Communications system with control frame protection
The M-BSSID scheme with CMICs and CIGTKs addresses latency and security issues in wireless communication by ensuring efficient and secure data transmission between access points and stations.
Patent Information
- Application Number
- JP2025074868
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-04-16
- Filing Date
- 2025-04-28
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-04-28
AI Technical Summary
Ensuring sufficient performance in wireless communication systems, including minimizing latency, resource consumption, and enhancing data security, is challenging due to inadequate protocols in communication between nodes of a network.
Implementing a multiple basic service set identifier (M-BSSID) scheme with control frame integrity checks (CMICs) using control frame integrity group temporal keys (CIGTKs) to secure communications between access points and stations, ensuring data integrity and minimizing latency.
The M-BSSID scheme with CMICs and CIGTKs enhances data throughput and security while reducing latency and resource consumption in wireless communication systems.
Smart Images

Figure 2025169910000001_ABST
Abstract
Description
[Technical Field]
[0001] TECHNICAL FIELD This disclosure relates generally to wireless communications, including wireless communications by electronic devices. [Background technology]
[0002] A communication system and method is used to convey wireless data between nodes of a communication network, which may include user equipment devices, wireless access points, wireless base stations, or other electronic devices.
[0003] Ensuring that a communication system exhibits a sufficient level of performance can be difficult: if care is not taken, communications between nodes of the communication network may exhibit excessive latency, consume excessive resources, or exhibit an inadequate level of data security. Summary of the Invention
[0004] A communication system is provided in which an access point (AP) communicates with stations (STAs). The AP may communicate with the STAs according to a communication protocol that implements a multiple basic service set identifier (M-BSSID) scheme. The AP may transmit an initial control frame (ICF) to the STAs associated with different basic service set identifiers (BSSIDs) maintained by the AP. The BSSIDs may include a transmit BSSID used for common management signaling and a non-transmit BSSID for each virtual network.
[0005] An AP can protect the ICF by generating one or more control message integrity checks (CMICs) and inserting the CMIC(s) into the ICF. As an example, the AP may use a control frame integrity group temporal key (CIGTK) to generate a common CMIC shared across BSSIDs. The CIGTK may be a BSSID-specific CIGTK for the transmitting BSSID or a BSSID-independent CIGTK shared across BSSIDs. The BSSID-independent CIGTK may be a newly defined CIGTK or a beacon integrity group temporal key (BIGTK). As another example, the AP may use different BSSID-specific CIGTKs for each BSSID to generate different CMICs in the ICF for each BSSID. The AP and STAs may perform secure communications under the M-BSSID scheme while minimizing latency and maximizing data throughput.
[0006] One aspect of the present disclosure provides a method for operating a station (STA) to communicate with an access point (AP). The method may include receiving, from the AP, a control frame including a control message integrity check (CMIC) shared by multiple basic service set identifiers (BSSIDs) of the AP. The method may include attempting to verify the CMIC in the control frame using one or more processors. The method may include transmitting an uplink signal to the AP using one or more antennas in response to verifying the CMIC in the control frame.
[0007] One aspect of the present disclosure provides an electronic device configured to communicate with an access point (AP). The electronic device may include a receiver configured to receive a control frame from the AP, the control frame including a first control message integrity check (CMIC) for a first basic service set identifier (BSSID) of the AP and a second CMIC for a second BSSID of the AP, the electronic device being associated with the first BSSID but not the second BSSID. The electronic device may include one or more processors configured to attempt to verify the first CMIC in the control frame. The electronic device may include a transmitter configured to transmit an uplink signal to the AP in response to verifying the first CMIC in the control frame.
[0008] One aspect of the present disclosure provides a method for operating an access point (AP) according to a communication protocol that implements a multiple basic service set identifier (M-BSSID) scheme. The method may include generating, using one or more processors, a control message integrity check (CMIC) based on a cryptographic key. The method may include transmitting, using one or more antennas, a control frame to a first station (STA) associated with a first basic service set identifier (BSSID) of the AP and to a second STA associated with a second BSSID of the AP that is different from the first BSSID. A header of the control frame may include the CMIC and a transmitter address (TA). The TA may identify a third BSSID that is different from the first BSSID and the second BSSID. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a diagram of an exemplary wireless communication system, according to some embodiments.
[0010] [Figure 2] 1 is a schematic diagram of an exemplary wireless station (STA), according to some embodiments.
[0011] [Figure 3] 1 is a schematic diagram of an exemplary wireless access point (AP), according to some embodiments.
[0012] [Figure 4] 1 is a timing diagram illustrating an example of how an AP and multiple STAs may perform downlink communications under a multiple basic service set identifier (M-BSSID) scheme, according to some embodiments.
[0013] [Figure 5] 1 is a timing diagram illustrating an example of how an AP and multiple STAs may perform uplink communications under an M-BSSID scheme, according to some embodiments.
[0014] [Figure 6] 1 illustrates how an exemplary transmitter device may perform integrity protection on transmitted control frames, according to some embodiments.
[0015] [Figure 7] 1 illustrates how an exemplary receiver device may integrity check an integrity-protected control frame received from a transmitting device, according to some embodiments.
[0016] [Figure 8] 1 is a timing diagram illustrating an example of integrity-protected communication between an AP and a STA of the same basic service set identifier (BSSID), according to some embodiments.
[0017] [Figure 9] FIG. 10 is a timing diagram illustrating an example of how an AP can integrity protect an Initial Control Frame (ICF) using different respective Control Message Integrity Checks (CMICs) for STAs associated with different BSSIDs, according to some embodiments.
[0018] [Figure 10] FIG. 10 is a timing diagram illustrating an example of how an AP may integrity protect an ICF using a common CMIC for STAs associated with different BSSIDs, according to some embodiments.
[0019] [Figure 11] FIG. 10 is a diagram of an example group key table stored on an AP and a STA in an example where the AP uses a BSSID-specific control frame integrity group temporal key (CIGTK) to generate a common CMIC for an integrity-protected ICF, according to some embodiments.
[0020] [Figure 12] FIG. 10 is a diagram of an example group key table stored on an AP and STAs in an example where the AP generates a shared CMIC for an integrity-protected ICF using a dedicated CIGTK shared across BSSIDs, according to some embodiments.
[0021] [Figure 13] FIG. 10 is a diagram of an example group key table stored on an AP and a STA in an example where the AP reuses a Beacon Integrity Group Temporal Key (BIGTK) to generate a shared CMIC for an integrity-protected ICF, according to some embodiments.
[0022] [Figure 14] FIG. 10 is a diagram of an example group key table stored on an AP and a STA in an example where separate CIGTKs for different BSSIDs are omitted and the AP generates a shared CMIC for an integrity-protected ICF using a dedicated CIGTK shared across BSSIDs, according to some embodiments.
[0023] [Figure 15]FIG. 10 is a diagram of an example of a group key table stored on the AP and different sets of STAs in an example where the AP generates a shared CMIC for an integrity-protected ICF using a dedicated CIGTK shared across BSSIDs, and one of the sets of STAs belongs to an opportunistic over-the-air encryption (OWE) network, according to some embodiments.
[0024] [Figure 16] 1 is a flowchart of example operations involved in performing wireless communication between an AP configured to communicate under an M-BSSID scheme and a STA associated with the AP's non-transmitting BSSID, according to some embodiments.
[0025] [Figure 17] 1 is a timing diagram illustrating an exemplary handshake procedure that may be performed between a STA and an AP, according to some embodiments.
[0026] [Figure 18] 1 illustrates an example of how an AP may include information identifying a cryptographic group key in a handshake message with the AP, according to some embodiments.
[0027] [Figure 19] FIG. 10 is a timing diagram illustrating an example of how an AP may include information identifying a selected cryptographic group key to be used by a STA to integrity check an integrity-protected ICF sent by the AP, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0028] 1 illustrates an example of a wireless communication system 108 (sometimes referred to herein as a wireless communication network 108, communication network 108, network 108, or system 108). It should be noted that FIG. 1 represents one possibility among many, and that features of the present disclosure may be implemented in any of a variety of systems, as appropriate. For example, the embodiments described herein may be implemented in any type of wireless device. The wireless embodiment described below is one exemplary embodiment.
[0029] 1, an exemplary wireless communication system 108 includes an access point (AP) 104 that communicates with one or more wireless devices 106 (e.g., a first wireless device 106A, a second wireless device 106B, etc.) over a transmission medium. The wireless devices 106A and 106B may be stations (STAs), non-AP STAs, or user devices (e.g., user equipment (UE) devices) such as wireless local area network (WLAN) devices. The wireless devices 106 may be referred to herein as STAs 106 or clients 106.
[0030] The STA 106 may be a device with wireless network connectivity, such as a mobile (e.g., cellular) phone, a handheld device, a wearable device (e.g., a watch device, a pendant device, a ring device, a head-mounted device such as a virtual, mixed, and / or augmented reality headset, goggles, a helmet, or glasses, etc.), a computer (e.g., a desktop computer, a laptop computer, a computer monitor including an embedded computer, etc.), a tablet computer, a media player, headphones, one or two wireless earphones, a television, a gaming device or console, a navigation device, an embedded system such as a system in which electronic equipment with a display is mounted in a kiosk or automobile, a wireless internet-connected voice-controlled speaker, a home entertainment device, a remote control device, a game controller, a user input device, peripheral, or accessory, an electronic stylus or pen, an unmanned aerial vehicle (UAV), an unmanned aerial controller (UAC), a computing device embedded in an automobile, vehicle, or kiosk, a device that implements the functionality of two or more of these devices, or virtually any type of wireless device.
[0031] The STAs 106 may include a processor (processing element) configured to execute program instructions stored in memory. The STAs 106 may perform any of the method embodiments described herein by executing such stored instructions. Alternatively or additionally, the STAs 106 may include a programmable hardware element, such as a field-programmable gate array (FPGA), an integrated circuit, and / or any of a variety of other possible hardware components configured to perform any of the method embodiments described herein, or any portion of any of the method embodiment embodiments described herein (e.g., individually or in combination).
[0032] The wireless communication system 108 may include one or more wireless access points (APs), such as AP 102. AP 102 may be a standalone AP or an enterprise AP and may include hardware that enables wireless communication with STAs 106, such as STAs 106A and 106B. AP 102 may also be equipped to communicate with network 100 (e.g., a WLAN, an enterprise network, and / or another communication network connected to the Internet, among other possibilities). Thus, AP 102 may facilitate communication among STAs 106 and / or between STAs 106 and network 100. AP 102 may be configured to provide communication via one or more wireless technologies, such as 802.11 a, b, g, n, ac, ad, ax, ay, be, bn, and / or any other 802.11 version, or cellular protocols, such as 5G or LTE, including unlicensed bands (LAA).
[0033] Network 100 may include any desired number of network nodes, terminals, and / or end hosts communicatively coupled using communication paths that include wired and / or wireless links. Wired links may include cables (e.g., Ethernet cables, fiber optic or other optical cables that use light to transmit signals, telephone cables, radio frequency cables such as coaxial cables or other transmission lines, etc.). Wireless links may include short-range wireless communication links operating over ranges of inches, feet, or tens of feet, medium-range wireless communication links operating over ranges of hundreds of feet, thousands of feet, miles, or tens of miles, and / or long-range wireless communication links operating over ranges of hundreds or thousands of miles.
[0034] The nodes of network 100 may be organized using one or more relay networks, mesh networks, local area networks (LANs), wireless local area networks (WLANs), ring networks (e.g., optical rings), cloud networks, virtual / logical networks, the Internet (e.g., may be communicatively coupled to one another via the Internet), combinations thereof, and / or any other desired network topology. The network nodes, terminals, and / or end hosts of network 100 may include network switches, network routers, optical add-drop multiplexers, other multiplexers, repeaters, modems, portals, gateways, servers, network cards (line cards), wireless access points, wireless base stations, and / or any other desired network components. The network nodes in network 100 may include physical components such as electronic devices, servers, computers, network racks, line cards, user equipment, etc., and / or may include virtual components that are logically defined in software and distributed across (or on) two or more underlying physical devices (e.g., in a cloud network configuration).
[0035] The communication area (or coverage area) of the AP 102 (or AP 104) may be referred to as a basic service area (BSA) or cell. The AP 102 (or AP 104) and the STAs 106 may be configured to communicate over a transmission medium using any of a variety of radio access technologies (RATs) or wireless communication technologies, such as Wi-Fi, LTE, LTE Advanced (LTE-A), 5G NR, ultra-wideband (UWB), etc. A given RAT may specify, for example, the physical methodology used in implementing a corresponding communication protocol (e.g., a WLAN protocol, a wireless personal area network (WPAN) protocol, a cellular telephony protocol such as a 3G protocol, a 4G (LTE) protocol, a 5G (NR) protocol, a UWB protocol, a satellite communication protocol, a satellite navigation protocol, a device-to-device (D2D) protocol, etc.).
[0036] AP 102, AP 104, and other similar access points (not shown), operating according to one or more cellular communication technologies, may therefore be provided as a network that can provide continuous or near-continuous overlapping service to STAs 106A and 106B and similar devices across a geographic area (e.g., via one or more wireless communication technologies). STAs may, for example, roam directly from one AP to another AP, or transition between APs and cellular network cells.
[0037] It should be noted that, at least in some cases, the STAs 106 may be capable of communicating using any of multiple wireless communication technologies. For example, the STAs 106 may be configured to communicate using one or more of Wi-Fi, LTE, LTE-A, 5G NR, Bluetooth, UWB, one or more satellite systems, etc. Other combinations of wireless communication technologies (including three or more wireless communication technologies) are also possible. Similarly, in some cases, the STAs 106 may be configured to communicate using only a single wireless communication technology.
[0038] 1 , the exemplary wireless communication system 108 may also include an AP 104 that communicates with the wireless device 106B over a transmission medium. The AP 104 also provides communication connectivity to the network 100. Thus, according to some embodiments, a wireless device may be able to connect to either or both of the AP 102 (or a cellular base station (BS)) and the AP 104 (or another access point) to access the network 100. For example, a STA may roam from the AP 102 to the AP 104 based on one or more factors, such as coverage, interference, and capacity. Note that the AP 104 may also be able to provide access to a different network (e.g., an enterprise Wi-Fi network, a home Wi-Fi network, etc.) than the network to which the AP 102 provides access.
[0039] In some implementations, the STAs 106 (e.g., STAs 106A and 106B) may include handheld devices such as smartphones or tablets, wearable devices such as smartwatches or smart glasses, and / or any of various types of devices with wireless communication capabilities. For example, one or more of the STAs 106A and / or 106B may be wireless devices intended for stationary or nomadic deployment, such as appliances, measuring devices, control devices, etc.
[0040] The STA 106B may also be configured to communicate with the STA 106A. For example, the STAs 106A and 106B may be capable of performing direct device-to-device (D2D) communication. In some embodiments, such direct communication between STAs may also or alternatively be referred to as peer-to-peer (P2P) communication. The direct communication may be supported by the AP 102 (e.g., the AP 102 may facilitate discovery, among various possible forms of assistant), or may be performed in a manner not supported by the AP 102. Such P2P communication may be performed using any of 3GPP-based D2D communication technologies, Wi-Fi-based P2P communication technologies, UWB, Bluetooth (BT), and / or various other direct communication technologies, according to various embodiments.
[0041] The STA 106 may include one or more devices or integrated circuits for facilitating wireless communications, potentially including a WLAN (e.g., Wi-Fi) modem, a cellular modem, and / or one or more other wireless modems. The wireless modem(s) may include one or more processors (processing elements) and various hardware components as described herein. The STA 106 may perform any (or any portion) of the method embodiments described herein by executing instructions on one or more programmable processors. Alternatively, or in addition, the one or more processors may include one or more programmable hardware elements, such as an FPGA (field programmable gate array) or other circuitry, configured to perform any of the method embodiments described herein, or any portion of any of the method embodiments described herein. The wireless modem(s) described herein may be used in a STA device as defined herein, a wireless device as defined herein, or a communication device as defined herein. The wireless modems described herein may also be used in an AP, a base station, a picocell, a femtocell, or other similar network-side device.
[0042] The STAs 106 may include one or more antennas for communicating using one or more wireless communication protocols or radio access technologies. In some embodiments, the STAs 106 may be configured to communicate using a single shared radio. The shared radio may be coupled to a single antenna or to multiple antennas (e.g., in the case of multiple-input multiple-power (MIMO)) to perform wireless communication. Alternatively, the STAs 106 may include two or more radios, each of which may be configured to communicate over a separate wireless link. Other configurations are possible.
[0043] 2 shows one possible block diagram of a STA device, such as STA 106. STA 106 may also be referred to herein as a UE 106, a UE device 106, a device 106, an electronic device 106, or a client 106. STA 106 may also be referred to herein as a non-AP STA 106, a non-AP device 106, or a non-AP client 106. As shown in FIG. 2, STA 106 may include radio circuitry, such as radio communication circuitry 230, a subsystem, such as a system-on-chip (SOC) 200, a display, such as display 260, and one or more interfaces, such as a connector interface (I / F) 220.
[0044] SOC 200 may include one or more portions configured for various purposes. For example, as shown in FIG. 2, SOC 200 may include one or more processors 202 and display circuitry 204. Processor(s) 202 may execute program instructions for STA 106. Display circuitry 204 may perform graphics processing and provide display signals to display 260. Display 260 may be a touch-sensitive display, a force-sensitive display, or a display without touch or force sensitivity. Display 260 may include, for example, one or more arrays of display pixels that emit light containing an image.
[0045] The SOC 200 may also include sensor circuitry, such as motion sensing circuitry 270. The motion sensing circuitry 270 may detect movement of the STA 106 using, for example, a gyroscope, an accelerometer, an inertial measurement unit (IMU), a compass, and / or any of a variety of other motion sensing components. The processor(s) 202 may also be coupled to a memory management unit (MMU) 240, which may be configured to receive addresses from the processor(s) 202 and translate those addresses into locations in memory or other storage circuitry (e.g., memory 206, read only memory (ROM) 250, flash (NAND) memory 210). The MMU 240 may be configured to perform memory protection and page table translation or setup. In some embodiments, the MMU 240 may be included as part of the processor(s) 202.
[0046] SOC 200 may be coupled to various other circuits of STA 106. For example, SOC 200 may be coupled to various types of memory (including, e.g., flash memory 210), a connector interface 220 (e.g., for coupling to a computer system, a dock, a charging station, etc.), a display 260, and wireless communication circuitry 230 (e.g., for performing wireless communication under LTE, LTE-A, 5G NR, Bluetooth, Wi-Fi, NFC, GPS, UWB, etc.).
[0047] The STA 106 may include at least one antenna 235. If desired, the STA 106 may include multiple antennas 235, such as at least a first antenna 235A and a second antenna 235B. The STA 106 may use the antennas 235 to perform wireless communications with access points, base stations, and / or other devices. For example, the STA 106 may use antennas 235A and 235B to perform wireless communications with the APs 102 and / or 104 of FIG. 1 . As mentioned above, the STA 106 may, in some embodiments, be configured to communicate wirelessly using multiple wireless communication standards or radio access technologies (RATs).
[0048] The wireless communication circuitry 230 may include one or more modems, such as a WLAN (e.g., Wi-Fi) modem 232, a cellular modem 234, and a Bluetooth modem 236. If desired, the wireless communication circuitry 230 may include additional modems for processing other RATs or wireless communication technologies. The STA 106 may use the WLAN modem 232 (sometimes referred to herein as the Wi-Fi modem 232) to perform Wi-Fi or other WLAN communications (e.g., over an 802.11 network) with one or more external devices (e.g., the APs 104 and / or 102 of FIG. 1). The STA 106 may use the Bluetooth modem 236 to perform Bluetooth or other WPAN communications with one or more external devices (e.g., another STA 106). The STA 106 may use the cellular modem 234 to perform cellular communications with one or more wireless base stations according to one or more cellular communication technologies (e.g., according to one or more 3GPP specifications).
[0049] As described herein, the STA 106 may include hardware and software components for implementing embodiments of the present disclosure. For example, one or more components of the wireless communication circuitry 230 (e.g., Wi-Fi modem 232, cellular modem 234, BT modem 236) of the STA 106 may be configured to perform some or all of the methods described herein, for example, by a processor executing program instructions stored in a memory medium (e.g., a non-transitory computer-readable memory medium), one or more processors configured as an FPGA (Field Programmable Gate Array), and / or using dedicated hardware components that may include an ASIC (Application Specific Integrated Circuit). The STA 106 may include a support structure, such as a housing. The housing may include conductive and / or dielectric housing walls, layers, and / or other structures.
[0050] If desired, the STAs 106 may include additional input / output devices (not shown for clarity) that can be used to enable data to be supplied to the STAs 106 and to enable data to be provided from the STAs 106 to external devices. For example, input / output devices may include user interface devices, data port devices (e.g., interface 220) (touch sensors, light-emitting components such as displays (e.g., display 260), displays without touch sensor capabilities, buttons (mechanical, capacitive, optical, etc.), scroll wheels, touchpads, keypads, keyboards, microphones, cameras, buttons, speakers, status indicators, audio jacks and other audio port components, digital data port devices, motion sensors (accelerometers, gyroscopes, and / or compasses that detect motion), capacitance sensors, proximity sensors, magnetic sensors, force sensors (e.g., force sensors coupled to a display to detect pressure applied to the display), temperature sensors, etc. In some configurations, keyboards, headphones, displays, pointing devices such as trackpads, mice, and joysticks, as well as other input / output devices, may be coupled to the STAs 106 using wired or wireless connections (e.g., some of the input / output devices may be peripherals coupled to the main processing unit or other parts of the STAs 106 via wired or wireless links).
[0051] 3 is a block diagram of an example of an electronic device such as AP 104 (or equivalently, AP 102 of FIG. 1). In some cases (e.g., in the context of 802.11 communications), AP 104 may also be referred to as an AP STA. Note that the AP of FIG. 3 is merely one example of a possible access point. As shown, AP 104 may include one or more processor(s) 304 capable of executing program instructions for AP 104. Processor 304 may also be coupled to MMU 340, which may be configured to receive addresses from processor 304 and translate those addresses into locations in memory (e.g., memory 360 and ROM 350) or other storage circuits, circuits, or devices.
[0052] The AP 104 may include at least one network port 370. The network port 370 may be configured to couple to a network and provide access to the network (e.g., network 100 of FIG. 1) for multiple devices, such as the STAs 106. The network port 370 (or additional network ports) may also, or alternatively, be configured to couple to a cellular network (e.g., a core network (CN) of a cellular service provider). The core network may provide mobility-related services and / or other services to multiple UE devices (e.g., the STAs 106). In some cases, the network port 370 may be coupled to a telephone network via the core network, and / or the core network may provide telephone communication (e.g., to and from other UE devices serviced by the cellular service provider).
[0053] The AP 104 may include one or more radios 330A-330N, each of which may be coupled to a respective communication chain 332 and at least one antenna 334, and possibly multiple antennas (e.g., a first radio 330A coupled to antenna 334A via communication chain 332A, an Nth radio 330N coupled to antenna 334N via communication chain 332N, etc.). The radios 330 may be configured to operate as radio transceivers that communicate with the STAs 106 via the communication chains 332 and antennas 334. The antenna(s) 334A-N communicate with the respective radios 330A-N via the communication chains 332A-N. The communication chains 332 may be receive chains, transmit chains, or may include both transmit and receive chains. The radios 330A-N may be configured to communicate according to various wireless communication standards, including, but not limited to, LTE, LTE-A, 5G NR, 6G, UWB, WLAN (Wi-Fi), WPAN (BT), etc. If desired, the AP 104 may be configured to operate on multiple wireless links using one or more radios 330A-N, with each radio used to operate on a separate wireless link.
[0054] The AP 104 may be configured to communicate wirelessly using one or more wireless communication standards. In some cases, the AP 104 may include multiple radios, which may enable a network entity to communicate according to multiple wireless communication technologies. For example, one possibility is that the AP 104 may include an LTE or 5G NR radio for performing communications according to LTE or 5G, and a Wi-Fi radio for performing communications according to Wi-Fi. In such a case, the AP 104 may be capable of operating as both a cellular base station and a Wi-Fi access point. Another possibility is that the AP 104 may include a multi-mode radio, which may perform communications according to any of multiple wireless communication technologies (e.g., NR and Wi-Fi, NR and LTE, etc.). Yet another possibility is that the AP 104 may be configured to operate exclusively as a Wi-Fi access point, for example, without cellular communication capabilities.
[0055] As described further herein below, the AP 104 may include hardware and software components for implementing or supporting the implementation of the features described herein. The processor(s) 304 of the AP 104 may be configured to implement or support the implementation of some or all of the methods described herein, for example, by executing program instructions stored in a memory medium (e.g., a non-transitory computer-readable memory medium) to operate multiple wireless links using multiple respective radios. Alternatively, the processor(s) 304 may be configured as a programmable hardware element, such as an FPGA (field programmable gate array), an ASIC (application-specific integrated circuit), or a combination thereof. Alternatively (or in addition), the processor(s) 304 of the AP 104, together with one or more of the other components 330, 332, 334, 340, 350, 360, 370, may be configured to implement or support the implementation of some or all of the features described herein.
[0056] Radio(s) 330 on the AP 104 may use antenna(s) 334 (FIG. 3), and wireless communication circuitry 230 on the STA 106 may use antenna(s) 235 (FIG. 2) to transmit and / or receive radio frequency signals within different frequency bands (sometimes referred to herein as communication bands or simply "bands") in the radio frequency domain. The frequency bands handled by the AP 104 and the STA 106 include satellite communication bands (e.g., C-band, S-band, L-band, X-band, W-band, V-band, K-band, K-band, L-band, X-band, W-band, V-band, K-band, K-band, L-band, X-band, W-band, V-band, K-band, K-band, L-band, X-band, W-band, V-band, K-band, K-band, L-band, X-band, W-band, V-band, K-band, V ... a Band, K uband, etc.), wireless local area network (WLAN) frequency bands such as the 2.4 GHz WLAN band (e.g., 2400-2480 MHz) (e.g., Wi-Fi® (IEEE 802.11) or other WLAN communication bands), the 5 GHz WLAN band (e.g., 5180-5825 MHz), the Wi-Fi® 6E band (e.g., 5925-7125 MHz), and / or other Wi-Fi® bands (e.g., 1875-5160 MHz), wireless personal area network (WPAN) frequency bands such as the 2.4 GHz Bluetooth® band or other WPAN communication bands (e.g., bands from about 600 MHz to about 5 GHz, 3G bands, 4G bands, etc.), LTE bands, cellular telephone frequency bands (such as 5G New Radio Frequency Band 1 (FR1) below 10 GHz, 5G New Radio Frequency Band 2 (FR2) between 20 GHz and 60 GHz, 6G bands, etc.), other centimeter wave or millimeter wave frequency bands between 10 and 300 GHz, near-field communications (NFC) frequency bands (e.g., at 13.56 MHz), satellite navigation frequency bands (e.g., GPS bands from 1565 to 1610 MHz, Global Navigation Satellite System (GLONASS) bands, BeiDou Navigation Satellite System (BDS) bands, etc.), ultra-wideband (UWB) frequency bands operating with the IEEE 802.15.4 protocol and / or other ultra-wideband communication protocols, communication bands under the 3GPP family of wireless communication standards, IEEE This may include communication bands under the 802.XX family of standards, and / or any other desired frequency band of interest.
[0057] Antenna(s) 334 (FIG. 3) and antenna(s) 235 (FIG. 2) may be formed using any desired antenna structure. For example, antennas may include antennas having resonating elements formed from loop antenna structures, patch antenna structures, inverted-F antenna structures, slot antenna structures, planar inverted-F antenna structures, helical antenna structures, monopole antennas, dipoles, hybrids of these designs, and the like. If desired, one or more antennas may include antenna resonating elements formed from a conductive portion of the device housing (e.g., a peripheral conductive housing structure extending around the periphery of the display on the STA 106). Filter circuits, switching circuits, impedance matching circuits, and / or other antenna tuning components may be adjusted to adjust the frequency response and radio performance of the antenna over time. If desired, multiple antennas may be implemented as a phased array antenna (e.g., each antenna forms a radiator or antenna element of a phased array antenna, which is sometimes referred to as a phased array antenna). In these scenarios, the phased array antenna can transmit radio frequency signals within a signal beam. The phase and / or magnitude of each radiator in a phased array antenna can be adjusted so that the radio frequency signals of each radiator interfere constructively and destructively to steer or direct the signal beam in a particular pointing direction (e.g., the direction of peak signal gain). The signal beam can be adjusted or steered over time.
[0058] The wireless communication circuit 230 may communicate radio frequency signals using antenna(s) 235 (FIG. 2). The radio(s) 330 may communicate radio frequency signals using antenna(s) 334 (FIG. 3). As used herein, the term "communicating radio frequency signals" refers to the transmission and / or reception of radio frequency signals (e.g., for performing one-way and / or two-way wireless communication with an external wireless communication device). As used herein, the term "communicating wireless data" refers to the transmission and / or reception of wireless data (e.g., carried by a corresponding radio frequency signal). An antenna may transmit radio frequency signals by radiating the radio frequency signals into free space (or into free space through an intervening device structure, such as a dielectric cover layer). An antenna can additionally or alternatively receive radio frequency signals from free space (or through an intervening device structure, such as a dielectric cover layer). The transmission and reception of radio frequency signals by an antenna respectively involves the excitation or resonance of an antenna current on an antenna resonating element within the antenna by the radio frequency signal within the frequency band(s) of operation of the antenna.
[0059] The wireless communication circuitry 230 may be coupled to antenna(s) 235 (FIG. 2) via one or more radio frequency transmission lines. The radio(s) 330 may be coupled to antenna(s) 334 (FIG. 3) via one or more radio frequency transmission lines. The communication chain(s) 332 (FIG. 3) may be disposed on the radio frequency transmission line between the antenna(s) 334 and the radio(s) 330. The radio frequency transmission line may include a coaxial cable, a microstrip transmission line, a stripline transmission line, an edge-coupled microstrip transmission line, an edge-coupled stripline transmission line, or a transmission line formed from a combination of these types of transmission lines. The radio frequency transmission line may be integrated into a rigid printed circuit board and / or a flexible printed circuit board, if desired. If desired, one or more radio frequency lines may be shared between radios or modems. A radio frequency front end (RFFE) module may be interposed in one or more of the radio frequency transmission paths (e.g., in the communication chain(s) 332 of FIG. 3 or in the radio communication circuitry 230 of FIG. 2) if desired. The radio frequency front end module may comprise a separate board, integrated circuit, chip, or package from the radio or modem, and may include filter circuits, switching circuits, amplifier circuits, impedance matching circuits, radio frequency coupler circuits, and / or any other desired radio frequency circuitry for operating on the radio frequency signals transmitted over the radio frequency transmission paths.
[0060] Processor(s) 202 (FIG. 2) and processor(s) 304 (FIG. 3) may each include one or more processors such as a microprocessor, microcontroller, digital signal processor, host processor, baseband processing circuitry (e.g., one or more baseband processors or baseband processor integrated circuits), application specific integrated circuit (ASIC), FPGA, central processing unit (CPU), graphics processing unit (GPU), etc. If desired, radio(s) 330 (FIG. 3) and / or wireless communication circuitry 230 may include one or more processors. The baseband circuitry in the STA 106 and / or the AP 104 may access communication protocol stacks on corresponding storage circuitry (e.g., memory 206 of FIG. 2 or memory 360 of FIG. 3 ) to perform user plane functions, for example, at the physical (PHY) layer, data link or medium access control (MAC) layer, RLC layer, PDCP layer, SDAP layer, and / or PDU layer, and / or to perform control plane functions at the PHY layer, MAC layer, RLC layer, PDCP layer, RRC layer, and / or non-access stratum layer.
[0061] The AP 104 (or the AP 102 of FIG. 1 ) may communicate with the STAs 106 via a corresponding wireless communication link. Radio frequency signals may be transmitted wirelessly between radios and antennas on the AP 104 and the STAs 106 to support the wireless communication link. The radio frequency signals may include wireless data modulated onto one or more carriers of the radio frequency signals (e.g., by a transmitter in the radio 330 of the AP 104 or a transmitter in a modem in the wireless communication circuitry 230 of the STAs 106). The wireless data may be organized, modulated onto, and demodulated from the radio frequency signals (e.g., by a receiver in the radio 330 of the AP 104 or a receiver in a modem in the wireless communication circuitry 230 of the STAs 106) in accordance with a corresponding communication protocol or standard (e.g., an IEEE 802.11 protocol or standard). The radio frequency signals may be transmitted in one or more frequency bands associated with the communication protocol.
[0062] An implementation in which the AP 104 and the STAs 106 communicate according to the IEEE 802.11 protocol or standard is described herein as an example. Under the 802.11 protocol, wireless data is organized into a series of frames or a flow of frames (e.g., Medium Access Control (MAC) frames) carried by a radio frequency signal. The frames, sometimes referred to as packets, may include management frames, control frames, data frames, beacon frames, association frames, authentication frames, acknowledgement (ACK) frames, block ACK frames, trigger frames, trigger response frames, and / or other types of frames. Each frame may include a frame header, a body (e.g., after the header), and a trailer (e.g., after the body). The header may include, for example, source address (SA) information identifying the transmitter of the frame (sometimes referred to herein as sender address (TA) information identifying the corresponding TA), destination address information identifying the intended recipient of some or all of the frame (sometimes referred to herein as recipient address (RA) information identifying the corresponding RA), routing information, identifier information identifying one or more aspects of some or all of the frame (e.g., information identifying the type of frame), an association identifier (AID) field, control information, etc. The body may include, for example, a data payload (e.g., a payload of audio data, video data, web browsing data, application data, etc.). The trailer may include check information useful for validating the frame to the recipient. Check information may include, by way of example, a frame check sequence (FCS) or a cyclic redundancy check (CRC) field. If desired, the header, body, and / or trailer may include one or more message integrity check (MIC) fields (e.g., the output of a hash value or other cryptographic function that takes different portions of the frame as input and is used to verify the integrity of the frame when received by the recipient).
[0063] Under the bidirectional communication link between the AP 104 and the STAs 106, frames are communicated both from the AP 104 to the STAs 106 and from the STAs 106 to the AP 104. The STAs 106 may transmit one or more ACK frames or Block ACK frames to the AP 104 to acknowledge successful receipt of one or more frames transmitted by the AP 104. The AP 104 may transmit one or more ACK frames or Block ACK frames to the STAs 106 to acknowledge successful receipt of one or more frames transmitted by the AP 104.
[0064] Radio frequency signals are transmitted in a downlink (DL) direction from the AP 104 to the STA 106. Radio frequency signals transmitted in the DL direction may also be referred to herein as DL signals. The DL signals may carry DL data (e.g., DL frames transmitted by the AP 104 to the STA 106). Radio frequency signals are transmitted in an uplink (UL) direction from the STA 106 to the AP 104. Radio frequency signals transmitted in the UL direction may also be referred to herein as UL signals. The UL signals may carry UL data (e.g., UL frames transmitted by the STA 106 to the AP 104).
[0065] A given AP 104 may support, maintain, and / or implement a basic service set (BSS) used in communicating with at least one STA 106 (e.g., according to a corresponding 802.11 protocol). If desired, a single physical AP 104 may simultaneously support, maintain, and / or implement multiple BSSs (e.g., support wireless communication with different STAs associated with multiple BSSs). The AP may, for example, utilize a first BSS to communicate with a first set of one or more STAs 106, a second BSS to communicate with a second set of one or more STAs 106, etc. When communication between the AP 104 and a given STA 106 is initiated, the STA registers with the AP 104 and then associates with the AP's corresponding BSS (a procedure called association). The BSS may include and / or identify corresponding communication / operational parameters, device capabilities, security level information, and / or other information associated with the communication service provided by the AP 104 to one or more STAs under that BSS.
[0066] Each BSS may be identified by a corresponding BSS identifier (BSSID). A BSSID may represent or correspond to, for example, a particular network address (e.g., a MAC address) and / or wireless network name established, owned, and / or maintained by an AP for wireless communication using the corresponding BSS. If desired, a given AP 104 may support, implement, and / or maintain multiple BSSIDs together or simultaneously in a communication scheme sometimes referred to herein as performing multiple BSSID (M-BSSID) operation or M-BSSID communication. When configured to perform M-BSSID communication, each BSSID maintained by the AP 104 corresponds to a different network address (e.g., a MAC address) and wireless network name maintained and operated by the AP.
[0067] Consider an example in which AP 104 is a Wi-Fi router or hotspot on a university campus and is configured to perform M-BSSID communication. In this example, AP 104 may simultaneously maintain a first BSSID named “STUDENT” for STAs 106 operated by students on the campus and corresponding to a first MAC address of AP 104, a second BSSID named “STAFF” for STAs 106 operated by staff on the campus and corresponding to a second MAC address of AP 104, a third BSSID named “GUEST” for STAs 106 operated by guests on the campus, and so on. Each BSSID may have different respective operating characteristics, security configurations, and / or settings. When STA 106 enters the wireless coverage area of the AP, a user of the STA may interact with a user interface of the STA to select one of the AP's BSSIDs to connect to. The AP may then associate the STA with that BSSID (e.g., if the STA meets one or more security conditions related to the BSSID, such as being registered with a user authorized to access that BSSID, providing the correct password to access that BSSID, etc.). Once associated with a given BSSID, the STA and the AP communicate wireless data using that BSSID (e.g., the BSS identified by the BSSID). This example is illustrative and not limiting.
[0068] When configured to perform M-BSSID communication (e.g., under an M-BSSID communication scheme), the AP 104 transmits a single beacon frame for multiple BSSIDs to minimize signaling overhead. The beacon frame may advertise the AP 104's different BSSIDs, for example, using the M-BSSID element of the beacon frame. In some implementations (e.g., earlier versions of the 802.11 protocol), the AP cannot simultaneously serve Enhanced Multi-Link Single Radio (EMLSR) STAs associated with different BSSIDs in a multi-user (MU) manner. In these implementations, only continuous data transmission may be possible (e.g., when data for a STA associated with a first BSSID is communicated during a first transmit opportunity (TXOP) before data for a STA associated with a second BSSID is communicated during a second TXOP). This may result in excessive latency and may reduce data throughput of wireless data communicated between the STA and the AP.
[0069] The communication protocol used to perform communication between the AP 104 and the STAs 106 may define an M-BSSID control frame to mitigate these latency and throughput issues. The AP 104 may transmit (broadcast) an M-BSSID control frame to multiple STAs 106 of different BSSIDs prior to UL or DL data transmission. Figure 4 is a timing diagram illustrating an example of how the AP 104 may transmit an M-BSSID control frame to STAs 106 of different BSSIDs prior to DL data transmission to the STAs.
[0070] In the example of Figure 4, row 400 illustrates a frame transmission by the AP 104, row 402 illustrates a frame transmission by a first STA 106A (also denoted as STA1), and row 404 illustrates a frame transmission by a second STA 106B (also denoted as STA2). The AP 104 has a dedicated BSSID, such as BSSID0 (e.g., a first MAC address uniquely assigned to a physical device forming the AP 104 during manufacture or assembly of the AP 104). BSSID0 is sometimes referred to herein as the "transmitted" BSSID0. The transmitted BSSID0 uniquely identifies the AP 104 and is not used for common management signaling. The transmitted BSSID0 may be used to point to or otherwise address the AP 104 during beacon frame transmissions and / or subsequent communications. The AP 104 is configured to perform M-BSSID communication and operate / maintain two or more BSSIDs used to associate one or more STAs 106, sometimes referred to herein as "non-transmitting" BSSIDs.
[0071] 4, the AP 104 simultaneously supports at least a first non-transmitting BSSID1 (e.g., a first network name associated with a second MAC address maintained at the AP 104) and a second non-transmitting BSSID2 (e.g., a second network name associated with a third MAC address maintained at the AP 104). The STA 106A may be associated with BSSID1. The STA 106A may have a corresponding network address, such as MAC address MSTA1. The MAC address MSTA1 may uniquely identify the STA 106A. The STA 106B may be associated with BSSID2. The STA 106B may have a corresponding network address, such as MAC address MSTA2. The MAC address MSTA2 may uniquely identify the STA 106B.
[0072] As shown in FIG. 4, the AP 104 may transmit an M-BSSID control frame, such as an Initial Control Frame (ICF) 406, to all STAs associated with a non-transmitting BSSID maintained by the AP 104. The ICF 406 may be a MU Request to Send (MU-RTS) frame or another type of ICF that precedes or initiates a DL data transmission. The ICF 406 may have a header (e.g., a MAC header) with a Receiver Address (RA) field set to “BROADCAST” (e.g., including one or more bits indicating or identifying a broadcast address, that the ICF 406 is a broadcast frame, and / or that the ICF 406 is intended to be received by all STAs 106 associated with the AP 104). The header may also have a Transmitter Address (TA) field set to BSSID0 of the AP 104 (e.g., the TA field may include one or more bits indicating or identifying the MAC address of BSSID0). The Transmitter Address (TA) is sometimes referred to as a source address. The receiver address (RA) is sometimes called the destination address.
[0073] The STA 106A and the STA 106B may receive the ICF 406. After a short reception and processing period (e.g., in response to receiving the ICF 406 and after at least a short inter-frame space (SIFS) has elapsed since the end of the transmission of the ICF 406), the STA 106A may transmit a clear to send (CTS) frame 408 to the AP 104. The header of the CTS frame 408 may have an RA field set to the transmit BSSID0 of the AP 104, indicating that the CTS frame 408 should be received by the AP 104 (e.g., the STA 106A may generate the CTS frame 408 to include in its RA field the transmit BSSID0 identified by the TA field of the ICF 406). The STA 106B may simultaneously transmit a CTS frame 410. The header of the CTS frame 410 may also have an RA field set to the transmit BSSID0 of the AP 104, indicating that the CTS frame 410 should be received by the AP 104 (e.g., the STA 106B may generate the CTS frame 410 to include in its RA field the transmit BSSID0 identified by the TA field of the ICF 406). The CTS frames 408 and 410 may indicate to the AP 104 that it can send DL data to the STAs 106A and 106B.
[0074] The AP 104 may receive the CTS frame 408 and the CTS frame 410. In response to receiving the CTS frames, after a short reception and processing time (e.g., at least 1 SIFS after the end of the transmission of the CTS frames), the AP 104 may transmit a first data frame 412 to the STA 106A and a second data frame 414 to the STA 106B (e.g., simultaneously with the transmission of the data frame 412). The data frames 412 and 414 may be, for example, MU Physical Protocol Data Unit (PPDU) frames.
[0075] The AP 104 may generate an RA field in the header of the data frame 412 to include or identify the MAC address MSTA1 of the STA 106A, uniquely indicating that the data frame 412 is intended for reception by the STA 106A (e.g., the data frame 412 may have RA=MSTA1). The AP 104 may generate a TA field in the header of the data frame 412 to include or identify the BSSID1 of the STA 106A (e.g., the data frame 412 may have TA=BSSID1, indicating that the data frame 412 was transmitted by the BSSID1 of the AP 104). Similarly, the AP 104 may set the RA field in the header of the data frame 414 to include or identify the MAC address MSTA2 of the STA 106B, uniquely indicating that the data frame 414 is intended for reception by the STA 106B (e.g., the data frame 414 may have RA=MSTA2). The AP 104 may set the TA field in the header of the data frame 414 to include or identify the BSSID2 of the STA 106B (e.g., the data frame 414 may have TA=BSSID2, indicating that the data frame 414 was transmitted by the BSSID2 of the AP 104).
[0076] The STA 106A may receive the data frame 412. In response to receiving the data frame 412, after a short reception and processing time (e.g., at least 1 SIFS has elapsed since the end of transmission of the data frame 412), the STA 106A may transmit an acknowledgment frame, such as a block acknowledgment (BA) frame 416, to the AP 104. The STA 106A may include or identify the MAC address MSTA1 of the STA 106A in the TA field of the BA frame 416 to uniquely indicate that the BA frame 416 was transmitted by the STA 106A (e.g., the BA frame 416 may have TA=MSTA1). The STA 106A may include or identify the BSSID1 associated with the STA 106A in the RA field of the BA frame 416 to indicate that the BA frame 416 is intended for reception by the non-transmitting BSSID1 of the AP 104 (e.g., the BA frame 416 may have RA=BSSID1). The BA frame 416 may serve as an acknowledgment to the AP 104 that the STA 106A has successfully received the wireless data payload of the data frame 412, after which the AP 104 may transmit a subsequent DL data frame to the STA 106A and / or the STA 106A may transmit a subsequent UL data frame to the AP 104.
[0077] Similarly, the STA 106B may receive the data frame 414 (e.g., simultaneously with the reception of the data frame 412 at the STA 106A). In response to receiving the data frame 414, after a short reception and processing time (e.g., at least SIFS after the end of the transmission of the data frame 414), the STA 106B may transmit an acknowledgment frame, such as a BA frame 418, to the AP 104. The STA 106B may include or identify the MAC address MSTA2 of the STA 106B in the TA field of the BA frame 418 to uniquely indicate that the BA frame 418 was transmitted by the STA 106B (e.g., the BA frame 418 may have TA=MSTA2). The STA 106B may include or identify BSSID2 associated with the STA 106B in the RA field of the BA frame 418 to indicate that the BA frame 418 is intended for reception by BSSID2 of the AP 104 (e.g., the BA frame 418 may have RA=BSSID2). The BA frame 418 may serve as an acknowledgment to the AP 104 that the STA 106B successfully received the wireless data payload of the data frame 414, after which the AP 104 may transmit a subsequent DL data frame to the STA 106B and / or the STA 106B may then transmit a subsequent UL data frame to the AP 104. The frame structure for the frames 406-418 may be specified by a communication protocol (e.g., an 802.11 protocol) governing communications between the STA 106 and the AP 104.
[0078] 5 is a timing diagram illustrating an example of how an AP 104 may transmit a control frame to a STA 106 of a different BSSID prior to transmission of UL data from the STA to the AP. In the example of FIG. 5, row 500 illustrates a frame transmission by the AP 104, row 502 illustrates a frame transmission by STA 106A, and row 504 illustrates a frame transmission by STA 106B.
[0079] 5, the AP 104 may transmit a control frame, such as an ICF 506, to all STAs associated with a non-transmitting BSSID maintained by the AP 104. The ICF 506 may be a trigger frame (TF) that triggers an UL data transmission by the STAs 106 or another type of ICF that precedes or initiates an UL data transmission by the STAs 106. The AP 104 may set the RA field in the header of the ICF 506 to a broadcast address and may set the TA field in the header of the ICF 506 to the AP 104's transmitting BSSID 0.
[0080] The STAs 106A and 106B may receive the ICF 506. After a short reception and processing period (e.g., in response to receiving the ICF 506 and after at least 1 SIFS has elapsed since the end of the transmission of the ICF 506), the STA 106A may transmit an UL data frame, such as data frame 508 (e.g., the ICF 506 may trigger the transmission of the data frame 508). Similarly, the STA 106B may transmit an UL data frame, such as data frame 510, in response to receiving the ICF 506 (e.g., the ICF 506 may trigger the transmission of the data frame 510). The data frames 508 and 510 may be, for example, trigger-based (TB) PPDU frames (e.g., frames triggered by the reception of a trigger frame and having a data payload carrying UL data for reception at the AP 104).
[0081] The STA 106A may set the TA field in the header of the data frame 508 to include or identify the MAC address MSTA1 of the STA 106A, which may uniquely indicate that the data frame 508 was transmitted by the STA 106A. The STA 106A may set the RA field in the header of the data frame 508 to include or identify a BSSID (e.g., BSSID1) associated with the STA 106A, which may indicate that the data frame 508 is intended for reception by BSSID1 of the AP 104. Similarly, the STA 106B may set the TA field in the header of the data frame 510 to include or identify the MAC address MSTA2 of the STA 106B, which may uniquely indicate that the data frame 510 was transmitted by the STA 106B. STA 106B may set the RA field in the header of data frame 510 to include or identify a BSSID associated with STA 106B (e.g., BSSID2) and may indicate that data frame 510 is intended for reception by BSSID2 of AP 104.
[0082] AP 104 may receive data frames 508 and 510. In response to receiving data frames 508 and 510, after a short reception and processing time (e.g., at least 1 SIFS after the end of transmission of data frames 508 and 510), AP 104 may broadcast an acknowledgment frame, such as a multi-STA block acknowledgment (M-BA) frame 512. AP 104 may, for example, set the RA field in the header of M-BA frame 512 to a broadcast address ("BROADCAST") and set the TA field in the header of M-BA frame 512 to BSSID0 to uniquely identify that AP 104 transmitted M-BA frame 512. The M-BA frame 512 may serve as an acknowledgment to the STAs 106A and 106B that the AP 104 successfully received the wireless data payloads of the data frames 508 and 510, after which the STAs 106A and 106B may transmit subsequent data frames to the AP 104 and / or the AP 104 may transmit subsequent data frames to the STAs 106A and / or 106B. The frame structure for the frames 506-512 may be specified by a communication protocol (e.g., an 802.11 protocol) governing communication between the STAs 106 and the AP 104.
[0083] To help optimize the security of wireless communications by the AP 104, the AP 104 may protect ICFs (e.g., MU-RTS frames as shown in FIG. 4, trigger frames as shown in FIG. 5, etc.) transmitted to the STAs 106 under the M-BSSID scheme. ICFs integrity protected by the AP 104 may be referred to herein as integrity-protected ICFs or secure CIFS (SICFs). Integrity-protecting the ICF may help the STAs verify that the ICF and subsequent data frames were actually transmitted by the AP 104 and not by an unauthorized device or network intruder (e.g., a so-called man-in-the-middle (MITM) attacker).
[0084] To integrity protect the ICF, the AP 104 may generate a control message integrity check (CMIC) (sometimes referred to herein as a CMIC field, CMIC information, or CMIC bits) for the ICF. The AP 104 may include the CMIC in an ICF transmitted to the STA 106. FIG. 6 is a diagram illustrating how an exemplary transmitter device 616 may generate an integrity-protected frame for transmission to a corresponding receiver device. In the example of FIG. 6, the transmitter device 616 may be the AP 104 generating an integrity-protected ICF from an unprotected ICF, such as ICF 602, for transmission to the STA 106. This is by way of example and not limitation. In general, the transmitter device 616 may be any desired device (e.g., the STA 106) transmitting any desired integrity-protected frame to any type of receiver device (e.g., the ICF 602 of FIG. 6 may be replaced with any desired frame to be integrity protected).
[0085] As shown in FIG. 6, the transmitter device 616 may include an encryption key storage 600 (e.g., in memory 360 or ROM 350 of FIG. 3), a cryptographic function 608 (e.g., implemented and / or performed using digital and / or analog logic, processor(s) 304 of FIG. 3, etc.), and a wireless transmitter such as the transmitter 614 (e.g., the radio(s) 330 and / or communication chain 332 of FIG. 3). The encryption key storage 600 may include a table, a database, other types of data structures, and / or dedicated storage on the transmitter device 616 (e.g., hard-coded and / or encrypted key storage on the AP 104). The cryptographic function 608 may include a hash function / algorithm. As an example, the cryptographic function 608 may be a Galois Message Authentication Code (GMAC) function or algorithm.
[0086] To integrity protect an initial / unprotected ICF, such as ICF 602, the transmitter device 616 may provide ICF information 606 from the ICF 602 as a first input to a cryptographic function 608. The ICF information 606 may include some or all of one or more fields of the ICF 602 (e.g., some or all of the payload of the ICF 602, some or all of one or more fields of the header of the ICF 602, etc.). The transmitter device 616 may also provide a selected cryptographic key 604 from the cryptographic key storage device 600 as a second input to the cryptographic function 608. The cryptographic function 608 may generate (e.g., calculate, compute, output, etc.) a CMIC 610 based on the selected cryptographic key 604 and the ICF information 606 (e.g., by hashing the ICF information 606 with the selected cryptographic key 604 according to the GMAC algorithm or another hash algorithm). The transmitter device 616 may then insert the CMIC 610 into a corresponding field of the ICF 602 to generate an integrity-protected ICF 612. The transmitter 614 may transmit the integrity-protected ICF 612 to a corresponding receiver device.
[0087] 7 is a diagram illustrating how an exemplary receiver device 708 may receive and perform an integrity check on an integrity-protected frame received from the transmitter device 616 of FIG. 6. In the example of FIG. 7, the receiver device 708 may be a STA 106 that performs an integrity check on an integrity-protected ICF 612 received from an AP 104. This is by way of example and not limitation. In general, the receiver device 708 may be any desired device (e.g., the AP 104) that receives any desired integrity-protected frame from any type of transmitter device (e.g., the integrity-protected ICF 612 of FIG. 7 may be replaced with any desired integrity-protected frame).
[0088] 7, receiver device 708 may include cryptographic key storage 702 (e.g., in memory 206 or ROM 250 of FIG. 2), cryptographic function 608 (e.g., implemented and / or performed using digital and / or analog logic, processor(s) 202 of FIG. 2, etc.), and a wireless receiver such as receiver 700 (e.g., in wireless communication circuitry 230 of FIG. 2). Cryptographic key storage 702 may include a table, database, other type of data structure, and / or dedicated key storage on transmitter device 616 (e.g., hard-coded and / or encrypted key storage on STA 106). Cryptographic function 608 may be the same cryptographic function used by transmitter device 616 (FIG. 6) to generate integrity-protected ICF 612.
[0089] The receiver 700 may receive the integrity-protected ICF 612 from the transmitter device 616 (FIG. 6). The receiver device 708 may extract the ICF information 606 (e.g., the integrity-protected portion of the ICF 602 of FIG. 6) from the integrity-protected ICF 612 and provide the ICF information 606 as a first input to the cryptographic function 608. The receiver device 708 may also provide the selected cryptographic key 604 from the cryptographic key storage device 702 as a second input to the cryptographic function 608. The receiver device 708 may receive the selected cryptographic key 604 from the transmitter device 616 (FIG. 6) during an initial registration, association, and / or handshake operation between the transmitter device 616 and the receiver device 708. Based on one or more bits in one or more fields of the integrity-protected ICF frame 612 and / or in another frame received from the transmitter device 616 (FIG. 6), the receiver device 708 may receive information identifying a cryptographic key stored on the cryptographic key storage device 702 (i.e., the selected cryptographic key 604) to provide to the cryptographic function 608.
[0090] The cryptographic function 608 may generate (e.g., calculate, compute, output, etc.) a candidate CMIC, such as candidate CMIC 704 (denoted as CMIC′), based on the selected cryptographic key 604 and the ICF information 606 (e.g., by hashing the ICF information 606 with the selected cryptographic key 604 according to a GMAC algorithm or another hash algorithm). Because the cryptographic function 608 is the same cryptographic function and the selected cryptographic key 604 is the same cryptographic key used by the transmitter device 616 to generate the CMIC 610 ( FIG. 6 ) included in the integrity-protected ICF 612, the candidate CMIC 704 output by the cryptographic function 608 will be the same as the CMIC 610 ( FIG. 6 ) if / when the integrity-protected ICF 612 is actually the integrity-protected ICF 612 transmitted by the transmitter device 616. On the other hand, if / when the frame received by receiver 700 was sent by a different device (eg, an unauthorized device such as a MITM attacker), candidate CMIC 704 will not match CMIC 610 .
[0091] The receiver device 708 may include comparison logic 706 (e.g., as implemented / performed using digital and / or analog logic and / or processor(s) 202 of FIG. 2). The comparison logic 706 may compare the CMIC 610 ( FIG. 6 ) included in the integrity-protected ICF 612 with the candidate CMIC 704. If / when the comparison logic 706 determines that the CMIC 610 in the integrity-protected ICF 612 matches / equals the candidate CMIC 704, the receiver device 708 has successfully integrity-checked the integrity-protected ICF 612 (e.g., verifies that the integrity-protected ICF 612 was transmitted by the expected and authorized transmitter device 616) and may pass the payload of the integrity-protected ICF 612 up the protocol stack for further processing. If desired, the receiver device 708 may also transmit an acknowledgment frame to the transmitter device 616 to acknowledge successful receipt of the integrity-protected ICF 612, and additional frames (e.g., data frames) may be communicated between the transmitter device 616 and the receiver device 708. On the other hand, if / when the comparison logic 706 determines that the CMIC 610 in the integrity-protected ICF 612 is different from the candidate CMIC 704, the receiver device 708 may not be able to successfully integrity check the integrity-protected ICF 612 (e.g., indicating that the frame may have been transmitted by an unexpected or unauthorized device), and the integrity-protected ICF 612 may be discarded. In this manner, the transmitter device 616 (FIG. 6) may safely and reliably transmit control frames to the receiver device 708.
[0092] Figure 8 is a timing diagram illustrating an example of how an AP 104 configured with an M-BSSID may transmit integrity-protected control frames to STAs 106A and 106B associated with the same BSSID. As shown in Figure 8, row 800 illustrates a frame transmission by the AP 104, row 802 illustrates a frame transmission by STA 106A, and row 804 illustrates a frame transmission by STA 106B. In the example of Figure 8, STAs 106A and 106B are both associated with the same non-transmitting BSSID (e.g., BSSID1).
[0093] The AP 104 may generate the integrity-protected ICF 806. The AP 104 may generate the integrity-protected ICF 806, for example, as the integrity-protected ICF 612 of FIG. 6. The integrity-protected ICF 806 may have the RA field set to the broadcast address. In this example, because both the STA 106A and the STA 106B belong to BSSID1, the AP 104 may set the TA field of the integrity-protected ICF 806 to BSSID1. The AP 104 may generate a CMIC (e.g., the CMIC 610 of FIG. 6) for the integrity-protected ICF 806, such as CMIC1. The AP 104 may generate CMIC1 using a cryptographic group key that corresponds to and / or is specific to BSSID1 (e.g., as the selected cryptographic key 604 of FIG. 6). The AP 104 may include CMIC1 in a header field or frame body of the integrity-protected ICF 806. The AP 104 may transmit (broadcast) the integrity-protected ICF 806.
[0094] The STAs 106A and 106B may receive the integrity-protected ICF 806. The STAs 106A and 106B may integrity check the integrity-protected ICF 806 using the encryption group key corresponding to BSSID1 (e.g., as shown in FIG. 7). The STAs 106A and 106B may receive the encryption group key corresponding to BSSID1 during a handshake operation with the AP 104 during or after association with BSSID1 of the AP 104. The integrity-protected ICF 806 may include information identifying that the STAs 106A and 106B should use the encryption group key corresponding to BSSID1 to integrity check the integrity-protected ICF 806. In response to successfully checking the integrity of the integrity-protected ICF 806, STA 106A may transmit a CTS frame 808 with an RA field identifying BSSID 1, and STA 106B may transmit a CTS frame 812 with an RA field identifying BSSID 1. AP 104 may receive CTS frames 808 and 812 in / using BSSID 1.
[0095] In response to receiving the CTS frame, the AP 104 may transmit a DL data frame (e.g., an MU PPDU frame having a header with RA=MSTA1 and TA=BSSID1) to the STA 106A and may transmit a DL data frame (e.g., an MU PPDU frame having a header with RA=MSTA2 and TA=BSSID1) to the STA 106B, as indicated by block 810. The STA 106A may receive the data frame addressed to the MAC address MSTA1, and the STA 106B may receive the data frame addressed to the MAC address MSTA2.
[0096] In response to receiving the DL data frame, the STA 106A may transmit a BA frame 814 to BSSID1 of the AP 104. The BA frame 814 may have the RA field set to BSSID1 and the TA field set to MAC address MSTA1. If desired, the STA 106A may integrity protect the BA frame 814 by generating an additional CMIC, such as CMIC2, based on one or more fields of the BA frame and inserting CMIC2 into the BA frame (e.g., the STA 106A forms the transmitter device 616 and the BA frame 814 replaces the ICF 602 of FIG. 6).
[0097] Similarly, in response to receiving the DL data frame, STA 106B may transmit a BA frame 816 to BSSID1 of AP 104. The BA frame 816 may have an RA field set to BSSID1 and a TA field set to MAC address MSTA2. If desired, STA 106B may integrity protect the BA frame 816 by generating an additional CMIC, such as CMIC3, based on one or more fields of the BA frame and inserting CMIC3 into the BA frame (e.g., if STA 106B forms the transmitter device 616 and the BA frame 816 replaces ICF 602 of FIG. 6). AP 104 may continue to communicate wireless data with STA 106A and STA 106B. The example of FIG. 8 illustrates DL data transmission from AP 104 to STAs 106A and 106B. Similar integrity protection may be applied to UL data transmissions from STAs 106A and 106B (eg, as shown in FIG. 5, where ICF 506, such as a trigger frame, may be integrity protected using CMIC1).
[0098] The example of Figure 8 illustrates integrity protection when STA 106A and STA 106B are both associated with the same BSSID (e.g., BSSID1). In an implementation where STA 106A is associated with non-transmitting BSSID1 and STA 106B is associated with BSSID2 (e.g., as shown in Figures 4 and 5), integrity protecting the ICF transmitted by AP 104 can lead to excessive latency and reduced data throughput if care is not taken. For example, in some scenarios, STA 106A may only have knowledge of the control frame integrity group key for non-transmitting BSSID1, and STA 106B may only have knowledge of the control frame integrity group key for BSSID2.
[0099] In these scenarios, the AP 104 can only transmit an integrity-protected ICF for a single non-transmitting BSSID at a time. For example, during a first TXOP, the AP 104 may transmit an integrity-protected ICF carrying a first CMIC, such as CMIC1, for the STA 106 associated with BSSID1 (e.g., STA 106A). After integrity checking the integrity-protected ICF carrying CMIC1, data frames may be communicated between the BSSID1 of the AP 104 and the STA 106 associated with the non-transmitting BSSID1. Then, during a second TXOP after the first TXOP, the AP 104 may transmit an integrity-protected ICF carrying a second CMIC, such as CMIC2, for the STA 106 associated with BSSID2 (e.g., STA 106B). After integrity checking the integrity-protected ICF carrying CMIC2, data frames may be communicated between the BSSID2 of the AP 104 and the STA 106 associated with BSSID2. This process may continue in each TXOP for each non-transmitting BSSID of the AP 104. Forcing STAs associated with different BSSIDs to be served in different TXOPs in this manner may result in reduced data throughput and excessive latency.
[0100] To maximize throughput and minimize latency when STA 106A and STA 106B are associated with different BSSIDs, AP 104 may generate an integrity-protected ICF, sometimes referred to herein as a secure ICF (SICF), using one or more techniques as described herein for transmission to STAs 106A and 106B. In a first implementation, for example, the SICF may carry separate CMICs for each non-transmitting BSSID of AP 104.
[0101] 9 is a timing diagram illustrating an example DL data transmission in which the AP 104 generates a SICF carrying separate CMICs for each non-transmitting BSSID of the AP 104. As shown in FIG. 9, row 900 illustrates a frame transmission by the AP 104, row 902 illustrates a frame transmission by STA 106A, and row 902 illustrates a frame transmission by STA 106B. In the example of FIG. 9, STA 106A is associated with BSSID 1 and STA 106B is associated with BSSID 2.
[0102] The AP 104 may generate the SICF 906. The SICF 906 may have its RA field set to “BROADCAST.” Because the STAs 106A and 106B are associated with different BSSIDs, the AP 104 may set the TA field of the SICF 906 to a unique BSSID, such as transmit BSSID0. The AP 104 may generate a first CMIC1 using a first BSSID-specific encryption group key (e.g., a first control frame integrity temporal group key) associated with BSSID1 and generate a second CMIC2 using a second BSSID-specific encryption group key (e.g., a second control frame integrity temporal group key) associated with BSSID2, using the process shown in FIG. 6. The AP 104 may insert both CMIC1 and CMIC2 into one or more fields of the SICF 906. In the DL data transmission scenario shown in FIG. 9, the SICF may be an integrity-protected MU-RTS, as an example. The AP 104 may transmit (broadcast) the SICF 906.
[0103] The STA 106A and the STA 106B may receive the SICF 906. The STA 106A may integrity check the SICF 906 using CMIC1 included in the SICF 906 and the first encryption group key associated with BSSID1 (e.g., using the process shown in FIG. 7). The STA 106A may receive the first encryption group key associated with BSSID1 during a handshake operation with the AP 104 during or after association with BSSID1 of the AP 104. The SICF 906 may include information identifying that the STA 106A will integrity check the SICF 906 using the first encryption group key associated with BSSID1. In response to successfully checking the integrity of the integrity-protected SICF 906, the STA 106A may transmit a CTS frame 908 with an RA field identifying BSSID0 of the AP 104. The AP 104 may receive the CTS frame 908 in BSSID0 using / BSSID0.
[0104] At the same time, the STA 106B may integrity check the SICF 906 using CMIC2 included in the SICF 906 and a second encryption group key associated with BSSID2 (e.g., using the process shown in FIG. 7). The STA 106B may receive the second encryption group key associated with BSSID2 during a handshake operation with the AP 104 during or after associating with BSSID2 of the AP 104. The SICF 906 may include information identifying that the STA 106B will integrity check the SICF 906 using the second encryption group key associated with BSSID2. In response to successfully checking the integrity of the integrity-protected SICF 906, the STA 106B may transmit a CTS frame 910 with an RA field identifying BSSID0 of the AP 104. The AP 104 may receive the CTS frame 910 in BSSID0 using / BSSID0. Utilizing BSSID0 in the RA fields of both CTS frame 908 and CTS frame 910 may serve to prevent collisions between the CTS frames, for example, even though STA 106A and STA 106B are associated with different BSSIDs.
[0105] In response to receiving the CTS frame, the AP 104 may transmit a DL data frame 912 (e.g., an MU PPDU frame having a header with RA=MSTA1 and TA=BSSID1) to the STA 106A and simultaneously transmit a DL data frame 914 (e.g., an MU PPDU frame having a header with RA=MSTA2 and TA=BSSID2) to the STA 106B. The STA 106A may receive the DL data frame 912, and the STA 106B may receive the DL data frame 914.
[0106] In response to receiving the DL data frame 912, the STA 106A may transmit an integrity-protected BA frame 916 (sometimes referred to herein as a secure BA frame (SBA)) to BSSID1 of the AP 104 (e.g., having a header with RA=BSSID1 and TA=MSTA1). In response to receiving the DL data frame 914, the STA 106B may transmit an SBA 918 to BSSID2 of the AP 104 (e.g., having a header with RA=BSSID2 and TA=MSTA2). The AP 104 may then continue to communicate wireless data with the STAs 106A and 106B. The example of FIG. 9 illustrates DL data transmission from the AP 104 to the STAs 106A and 106B. Similar integrity protection may be applied to UL data transmissions from STAs 106A and 106B (e.g., as shown in FIG. 5, where an ICF 506, such as a trigger frame, may be integrity protected using CMIC1 and CMIC2 included within the trigger frame).
[0107] Including both CMIC1 and CMIC2 in the SICF 906 may minimize latency and maximize data throughput while serving STA 106A and STA 106B despite them belonging to different BSSIDs (e.g., allowing simultaneous transmission of DL data frames 912 and 914 rather than transmitting the DL data frames in separate TXOPs). However, including respective CMICs for each non-transmitting BSSID increases the size of the control frame, which may undesirably increase protocol overhead and implementation complexity. For example, the SICF 906 may also need to include separate packet number (PN) and key identifier (KeyID) fields for each CMIC included in the SICF (e.g., for each BSSID served by the SICF).
[0108] To minimize the size of the SICF (e.g., minimize protocol overhead and implementation complexity), the SICF may instead include only a single CMIC that is common to (shared by) each of the BSSIDs and STAs served by the AP 104. The SICF 1000 of FIG. 10 is an example of a SICF that includes only a single common CMIC shared across each of the BSSIDs of the AP 104. As shown in FIG. 10, the AP 104 may integrity protect the SICF 1000 using a common control message integrity check CCMIC (sometimes referred to herein as a shared or combined CCMIC, CCMIC field, CCMIC information, or CCMIC bits). The AP 104 may include the common control message integrity check CCMIC in a header field or frame body of the SICF 1000.
[0109] The AP 104 may use the selected cryptographic group key to generate a common control message integrity check CCMIC (e.g., using the process shown in FIG. 6). The selected cryptographic group key may be used by STAs associated with all or a subset of the AP 104's non-transmitting BSSIDs to integrity check the SICF 1000. For example, the STA 106A may use the selected cryptographic group key to integrity check the SICF 1000 received from the AP 104 (e.g., using the process shown in FIG. 7). The STA 106B may also use the selected cryptographic group key to integrity check the SICF 1000 received from the AP 104 (e.g., using the process shown in FIG. 7), even though the STA 106B is associated with a different BSSID than the STA 106A. The STAs 106A and 106B may receive the selected cryptographic group key used to generate the common control message integrity check CCMIC in a handshake operation with the AP 104 during or after association with the AP 104. If desired, the SICF 1000 may include information identifying a selected cryptographic group key used by the STAs 106A and 106B in integrity checking the SICF 1000. In response to successfully checking the integrity of the integrity-protected SICF 1000, the STA 106A may transmit a CTS frame 908 and the STA 106B may transmit a CTS frame 910.
[0110] The examples of Figures 4, 5, 9, and 10 show the simplest case where the AP 104 has two non-transmitting BSSIDs (e.g., BSSID1 and BSSID2). This is illustrative and not limiting. In general, the AP 104 may have more than two non-transmitting BSSIDs. The examples of Figures 5, 9, and 10 show the simplest case where BSSID1 and BSSID2 are each associated with a single STA 106. This is illustrative and not limiting. In general, any desired number of STAs may be associated with each non-transmitting BSSID of the AP 104. In other words, the systems and methods described herein may be applied to and generalized to any number of STAs 106 associated with any number of non-transmitting BSSIDs of a given AP 104.
[0111] The different cryptographic group keys may be utilized by the AP 104 to generate a common control message integrity check CCMIC for the SICF 1000 (e.g., using the process of FIG. 6) and to verify the integrity of the SICF 1000 at the STA 106 (e.g., using the process of FIG. 7). As an example, the AP 104 may use a BSSID-specific control frame integrity group transient key (CIGTK) (sometimes referred to herein as a control frame integrity group key, control integrity group key, control integrity transient key, or control integrity transient group key) to generate the common control message integrity check CCMIC.
[0112] 11 is a diagram of an exemplary group key table that may be maintained at the AP 104 and a given STA 106 (e.g., STA 106A or STA 106B of FIG. 10) for use in integrity protection and validation for the SICF 1000. As shown in FIG. 11, the AP 104 may store and maintain an AP group key table 1100. The AP 104 may store the AP group key table 1100, for example, when the AP 104 forms the transmitter device 616 of FIG. 6 (e.g., when a SICF precedes a subsequent DL data frame transmission to the STA 106), in the encryption key storage device 600 of FIG. 6, and / or in the encryption key storage device 702 of FIG. 7 (e.g., when a SICF precedes a subsequent UL data transmission by the STA 106). A given STA 106 (e.g., STA 106A or STA 106B) may store and maintain an STA group key table 1102. The STA 106 may store the STA group key table 1102, for example, in the encryption key storage device 600 of Figure 6 when the STA 106 forms the transmitter device 616 of Figure 6 (e.g., to transmit an integrity-protected BA frame to the AP 104) and / or in the encryption key storage device 702 of Figure 7 when the STA 106 forms the receiver device 708 of Figure 7 (e.g., to integrity check a received SICF frame). The group key tables 1100 and 1102 may include tables, database entries, register entries, and / or any other desired data structures.
[0113] 11, the AP group key table 1100 may include a set of BSSID-specific group keys, each corresponding to a particular BSSID of the AP 104. The first column of the set of BSSID-specific group keys shown in the AP group key table 1100 of FIG. 11 may be associated with the transmitting BSSID of the AP 104 (i.e., BSSID0). The BSSID-specific group key associated with BSSID0 may include a group transient key (GTK), such as group transient key GTK0, an integrity group transient key (IGTK), such as integrity group transient key IGTK0, and a control frame integrity group transient key CIGTK, such as control frame integrity group transient key CIGTK0. The remaining n columns of the set of BSSID-specific group keys shown in the AP group key table 1100 of FIG. 11 may each be associated with a different individual non-transmitting BSSID maintained by the AP 104, from the first non-transmitting BSSID (e.g., BSSID1) through the nth non-transmitting BSSID (e.g., BSSIDn). Each non-transmitting BSSID may have a corresponding Group Temporal Key GTK, Integrity Group Temporal Key IGTK, and Control Frame Integrity Group Temporal Key CIGTK (e.g., BSSID1 may have a corresponding GTK such as GTK1, an IGTK such as IGTK1, and a CIGTK such as CIGTK1; BSSIDn may have a corresponding GTK such as GTKn, an IGTK such as IGTKn, and a CIGTK such as CIGTKn).
[0114] The STA group key table 1102 may also include a BSSID-specific group key for a BSSID (e.g., BSSIDi, where i is an integer index from 1 to n that identifies the BSSID associated with the STA) associated with the STA 106 having the STA group key table 1102. The BSSID-specific group key may include a corresponding group transient key GTKi (e.g., GTK1 when the STA 106 having the STA group key table 1102 is associated with BSSID1, GTKn when the STA 106 having the STA group key table 1102 is associated with BSSIDn, etc.), a corresponding integrity group transient key IGTKi (e.g., IGTK1 when the STA 106 having the STA group key table 1102 is associated with BSSID1, IGTKn when the STA 106 having the STA group key table 1102 is associated with BSSIDn, etc.), and a corresponding control frame integrity group transient key CIGTKi (e.g., CIGTK1 when the STA 106 having the STA group key table 1102 is associated with BSSID1, CIGTKn when the STA 106 having the STA group key table 1102 is associated with BSSIDn, etc.).
[0115] The AP 104 may use the BSSID-specific group temporary keys GTK1 through GTKn to generate hash codes to be appended to DL data frames (e.g., DL PPDU frames) sent to STAs 106 associated with the corresponding BSSIDs (e.g., by hashing message data from the DL data frames with the corresponding group temporary keys GTK). The AP 104 may, for example, use group temporary key GTK1 to encrypt data frames sent to STAs 106 associated with BSSID1, and group temporary key GTKn to encrypt data frames sent to STAs 106 associated with BSSIDn, and so on. The STAs 106 may then use their stored group temporary keys GTKi to decrypt message data encrypted at the AP 104 using the same group temporary keys GTKi.
[0116] The AP 104 may use the integrity group temporal key IGTK to integrity protect management frames transmitted to the STAs 106 associated with the corresponding BSSID. This may include generating CMICs for the management frames using the corresponding integrity group temporal key IGTK and inserting the generated CMICs into the management frames transmitted to the STAs 106. The STAs 106 may then use their stored integrity group temporal key IGTKi to generate a CMIC for their associated BSSIDi and compare the generated CMIC with the CMIC included in the management frame to verify that the management frame was transmitted by the expected AP 104.
[0117] The AP 104 may use the control frame integrity group temporal key CIGTK to integrity protect control frames (e.g., ICFs) addressed to the STAs 106 of a single BSSID. This may include generating a CMIC for the ICF using the corresponding control frame integrity group temporal key CIGTK, inserting the generated CMIC into the ICF, and transmitting the ICF to the STAs 106 of the corresponding BSSID. The STA 106 can then use its stored control frame integrity group temporal key CIGTKi to generate a CMIC for its associated BSSIDi and compare the generated CMIC with the CMIC included with the ICF to verify that the ICF frame was sent by the expected AP 104.
[0118] The AP group key table 1100 and the STA group key table 1102 may also store a BSSID-independent common group key, such as a Beacon Integrity Group Temporal Key (BIGTK). The AP 104 may use the BIGTK to integrity protect beacon frames transmitted to the STAs 106. Because the AP 104 transmits a single beacon frame to all STAs and BSSIDs under the M-BSSID communication scheme, all STAs 106 may use the same BIGTK to integrity check and / or decrypt beacon frames regardless of the STA's BSSID.
[0119] In the example of Figure 11, the AP 104 generates the SICF 1000 (Figure 10) based on its control frame integrity group transient key CIGTK0 for its transmitting BSSID0. The AP 104 may use, for example, the control frame integrity group transient key CIGTK0 from the AP group key table 1100 as the selected encryption key 604 provided to the encryption function 608 (Figure 6), which outputs the common control message integrity check CCMIC (e.g., as the CMIC 610 of Figure 6). The AP 104 may then insert the CCMIC into a field of the SICF 1000 and transmit the SICF 1000 to the STA 106 (e.g., as the integrity-protected ICF 612 of Figure 6). Because the control frame integrity group transient key CIGTK0 is unique to the AP 104 but not to any non-transmitting BSSID, the same control frame integrity group transient key CIGTK0 may be particularly suitable for generating the SICF 1000 that is broadcast across the BSSIDs of the AP 104.
[0120] As indicated by arrow 1104, the STA 106 may also store the control frame integrity group transient key CIGTK0 associated with the transmitting BSSID0 of the AP 104 (e.g., as one of its BSSID-independent common group keys in the STA group key table 1102). The STA 106 may receive the control frame integrity group transient key CIGTK0 from the AP 104, for example, during a handshake operation prior to the transmission of the SICF 1000 by the AP 104. The STA 106 may receive the SICF 1000 transmitted by the AP 104 and integrity check the SICF 1000 based on the control frame integrity group transient key CIGTK0. The STA 106 may use, for example, the control frame integrity group transient key CIGTK0 from the STA group key table 1102 as the selected encryption key 604 provided to the encryption function 608 (FIG. 7), which outputs the common control message integrity check CCMIC (e.g., as the candidate CMIC 704 in FIG. 7). The STA 106 may then compare its generated common control message integrity check CCMIC with the common control message integrity check CCMIC received in the SICF 1000 to verify that the SICF was sent by the expected AP 104.
[0121] 11 , the control frame integrity group transient key CIGTK0 associated with transmitting BSSID0 of the AP 104 is used to generate the common control message integrity check CCMIC for the SICF 1000. As another example shown in FIG. 12 , the AP 104 may use a dedicated (e.g., unique or newly defined) control frame integrity group transient key CCIGTK (sometimes referred to herein as a common control frame integrity group transient key, control frame integrity group transient key, control integrity group transient key, or control integrity group key) for use in generating the common control message integrity check CCMIC for the SICF 1000. The dedicated control frame integrity group transient key CCIGTK is different from the control frame integrity group transient key CIGTK0 associated with transmitting BSSID0 of the AP 104 and different from each of the control frame integrity group transient keys CIGTK1 through CIGTKn associated with each of the non-transmitting BSSIDs (e.g., BSSID1 through BSSIDn) of the AP 104.
[0122] As shown in FIG. 12, the AP group key table 1100 may store the dedicated control frame integrity group transient key CCIGTK as one of its BSSID-independent common group keys. The AP 104 may generate the SICF 1000 (FIG. 10) based on the dedicated control frame integrity group transient key CCIGTK stored in the AP group key table 1100. The AP 104 may use, for example, the dedicated control frame integrity group transient key CCIGTK as the selected encryption key 604 provided to the encryption function 608 (FIG. 6), which outputs the common control message integrity check CCMIC (e.g., as the CMIC 610 of FIG. 6). The AP 104 may then insert the CCMIC into a field of the SICF 1000 and transmit the SICF 1000 to the STA 106 (e.g., as the integrity-protected ICF 612 of FIG. 6).
[0123] As indicated by arrow 1200, the STA 106 may also store the dedicated control frame integrity group transient key CCIGTK as one of its BSSID-independent common group keys. The STA 106 may receive the dedicated control frame integrity group transient key CCIGTK from the AP 104, for example, during a handshake operation prior to the AP 104 transmitting the SICF 1000. The STA 106 may receive the SICF 1000 transmitted by the AP 104 and use the dedicated control frame integrity group transient key CCIGTK to integrity check the SICF 1000. The STA 106 may use the dedicated control frame integrity group transient key CCIGTK stored in the STA group key table 1102, for example, as the selected encryption key 604 provided to the encryption function 608 (FIG. 7), which outputs the common control message integrity check CCMIC (e.g., as the candidate CMIC 704 of FIG. 7). The STA 106 may then compare its generated common control message integrity check CCMIC with the common control message integrity check CCMIC received in the SICF 1000 to verify that the SICF was sent by the expected AP 104. Generating the common control message integrity check CCMIC using the dedicated control frame integrity group transient key CCIGTK may provide the same level of security robustness to all STAs regardless of their associated BSSID, but may require additional storage at the AP and STAs to store the dedicated control frame integrity group transient key CCIGTK.
[0124] 13, the AP 104 may reuse a Beacon Integrity Group Temporal Key (BIGTK) stored on the AP Group Key Table 1100 to generate the Common Control Message Integrity Check CCMIC for the SICF 1000. This may help minimize the storage required at the AP 104 and the STAs 106, as the AP and the STAs do not need to store additional encryption keys to integrity protect and check the SICF 1000.
[0125] The AP 104 may use, for example, the BIGTK as the selected encryption key 604 provided to the cryptographic function 608 (FIG. 6), which outputs the common control message integrity check CCMIC (e.g., as CMIC 610 in FIG. 6). The AP 104 may then insert the CCMIC into a field of the SICF 1000 and transmit the SICF 1000 to the STA 106 (e.g., as the integrity-protected ICF 612 in FIG. 6). The STA 106 may use the BIGTK stored in the STA group key table 1102 as the selected encryption key 604 provided to the cryptographic function 608 (FIG. 7), which outputs the common control message integrity check CCMIC (e.g., as the candidate CMIC 704 in FIG. 7). The STA 106 may then compare its generated common control message integrity check CCMIC with the common control message integrity check CCMIC received in the SICF 1000 to verify that the SICF was sent by the expected AP 104. Using the BIGTK to generate the common control message integrity check CCMIC can provide the same level of security robustness to all STAs regardless of their associated BSSID and can minimize the storage required in the AP group table 1100 and the STA group key table 1102. However, the STA may be vulnerable to an internal attack from a STA that knows the BIGTK but is connected to a less robust network (BSSID), such as the AP's guest network.
[0126] 14, the AP 104 and the STAs 106 across all of the BSSIDs of the AP 104 may use a dedicated control frame integrity group transient key CCIGTK to integrity protect and integrity check both SICF 1000 addressed to all STAs across the BSSIDs (e.g., with RA=“BROADCAST”) and control frames (e.g., ICF) sent to STAs of a single BSSID (e.g., with RA=BSSIDi). This may allow the control frame integrity group transient key CCIGTK (FIGS. 11-13) to be omitted from the BSSID-specific group keys in the AP group key table 1100 and the STA group key table 1102. This may serve to minimize the amount of storage consumed by the AP group table 1100 and the STA group key table 1102, but may provide less robust security than maintaining a separate control frame integrity group transient key CCIGTK for each BSSID of the AP 104.
[0127] In the examples of FIGS. 10-14, the SICF 1000 is transmitted to STAs 106 associated with all of the AP 104's BSSIDs (e.g., RA="BROADCAST"). If desired, the SICF 1000 may instead be transmitted to STAs 106 associated with a subset (e.g., some but not all) of the AP 104's BSSIDs. A set of BSSs within multiple BSSIDs may either have the same common control frame integrity group key, no common control frame integrity group key, or no BIGTK. As an example, the AP 104 may support a set of Opportunistic Over-the-Air Encryption (OWE) BSSs, which do not authenticate the STAs but set up encryption keys for the BSSs. A common CIGTK may not be shared with STAs within the OWE because a common CIGTK could allow attacks with a valid integrity checksum. STAs associated with the OWE BSSs in the M-BSSID beacon frame do not share the BIGTK for the same reason. Similarly, if the BSS security mode does not enable beacon protection or control frame integrity protection, the BIGTK or common CIGTK is not provided to the STA. Under this type of implementation, different security level networks can be included in the same M-BSSID beacon frame.
[0128] 15 shows an example in which an AP 104 associates with STAs 106 a first set of BSSIDs (e.g., BSSID1 through BSSIDm) that support robust security capabilities and a second set of BSSIDs (e.g., BSSIDn) that form an OWE network. A STA group key table 1102 may be stored on the STAs 106 associated with BSSIDi in the first set. There may also be a STA group key table 1502 stored on the STAs 106 of the second set and associated with BSSIDn (the OWE network). In this example, when the SICF 1000 (FIG. 10) is addressed to a STA associated with BSSID1 through BSSIDm, the SICF 1000 may include a CMIC generated using the dedicated control frame integrity group transient key CCIGTK stored in the AP group key table 11000 and verified using the dedicated control frame integrity group transient key CCIGTK stored in the STA group key table 1102. The STA 106 associated with OWE(BSSIDn) does not store a dedicated control frame integrity group temporal key CCIGTK, and the AP group key table 1100 does not use a BSSID-independent common group key for BSSIDn (as indicated by the empty region 1500).
[0129] 16 is a flowchart of example operations involved in conducting wireless communication between a STA 106 configured under the M-BSSID scheme and an AP 104. In operation 1600, the STA 106 may register and associate with a corresponding non-transmitting BSSIDi (e.g., BSSID1, BSSID2, etc.) of the AP 104. Some or all of operation 1602 may be performed simultaneously with operation 1600, if desired.
[0130] In operation 1602, the AP 104 may perform a handshake operation with the STA 106. If desired, the AP 104 may transmit (in operation 1604) a set of cryptographic group keys to the STA 106 during the handshake operation. The encryption group key transmitted to STA 106 may include, for example, a BSSID-independent common group key such as BIGTK stored in AP group key table 1100 (FIGS. 11-15) and / or a dedicated control frame integrity group transient key CCIGTK stored in AP group key table 1100 (FIGS. 12, 14, and 15), a control frame integrity group transient key CIGTK0 for the transmitting BSSID0 of AP 104 (FIG. 11), a group transient key GTK for BSSIDi associated with STA 106 (FIGS. 11-14), an integrity group transient key IGTKi for BSSIDi associated with STA 106 (FIGS. 11-14), and / or a control frame integrity group transient key CIGTKi for BSSIDi associated with STA 106 (FIGS. 11-13). STA 106 may store the received cryptographic group key in its STA group key table 1102 (FIGS. 11-15) for use in subsequent communications.
[0131] In operation 1606, in an implementation in which the AP 104 uses a separate CMIC for each BSSIDi supported by the AP to integrity protect the transmitted SICF (e.g., SICF 906 of FIG. 9), the AP 104 may generate a separate CMIC for each BSSIDi supported by the AP. The AP 104 may generate the CMIC for each BSSIDi using, for example, the separate control frame integrity group transient key CIGTKi (FIGS. 11-13) associated with that BSSIDi (e.g., using the control frame integrity group transient key CIGTK1 as the selected encryption key 604 of FIG. 6 to generate CMIC1 for BSSID1, using the control frame integrity group transient key CIGTK2 as the selected encryption key 604 of FIG. 6 to generate CMIC2 for BSSID2, etc.).
[0132] In an implementation in which the AP 104 uses a common control message integrity check CCMIC for all BSSIDs supported by the AP to integrity protect a transmitted SICF (e.g., SICF 1000 of FIG. 10), the AP 104 may generate the common control message integrity check CCMIC using, for example, a dedicated control frame integrity group transient key CCIGTK (FIGS. 12, 14, and 15) (e.g., using the control frame integrity group transient key CCIGTK as the selected encryption key 604 of FIG. 6 to generate the common control message integrity check CCMIC in the encryption function 608), or may generate the common control message integrity check CCMIC using a dedicated BIGTK for the AP 104 (FIG. 13) (e.g., using the BIGTK as the selected encryption key 604 of FIG. 6 to generate the common control message integrity check CCMIC in the encryption function 608).
[0133] The AP 104 may insert the CMIC generated in operation 1606 into an ICF (e.g., an MU-RTS frame, a trigger frame, etc.) to be transmitted to the STA 106 and generate a corresponding SICF (e.g., SICF 906 of FIG. 9 or SICF 1000 of FIG. 10). The AP 104 may also insert information into the SICF (e.g., one or more bits in one or more header fields of the SICF) that identifies or indicates a selected cryptographic group key used by the AP 104 to generate the CMIC in the SICF. In operation 1608, the AP 104 may transmit the SICF to the STA 106, including the generated CMIC and information identifying the selected cryptographic group key.
[0134] In operation 1610, the STA 106 receives the SICF. The STA 106 may use the selected cryptographic group key(s) identified by the received SICF to integrity check the SICF (e.g., using the procedure shown in FIG. 7). Integrity checking the SICF is sometimes referred to herein as verifying or attempting to verify the CMIC of the SICF. For example, the STA 106 may use the dedicated control frame integrity group transient key CCIGTK or BIGTK as the selected cryptographic key 604 of FIG. 7 to generate a candidate common control message integrity check CCMIC and may compare the candidate common control message integrity check CCMIC with the common control message integrity check CCMIC included in the SICF. The STA 106 may use the BSSID-specific control frame integrity group temporal key CIGTK or the BSSID-independent control frame integrity group temporal key CCIGTK as the selected encryption key to generate a candidate common control message integrity check CCMIC and may compare the candidate common control message integrity check CCMIC with the common control message integrity check CCMIC included in the SICF. If / when the common control message integrity check CCMIC included in the SICF matches the candidate common control message integrity check CCMIC, the STA 106 may pass the integrity check, and processing may proceed to operation 1612. As another example, the STA 106 may use the control frame integrity group temporal key CIGTKi for its associated BSSIDi to generate a candidate control message integrity check CMIC' and may compare the candidate control message integrity check CMIC' with the control message integrity check CMIC included in the SICF for its associated BSSIDi. If / when the control message integrity check CMIC included in the SICF for BSSID i of the STA 106 matches the candidate control message integrity check CMIC′, the STA 106 may pass the integrity check and processing may proceed to operation 1612 .
[0135] In operation 1612 (e.g., in response to passing / verifying the integrity check), the STA 106 may send a response (e.g., an ACK frame, a BA frame, an M-BA frame, etc.) to the AP 104. If desired, the STA 106 may integrity protect the response. The AP 104 and the STA 106 may then communicate a data frame (e.g., a data frame preceded or triggered by the SICF).
[0136] 17 is a timing diagram illustrating an exemplary handshake procedure between the AP 104 and the STA 106 (e.g., as performed in operation 1602 of FIG. 16). As shown in FIG. 17, the handshake procedure may include transmitting a first message (MSG1) from the AP 104 to the STA 106. The STA 106 may then acknowledge or respond to receipt of MSG1 with transmitting a second message (MSG2) from the STA 106 to the AP 104. The AP 104 may then acknowledge or respond to receipt of MSG2 with transmitting a third message (MSG3) from the AP 104 to the STA 106. The STA 106 may then acknowledge or respond to receipt of MSG3 with transmitting a fourth message (MSG4) from the STA 106 to the AP 104. This example is illustrative and not limiting. The handshake procedure may include additional messaging, or other handshake procedures may be used.
[0137] If desired, the AP 104 may include the set of cryptographic group keys in MSG3 (e.g., in operation 1604 of FIG. 16). The AP 104 may, for example, include the set of cryptographic group keys in one or more key data elements (KDEs) of MSG3. MSG3 may, for example, include a different, individual KDE for each cryptographic group key sent to the STA 106.
[0138] 18 is a diagram of an example KDE that may be included in MSG3 for a corresponding cryptographic group key sent from the AP 104 to the STA 106 during a handshake. As shown in FIG. 18, the KDE may include a key identifier (KeyID) field 1800, a CIPN field 1802, a reserved field 1804, a key type field 1806, a link identifier (LinkID) field 1808, and a key data field 1810. The key data field 1810 may include the cryptographic group key being sent to the STA 106. The key ID field 1800 may identify the cryptographic group key included in the key data field 1810. The CIPN field 1802 is a packet number associated with the CIGTK. The key type field 1806 indicates whether the cryptographic group key contained in the key data field 1810 is a BSSID-specific cryptographic group key (e.g., CIGTKi) or whether the cryptographic group key contained in the key data field 1810 is a BSSID-independent common group key shared by all BSSIDs (e.g., CCIGTK or BIGTK). The example of Figure 18 is illustrative, and generally, other container structures can be used to communicate one or more cryptographic group keys to the STAs 106.
[0139] 19 illustrates an example of how the AP 104 may include information identifying / indicating the selected cryptographic group key in the SICF sent to the STA 106 (e.g., in operation 1608 of FIG. 19). This information may serve to inform the STA 106 which of its stored cryptographic group keys will be used to verify the integrity of the SICF. This information may also be referred to as a KDE selector or KDE selector information.
[0140] 19, the SICF may include a header field 1900. The header field 1900 may include a key or KDE identifier / selector field, such as field 1902. Field 1902 may include a key type field 1904 and a key identifier field 1906. The key type field 1904 and the key identifier field 1906 may collectively identify which of the stored cryptographic group keys the STA 106 should use to verify the integrity of the SICF. The key type field 1904 and the key identifier field 1906 may be relatively small (e.g., may be single-bit fields each containing only a single bit) to minimize the overhead of the SICF.
[0141] For example, the key type field 1904 may have a value of “1” when the selected encryption group key is a BSSID-specific key (e.g., when the selected encryption group key is a control frame integrity group transient key CIGTKi for the STA's BSSIDi) or a value of “0” when the selected encryption group key is shared by two or more BSSIDs of the AP (e.g., when the selected encryption group key is a dedicated control frame integrity group transient key CCIGTK or BIGTK). The key identifier field 1906 may be used, for example, to resolve ambiguity within the same key type of the key type field 1904 to identify the selected encryption group key (e.g., may have a value of “1” when a first encryption group key is used for the dedicated control frame integrity group transient key CCIGTK and may have a value of “0” when a second encryption group key is used for the dedicated control frame integrity group transient key CCIGTK). Other frame structures and reporting mechanisms may be used to inform the STA 106 of the selected encryption group key.
[0142] As used herein, the term "concurrent" means at least partially overlapping in time. In other words, a first and second event are referred to herein as being "concurrent" with one another if at least a portion of the first event occurs at the same time as at least a portion of the second event (e.g., if at least a portion of the first event occurs during, while, or when at least a portion of the second event occurs). A first and second event can be concurrent if the first and second events are simultaneous (e.g., if the entire duration of the first event overlaps in time with the entire duration of the second event), but can also be concurrent if the first and second events are non-concurrent (e.g., if the first event begins before or after the start of the second event, if the first event ends before or after the end of the second event, or if the first and second events do not partially overlap in time). As used herein, the term "while" is synonymous with "concurrent." The term "when" also implies at least some concurrency (e.g., event A occurring "when" event B occurs means that at least part of event A is simultaneous with at least part of event B).
[0143] The STAs 106 and APs 102 / 104 (FIG. 1) may collect and / or use personally identifiable information. It is well understood that use of personally identifiable information should comply with generally recognized privacy policies and practices that meet or exceed industry or government requirements for maintaining user privacy. In particular, personally identifiable information data should be managed and handled in a manner that minimizes the risk of unintended or unauthorized access or use, and the nature of authorized use should be clearly indicated to users.
[0144] The methods and operations described above in connection with FIGS. 1-19 may be performed by components of the STA and / or AP using software, firmware, and / or hardware (e.g., dedicated circuitry or hardware). Software code for performing these operations may be stored in a non-transitory computer-readable storage medium (e.g., a tangible computer-readable storage medium) stored in one or more of the components of the STA and / or AP. The software code may be referred to as software, data, instructions, program instructions, or code. The non-transitory computer-readable storage medium may include non-volatile random-access memory (NVRAM), a drive such as a removable flash drive or other removable medium, other types of random access memory, etc. The software stored in the non-transitory computer-readable storage medium may be executed by processing circuitry of one or more of the components of the STA and / or AP. The processing circuitry may include a microprocessor, a central processing unit (CPU), an application-specific integrated circuit having processing circuitry, or other processing circuitry.
[0145] For one or more aspects, at least one of the components depicted in one or more of the foregoing figures may be configured to perform one or more operations, techniques, processes, or methods as described in the example section below. For example, circuitry associated with an electronic device, an authentication server, one or more processors, etc., as described above in connection with one or more of the foregoing figures, may be configured to operate according to one or more of the examples described below in the example section. [Example]
[0146] Further exemplary aspects are provided in the following sections.
[0147] Example 1 includes a method of operating a station (STA) to communicate with an access point (AP), the method including: receiving from the AP a control frame including a control message integrity check (CMIC) shared by multiple basic service set identifiers (BSSIDs) of the AP; attempting to verify, using one or more processors, the CMIC in the control frame; and transmitting, in response to verifying the CMIC in the control frame, an uplink signal to the AP using one or more antennas.
[0148] Example 2 includes the method of Example 1 or any other example or combination of examples herein, wherein the control frame has a receiver address (RA) field that includes a broadcast address and a transmitter address (TA) field that identifies the BSSID of an AP that is served by the AP and is not associated with any STA.
[0149] Example 3 includes the method of any of Example 1 or Example 2, or any other example or combination of examples herein, wherein the control frame comprises a multi-user request to send (MU-RTS) frame, and the uplink signal comprises a clear to send (CTS) frame with an additional RA field including a BSSID of an AP that is not associated with any STA served by the AP.
[0150] Example 4 includes the method of any of Examples 1 to 3 or any other example or combination of examples herein, wherein the control frame comprises a trigger frame, and the uplink signal comprises a trigger-based physical protocol data unit (TB PPDU) frame.
[0151] Example 5 includes the method of any of Examples 1 to 4 or any other example or combination of examples herein, wherein attempting to verify the CMIC includes attempting to verify the CMIC based on the cryptographic group key received from the AP.
[0152] Example 6 includes the method of any of Examples 1 to 5 or some other example or combination of examples herein, wherein the encryption group key has a BSSID-specific control frame integrity group transient key (CIGTK) associated with a dedicated BSSID of the AP, and the dedicated BSSID is not associated with any STA served by the AP.
[0153] Example 7 includes the method of any of Examples 1 to 6 or some other example or combination of examples herein, wherein the encryption group key comprises a BSSID-independent control frame integrity group temporal key (CIGTK) shared by multiple BSSIDs of the AP.
[0154] Example 8 includes the method of any of Examples 1 to 7 or some other example or combination of examples herein, wherein the cryptographic group key includes a Beacon Integrity Group Temporal Key (BIGTK) used by the AP to integrity protect beacon frames transmitted by the AP.
[0155] Example 9 includes the method of any of Examples 1 to 8 or any other example or combination of examples herein, and further includes receiving a key data element (KDE) in a third message of the handshake procedure between the STA and the AP, where the KDE indicates a cryptographic group key.
[0156] Example 10 includes the method of any of Examples 1 to 9 or any other example or combination of examples herein, wherein the control frame includes one or more header fields that identify the cryptographic group key.
[0157] Example 11 includes the method of any of Examples 1 to 10 or some other example or combination of examples herein, wherein the one or more header fields include a single-bit key type field and a single-bit key identifier field.
[0158] Example 12 includes an electronic device configured to communicate with an access point (AP), the electronic device comprising: a receiver configured to receive a control frame from the AP including a first control message integrity check (CMIC) for a first basic service set identifier (BSSID) of the AP and a second CMIC for a second BSSID of the AP, the electronic device being associated with the first BSSID but not the second BSSID; one or more processors configured to attempt to verify the first CMIC in the control frame; and a transmitter configured to transmit an uplink signal to the AP in response to verifying the first CMIC in the control frame.
[0159] Example 13 includes the method of Example 12 or any other example or combination of examples herein, wherein the one or more processors are configured to attempt to verify the first CMIC in the control frame by generating a candidate CMIC based on a control frame integrity group temporal key (CIGTK) associated with the first BSSID and comparing the candidate CMIC to the first CMIC in the control frame.
[0160] Example 14 includes the method of any of Examples 12, 13, or some other examples or combinations of examples herein, wherein the control frame includes a multi-user request to send (MU-RTS) frame, and the uplink signal includes a clear to send (CTS) frame having a receiver address field with a third BSSID of the AP that is different from the first BSSID and the second BSSID.
[0161] Example 15 includes the method of any of Examples 12 to 14 or any other example or combination of examples herein, wherein the control frame comprises a trigger frame, and the uplink signal comprises a trigger-based physical protocol data unit (TB PPDU) frame.
[0162] Example 16 includes a method of operating an access point (AP) according to a communication protocol that implements a multiple basic service set identifier (M-BSSID) scheme, the method including: using one or more processors to generate a control message integrity check (CMIC) based on a cryptographic key; and using one or more antennas to transmit a control frame to a first station (STA) associated with a first basic service set identifier (BSSID) of the AP and to a second STA associated with a second BSSID of the AP that is different from the first BSSID, wherein a header of the control frame includes the CMIC and a transmitter address (TA), and the TA identifies a third BSSID that is different from the first BSSID and the second BSSID.
[0163] Example 17 includes the method of Example 16 or any other example or combination of examples herein, wherein the encryption key includes a BSSID-specific control frame integrity group temporal key (CIGTK) associated with the third BSSID.
[0164] Example 18 includes the method of any of Examples 16, 17, or some other example or combination of examples herein, wherein the encryption key includes a BSSID-independent control frame integrity group temporary key shared by the first BSSID and the second BSSID.
[0165] Example 19 includes the method of any of Examples 16-18 or any other example or combination of examples herein, wherein the encryption key includes a Beacon Integrity Group Temporal Key (BIGTK).
[0166] Example 20 includes the method of any of Examples 16 to 19 or any other example or combination of examples herein, wherein the encryption key includes a BSSID-specific Control Frame Integrity Group Temporal Key (CIGTK) associated with the first BSSID, and the method further includes generating, using the one or more processors, an additional CMIC based on the additional CIGTK associated with the second BSSID, and wherein the header of the control frame includes the additional CMIC.
[0167] Example 21 may include an apparatus including means for performing one or more elements of a method described in or related to any of Examples 1 to 20, or any combination thereof, or any other method or process described herein.
[0168] Example 22 may include one or more non-transitory computer-readable media containing instructions that, upon execution by one or more processors of an electronic device, cause the electronic device to perform one or more elements of a method described in or related to any of Examples 1-20, or any combination thereof, or any other method or process described herein.
[0169] Example 23 may include an apparatus including logic, modules, or circuitry for performing one or more elements of a method described in or related to any of Examples 1 to 20, or any combination thereof, or any other method or process described herein.
[0170] Example 24 may include any method, technique, or process described in or related to any of Examples 1-20, or any combination thereof, or any part or portion thereof.
[0171] Example 25 may include an apparatus including one or more processors and one or more non-transitory computer-readable storage media containing instructions that, when executed by the one or more processors, cause the one or more processors to perform a method, technique, or process described in or related to any of Examples 1 to 20, or any combination thereof, or portions thereof.
[0172] Example 26 may include signals described in or related to any of Examples 1-20, or any combination thereof, or parts or portions thereof.
[0173] Example 27 may include a datagram, information element, packet, frame, segment, PDU, or message described or related to any of Examples 1-20, or any combination thereof, or a portion or part thereof, or others described in this disclosure.
[0174] Example 28 may include a signal encoded with data described in or related to any of Examples 1-20, or any combination thereof, or a portion or parts thereof, or other methods described in this disclosure.
[0175] Example 29 may include a signal encoded with a datagram, IE, packet, frame, segment, PDU, or message described in or related to any of Examples 1-20, or any combination thereof, or a portion or part thereof, or a signal described in any manner otherwise in this disclosure.
[0176] Example 30 may include an electromagnetic signal carrying a plurality of computer-readable instructions, where execution of the plurality of computer-readable instructions by one or more processors causes the one or more processors to perform a method, technique, or process described in or related to any of Examples 1-20, or any combination thereof, or portions thereof.
[0177] Example 31 may include a computer program including instructions, where execution of the program by a processing element causes the processing element to perform a method, technique, or process, or a portion thereof, described in or related to any of Examples 1-20, or any combination thereof.
[0178] Example 32 may include signals in a wireless network as shown and described herein.
[0179] Example 33 may include a method of communicating in a wireless network as shown and described herein.
[0180] Example 34 may include a system for providing wireless communication as shown and described herein.
[0181] Example 35 may include a device for providing wireless communication as shown and described herein.
[0182] According to one embodiment, a method is provided for operating a station (STA) to communicate with an access point (AP), the method including: receiving, from the AP, a control frame including a control message integrity check (CMIC) shared by multiple basic service set identifiers (BSSIDs) of the AP; attempting, by the STA, to verify the CMIC in the control frame; and transmitting, by the STA, an uplink signal to the AP in response to verifying the CMIC in the control frame.
[0183] According to another embodiment, the control frame optionally includes a receiver address (RA) field containing the broadcast address and a transmitter address (TA) field indicating the transmitting BSSID of the AP used for management signaling of multiple BSSIDs.
[0184] According to another embodiment, the control frame optionally comprises a multi-user request to send (MU-RTS) frame, and the uplink signal comprises a clear to send (CTS) frame with an additional RA field having a transmit BSSID of an AP that is not associated with any STA served by the AP.
[0185] According to another embodiment, the control frame optionally includes a trigger frame, and the uplink signal optionally includes a trigger-based physical protocol data unit (TB PPDU) frame.
[0186] According to another embodiment, attempting to verify the CMIC optionally includes attempting to verify the CMIC based on a cryptographic group key received from the AP.
[0187] According to another embodiment, the cryptographic group key optionally includes a BSSID-specific control frame integrity group temporal key (CIGTK) associated with the AP's dedicated BSSID.
[0188] According to another embodiment, the cryptographic group key optionally comprises a BSSID-independent control frame integrity group temporal key (CIGTK) shared by at least two BSSIDs of the AP.
[0189] According to another embodiment, the cryptographic group key optionally includes a Beacon Integrity Group Temporal Key (BIGTK) that serves to integrity protect the beacon frames transmitted by the AP.
[0190] According to another embodiment, the method optionally includes receiving a key data element (KDE) in a third message of a handshake procedure between the STA and the AP, the KDE indicating a cryptographic group key.
[0191] According to another embodiment, the control frame optionally includes one or more header fields that indicate a cryptographic group key.
[0192] According to another embodiment, the one or more header fields optionally include a single-bit key type field and a single-bit key identifier field.
[0193] According to one embodiment, an electronic device configured to communicate with an access point (AP) is provided, the electronic device including: a receiver configured to receive a control frame from the AP including a first control message integrity check (CMIC) for a first basic service set identifier (BSSID) of the AP and a second CMIC for a second BSSID of the AP, the electronic device being associated with the first BSSID but not the second BSSID; one or more processors configured to attempt to verify the first CMIC in the control frame; and a transmitter configured to transmit an uplink signal to the AP when the first CMIC in the control frame is successfully verified.
[0194] According to another embodiment, the one or more processors are configured to attempt to verify a first CMIC in the control frame by, optionally, generating a candidate CMIC based on a Control Frame Integrity Group Temporal Key (CIGTK) associated with the first BSSID and comparing the candidate CMIC with the first CMIC in the control frame.
[0195] According to another embodiment, the control frame optionally includes a multi-user request to send (MU-RTS) frame, and the uplink signal includes a clear to send (CTS) frame having a receiver address field with a third BSSID of the AP that is different from the first BSSID and the second BSSID.
[0196] According to another embodiment, the control frame optionally includes a trigger frame, and the uplink signal optionally includes a trigger-based physical protocol data unit (TB PPDU) frame.
[0197] According to one embodiment, there is provided a method of operating an access point (AP) according to a communication protocol implementing a multiple basic service set identifier (M-BSSID) scheme, the method including: generating, by the AP, a control message integrity check (CMIC) based on an encryption key; and transmitting, by the AP, a control frame to a first station (STA) associated with a first basic service set identifier (BSSID) of the AP and to a second STA associated with a second BSSID of the AP that is different from the first BSSID, wherein a header of the control frame includes the CMIC and a transmitter address (TA), the TA indicating a third BSSID that is different from the first BSSID and the second BSSID.
[0198] According to another embodiment, the encryption key optionally includes a BSSID-specific Control Frame Integrity Group Temporal Key (CIGTK) associated with the third BSSID.
[0199] According to another embodiment, the encryption key optionally comprises a BSSID-independent control frame integrity group temporal key shared by the first BSSID and the second BSSID.
[0200] According to another embodiment, the encryption key optionally comprises a Beacon Integrity Group Temporal Key (BIGTK).
[0201] According to another embodiment, the encryption key optionally includes a BSSID-specific Control Frame Integrity Group Temporal Key (CIGTK) associated with the first BSSID, and the method optionally includes generating, using the one or more processors, an additional CMIC based on the additional CIGTK associated with the second BSSID, and the header of the control frame includes the additional CMIC.
[0202] Any of the above examples may be combined with any other example (or combination of examples) unless otherwise stated. The foregoing description of one or more implementations provides illustration and description, but is not intended to be exhaustive or to limit the scope of the aspects to the precise form disclosed.
Claims
1. 1. A method of operating a station (STA) to communicate with an access point (AP), the method comprising: receiving a control frame from the AP, the control frame including a control message integrity check (CMIC) shared by multiple basic service set identifiers (BSSIDs) of the AP; attempting, by the STA, to verify the CMIC in the control frame; transmitting, by the STA, an uplink signal to the AP in response to verifying the CMIC in the control frame; A method comprising:
2. The control frame a receiver address (RA) field having a broadcast address; a transmitter address (TA) field indicating the transmitting BSSID of the AP used for management signaling of multiple BSSIDs.
3. 3. The method of claim 2, wherein the control frame comprises a multi-user request-to-send (MU-RTS) frame, and the uplink signal comprises a clear-to-send (CTS) frame with an additional RA field having the transmitting BSSID of the AP that is not associated with any STA served by the AP.
4. 3. The method of claim 2, wherein the control frame comprises a trigger frame and the uplink signal comprises a trigger-based physical protocol data unit (TB PPDU) frame.
5. The method of claim 1 , wherein attempting to verify the CMIC comprises attempting to verify the CMIC based on an encryption group key received from the AP.
6. The method of claim 5 , wherein the cryptographic group key comprises a BSSID-specific control frame integrity group temporal key (CIGTK) associated with a dedicated BSSID of the AP.
7. The method of claim 5 , wherein the cryptographic group key comprises a BSSID-independent control frame integrity group temporal key (CIGTK) shared by at least two BSSIDs of the AP.
8. The method of claim 5 , wherein the cryptographic group key comprises a Beacon Integrity Group Temporal Key (BIGTK) that serves to integrity protect beacon frames transmitted by the AP.
9. receiving a key data element (KDE) in a third message of a handshake procedure between the STA and the AP, the KDE indicating the cryptographic group key; The method of claim 5.
10. The method of claim 5 , wherein the control frame has one or more header fields that indicate the cryptographic group key.
11. 11. The method of claim 10, wherein the one or more header fields comprise a single-bit key type field and a single-bit key identifier field.
12. 1. An electronic device configured to communicate with an access point (AP), the electronic device comprising: a receiver configured to receive a control frame from the AP, the control frame including a first Control Message Integrity Check (CMIC) for a first Basic Service Set Identifier (BSSID) of the AP and a second CMIC for a second BSSID of the AP, wherein the electronic device is associated with the first BSSID but not the second BSSID; one or more processors configured to attempt to verify the first CMIC in the control frame; a transmitter configured to transmit an uplink signal to the AP when the first CMIC in the control frame is successfully verified; An electronic device comprising:
13. The one or more processors: generating a candidate CMIC based on a control frame integrity group temporal key (CIGTK) associated with the first BSSID; comparing the candidate CMIC to the first CMIC in the control frame; 13. The electronic device of claim 12, configured to attempt to verify the first CMIC in the control frame by:
14. 13. The electronic device of claim 12, wherein the control frame comprises a multi-user request-to-send (MU-RTS) frame, and the uplink signal comprises a clear-to-send (CTS) frame having a receiver address field with a third BSSID of the AP that is different from the first BSSID and the second BSSID.
15. 13. The electronic device of claim 12, wherein the control frame comprises a trigger frame and the uplink signal comprises a trigger-based physical protocol data unit (TB PPDU) frame.
16. 1. A method of operating an access point (AP) according to a communication protocol that implements a multiple basic service set identifier (M-BSSID) scheme, the method comprising: generating, by the AP, a control message integrity check (CMIC) based on an encryption key; transmitting, by the AP, a control frame to a first station (STA) associated with a first basic service set identifier (BSSID) of the AP and to a second STA associated with a second BSSID of the AP that is different from the first BSSID; The header of the control frame includes the CMIC and a transmitter address (TA), The TA indicates a third BSSID that is different from the first BSSID and the second BSSID.
17. 17. The method of claim 16, wherein the encryption key comprises a BSSID-specific Control Frame Integrity Group Temporal Key (CIGTK) associated with the third BSSID.
18. 17. The method of claim 16, wherein the encryption key comprises a BSSID-independent control frame integrity group temporal key shared by the first BSSID and the second BSSID.
19. The method of claim 16 , wherein the encryption key comprises a Beacon Integrity Group Temporal Key (BIGTK).
20. The encryption key comprises a BSSID-specific control frame integrity group temporal key (CIGTK) associated with the first BSSID, and the method further comprises:
17. The method of claim 16, further comprising: using the one or more processors to generate an additional CMIC based on an additional CIGTK associated with the second BSSID, wherein the header of the control frame includes the additional CMIC.
Citation Information
Patent Citations
Enhanced beacon frames in wireless communications
US20190200278A1
Implementing wake-up radio (WUR) device communications
US20190208470A1
ACCESS MANAGEMENT TO MULTI-USER UPLINK RANDOM RESOURCE UNITS BY A PLURALITY OF BSSs
US20230422314A1
Device and method for transmitting beacon frame
WO2024071665A1