by the encryption circuit 210 to provide replay and integrity protection for management frames. Specifically, the encryption circuit 210 may generate the encrypted data payload and the authentication tag 1 as described hereinabove and may output the authentication tag 1 to the MPDU construction logic 250 and output the encrypted data payload to the switching circuit 215.Since the encryption unit 205 is in the "data encryption and authentication" mode, the switching circuit 215 can output the encrypted data payload (not the copied data payload) to the MPDU construction logic 250 because the encrypted data is to be sent.
[0050] The MPDU construction logic 250 may generate an encrypted MPDU using the MAC header, the authentication tag 1, the encrypted data payload, and the GCMP header, and the MAC circuit 120 may output the encrypted MPDU to the transmitter 100, which may send the encrypted MPDU to the receiver 150.
[0051] At block 425, the MAC circuit 170 may receive the MPDU transmitted by the transmitter 100 and may parse from the MPDU the MAC header, the MAC address (shown as A2 in the FIG.), and either the data payload (when the authentication control flag of the encryption unit 205 is set to the first value (1)) of the received MPDU or the encrypted data payload (when the authentication control flag of the encryption unit 205 is set to the second value (0)) of the received MPDU. The MAC circuit 170 may generate an Additional Authentication Data (AAD) unit (similar to the AAD generated by the MAC circuit 120) based on information in the MAC header, including the MPDU Frame Control (FC) field and a number of MPDU address fields, as is known in the art. The MAC circuit 170 may also generate a nonce based on the MAC address and the current value of the packet number (shown as PN in the FIGS.), as described with respect to Fig. 2A. The MAC circuit 170 may further parse from the received MPDU the authentication tag 1 (which includes the MIC) generated by the encryption circuit 210 and the encryption key (from the encryption header).
[0052] At block 430, if the authentication control flag of the encryption / decryption unit 230 is set to the first value (1), the encryption / decryption circuit 235 may encrypt the data payload using the encryption key and the nonce to generate an encrypted data payload. The encryption / decryption circuit 235 may also generate the authentication tag 2, which includes a message integrity code (MIC), which the encryption / decryption circuit 235 may calculate based on the AAD and the encryption of the data payload, as discussed with respect to the authentication tag 1 generated by the encryption circuit 210. The encryption / decryption circuit 235 may output the authentication tag 2 to the encryption / decryption unit 230 and output the encrypted data payload to the switching circuit 240.The switching circuit 240 may also receive the data payload as shown in . Fig. 2B. In particular, the encryption / decryption unit 230 may copy the data payload block by block and provide the copied data payload to the switching circuit 240. Because the encryption / decryption unit 230 is in "authentication" mode, the switching circuit 240 may output the copied data payload (not the encrypted data payload) since the encrypted data is not needed.
[0053] When the authentication control flag of the encryption / decryption unit 230 is set to the second value (0), the encryption / decryption circuit 235 may decrypt the encrypted data payload using the encryption key and the nonce to generate the data payload. The encryption / decryption circuit 235 may also generate an authentication tag including a message integrity code (MIC), which the encryption / decryption circuit 235 may calculate based on the AAD and the decryption of the encrypted data payload. More specifically, when the encryption / decryption circuit 235 performs decryption operations on the data payload, its internal state (i.e.,The internal state of the encryption and hashing algorithm implemented by encryption / decryption circuitry 235 as data decryption proceeds block by block through the encrypted data payload. The internal state of encryption / decryption circuitry 235 during decryption of the last block of the encrypted data payload is used by encryption / decryption circuitry 235, along with the AAD, to generate authentication tag 2. Encryption / decryption circuitry 235 may output authentication tag 2 and may output the (decrypted) data payload to switching circuitry 215. Switching circuitry 240 may also receive the encrypted data payload, as shown in FIG. Fig. 2C. In particular, the encryption / decryption unit 230 may copy the encrypted data payload block by block and provide the copied encrypted data payload to the switching circuit 240.
[0054] In either case, at block 435, the encryption / decryption unit 230 may compare the authentication tag 2 with the received authentication tag 1 to determine if they match. If the authentication tag 2 and the authentication tag 1 match, the encryption / decryption unit 230 may confirm that the management frames of the cleartext MPDU received from the transmitter 100 have not been tampered with. If the authentication tag 2 and the authentication tag 1 do not match, the encryption / decryption unit 230 may determine that the management frames of the cleartext MPDU received from the transmitter 100 have been tampered with and indicate an error / discard the data payload.
[0055] Fig. 5 is a flow diagram of a method 500 for implementing an authenticated encryption algorithm to operate in both a data encryption and authentication mode of operation and an authentication-only mode of operation, according to some embodiments of the present disclosure. The method 500 may be performed by processing logic that may include hardware (e.g., circuitry, dedicated logic, programmable logic, a processor, a processing device, a central processing unit (CPU), a system-on-chip (SoC), etc.), software (e.g., instructions executing on a processing device), firmware (e.g., microcode), or a combination thereof. For example, the method 500 may be performed by the MAC circuits 120 and 170.
[0056] With reference also to Fig. 3A and Fig. 3B, at block 505, if the authentication control flag of MAC circuitry 120 is 1 (i.e., encryption unit 205 and encryption / decryption unit 230 are both operating in "authentication" mode), switching circuitry 215 may receive the AAD and the data payload and may concatenate the AAD with the data from the data payload to generate an extended AAD that includes the data from the data payload. At block 510, switching circuitry 215 may set the length of the data payload to zero (since its data is now part of the extended AAD) and output both the extended AAD and the data payload (which now has a data length of zero) to encryption circuitry 210.
[0057] Encryption circuitry 210 may receive the extended AAD, the data payload (zero data length), the encryption key, and the nonce. Because the data payload length is zero, encryption circuitry 210 performs no encryption at block 515 and instead generates only Authentication Tag 1 for the extended AAD. Encryption circuitry 210 may output Authentication Tag 1 along with the extended AAD to MPDU construction logic 250. MPDU construction logic 250 may generate a plaintext MPDU using the MAC header, the extended AAD, Authentication Tag 1, and the GCMP header. MAC circuitry 120 may output the plaintext MPDU to transmitter 100, which may transmit the plaintext MPDU and the encryption key to receiver 150.
[0058] Fig. 3B illustrates MAC circuitry 170 when the authentication control flag of encryption / decryption unit 230 (and thus the authentication control flag of encryption unit 205) is set to a value of 1 (i.e., encryption unit 205 and encryption / decryption unit 230 are both operating in "authentication" mode). At block 520, in response to receiving the plaintext MPDU from transmitter 100, MAC circuitry 170 may parse from the plaintext MPDU the MAC header, the MAC address (shown as A2 in FIGS.), the data payload (from the extended AAD), and the authentication tag 1. MAC circuitry 170 may generate an AAD and a nonce based on the MAC address and the current value of the packet number (shown as PN in FIGS.).
[0059] Switching circuitry 240 may receive the AAD and the data payload and, at block 525, may concatenate the AAD with the data from the data payload to generate an extended AAD that includes the data from the data payload. At block 530, switching circuitry 240 may set the length of the data payload to zero (since its data is now part of the extended AAD) and output both the extended AAD and the data payload (which now has a data length of zero).
[0060] Encryption / decryption circuitry 235 may receive the extended AAD, the data payload (zero data length), the encryption key, and the nonce. Because the data payload length has been set to zero, encryption / decryption circuitry 235 may not perform decryption on the data payload and instead generate only an authentication tag 2.
[0061] At block 535, the encryption / decryption unit 230 may compare the authentication tag 2 with the received authentication tag 1 to determine if they match. If the authentication tag 2 and the authentication tag 1 match, the encryption / decryption unit 230 may confirm that the management frames of the plaintext MPDU received from the transmitter 100 have not been tampered with. If the authentication tag 2 and the authentication tag 1 do not match, the encryption / decryption unit 230 may determine that the management frames of the encrypted MPDU received from the transmitter 100 have been tampered with and indicate an error / discard the encrypted data payload.
[0062] If the authentication control flag of MAC circuit 120 is 0 (i.e., encryption unit 205 and encryption / decryption unit 230 are both operating in "data encryption and authentication" mode), switching circuit 215 may receive the AAD and data payload and forward the AAD and data payload to encryption circuit 210, which may generate an encrypted data payload and authentication tag 1. Encryption circuit 210 may output authentication tag 1 and the encrypted data payload to MPDU construction logic 250. The MPDU construction logic 250 may generate an encrypted MPDU using the MAC header, the authentication tag 1, the encrypted data payload, and the GCMP header, and the MAC circuit 120 may output the encrypted MPDU to the transmitter 100, which may send the encrypted MPDU to the receiver 150.
[0063] With reference also to Fig. 3C, in response to receiving the encrypted MPDU from the transmitter 100, the MAC circuitry 170 may parse from the encrypted MPDU the MAC header, the MAC address (shown as A2 in FIG. 1), the encrypted data payload (from the extended AAD), and the authentication tag 1. The MAC circuitry 170 may generate an AAD and a nonce based on the MAC address and the current value of the packet number (shown as PN in FIG. 1).
[0064] Switching circuitry 240 may receive the AAD and the encrypted data payload and may forward the AAD and the encrypted data payload to encryption / decryption circuitry 235, which may decrypt the encrypted data payload and generate an authentication tag 2, as discussed hereinabove. Encryption / decryption unit 230 may compare authentication tag 2 with the received authentication tag 1 to determine if they match. If authentication tag 2 and authentication tag 1 match, encryption / decryption unit 230 may confirm that the encrypted MPDU management frames received from transmitter 100 have not been tampered with.If the authentication tag 2 and the authentication tag 1 do not match, the encryption / decryption unit 230 may determine that the management frames of the encrypted MPDU received from the transmitter 100 have been tampered with and indicate an error / discard the encrypted data payload.
[0065] Fig. 6 is a simplified block diagram of the transmitter 100 with a more detailed view of the internal workings of the WLAN transceiver 115, according to some embodiments of the present disclosure. The transmitter 100 may include a general-purpose input / output (GPIO) 605 and the WLAN transceiver 115. The GPIO 605 may include an uncommitted digital signal pin that may be used as an input or output for the WLAN transceiver 115. The WLAN transceiver 115 may include a processing device 605, a memory 610, a physical layer chip 615, and a media access control (MAC) layer chip 620. The physical layer chip 615 may handle the conversion of a signal from a clocked digital format to an analog format suitable for longer-range transmission, and vice versa.The MAC layer chip 620 may assemble bits received from the physical layer chip 615 into packets and validate them, as well as receive packets of data from, for example, the processing device 605 and convert them into bit streams to be provided to the physical layer chip 615. It should be noted that . Fig. 6 illustrates an embodiment where the WLAN transceiver 115 includes its own dedicated processing device and memory, and the instructions for performing the techniques described herein may be included as firmware within the memory of the WLAN transceiver 115.
[0066] Fig. Figure 7 is a block diagram illustrating a communication device 700 according to some embodiments of the present disclosure. The communication device 700 may include the exemplary embodiments of the transmitter 100 and the receiver 150, or portions thereof, as described with respect to Fig.1-3B. The communication device 700 may be in the form of a computer system within which sets of instructions may be executed to cause the communication device 700 to perform any one or more of the methodologies discussed herein. The communication device 700 may operate as a standalone device or may be connected (e.g., networked) to other machines. In a networked deployment, the communication device 700 may operate in the capacity of a server or client machine in a server-client network environment, or as a peer machine in a P2P (or distributed) network environment.
[0067] The communication device 700 may be an Internet of Things (IoT) device, a server computer, a client computer, a personal computer (PC), a tablet, a set-top box (STB), a voice-activated hub (VCH), a personal digital assistant (PDA), a mobile phone, a web appliance, a network router, a switch or bridge, a television, speakers, a remote control, a monitor, a portable multimedia device, a portable video player, a portable gaming device, or a control panel, or any other machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be performed by that machine.Furthermore, although only a single communication device 700 is illustrated, the term "device" should also be understood to include any collection of machines that individually or collectively execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.
[0068] The communication device 700 is shown as including processor(s) 702. In embodiments, the communication device 700 and / or processor(s) 702 may include processing device(s) 705, such as a system-on-chip processing device developed by Cypress Semiconductor Corporation, San Jose, California. Alternatively, the communication device 700 may include one or more other processing devices known to those skilled in the art, such as a microprocessor or central processing unit, an application processor, a host controller, a controller, a special-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or the like.The bus system 701 may include a communication block (not shown) to communicate with an internal or external component, such as an embedded controller or an application processor, via communication interface(s) 709 and / or the bus system 701.
[0069] Components of communication device 700 may be located on a common carrier substrate, such as an IC die substrate, a multi-chip module substrate, or the like. Alternatively, components of communication device 700 may be one or more separate ICs and / or discrete components.
[0070] The memory system 704 may include volatile memory and / or non-volatile memory that can communicate with each other via the bus system 701. The memory system 704 may include, for example, random access memory (RAM) and program flash. RAM may be static RAM (SRAM), and program flash may be non-volatile memory that can be used to store firmware (e.g., control algorithms executable by processor(s) 702 to implement operations described herein). The memory system 704 may include instructions 703 that, when executed, perform the methods described herein. Portions of the memory system 704 may be dynamically allocated to provide caching, buffering, and / or other memory-based functionality.
[0071] The storage system 704 may include a drive unit providing a machine-readable medium on which one or more sets of instructions 703 (e.g., software) may be stored, embodying any one or more of the methodologies or functions described herein. The instructions 703 may also be located entirely or at least partially within the other storage devices of the storage system 704 and / or within the processor(s) 702 during their execution by the communication device 700, which in some embodiments represents machine-readable media. The instructions 703 may further be sent or received over a network via the communication interface(s) 709. The communication interface(s) 709 may be located wherever the communication device 100 discussed herein is implemented.
[0072] Although a machine-readable medium is a single medium in some embodiments, the term "machine-readable medium" should be understood to include a single medium or multiple media (e.g., a centralized or distributed database and / or associated caches and servers) that store the one or more sets of instructions. The term "machine-readable medium" should also be understood to include any medium capable of storing or encoding a set of instructions for execution by the machine, and that causes the machine to perform any one or more of the example operations described herein. Accordingly, the term "machine-readable medium" should be understood to include, but is not limited to, solid-state storage and optical and magnetic media.
[0073] Communication device 700 is further shown to include display interface(s) 706 (e.g., a liquid crystal display (LCD), a touchscreen, a cathode ray tube (CRT), and software and hardware support for display technologies), audio interface(s) 708 (e.g., microphones, speakers, and software and hardware support for microphone input / output and speaker input / output). Communication device 700 is also shown to include user interface(s) 710 (e.g., keyboard, buttons, switches, touchpad, touchscreens, and software and hardware support for user interfaces).
[0074] In the foregoing description, numerous details are set forth. However, it will be apparent to one skilled in the art having the benefit of this disclosure that embodiments of the present disclosure may be practiced without these specific details. In some instances, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring the description.
[0075] Some sections of the detailed description are presented in the form of algorithms and symbolic representations of operations on data bits within a computer memory. These algorithmic descriptions and representations are the means used by those skilled in the data processing field to most effectively communicate the content of their work to others skilled in the art. An algorithm is seen herein and generally as a self-consistent sequence of steps that leads to a desired result. The steps are those that require physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical or magnetic signals capable of being stored, transmitted, combined, compared, and otherwise manipulated.It has sometimes been found convenient, mainly for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like.
[0076] It should be noted, however, that all of these and similar terms are to be associated with the corresponding physical quantities and are merely convenient labels applied to those quantities. Unless specifically stated otherwise, as is evident from the discussion above, it is to be understood that throughout the specification, discussions employing terms such as "send," "receive," "compare," "determine," "detect," "classify," or the like refer to the actions and processes of a computing system or similar electronic computing device that manipulates and converts data represented as physical (e.g., electronic) quantities within the computing system's registers and memories into other data similarly represented as physical quantities within the computing system's memories or registers or other such information storage, transmission, or display devices.
[0077] The words "example" or "exemplary" are used herein to mean that they serve as an example, instance, or illustration. Any aspect or design described herein as an "example" or "exemplary" is not necessarily to be construed as preferred or advantageous over other aspects or designs. Rather, the use of the words "example" or "exemplary" is intended to represent concepts in a concrete manner. As used in this patent application, the term "or" is intended to mean an inclusive "or" rather than an exclusive "or." That is, unless otherwise specified or clear from the context, "X includes A or B" is intended to mean any of the naturally inclusive permutations. That is, if X includes A, X includes B, or X includes both A and B, then in all of the foregoing cases, "X includes A or B" is satisfied.Furthermore, as used in this patent application and the appended claims, the articles "a" and "an" should generally be interpreted to mean "one or more" unless otherwise specified or the context clearly indicates that they are directed to a singular form. Furthermore, the use of the term "an embodiment" or "an implementation" throughout is not intended to mean the same embodiment or implementation unless specifically described as such.
[0078] Embodiments described herein may also relate to an apparatus for performing the operations described herein. This apparatus may be specially constructed for the required purposes, or it may include a general-purpose computer that is selectively activated or reconfigured by a computer program stored in the computer. Such a computer program may be stored in a non-transitory computer-readable storage medium, such as, but not limited to, any type of disk, including floppy disks, optical disks, CD-ROMs and magnetic-optical disks, read-only memories (ROMs), random access memories (RAMs), EPROMs, EEPROMs, magnetic or optical cards, flash memory, or any type of medium suitable for storing electronic instructions. The term "computer-readable storage medium" should be understood to include a single medium or multiple media (e.g.,a centralized or distributed database and / or associated caches and servers) that stores one or more sets of instructions. The term "computer-readable medium" shall also be understood to include any medium capable of storing, encoding, or carrying a set of instructions for execution by the machine and that causes the machine to perform any one or more of the methodologies of the present embodiments. Accordingly, the term "computer-readable storage medium" shall be understood to include, but is not limited to, solid-state storage, optical media, magnetic media, any medium capable of storing a set of instructions for execution by the machine and that causes the machine to perform any one or more of the methodologies of the present embodiments.
[0079] The algorithms and displays presented herein do not inherently relate to any particular computer or other device. Various general-purpose systems may be used with programs according to the teachings herein, or it may prove convenient to construct a more specialized device to perform the required method steps. The required structure for a variety of these systems will be apparent from the following description. Furthermore, the present embodiments are not described with reference to any particular programming language. It is understood that a variety of programming languages may be used to implement the teachings of the embodiments described herein.
[0080] The foregoing description sets forth numerous specific details, such as examples of specific systems, components, methods, and so forth, in order to provide a thorough understanding of several embodiments of the present disclosure. However, it will be apparent to one skilled in the art that at least some embodiments of the present disclosure may be practiced without these specific details. In other instances, well-known components or methods are not described in detail or are presented in simple block diagram format to avoid unnecessarily obscuring the present embodiments. Thus, the specific details set forth above are merely exemplary. Particular implementations may depart from these exemplary details and still be considered within the scope of the present embodiments.
[0081] It is understood that the foregoing description is intended to be illustrative and not restrictive. Many other embodiments will be apparent to those skilled in the art upon reading and understanding the foregoing description. The scope of the embodiments should therefore be determined by reference to the appended claims, along with the full scope of equivalents to which such claims are entitled. QUOTES CONTAINED IN THE DESCRIPTION
[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature
[0000] US 63 / 563,049
[0001]
Claims
[1] A system that includes: a transmitter device comprising: a first encryption device configured to: Performing an encryption process on data to generate encrypted data; generating a first authentication tag based at least in part on the encryption process; if a first control flag of the first encryption device has a first value, outputting the data for transmission as part of a MAC protocol data unit (MPDU) including the first authentication tag; and if the first control flag has a second value, outputting the encrypted data for transmission as part of the MPDU; and a receiver device configured to receive the MPDU from the transmitter device, the receiver device including: a second encryption device configured to operate based on a value of a second control flag, wherein, when the second control flag has the first value, the second encryption device is to: Receiving the data and the first authentication tag from the MPDU; performing the encryption process on the data to generate second encrypted data; Generating a second authentication tag based at least in part on the encryption process; and Comparing the first authentication tag and the second authentication tag to validate one or more management frames associated with the data. [2] The system of claim 1, wherein, when the second control flag has the second value, the second encryption device is configured to: Receiving the encrypted data and the first authentication tag from the MPDU; Performing a decryption process on the encrypted data to generate the data; Generating a third authentication tag based at least in part on the decryption process; and Comparing the first authentication tag and the third authentication tag to validate the one or more management frames associated with the data. [3] The system of claim 1, wherein the first encryption device includes: an encryption circuit configured to perform the encryption process and generate the first authentication tag; and a switching circuit to operate based on the value of the first control flag, the switching circuit being configured to: Receiving the data and the encrypted data; if the first control flag has the first value, output the data; and If the first control flag has the second value, output the encrypted data. [4] The system of claim 2, wherein the receiver device includes: an encryption circuit configured to perform the encryption or decryption process and generate the second authentication tag; and a switching circuit to operate based on the value of the second control flag, the switching circuit being configured to: Receiving the data and the encrypted data; if the second control flag has the first value, output the data; and If the second control flag has the second value, output the data. [5] The system of claim 1, wherein the first encryption device generates the first authentication tag based on an internal state of the encryption process. [6] The system of claim 1, wherein the second encryption device is further configured to set the value of the second control flag based on the value of the first control flag. [7] The system of claim 1, wherein the first authentication tag and the second authentication tag each include a message integrity code (MIC). [8] A procedure that includes: performing, by a first encryption device of a transmitter device, an encryption process on data to generate encrypted data; generating a first authentication tag based at least in part on the encryption process; if a first control flag of the first encryption device has a first value, outputting the data for transmission as part of a MAC protocol data unit (MPDU) including the first authentication tag; and if the first control flag has a second value, outputting the encrypted data for transmission as part of the MPDU; Receiving, by a receiver device, the MPDU, the receiver device including a second encryption device to operate based on a value of a second control flag; if the second control flag has the first value, receiving, by the second encryption device, the data and the first authentication tag from the MPDU; performing the encryption process on the data to generate second encrypted data; Generating a second authentication tag based at least in part on the encryption process; and Comparing the first authentication tag and the second authentication tag to validate one or more management frames associated with the data. [9] A method according to claim 8, further comprising: if the second control flag has the second value, receiving, by the second encryption device, the encrypted data and the first authentication tag from the MPDU; Performing a decryption process on the encrypted data to generate the data; Generating a third authentication tag based at least in part on the decryption process; and Comparing the first authentication tag and the third authentication tag to validate the one or more management frames associated with the data. [10] The method of claim 8, wherein outputting the data for transmission as part of the MPDU and outputting the encrypted data for transmission as part of the MPDU are performed by a switching circuit configured to operate based on the value of the first control flag. [11] The method of claim 8, wherein the first authentication tag is generated based on an internal state of the encryption process. [12] The method of claim 8, further comprising: Setting, by the second encryption device, the value of the second control flag based on the value of the first control flag. [13] The method of claim 8, wherein the first authentication tag and the second authentication tag each include a message integrity code (MIC). [14] A system that includes: a transmitter device comprising: a first encryption device configured to: Receiving a data payload and an Additional Authentication Data (AAD) unit; Concatenating data from the data payload and the AAD to generate an extended AAD; Setting a data length of the data payload to zero; Performing an encryption process on the data payload; generating a first authentication tag based at least in part on the encryption process; Outputting the extended AAD and the first authentication tag for transmission as part of a MAC protocol data unit (MPDU); a receiver device configured to receive the MPDU from the transmitter device, the receiver device including: a second encryption device configured to: Receiving a second data payload and the first authentication tag from the MPDU; Receiving a second AAD; concatenating the second AAD with data from the second data payload to generate a second extended AAD; performing a decryption process on the second data payload; Generating a second authentication tag based at least in part on the decryption process; and Comparing the first authentication tag and the second authentication tag to validate one or more management frames associated with the data. [15] The system of claim 14, wherein the first encryption device includes: a switching circuit configured to: Receiving the data payload and the AAD; Concatenate the data from the data payload and the AAD to create an extended AAD; Setting a data length of the data payload to zero; and Outputting the extended AAD and the data payload; and an encryption circuit configured to: Receive the extended AAD and data payload; Performing the encryption process on the data payload; and Generating the first authentication tag. [16] The system of claim 14, wherein the receiver device includes: a switching circuit configured to: Receiving the second data payload and the first authentication tag from the MPDU; Receiving the second AAD; concatenating the second AAD with data from the second data payload to generate a second extended AAD; and an encryption circuit configured to: performing the decryption process on the second data payload; and Generating a second authentication tag based at least in part on the decryption process. [17] The system of claim 14, wherein the first encryption device generates the first authentication tag based on an internal state of the encryption process. [18] The system of claim 14, wherein the first encryption device generates the first authentication tag further based on the extended AAD. [19] The system of claim 14, wherein the first authentication tag and the second authentication tag each include a message integrity code (MIC). [20] The system of claim 14, wherein the first encryption device performs the encryption process in a Galois / Counter mode of operation.
Citation Information
Patent Citations
US-ANMELDUNGNR.63/563,049