Protection block acknowledgment mechanism
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-03-23
- Publication Date
- 2026-03-17
AI Technical Summary
Wireless communication systems face challenges in protecting against various types of attacks, such as injecting fake block acknowledgement request frames, injecting false data frames, and replaying data frames with modified sequence numbers, which can disrupt system performance and lead to denial of service.
The proposed solution involves generating a protective frame to update the block acknowledgement (BA) window with an updated start sequence number (SSN) and using additional authentication data (AAD) to encrypt Media Access Control (MAC) protocol data units (MPDUs), thereby protecting against false data frames and replay attacks.
This approach helps prevent disruptions in effective frame delivery, improves system performance by reducing processing overhead, and ensures the integrity and authenticity of data frames in wireless communication systems.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] (CROSS REFERENCE TO RELATED APPLICATIONS) This application claims priority to Indian Patent Application No. 202241022313, filed on April 14, 2022, which is assigned to the assignee of the present application and is expressly incorporated by reference in its entirety as if fully set forth below and for all applicable purposes.
[0002] Certain aspects of the present disclosure relate generally to wireless communications, and more particularly, to protecting various types of messages in wireless networks.
[0003] 2. Description of Related Art Wireless communication networks have been widely deployed to provide various communication services such as voice, video, packet data, messaging, broadcast, etc. These wireless networks may be multiple-access networks capable of supporting multiple users by sharing available network resources. Examples of such multiple-access networks include Code Division Multiple Access (CDMA) networks, Time Division Multiple Access (TDMA) networks, Frequency Division Multiple Access (FDMA) networks, Orthogonal FDMA (OFDMA) networks, and Single Carrier FDMA (SC-FDMA) networks.
[0004] To address the problem of increasing bandwidth requirements for wireless communication systems, various schemes have been developed to enable multiple user terminals to communicate with a single access point by sharing channel resources while achieving high data throughput. Multiple Input Multiple Output (MIMO) technology represents one such approach that has emerged as a popular technology for communication systems. MIMO technology has been adopted in several wireless communication standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard. IEEE 802.11 refers to a set of air interface standards for Wireless Local Area Networks (WLANs) developed by the IEEE 802.11 committee for short-range communication (such as tens of meters to hundreds of meters). Summary of the Invention
[0005] The systems, methods, and devices of the present disclosure each have several innovative aspects, no single aspect of which is solely responsible for the desirable properties disclosed herein.
[0006] Certain aspects of the present disclosure provide a method for wireless communication in a first wireless device. The method generally includes generating a protected frame indicating 1) an updated starting sequence number (SSN) of a block acknowledgment (BA) window and 2) an intended purpose of the protected frame as a request to update the BA window with the updated SSN, outputting the protected frame for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement, generating a plurality of medium access control (MAC) Protocol Data Units (MPDUs) having an SN within the updated BA window, and outputting the plurality of MPDUs for transmission to the second wireless device.
[0007] Certain aspects of the present disclosure provide a method for wireless communication in a second wireless device. The method generally includes acquiring a protected frame from a first wireless device with which the second wireless device has established a protected block acknowledgment (BA) agreement, the protected frame indicating 1) an updated starting sequence number (SSN) of a block acknowledgment (BA) window and 2) an intended purpose of the protected frame as a request to update the BA window with the updated SSN, and maintaining a bitmap to track whether Medium Access Control (MAC) Protocol Data Units (MPDUs) having SNs within the updated BA window were successfully acquired by the second wireless device.
[0008] Certain aspects of the present disclosure provide a method for wireless communication in a wireless device that generally includes acquiring a data frame having a medium access control (MAC) protocol data unit (MPDU) that fails at least one of a decoding check or an integrity check, and in response to the failure, clearing an entry in a bitmap used to track successfully acquired MPDUs by the wireless device or an entry in a bitmap used to track successfully acquired MPDUs by the wireless device that corresponds to the received MPDU.
[0009] Certain aspects of the present disclosure provide a method for wireless communication in a first wireless device. The method generally includes generating a data frame having a medium access control (MAC) protocol data unit (MPDU) encrypted with additional authentication data (AAD) applied to a sequence number (SN) of the MPDU, and outputting the data frame for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement.
[0010] Certain aspects of the present disclosure provide a method for wireless communication in a second wireless device. The method generally includes obtaining a data frame from a first wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement, and extracting a medium access control (MAC) protocol data unit (MPDU) from the data frame based on additional authentication data (AAD) decomposition using a sequence number (SN) of the MPDU.
[0011] Certain aspects of the present disclosure provide a method for wireless communication in a first wireless device. The method generally includes modifying a Medium Access Control (MAC) Protocol Data Unit (MPDU) by performing an operation with a sequence number (SN) of the MPDU to obtain a modified MPDU, generating a data frame having an encrypted version of the modified MPDU, and outputting the data frame for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement.
[0012] Certain aspects of the present disclosure provide a method for wireless communication in a second wireless device. The method generally includes obtaining a data frame having a modified version of a sequence number (SN) of a medium access control (MAC) protocol data unit (MPDU) from a first wireless device with which the second wireless device has established a protected block acknowledgment (BA) agreement, performing a cyclic redundancy check (CRC) test based on the modified version of the MPDU, and if the CRC test passes, performing an operation with the SN to recover an original MPDU from the modified version of the MPDU for which the CRC test passes, and updating a BA bitmap to indicate successful reception of the original MPDU.
[0013] To the accomplishment of the foregoing and related ends, the one or more aspects comprise the features hereinafter fully described and particularly pointed out in the claims. The following description and the annexed drawings set forth in detail certain illustrative features of the one or more aspects. These features are indicative, however, of only a few of the various ways in which the principles of the various aspects may be employed.
[0014] So that the above-mentioned features of the present disclosure may be understood in detail, a more particular description thereof, briefly summarized above, may be had by reference to the embodiments, some of which are illustrated in the accompanying drawings, in which it should be noted, however, that the accompanying drawings illustrate only some typical embodiments of the present disclosure, and that the description may admit of other equally effective embodiments. [Brief description of the drawings]
[0015] [Figure 1] FIG. 1 is a diagram of an example wireless communication network, in accordance with certain aspects of the present disclosure. [Diagram 2] 1 is a block diagram of an example access point (AP) and example wireless stations (STAs) in accordance with certain aspects of the present disclosure. [Diagram 3] FIG. 13 is a call flow diagram illustrating an example block acknowledgment procedure, according to an aspect of the disclosure. [Figure 4] FIG. 2 is a call flow diagram illustrating an example mechanism for protecting against false block acknowledgment requests (BARs), according to an aspect of the disclosure. [Diagram 5] FIG. 1 is a call flow diagram illustrating an example mechanism for protecting against false data frames, according to an aspect of the present disclosure. [Figure 6A] 1 illustrates example logic and example sequence control fields for protecting against false data frames, according to an aspect of the present disclosure. [Figure 6B] 1 illustrates example logic and example sequence control fields for protecting against false data frames, according to an aspect of the present disclosure. [Figure 7] FIG. 1 is a call flow diagram illustrating an example mechanism for protecting against replay of data frames with modified sequence numbers, according to an aspect of the disclosure. [Figure 8] 1 illustrates example logic for protecting against replay of data frames with modified sequence numbers in accordance with an aspect of the present disclosure. [Figure 9]1 illustrates example operations for wireless communication in a wireless device in accordance with certain aspects of the present disclosure. [Figure 10] 1 illustrates example operations for wireless communication in a wireless device in accordance with certain aspects of the present disclosure. [Figure 11] 1 illustrates example operations for wireless communication in a wireless device in accordance with certain aspects of the present disclosure. [Figure 12] 1 illustrates example operations for wireless communication in a wireless device in accordance with certain aspects of the present disclosure. [Figure 13] 1 illustrates example operations for wireless communication in a wireless device in accordance with certain aspects of the present disclosure. [Figure 14] 1 illustrates example operations for wireless communication in a wireless device in accordance with certain aspects of the present disclosure. [Figure 15] 1 illustrates example operations for wireless communication in a wireless device in accordance with certain aspects of the present disclosure. [Figure 16] 1 illustrates exemplary components capable of performing the operations described herein.
[0016] For ease of understanding, the same reference numbers have been used, where possible, to designate identical elements common to the figures, and it is contemplated that elements disclosed in one embodiment may be beneficially utilized on other embodiments without specific recitation. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0017] Aspects of the present disclosure relate generally to wireless communications, and more particularly, to protecting various types of messages in wireless networks.
[0018] There are many different types of attacks that a hostile device (attacker) can perform to cause harm in a wireless network. Examples of such attacks include injecting Block Acknowledgement Request (BAR) frames, injecting fake data frames, and replaying genuine but altered sequence numbers (SN) of data frames.
[0019] Each of these types of attacks can impact system performance not only due to bandwidth consumption, but also processing overhead and potential disruption of delivery of valid frames (denial of service). In some cases, attacks may go undetected, and in such cases may disrupt the scoreboard context maintained at the receiver for packets successfully received by the SN.
[0020] Aspects of the present disclosure propose various mechanisms to protect against these types of attacks, which may help prevent potential disruptions to valid frame delivery and therefore help improve overall system performance.
[0021] Wireless Communication Systems Overview Various aspects of the present disclosure will now be described more fully with reference to the accompanying drawings. However, the present disclosure may be embodied in many different forms and should not be construed as being limited to any specific structure or function presented throughout the present disclosure. Rather, these aspects are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. Based on the teachings herein, those skilled in the art will understand that the scope of the present disclosure is intended to encompass all aspects of the present disclosure disclosed herein, whether implemented independently or in combination with any other aspects of the present disclosure. For example, an apparatus can be implemented or a method can be practiced using any number of the aspects described herein. It is intended that the scope of the present disclosure encompass such an apparatus or method that is implemented using other structure, functionality, or structure and functionality in addition to or other than the various aspects of the present disclosure described herein. It is understood that any aspect of the present disclosure disclosed herein may be embodied by one or more elements of a claim.
[0022] The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any aspect described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other aspects.
[0023] Although specific aspects are described herein, numerous variations and permutations of these aspects fall within the scope of the present disclosure. Although some benefits and advantages of the preferred aspects are described, the scope of the present disclosure is not limited to any particular benefit, application, or purpose. Rather, the aspects of the present disclosure are intended to be broadly applicable to different wireless technologies, system configurations, networks, and transmission protocols, some of which are illustrated by way of example in the figures and the following description of the preferred aspects. The detailed description and drawings are merely illustrative of the present disclosure, rather than limiting, the scope of the present disclosure being defined by the appended claims and their equivalents.
[0024] The techniques described herein can be used for various broadband wireless communication systems, including communication systems based on orthogonal multiplexing schemes. Examples of such communication systems include Spatial Division Multiple Access (SDMA) systems, Time Division Multiple Access (TDMA) systems, Orthogonal Frequency Division Multiple Access (OFDMA) systems, Single-Carrier Frequency Division Multiple Access (SC-FDMA) systems, etc. SDMA systems may utilize sufficiently different directions to simultaneously transmit data belonging to multiple user terminals. TDMA systems allow multiple user terminals to share the same frequency channel by dividing the transmission signal into different time slots, each time slot being assigned to a different user terminal. OFDMA systems utilize Orthogonal Frequency Division Multiplexing (OFDM), a modulation technique that partitions the entire system bandwidth into multiple orthogonal subcarriers. These subcarriers may also be referred to as tones, bins, etc. In OFDM, each subcarrier can be independently modulated with data. An SC-FDMA system may utilize Interleaved FDMA (IFDMA) for transmitting on subcarriers distributed across the system bandwidth, Localized FDMA (LFDMA) for transmitting on blocks of adjacent subcarriers, or Enhanced FDMA (EFDMA) for transmitting on multiple blocks of adjacent subcarriers. In general, modulation symbols are sent with OFDM in the frequency domain and with SC-FDMA in the time domain.
[0025] The teachings herein may be incorporated into (e.g., implemented within or performed by) various wired or wireless devices (e.g., nodes). In some aspects a wireless node implemented in accordance with the teachings herein may comprise an access point or an access terminal.
[0026] An access point ("AP") may comprise, be implemented as, or be known as a Node B, Radio Network Controller ("RNC"), evolved Node B (eNB), base station controller ("BSC"), base transceiver station ("BTS"), base station ("BS"), transceiver function ("TF"), wireless router, wireless transceiver, basic service set ("BSS"), enhanced service set ("ESS"), radio base station ("RBS"), or some other terminology.
[0027] An access terminal ("AT") may comprise, be implemented as, or be known as a subscriber station, subscriber unit, mobile station (MS), remote station, remote terminal, user terminal (UT), user agent, user device, user equipment (UE), user station, or some other terminology. In some implementations, an access terminal may comprise a mobile phone, a cordless phone, a session initiation protocol ("SIP") phone, a wireless local loop ("WLL") station, a personal digital assistant ("PDA"), a handheld device with wireless connectivity, a station ("STA"), or some other suitable processing device connected to a wireless modem. Thus, one or more aspects taught herein may be incorporated into a phone (such as a mobile phone or smartphone), a computer (such as a laptop), a tablet, a portable communication device, a portable computing device (such as a personal data assistant), an entertainment device (such as a music or video device, or satellite radio), a global positioning system (GPS) device, or any other suitable device configured to communicate via a wireless or wired medium. In some aspects, the node is a wireless node. Such a wireless node may, for example, provide connectivity for or to a network (eg, a wide area network such as the Internet or a cellular network) via a wired or wireless communications link.
[0028] Exemplary Wireless Communication System 1 illustrates an example wireless communication system 100 in accordance with certain aspects of the present disclosure. The system 100 may be a multiple-input multiple-output (MIMO) / multi-link operation (MLO) system 100. In an aspect, the AP 110 and the wireless station 120a may be MLDs as further described herein with respect to FIG.
[0029] For simplicity, only one AP 110 is shown in FIG. 1. An AP is generally a fixed station that communicates with wireless STAs and may also be referred to as a base station (BS) or some other terminology. A wireless STA may be fixed or mobile and may also be referred to as a mobile STA, a wireless device, or some other terminology. An AP 110 may communicate with one or more wireless STAs 120 at any given moment on a downlink (DL) and / or an uplink (UL). The DL (i.e., forward link) is the communication link from the AP 110 to the wireless STAs 120, and the UL (i.e., reverse link) is the communication link from the wireless STAs 120 to the AP 110. A wireless STA 120 may also communicate peer-to-peer with another wireless STA 120 via a direct link, such as, for example, a tunneled direct link setup (TDLS). A system controller 130 may be in communication with the access points and may provide coordination and control for the access points.
[0030] Although the following portions of the disclosure describe wireless STAs 120 capable of communicating via spatial division multiple access (SDMA), in some aspects the wireless STAs 120 may also include some wireless STAs 120 that do not support SDMA. Thus, in such aspects, the AP 110 may be configured to communicate with both SDMA and non-SDMA wireless STAs 120. This approach may advantageously allow older version wireless STAs 120 ("legacy" stations) to remain deployed in the enterprise, extending their useful life, while allowing newer SDMA wireless STAs 120 to be introduced accordingly.
[0031] The system 100 employs multiple transmit antennas and multiple receive antennas for data transmission on the DL and UL. apThe set of K selected wireless stations 120 collectively represents the multiple-input for DL transmissions and the multiple-input for UL transmissions. In pure SDMA, if the data symbol streams for the K wireless STAs are not multiplexed in code, frequency, or time by any means, then the N ap ≧K≧1. If the data symbol streams can be multiplexed using TDMA techniques, different code channels with CDMA, disjoint sets of subbands with OFDM, etc., K may be greater than or equal to N ap Each selected wireless STA transmits user-specific data to the access point and / or receives user-specific data from the access point. In general, each selected wireless STA may be connected to one or more antennas (i.e., N sta ≧1). The K selected wireless STAs may have the same number of antennas or different numbers of antennas.
[0032] The system 100 may be a time division duplex (TDD) system or a frequency division duplex (FDD) system. For a TDD system, the DL and UL share the same frequency band. For an FDD system, the DL and UL use different frequency bands. The system 100 may also utilize a single carrier or multiple carriers for transmission. Each wireless STA may be equipped with a single antenna or multiple antennas. The system 100 may also be a TDMA system if the wireless STAs 120 share the same frequency channel by dividing transmission / reception into different time slots, with each time slot being assigned to a different wireless STA 120.
[0033] 2 illustrates a block diagram of an AP 110 and two wireless STAs 120m and 120x in a MIMO / MLO system such as system 100, in accordance with some aspects of the present disclosure. In some aspects, the AP 110 and / or the wireless STAs 120m and 120x can perform various techniques to ensure that non-AP MLDs can receive group-addressed frames.
[0034] The AP110 is ap The wireless STA 120m includes N antennas 224a to 224t. sta,m Equipped with 252ma~252mu antennas, the wireless STA120x supports N sta,x The AP 110 includes antennas 252xa-252xu. The AP 110 is a transmitting entity in DL and a receiving entity in UL. Each wireless STA 120 is a transmitting entity in UL and a receiving entity in DL. As used herein, a "transmitting entity" is an independently operating apparatus or device capable of transmitting data over a wireless channel, and a "receiving entity" is an independently operating apparatus or device capable of receiving data over a wireless channel. The term communication generally refers to transmission, reception, or both. In the following description, the subscript "DL" refers to downlink, the subscript "UL" refers to uplink, and the subscript "DL" refers to uplink. UL N wireless STAs are selected for simultaneous transmission on the uplink, DL N wireless STAs are selected for simultaneous transmission on the downlink, UL is N DL may or may not be equal to N UL and N DL may be a static value or may change for each scheduling interval. Beam-steering or some other spatial processing technique may be used at the access point and the wireless station.
[0035] On the UL, for each wireless STA 120 selected for UL transmission, a transmit (TX) data processor 288 receives traffic data from a data source 286 and control data from the controller 280. The TX data processor 288 processes (e.g., encodes, interleaves, and modulates) the traffic data for the wireless station based on a coding and modulation scheme associated with the rate selected for the wireless STA and provides a data symbol stream. A TX spatial processor 290 performs spatial processing on the data symbol stream and provides Ns ta,m N antennas sta,m Each transceiver (TMTR) 254 receives and processes (e.g., converts to analog, amplifies, filters, and frequency upconverts) a respective transmit symbol stream to generate an uplink signal. sta,m The transceivers 254 are sta,m N for transmission from antennas 252 sta,m UL signals to the AP 110.
[0036] N UL wireless STAs may be scheduled for simultaneous transmission on the uplink, each performing spatial processing on its data symbol stream and transmitting its set of transmit symbol streams on the UL to the AP 110.
[0037] In AP110, N ap The antennas 224a through 224ap transmit all N UL 10, each of which receives UL signals from one or more wireless STAs. Each antenna 224 provides a received signal to a respective transceiver (RCVR) 222. Each transceiver 222 performs processing complementary to that performed by transceiver 254 and provides a received symbol stream. A receive (RX) spatial processor 240 comprises: ap N transceivers 222 apperforming receiver spatial processing on the N received symbol streams; UL The RX data processor 242 provides recovered UL data symbol streams. The receiver spatial processing is performed in accordance with channel correlation matrix inversion (CCMI), minimum mean square error (MMSE), soft interference cancellation (SIC), or some other technique. Each recovered UL data symbol stream is an estimate of the data symbol stream transmitted by a respective wireless station. The RX data processor 242 processes (e.g., demodulates, deinterleaves, and decodes) each recovered uplink data symbol stream in accordance with the rate used for that stream to obtain decoded data. The decoded data for each wireless STA may be provided to a data sink 244 for storage and / or to controller 230 for further processing.
[0038] On the DL, at the AP 110, the TX data processor 210 determines N DL The TX data processor 210 receives traffic data for the N wireless stations from a data source 208, control data from a controller 230, and possibly other data from a scheduler 234. Various types of data may be sent on different transport channels. The TX data processor 210 processes (e.g., encodes, interleaves, and modulates) the traffic data for each wireless station based on the rate selected for that wireless station. ... DL The DL data symbol streams are DL The TX spatial processor 220 provides N DL performing spatial processing (such as precoding or beamforming, as described in this disclosure) on the DL data symbol streams; ap N transmit symbol streams apEach transceiver 222 receives and processes a respective transmit symbol stream to generate a DL signal. ap The transceivers 222 are ap N for transmission from antennas 224 ap The DL signal is provided to the wireless STA.
[0039] In each wireless STA 120, N sta,m The antennas 252 are connected to the access point 110 through ap Each transceiver 254 processes a received signal from an associated antenna 252 and provides a received symbol stream. The RX spatial processor 260 receives N DL signals. sta,m N out of 254 transceivers sta,m The RX data processor 270 performs receiver spatial processing on the received symbol streams and provides a recovered DL data symbol stream to the wireless station. The receiver spatial processing is performed in accordance with CCMI, MMSE, or some other technique. The RX data processor 270 processes (e.g., demodulates, deinterleaves, and decodes) the recovered DL data symbol stream to obtain decoded data for the wireless station.
[0040] In each wireless STA 120, a channel estimator 278 estimates the DL channel response and provides a DL channel estimate, which may include a channel gain estimate, an SNR estimate, a noise variance, etc. Similarly, a channel estimator 228 estimates the UL channel response and provides a UL channel estimate. The controller 280 for each wireless STA typically calculates the downlink channel response matrix H dn,m The controller 230 derives a spatial filter matrix for the wireless station based on the effective UL channel response matrix H up,effThe controller 230 and 280 also control the operation of various processing units in the AP 110 and the wireless STA 120, respectively.
[0041] 3 illustrates various components that may be utilized in a wireless device 302 that may be used in the system 100 according to some aspects of the disclosure. The wireless device 302 is one example of a device that may be configured to implement various methods described herein. The wireless device 302 may be an AP 110 or a user terminal.
[0042] The wireless device 302 may include a processor 304 that controls operation of the wireless device 302. The processor 304 may also be referred to as a central processing unit (CPU). The memory 306 may include both read-only memory (ROM) and random access memory (RAM) and provides instructions and data to the processor 304. A portion of the memory 306 may also include non-volatile random access memory (NVRAM). The processor 304 typically performs logical and arithmetic operations based on program instructions stored in the memory 306. The instructions in the memory 306 may be executable to implement the methods described herein.
[0043] The wireless device 302 may also include a housing 308 that may include a transmitter 310 and a receiver 312 to enable transmission and reception of data between the wireless device 302 and a remote location. The transmitter 310 and receiver 312 may be combined into a transceiver 314. A single or multiple transmit antennas 316 may be attached to the housing 308 and may be electrically coupled to the transceiver 314. The wireless device 302 may also include multiple transmitters, multiple receivers, and multiple transceivers (not shown).
[0044] The wireless device 302 may also include a signal detector 318 that can be used to detect and quantify the level of signals received by the transceiver 314. The signal detector 318 may detect such signals as total energy, energy per subcarrier per symbol, power spectral density, and other signals. The wireless device 302 may also include a digital signal processor (DSP) 320 for use in processing the signals.
[0045] The various components of the wireless device 302 may be coupled together by a bus system 322, which may include a power bus, a control signal bus, and a status signal bus in addition to a data bus.
[0046] Some aspects of the present disclosure are directed to apparatus and techniques for implementing multi-link communication. For example, some aspects provide techniques for managing data flows across multiple links by MLD. Multiple bands can be implemented for a wireless device. For example, a wireless device may support at least one of a 2.4 GHz band, a 5 GHz band, or a 6 GHz band and be capable of operating on two or more links spanning these bands. In multi-link communication, a data flow can be transmitted across multiple radio links that may be associated with different bands.
[0047] Exemplary Block Acknowledgement Mechanism Block Acknowledgement (Block Ack or BA) generally refers to a mechanism for combining the acknowledgements of multiple MPDUs into a single frame. As shown in FIG. 3, a BA session may be established (negotiated) between a transmitting station (originator STA) and a receiving station (receiver STA) through an exchange of BA Addition (ADDBA) request and response frames. In some cases, the originator STA may first verify that the recipient STA has the capability to participate in a secure BA session based on the BA capability bit. Also, note that the originator STA may be an AP or a non-AP device. Similarly, the recipient STA may be an AP or a non-AP device. In other words, each BA session negotiated is for a specific direction (UL or DL) and per TID.
[0048] If the recipient STA has the capability to participate in a secure BA session, the originator STA sends an ADDBA request frame indicating the traffic ID (TID) for which the BA session is being set up. The recipient STA will respond with an ADDBA response frame. The recipient STA has the option to accept or reject the request. If the recipient STA accepts, then a secured BA agreement is said to exist between the originator STA and the recipient STA.
[0049] After a protected or unprotected Block ACK session has been negotiated between an AP and a station, the AP and the WLAN station can participate in a contention-free burst and a block of QoS data frames (MPDUs) can be transmitted from the sender to the receiver. The receiver STA can maintain a scorecard for MPDUs received within a particular window, with bits indicating which MPDUs in a sequence were successfully received.
[0050] An originator requests an acknowledgment of an outstanding QoS data frame by sending a BA request frame. The request can be implicitly carried in the data frame itself (signaled in a field in the MAC header) or the request can be sent as an explicit frame. In a non-protected BA configuration, the originator can send a Block Ack Request (BAR) frame. In response, the recipient STA can send a BA with a bitmap reflecting a scorecard indicating the number of packets successfully received by the AP.
[0051] Exemplary Mechanisms for Protecting Against False BAR Frames BAR frames are control frames, and all control frames are unprotected (or unencrypted). In some cases, a hostile device (attacker) can perform an attack by sending (injecting) a false BAR frame. This type of attack is possible because BAR frames are not protected in conventional wireless systems.
[0052] BAR frames are typically used for two general purposes: the first, as described above, is to obtain ACK information for the previous burst of frames sent in a transmit opportunity (TXOP), and the second, is to clear the receive reordering buffer at the receiver.
[0053] Injection of a fake BAR frame can have the following effects: An attacker can set the Block ACK Start Sequence control subfield in the BAR frame to an arbitrary value. If this kind of attack goes unnoticed, it will disrupt the reordering buffer and scoreboard context at the receiver. This disruption can result in a change in the Start Sequence Number (SSN), creating confusion about what sequence number the receiver should expect next (WinStartB). This can result in a denial of service attack, where an attacker can block the delivery of genuine data frames for a particular TID.
[0054] According to conventional procedures, a STA that has established a protected BA agreement (session) does not use the SSN field in the BAR frame to update WinStartB. Instead, the originator STA sends a protected management frame (i.e., an ADDBA request frame) to update WinStartB. The recipient ignores the other fields of the ADDBA request frame except for the SSN.
[0055] However, this existing procedure creates potential problems because an originator can send an ADDBA request frame to update parameters (such as timeouts) for an existing BA agreement. However, aspects of the present disclosure may address these potential problems by providing a mechanism to distinguish ADDBA request frames sent to advance a window (WinStartB) from ADDBA request frames sent to update parameters. Additionally, aspects of the present disclosure may help alleviate ambiguity regarding whether an ADDBA response frame is required when an ADDBA request is sent to advance a window.
[0056] As shown in Figure 4, some aspects of the present disclosure may help protect against false BARs by establishing a protected BA agreement using a frame that indicates 1) an updated starting sequence number (SSN) of the block acknowledgment (BA) window, and 2) the intended purpose of the protected frame as a request to update the BA window with the updated SSN. There are various options for how this frame may be constructed.
[0057] For example, according to the first option, a new Block ACK action frame may be defined. Defining a new Block ACK action frame may provide a clear separation between the legacy protected BA procedure and the latest procedure proposed herein. Given that typical conventional systems do not implement protected BA frames, such a change (to support this newly defined BA action frame) may not affect devices that are already deployed. If a BA action frame is supported, the new frame may be defined in a manner that provides a clear separation with the legacy BA procedure. This approach may also help to address legacy interoperability cases where some devices are known to inaccurately advertise support for protected BA procedures.
[0058] One potential benefit of this approach is that some implementations may use a separate processing path for handling the (newly defined) frame quickly. Typically, other types of management frames are processed on a slower path (than action frames). Using an ADDBA request frame may force the receiver to use this faster path (because, for example, it may not be able to distinguish ADDBA requests sent for window advancement or parameter updates). Another potential benefit is that this approach may also eliminate the need for an explicit (management) response frame, since this newly defined frame can be processed quickly. This may help ensure that the originator and receiver are in the same state (synchronized) with respect to WinStartO (which generally refers to the lowest sequence number in the SN window) and that WinStartB is synchronized.
[0059] Other potential options for distinguishing ADDBA request frames sent to advance a window (WinStartB) from ADDBA requests sent to update parameters include using an existing field (subfield) within the action field of the ADDBA request frame. For example, the fragment number (Frag Num) could be set to a specific value (e.g., Frag Num=1) as an indication. Another option is to use a field within the frame header of the ADDBA request frame. Because the frame header is processed early, this approach may help the receiver quickly determine the intent of the frame and therefore take a different (faster) path for processing the frame.
[0060] Exemplary Mechanisms for Protecting Against Fake Data Frames In some cases, an attacker may send (inject) a fake data frame, e.g., a data frame with an arbitrary sequence number (SN). In conventional systems, this kind of attack cannot be detected until the decryption / integrity check is performed. Unfortunately, by that time, the scoreboard context (and possibly WinStartR, which defines the start of the SN window) will have been updated.
[0061] Some aspects of the present disclosure may help protect against bogus data frames by having a recipient STA take a particular action in response to receiving a data frame having an MPDU that failed at least one of a decoding or integrity check. As an example, in response to a failure, the recipient may clear an entry in a bitmap used to track MPDUs successfully received by the wireless device, or the recipient may clear an entry in a bitmap used to track MPDUs successfully received by the wireless device that corresponds to the received MPDU.
[0062] If the recipient STA maintains a partial state, then it may clear the BA scoreboard context (if a fake data frame is detected). If the recipient STA maintains a full state, then it may not update the value of WinStartR and may clear the BA scoreboard context for that MPDU if a fake data frame is detected. This approach may require some implementation changes to track MPDUs. Alternatively, the standard could mandate or recommend that STAs negotiating a protection BA shall maintain partial state.
[0063] Exemplary Mechanisms for Protecting Against Replay of Authentic Data Frames In some cases, an attacker may perform an attack by replaying (retransmitting) a genuine data frame. For example, an attacker could record a genuine MPDU (or AMPDU) and replay the recorded (A)MPDU with a modified sequence number (or SN). Since the field carrying the SN is not protected, the attacker would know the real SN. The frame should pass the decoding and integrity checks since it is a replayed frame. As a result, this kind of attack may go unnoticed until a packet number (PN) based replay check is performed. Unfortunately, the PN based replay check is usually performed much later in the processing chain. By this point, the scoreboard context (and possibly WinStartR) will have been updated. This may also result in a false entry in the reordering buffer (and possibly updating WinStartB).
[0064] As illustrated by the call flow diagram 500 of FIG. 5, some aspects of the disclosure may help protect against fake data frames by encrypting an MPDU with Additional Authentication Data (AAD) applied to the MPDU's sequence number (SN). The recipient STA may then extract the MPDU based on AAD decomposition using the MPDU SN. Block diagram 600 of FIG. 6A illustrates how such encryption may be performed using AAD construction logic that takes unmasked SN bits as input. As illustrated by the example field 650 of FIG. 6B, this may be accomplished by unmasking bits in the SN subfield of the MPDU's sequence control (SC) field.
[0065] This approach to protect against replay of genuine data frames with modified SNs may be implemented by mandating SN protection in the protection BA. In some cases, this may include updating the standard to specify that SN bits are not masked during AAD calculation. If partial state is used, then flush the scoreboard context for an error condition (SN check failed).
[0066] As illustrated by the call flow diagram 700 of Figure 7, in some cases, at the originator, before encrypting the MPDU, a portion of the MPDU may be logically XORed with the SN to generate a modified MPDU (denoted as MPDU'). The modified MPDU (MPDU') is then encrypted and passed further down. A CRC is generated based on the encrypted (modified) MPDU and the MAC header (which contains the SN in the sequence control field).
[0067] At the receiving STA, if the SN is changed (i.e., changed by the attack scenario described above), the CRC verification will fail for the received MPDU, and the MPDU will be discarded (not passed further up the chain).
[0068] As shown by process flow diagram 800 of FIG. 8, if the SN is unchanged (i.e., a genuine frame), the CRC check will be successful. Therefore, only if the CRC passes, the SN will be used to recover the original MPDU and passed to the scoreboard context, and a BA will be sent. After MPDU decoding, the SN can be XORed with parts of the MPDU to recover the original (unmodified MPDU) content. The unmodified MPDU can then be passed to a reordering buffer and later processed for a replay check. In this case, the replay check should pass, since the replayed MPDU with the modified SN would not have reached this point in the processing (and would have been discarded after the CRC check failed).
[0069] In some cases, for an MPDU that is successfully decoded and passes the integrity check, if the replay check fails and if the receiver STA maintains partial state, then the receiver STA may not update the value of WinStartB. In this case, the receiver STA may clear the scoreboard context and clear the entry for that MPDU from the reordering buffer. If the receiver STA maintains complete state, then the receiver STA may not update the values of WinStartB and WinStartR. In this case, the receiver STA may clear the scoreboard context for that MPDU and shall clear the entry for that MPDU from the reordering buffer. This approach may include tracking the MPDUs in the scoreboard context and the reordering buffer.
[0070] Aspects of the present disclosure may also help address scenarios in which a transmitter (originator STA) receives an unsolicited BA. According to some aspects, the transmitter may be expected to ignore a BA that arrives unexpectedly (e.g., without receiving any solicitation MPDU from the transmitter SIFS before the BA is received). Ignoring unsolicited BAs in this way may help avoid state confusion at the transmitter.
[0071] Example Operation 9 is a flow diagram illustrating example operations 900 for wireless communication in accordance with certain aspects of the present disclosure. The operations 900 may be performed by a first wireless device, such as, for example, a wireless station (STA).
[0072] The operations 900 begin, at 905, by generating a protected frame indicating 1) an updated starting sequence number (SSN) of a block acknowledgment (BA) window, and 2) an intended purpose of the protected frame as a request to update the BA window with the updated SSN. At 910, a first wireless device for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement with the protected frame. At 915, the first wireless station generates a plurality of medium access control (MAC) protocol data units (MPDUs) having SNs within the updated BA window. At 920, the first wireless station outputs a plurality of MPDUs for transmission to the second wireless device.
[0073] 10 is a flow diagram illustrating example operations 1000 for wireless communication in accordance with certain aspects of the present disclosure. The operations 1000 may be performed, for example, by a second wireless device (e.g., a STA).
[0074] The operations 1000 begin at 1005 by a second wireless device acquiring a protection frame from a first wireless device with which it has established a protection block acknowledgment (BA) agreement, the protection frame indicating 1) an updated starting sequence number (SSN) of the block acknowledgment (BA) window, and 2) the intended purpose of the protection frame as a request to update the BA window with the updated SSN. At 1010, the second wireless device maintains a bitmap to track which medium access control (MAC) protocol data units (MPDUs) having SNs within the updated BA window were successfully acquired by the second wireless device.
[0075] 11 is a flow diagram illustrating example operations 1100 for wireless communication in accordance with certain aspects of the present disclosure. The operations 1100 may be performed, for example, by a wireless device (e.g., a STA).
[0076] The operations 1100 begin by capturing a data frame having a medium access control (MAC) protocol data unit (MPDU) that has failed at least one of a decoding check or an integrity check, at 1105. In response to the failure, at 1110, the wireless device clears an entry in a bitmap used to track MPDUs successfully captured by the wireless device or an entry in a bitmap used to track MPDUs successfully captured by the wireless device that corresponds to the received MPDU.
[0077] 12 is a flow diagram illustrating example operations 1200 for wireless communication in accordance with certain aspects of the present disclosure. The operations 1200 may be performed, for example, by a first wireless device (e.g., a STA).
[0078] The operations 1200 begin, at 1205, by generating a data frame having a medium access control (MAC) protocol data unit (MPDU) encrypted with additional authentication data (AAD) applied to a sequence number (SN) of the MPDU. At 1210, a first wireless device outputs the data frame for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement.
[0079] 13 is a flow diagram illustrating example operations 1300 for wireless communication in accordance with certain aspects of the present disclosure. The operations 1300 may be performed, for example, by a second wireless device (e.g., a STA).
[0080] The operations 1300 begin, at 1305, by obtaining a data frame from a first wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement. At 1310, the second wireless device extracts a medium access control (MAC) protocol data unit (MPDU) from the data frame based on additional authentication data (AAD) decomposition using a sequence number (SN) of the MPDU.
[0081] 14 is a flow diagram illustrating example operations 1400 for wireless communication in accordance with certain aspects of the present disclosure. The operations 1400 may be performed, for example, by a first wireless device (e.g., a STA).
[0082] The operations 1400 begin, at 1405, by modifying an original Medium Access Control (MAC) Protocol Data Unit (MPDU) by performing an operation with a sequence number (SN) of the MPDU to obtain a modified MPDU. At 1410, the first wireless device generates a data frame having an encrypted version of the modified MPDU. At 1415, the first wireless device outputs the data frame for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement.
[0083] 15 is a flow diagram illustrating example operations 1500 for wireless communication according to certain aspects of the present disclosure. The operations 1500 may be performed, for example, by a second wireless device (e.g., a STA).
[0084] The operations 1500 begin, at 1505, by a second wireless device receiving a data frame having a modified version of a medium access control (MAC) protocol data unit (MPDU) sequence number (SN) from a first wireless device with which the second wireless device has established a protected block acknowledgment (BA) agreement. At 1510, the first wireless device performs a cyclic redundancy check (CRC) test based on the modified version of the MPDU. At 1515, if the CRC test passes, the second wireless device performs an operation using the SN to recover the original MPDU from the modified version of the MPDU for which the CRC test passes, and updates the BA bitmap to indicate successful reception of the original MPDU.
[0085] The various operations of the methods described above may be performed by any suitable means capable of performing the corresponding functions, which may include various hardware component(s) or software component(s) including, but not limited to, circuits, application specific integrated circuits (ASICs), or processors, or various hardware module(s) or software module(s). Generally, when operations are illustrated in figures, the operations may have corresponding equivalent means-plus-function components that are similarly numbered.
[0086] Exemplary Devices FIG. 16 illustrates a communications device 1600 that may include various components operable, configured, or adapted (e.g., corresponding to means-plus-function components) to perform operations for the techniques disclosed herein, such as those illustrated in FIGS. 9-15.
[0087] The communications device 1600 includes a processing system 1602 coupled to a transceiver 1608 (e.g., a transmitter or receiver). The transceiver 1608 is configured to transmit and receive signals for the communications device 1600, such as various signals as described herein, via an antenna 1610. The processing system 1602 may be configured to perform processing functions for the communications device 1600, including processing signals received by or to be transmitted by the communications device 1600.
[0088] The processing system 1602 includes a processor 1604 coupled to a computer-readable medium / memory 1612 via a bus 1606. In some aspects, the computer-readable medium / memory 1612 is configured to store instructions (e.g., computer-executable code) that, when executed by the processor 1604, cause the processor 1604 to perform the operations illustrated in FIGS. 9-15 or other operations for implementing various techniques described herein.
[0089] In some aspects, computer readable medium / memory 1612 stores code for outputting 1614 (e.g., an example of a means for outputting), code for obtaining 1615 (e.g., an example of a means for obtaining), code for maintaining 1616 (e.g., an example of a means for maintaining), code for generating 1617 (e.g., an example of a means for generating), code for extracting 1618 (e.g., an example of a means for extracting), and code for modifying 1619 (e.g., an example of a means for modifying).
[0090] In some aspects, the processor 1604 has circuitry configured to execute code stored in the computer readable medium / memory 1612. The processor 1604 includes circuitry for outputting 1624 (e.g., an example of a means for outputting), circuitry for obtaining 1625 (e.g., an example of a means for obtaining), code for generating 1626 (e.g., an example of a means for generating), code for extracting 1627 (e.g., an example of a means for extracting), and circuitry for modifying 1630 (e.g., an example of a means for modifying).
[0091] The transceiver 1608 may provide a means for receiving information, such as packets, user data, or control information associated with various information channels (control channel, data channel, etc.). The information may be passed to other components of the device 1600. The transceiver 1608 may be an embodiment of an aspect of the transceiver 254 described with reference to FIG. 2. The antenna 1610 may correspond to a single antenna or a set of antennas. The transceiver 1608 may provide a means for transmitting signals generated by other components of the device 1600.
[0092] In some cases, a device may have an interface (means for outputting) for outputting a frame for transmission, rather than actually transmitting the frame. For example, a processor may output a frame to a radio frequency (RF) front end for transmission via a bus interface. Similarly, a device may have an interface (means for acquiring) for acquiring a frame received from another device, rather than actually receiving the frame. For example, a processor may acquire (or receive) a frame from an RF front end for reception via a bus interface. In some cases, the interface for outputting a frame for transmission and the interface for acquiring a frame (sometimes referred to herein as a first and second interface) may be the same interface.
[0093] The means for establishing, maintaining, generating, extracting, and / or modifying may include any of the various processors and / or transceivers shown in FIG. 2 or FIG. 16.
[0094] Exemplary Aspects Example implementations are described in the following numbered embodiments.
[0095] Aspect 1. A method for wireless communications in a first wireless device, the method including: generating a protection frame indicating 1) an updated starting sequence number (SSN) of a block acknowledgment (BA) window and 2) an intended purpose of the protection frame as a request to update the BA window with the updated SSN; outputting the protection frame for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement; generating a plurality of medium access control (MAC) protocol data units (MPDUs) having SNs within the updated BA window; and outputting the plurality of MPDUs for transmission to the second wireless device.
[0096] Aspect 2. The method of aspect 1, further comprising: outputting an MPDU indicating a BA request for transmission to the second wireless device; and, in response to the request, obtaining a BA from the second wireless device indicating which of the MPDUs within the updated BA window were successfully received by the second wireless device.
[0097] Aspect 3. The method of any of aspects 1 or 2, wherein the protection frame includes a BA action frame designed to update a BA window.
[0098] Aspect 4. The method of aspect 3, wherein the protected frame indicates an intended purpose via at least one of a category field or a BA action field of the protected frame.
[0099] Aspect 5. The method of any one of aspects 1 to 4, further comprising obtaining an acknowledgment of the protection frame from the second wireless device.
[0100] Aspect 6. The method of any one of aspects 1 to 5, wherein the protection frame comprises an add BA (ADDBA) request frame.
[0101] Aspect 7. The method of aspect 6, wherein the protected frame includes a field that is set to a specific value to indicate an intended purpose.
[0102] Aspect 8. The method of aspect 7, wherein the field is in a frame header of the ADDBA request frame.
[0103] Aspect 9. A method for wireless communications in a second wireless device, the method including: acquiring a protection frame from a first wireless device with which the second wireless device has established a protected block acknowledgment (BA) agreement, the protection frame indicating 1) an updated starting sequence number (SSN) of a block acknowledgment (BA) window and 2) an intended purpose of the protection frame as a request to update the BA window with the updated SSN; and maintaining a bitmap to track medium access control (MAC) protocol data units (MPDUs) having an SN within the updated BA window that was successfully acquired by the second wireless device.
[0104] Aspect 10. The method of aspect 9, further comprising: acquiring a BA request from the first wireless device; and outputting, for transmission to the first wireless device, an MPDU indicating a BA indicating which of the MPDUs within the updated BA window were successfully acquired by the second wireless device according to the bitmap.
[0105] Example 11. The method of any of examples 9 or 10, wherein the protection frame includes a BA action frame designed to update the BA window.
[0106] Aspect 12. The method of aspect 11, wherein the protected frame indicates an intended purpose via at least one of a category field or a BA action field of the protected frame.
[0107] Example 13. The method of any one of Examples 9 to 12, further comprising outputting an acknowledgment of the protected frame for transmission to the first wireless device.
[0108] Example 14. The method of any one of examples 9 to 13, wherein the protection frame comprises an add BA (ADDBA) request frame.
[0109] Aspect 15. The method of aspect 14, wherein the protection request frame includes a field set to a specific value to indicate an intended purpose.
[0110] Aspect 16. The method of aspect 15, wherein the field is in a frame header of the ADDBA request frame.
[0111] Aspect 17. A method for wireless communications in a wireless device, the method including: acquiring a data frame having a medium access control (MAC) protocol data unit (MPDU) that fails at least one of a decoding check or an integrity check; and in response to the failure, clearing an entry in a bitmap used to track MPDUs successfully acquired by the wireless device, or an entry in a bitmap used to track MPDUs successfully acquired by the wireless device that corresponds to the received MPDU.
[0112] Aspect 18. The method of aspect 17, further comprising maintaining partial state information, wherein a bitmap for a particular traffic ID (TID) is maintained only for a limited amount of time. A current transmit opportunity (TXOP).
[0113] Aspect 19. The method of any of aspects 17 or 18, further comprising maintaining full state information, where bitmaps for different traffic types are maintained until an associated block acknowledgment (BA) session is terminated, the bitmap being for a session corresponding to an MPDU that failed at least one of a decoding check or an integrity check, and clearing comprises clearing the bitmap.
[0114] Aspect 20. The method of aspect 19, wherein the wireless device maintains a current value for a parameter representing the position of the lowest sequence number in the bitmap after clearing the bitmap.
[0115] Aspect 21. A method for wireless communication in a first wireless device, the method including: modifying an original Medium Access Control (MAC) Protocol Data Unit (MPDU) by performing an operation with a sequence number (SN) of the MPDU to obtain a modified MPDU; generating a data frame having an encrypted version of the modified MPDU; and outputting the data frame for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement.
[0116] Aspect 22. The method of aspect 21, wherein modifying the original MPDU by performing an operation with the SN includes performing a logical operation with the portion of the original MPDU and the SN.
[0117] Aspect 23. The method of any of aspects 21 or 22, wherein the data frame includes a cyclic redundancy check (CRC) value generated based on an encrypted version of the modified MPDU and a MAC header.
[0118] Aspect 24. A method for wireless communications in a second wireless device, the method including: obtaining a data frame having a sequence number (SN) of a modified version of a medium access control (MAC) protocol data unit (MPDU) from a first wireless device with which the second wireless device has established a protected block acknowledgment (BA) agreement; performing a cyclic redundancy check (CRC) test based on the modified version of the MPDU; and, if the CRC test passes, performing an operation using the SN to recover an original MPDU from the modified version of the MPDU if the CRC test passes; and updating a BA bitmap to indicate successful reception of the original MPDU.
[0119] Aspect 25. The method of aspect 24, wherein performing an operation using the SN to recover the original MPDU includes performing a logical operation using the portion of the modified version of the MPDU and the SN.
[0120] Aspect 26. The method of any of aspects 24 or 25, further comprising passing the original version of the MPDU to a reordering buffer if the CRC test passes.
[0121] Aspect 27. A method for wireless communication in a first wireless device, the method including: generating a data frame having a medium access control (MAC) protocol data unit (MPDU) encrypted with additional authentication data (AAD) applied to a sequence number (SN) of the MPDU; and outputting the data frame for transmission to a second wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement.
[0122] Aspect 28. A method for wireless communication in a second wireless device, the method including: obtaining a data frame from a first wireless device with which the first wireless device has established a protected block acknowledgment (BA) agreement; and extracting a medium access control (MAC) protocol data unit (MPDU) from the data frame based on additional authentication data (AAD) decomposition using a sequence number (SN) of the MPDU.
[0123] Aspect 29. A method for wireless communication in a first wireless device, the method including: obtaining an unsolicited block acknowledgment (BA) frame from a second wireless device; and ignoring the unsolicited BA frame.
[0124] Aspect 30. The method of aspect 29, wherein the unsolicited BA frame is acquired regardless of the first wireless device outputting a request frame for transmission a short inter-frame space (SIFS) prior to acquiring the unsolicited BA.
[0125] Aspect 31. An apparatus for wireless communication, comprising: a memory including instructions; and one or more processors configured to execute the instructions and cause the apparatus to perform a method as described in any one of aspects 1 to 30.
[0126] Example 32. An apparatus for wireless communication, comprising means for performing the method of any one of examples 1 to 30.
[0127] Aspect 33. A non-transitory computer-readable medium comprising instructions that, when executed by an apparatus, cause the apparatus to perform a method according to any one of aspects 1 to 30.
[0128] Aspect 34. A wireless device comprising at least one transceiver, a memory including instructions, and one or more processors configured to execute the instructions and cause the wireless device to perform a method according to any one of aspects 1 to 8, wherein the at least one transceiver is configured to transmit a protected frame and a plurality of MPDUs.
[0129] Aspect 35. A wireless device comprising at least one transceiver, a memory including instructions, and one or more processors configured to execute the instructions and cause the wireless device to perform a method described in any one of aspects 9 to 16, wherein the at least one transceiver is configured to receive a protection frame.
[0130] Aspect 36. A wireless device comprising at least one transceiver, a memory including instructions, and one or more processors configured to execute the instructions and cause the wireless device to perform a method described in any one of aspects 17 to 20, wherein the at least one transceiver is configured to receive data frames.
[0131] Aspect 37. A wireless device comprising at least one transceiver, a memory including instructions, and one or more processors configured to execute the instructions and cause the wireless device to perform a method described in any one of aspects 21 to 23, wherein the at least one transceiver is configured to transmit data frames.
[0132] Aspect 38: A wireless device comprising at least one transceiver, a memory including instructions, and one or more processors configured to execute the instructions and cause the wireless device to perform a method described in any one of aspects 24 to 26, wherein the at least one transceiver is configured to receive data frames.
[0133] Aspect 39. A wireless device comprising at least one transceiver, a memory including instructions, and one or more processors configured to execute the instructions and cause the wireless device to perform a method according to any one of aspects 27, wherein the at least one transceiver is configured to transmit data frames.
[0134] Aspect 40. A wireless device comprising at least one transceiver, a memory including instructions, and one or more processors configured to execute the instructions and cause the wireless device to perform a method according to any one of aspects 28, wherein the at least one transceiver is configured to receive data frames.
[0135] Aspect 41. A wireless device comprising at least one transceiver, a memory containing instructions, and one or more processors configured to execute the instructions and cause the wireless device to perform a method described in any one of aspects 29, wherein the at least one transceiver is configured to receive an unsolicited BA frame.
[0136] Additional Considerations As used herein, the term "determining" encompasses a wide variety of actions. For example, "determining" can include calculating, computing, processing, deriving, investigating, searching (such as searching a table, database, or another data structure), ascertaining, and the like. Also, "determining" can include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), and the like. Also, "determining" can include resolving, selecting, electing, establishing, and the like.
[0137] As used herein, a phrase referring to "at least one of" a list of items refers to any combination of those items, including single members. As an example, "at least one of a, b, or c" is intended to include a, b, c, ab, ac, bc, and abc.
[0138] The various example logic, logic blocks, modules, circuits, and algorithmic processes described in connection with the implementations disclosed herein may be implemented as electronic hardware, computer software, or a combination of both. Interchangeability between hardware and software has been described generally in terms of functionality and illustrated in the various example components, blocks, modules, circuits, and processes above. Whether such functionality is implemented in hardware or software depends on the particular application and design constraints imposed on the overall system.
[0139] The hardware and data processing devices used to implement the various example logic, logic blocks, modules, and circuits described in connection with the aspects disclosed herein may be implemented or performed using general purpose single-chip or multi-chip processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, or any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. In some implementations, certain processes and methods may be performed by circuitry specific to a given function.
[0140] In one or more aspects, the functions described may be implemented in hardware, digital electronic circuitry, computer software, firmware, or any combination thereof, including the structures disclosed herein and their structural equivalents. Implementations of the subject matter described herein may also be implemented as one or more computer programs, i.e., as one or more modules of computer program instructions encoded on a computer storage medium for execution by or to control the operation of a data processing apparatus.
[0141] If implemented in software, the functions may be stored on or transmitted over a computer-readable medium as one or more instructions or code. The processes of the methods or algorithms disclosed herein may be implemented in processor-executable software modules that may reside on a computer-readable medium. Computer-readable media includes both computer storage media and communication media, including any medium that may enable a computer program to be transferred from one place to another. A storage medium may be any available medium that can be accessed by a computer. By way of example, and not limitation, such computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection may be properly termed a computer-readable medium. Disk and disc as used herein include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc, where disks typically reproduce data magnetically while discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer readable media. Additionally, operations of a method or algorithm may reside on machine readable and computer readable media, which may be embodied in a computer program product as one or any combination or set of code and instructions.
[0142] Various modifications to the implementations described in this disclosure may be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other implementations without departing from the spirit or scope of the present disclosure. Thus, the claims are not intended to be limited to the implementations shown herein, but are to be accorded the widest scope consistent with this disclosure, the principles and novel features disclosed herein.
[0143] Some features described in the context of separate implementations may also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation may also be implemented separately in multiple implementations or in any suitable subcombination. Furthermore, although features may be described above as working in some combinations and may even initially be claimed as such, one or more features from a claimed combination may, in some cases, be deleted from the combination, and the claimed combination may be directed to a subcombination or a variation of the subcombination.
[0144] Similarly, although operations are shown in the figures in a particular order, this should not be understood as requiring such operations to be performed in the particular order or sequential order shown, or that all of the operations shown be performed, to achieve desirable results. Furthermore, the figures may generally depict one or more exemplary processes in the form of a flow diagram. However, other operations not shown may be incorporated into the exemplary process depicted in the schematic. For example, one or more additional operations may be performed before, after, simultaneously with, or between any of the depicted operations. In some circumstances, multitasking and parallel processing may be advantageous. Moreover, the separation of various system components in the above implementations should not be understood as requiring such separation in all implementations, and it should be understood that the described program components and systems may generally be integrated together in a single software product or packaged in multiple software products. In addition, other implementations are within the scope of the following claims. In some cases, the actions recited in the claims may be performed in a different order and still achieve desirable results.
Claims
1. A device for wireless communication, Memory containing instructions, One or more processors, which execute the instructions and provide the device, To generate a protection frame that indicates: 1) the updated start sequence number (SSN) of the block acknowledgment (BA) window, and 2) the intended purpose of the protection frame as a request to update the BA window with the updated SSN, The device outputs the protection frame for transmission to a wireless device with which a protection block acknowledgment (BA) agreement has been established. The updated BA window generates multiple Media Access Control (MAC) protocol data units (MPDUs) having SNs, To transmit to the aforementioned wireless device, the multiple MPDUs are made to output, One or more processors configured as such, A device equipped with the following features.
2. The one or more processors execute the instruction and the device, To transmit to the aforementioned wireless device, an MPDU is output that instructs a BA request. The apparatus according to claim 1, further configured to cause the wireless device to obtain a BA indicating which of the plurality of MPDUs in the updated BA window was successfully received by the wireless device in response to the aforementioned request.
3. The apparatus according to claim 1, wherein the protective frame includes a BA action frame designed to update the BA window.
4. The apparatus according to claim 3, wherein the protective frame indicates the intended purpose via at least one of the category field or BA action field of the protective frame.
5. The apparatus according to claim 1, wherein the one or more processors are further configured to execute the instructions and cause the apparatus to obtain an acknowledgment of the protection frame from the wireless device.
6. The protection frame includes a BA addition (ADDBA) request frame, preferably, The protective frame includes fields set to specific values to indicate the intended purpose, more preferably, The apparatus according to claim 1, wherein the field is located in the frame header of the ADDBA request frame.
7. The apparatus according to claim 1, further comprising at least one transceiver configured to transmit the protective frame and the plurality of MPDUs, wherein the apparatus is configured as a wireless device.
8. A method performed by a device for wireless communication, The steps of generating a protection frame that indicates: 1) an updated start sequence number (SSN) of a block acknowledgment (BA) window, and 2) the intended purpose of the protection frame as a request to update the BA window with the updated SSN; The steps include: outputting the protection frame for transmission to a wireless device with which the device has established a protection block acknowledgment (BA) agreement; The steps include generating a plurality of media access control (MAC) protocol data units (MPDUs) having SNs within the updated BA window, The step includes outputting the plurality of MPDUs for transmission to the wireless device. method.
9. A device for wireless communication, Memory containing instructions, One or more processors, which execute the instructions and provide the device, The device causes the wireless device with which a protective block acknowledgment (BA) agreement has been established to obtain a protective frame indicating: 1) the updated start sequence number (SSN) of the block acknowledgment (BA) window, and 2) the intended purpose of the protective frame as a request to update the BA window with the updated SSN. One or more processors configured to maintain a bitmap for tracking multiple media access control (MAC) protocol data units (MPDUs) having SNs within the updated BA window successfully acquired by the device, A device equipped with the following features.
10. The one or more processors execute the instruction and the device, The wireless device is made to obtain a BA request. The apparatus according to claim 9, further configured to output an MPDU for transmission to the wireless device, which indicates a BA indicating which of the plurality of MPDUs in the updated BA window was successfully acquired by the apparatus, according to the bitmap.
11. The protective frame includes a BA action frame designed to update the BA window, preferably, The apparatus according to claim 9, wherein the protective frame indicates the intended purpose via at least one of the category field or BA action field of the protective frame.
12. The apparatus according to claim 9, wherein the one or more processors are further configured to execute the instruction and cause the apparatus to output an acknowledgment of the protection frame for transmission to the apparatus.
13. The protection frame includes a BA addition (ADDBA) request frame, preferably, The ADDBA request frame includes a field set to a specific value to indicate the intended purpose, more preferably, The apparatus according to claim 9, wherein the field is located in the frame header of the ADDBA request frame.
14. The apparatus according to claim 9, further comprising at least one transceiver configured to receive the protective frame, wherein the apparatus is configured as a wireless device.
15. A method performed by a device for wireless communication, The steps include: obtaining a protection frame from a wireless device with which the device has established a protection block acknowledgment (BA) agreement, which indicates: 1) an updated start sequence number (SSN) of the block acknowledgment (BA) window; and 2) the intended purpose of the protection frame as a request to update the BA window with the updated SSN; The device has a bitmap for tracking a plurality of media access control (MAC) protocol data units (MPDUs) having SNs within the updated BA window successfully acquired by the device. method.