Securing frames using integrity protection and encryption
Securing frames with a security key identifier, packet number, and integrity check validates and encrypts control information, addressing attacks and ensuring efficient, secure wireless communications.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2026-03-10
AI Technical Summary
Malicious actors can attack wireless communications by targeting frames containing control information, leading to denial of service, power consumption, and waste of radio frequency resources, particularly in ultra-high reliability (UHR) communications.
Frames are secured with a security key identifier, packet number, and integrity check, where the integrity check is calculated based on the frame's content and security key, allowing receivers to validate the frame's authenticity and discard invalid or tampered frames.
This approach enhances security by quickly validating control frames, preventing power waste and resource misuse, while being backward compatible with existing devices, and protecting user privacy by encrypting MAC headers.
Smart Images

Figure 2026508201000001_ABST
Abstract
Description
[Technical Field]
[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS)
[0001] This application claims priority to U.S. Patent Application No. 18 / 365,946, filed August 4, 2023, which claims the benefit of and priority to U.S. Provisional Patent Application No. 63 / 487,879, filed March 1, 2023, and U.S. Provisional Patent Application No. 63 / 504,189, filed May 24, 2023, which are assigned to the assignee of the present application and are expressly incorporated by reference in their entireties as if fully set forth below and for all applicable purposes.
[0002] FIELD OF THE DISCLOSURE
[0002] The present disclosure relates generally to wireless communications, and more particularly to securing frames, especially frames that contain control information. [Background technology]
[0003]
[0003] A wireless local area network (WLAN) may be formed by one or more wireless access points (APs) that provide a shared wireless communication medium for use by multiple client devices, also referred to as wireless stations (STAs) or user equipments (UEs). The basic building block of a WLAN conforming to the Institute of Electrical and Electronics Engineers (IEEE) 802.11 family of standards is the Basic Service Set (BSS) managed by the AP. Each BSS is identified by a Basic Service Set Identifier (BSSID) advertised by the AP. The AP periodically broadcasts beacon frames to enable any STA within wireless range of the AP to establish or maintain a communication link with the WLAN.
[0004] In some WLANs, APs and STAs may engage in reliable communications, e.g., ultra-high reliability (UHR) communications. UHR communications may rely on the transmission of control information for many purposes, such as acknowledgments, network allocation vector (NAV) settings, sounding, triggers, crosslink control signaling, etc.
[0005] Malicious actors may attack wireless communications by targeting frames containing control information. Such attacks may result in denial of service, power consumption at UEs, unreliable communications, and waste of radio frequency resources. Summary of the Invention
[0006]
[0006] The systems, methods, and devices disclosed herein each have several innovative aspects, no single aspect of which is solely responsible for the desirable attributes disclosed herein.
[0007] One innovative aspect of the subject matter described in this disclosure can be implemented in a wireless communication device including: a memory including instructions; and one or more processors, the one or more processors configured to execute the instructions to cause a device to generate a frame including a security key identifier (ID), a packet number (PN), and an integrity check; and output the frame for transmission, the frame including the security key identifier, a packet number (PN), and an integrity check, the integrity check being based on one or more portions of the frame, and the generating including calculating the integrity check based at least on the security key.
[0008] Another innovative aspect of the subject matter described in this disclosure can be implemented in a wireless communication device. The wireless communication device includes a memory including instructions and one or more processors, the one or more processors configured to execute the instructions to cause a device to obtain a frame including a security key identifier (ID), a packet number (PN), and an integrity check, and to verify the validity of the frame based on a comparison of the integrity check to another integrity check that is based on at least the security key and one or more portions of the frame.
[0009] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications. The method includes generating a frame including a security key identifier (ID), a packet number (PN), and an integrity check, where the integrity check is based on one or more portions of the frame, and where generating includes calculating the integrity check based at least on the security key; and transmitting the frame.
[0010] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communication that includes obtaining a frame that includes a security key identifier (ID), a packet number (PN), and an integrity check, and responding to the frame based on a comparison of the integrity check with another integrity check that is based on at least the security key and one or more portions of the frame.
[0011]
[0011] The details of one or more implementations of the subject matter described in this disclosure are set forth in the accompanying drawings and the following description. Other features, aspects, and advantages will become apparent from the description, drawings, and claims. Please note that the relative dimensions of the following figures may not be drawn to scale. [Brief explanation of the drawings]
[0012] [Figure 1]
[0012] A pictorial diagram of an exemplary wireless communication network is shown. [Figure 2AB]
[0013] FIG. 2A shows a trigger frame in block form.
[0014] FIG. 2B illustrates a set of trigger-based communications. [Figure 3AB]
[0015] 3A and 3B show exemplary control message integrity check (MIC) fields (CMFs). [Figure 4]
[0016] 1 illustrates an exemplary secure trigger frame. [Figure 5]
[0017] 10 illustrates an embodiment of incorporating a CMF within the user information list field of a trigger frame. [Figure 6]
[0018] 1 illustrates an exemplary secure null data packet (NDP) announcement frame. [Figure 7]
[0019] 10 illustrates an embodiment of incorporating a CMF within the STA information list field of an NDP announcement frame. [Figure 8]
[0020] 1 illustrates an exemplary secure multi-station block acknowledgment (M-BA) frame. [Figure 9]
[0021] 10 illustrates an embodiment of incorporating a CMF within the Per AID TID information field of a secure M-BA frame. [Figure 10]
[0022] 1 illustrates an exemplary secure multiple traffic identifier (multi-TID) block acknowledgment request (BAR) frame. [Figure 11]
[0023] 1 illustrates an exemplary medium access control (MAC) protocol data unit (PDU) in accordance with certain aspects of the present disclosure. [Figure 12]
[0024] 1 illustrates an exemplary algorithm for encrypting data in a MAC PDU (MPDU) according to prior art known techniques. [Figure 13]
[0025] 1 illustrates an exemplary algorithm for encrypting and protecting MAC header fields for individually addressed quality of service (QoS) data frames or management frames. [Figure 14]
[0026] 1 illustrates an exemplary algorithm for encrypting and protecting MAC header fields for QoS Null frames, Retry QoS Data frames, or Management frames. [Figure 15]
[0027] 1 illustrates one embodiment incorporating a header protection (HDR PRO) field within the MPDU. [Figure 16]
[0028] 1 is an exemplary call flow illustrating communication between an AP, a UHR STA, a non-UHR STA, and an attacker device. [Figure 17]
[0029] 1 shows a flowchart illustrating an exemplary process that may be performed by a wireless transmitter to support frame security. [Figure 18]
[0030] 1 shows a flowchart illustrating an exemplary process that can be performed by a wireless receiver to support frame security. [Figure 19]
[0031] 1 is a block diagram of an exemplary access point (AP) and exemplary wireless stations (STAs) in accordance with certain aspects of the present disclosure. [Figure 20]
[0032] 1 illustrates a block diagram of an example wireless communication device that supports frame security. [Figure 21]
[0033] 1 illustrates a block diagram of an example wireless communication device that supports frame security.
[0013]
[0034] Like reference numbers and designations in the various drawings indicate like elements. DETAILED DESCRIPTION OF THE INVENTION
[0014]
[0035] The following description is directed to several specific examples for purposes of illustrating innovative aspects of the present disclosure. However, those skilled in the art will readily recognize that the teachings herein can be applied in many different ways. Some or all of the described examples may be implemented in accordance with, among other standards, the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, the IEEE 802.15 standard, the Bluetooth® standard as defined by the Bluetooth Special Interest Group (SIG), or the Third Generation Partnership Project (3GPP). rdThe present invention may be implemented in any device, system, or network capable of transmitting and receiving radio frequency (RF) signals in accordance with one or more of the Long Term Evolution (LTE), 3G, 4G, or 5G (New Radio (NR)) standards promulgated by the Third Generation Partnership Project (3GPP). The described embodiments may be implemented in any device, system, or network capable of transmitting and receiving RF signals according to one or more of the following techniques: code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), spatial division multiple access (SDMA), rate-splitting multiple access (RSMA), multi-user shared access (MUSA), single-user (SU) multiple-input multiple-output (MIMO), and multi-user (MU)-MIMO.The described embodiments may also be implemented using other wireless communication protocols or RF signals suitable for use in one or more of a wireless personal area network (WPAN), a wireless local area network (WLAN), a wireless wide area network (WWAN), a wireless metropolitan area network (WMAN), or an internet of things (IOT) network.
[0015]
[0036] Various aspects relate generally to securing frames, particularly frames containing control information. In some embodiments, a frame is transmitted with a field containing a security key identifier (ID), at least a portion of a packet number (PN), and at least a portion of an integrity check calculated based on one or more portions of the frame containing control information and the security key. The security key may be a temporal key used for control packets, sometimes referred to as an integrity group temporal key (IGTK), a pairwise temporal key (PTK), or a control integrity temporal key (CIGTK). Such a CIGTK may be shared between the AP and the authenticated STA during or after authentication. The packet number may be an IGTK packet number or an integrity pairwise temporal key (IPTK) packet number. In some cases, the frame may include only a portion of the complete PN, e.g., the two least significant octets of the complete PN, and the remaining portion of the complete PN may be exchanged periodically or separately between devices via encrypted management frames. In some cases, the frame may include only a portion of the calculated integrity check, e.g., the four least significant octets.
[0016]
[0037] In some embodiments, the frame may be a trigger frame, a null data packet (NDP) announcement frame, a multi-station block acknowledgment (M-BA) frame, a compressed block Ack frame, a block acknowledgment request (BAR) frame, or another type of control frame. In various frames, the ID, PN, and integrity check may be included in the frame's information field, including reserved values, or in the frame's padding. A receiver receiving such a frame can validate the frame by computing an integrity check for the frame using a security key identified by the ID included in the frame and comparing the computed integrity check with the integrity check included in the frame. Furthermore, a receiver receiving such a frame can verify that the frame is not a replay of a frame already received by the receiver by checking that the PN of the frame is an expected PN, such as the next PN in a sequence.
[0017]
[0038] In certain Wi-Fi communication systems, the MAC header of a MAC PDU (also referred to as an MPDU, MAC frame, or packet) is not encrypted, and therefore the unencrypted MAC header is transmitted along with the encrypted data of the MAC PDU. In such cases, portions of some fields of the MAC header may be protected from tampering by being included in additional authenticated data (AAD) of the MPDU. If an attacker attempts to tamper with some of the fields included in the AAD of a transmitted MPDU, or while transmitting a repeat of the MPDU (e.g., an attack frame), the receiver can detect those changes and reject (e.g., discard) the frame.
[0018]
[0039] Because certain Wi-Fi communication systems do not encrypt the headers of MPDUs, the headers of MPDUs sent by a STA may be used to track the activity of the STA. For example, a STA's participation in a video call over a Wi-Fi network may be tracked, and other activity by the same STA may also be linked to the STA.
[0019]
[0040] Certain aspects of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages: In some embodiments, by validating control frames, a UE can avoid wasting power and radio frequency resources if the UE receives an invalid control frame from an attacker. Furthermore, in contrast to some techniques in which large portions of a frame are encrypted, causing the device to spend a significant amount of time decrypting portions of the frame, the described techniques can be used to quickly validate control frames, allowing the device to respond to the control frame quickly. If an attacker repeats a control frame, the receiver will discard the repetition because the packet number will not match the expected packet number. If an attacker modifies data in a legitimate control frame, the receiver will discard the modified frame because the integrity check it calculates will not match the integrity check in the received frame. If an attacker attempts to send a frame masquerading as the controller, the receiver will discard the frame because the included integrity check will not match the integrity check calculated by the receiver because the attacker does not have the same security key. If an attacker copies the Control Message Integrity Check (MIC) field (CMF) from a legitimate frame into another frame, the receiver will discard the frame because the packet number is not what is expected at the receiver or the included integrity check does not match the integrity check calculated by the receiver. The techniques described herein also have the advantage of being backward compatible, so that devices not programmed to use the described techniques can still successfully receive and respond to frames containing the ID, PN, and integrity check.
[0020]
[0041] Aspects of the present disclosure provide a method and apparatus for encrypting a MAC header of an MPDU transmitted by a node (e.g., an AP or a STA) and for a receiving node to decrypt the MAC header. By encrypting the header of the MPDU, the privacy of a user of the node transmitting or receiving the MAC PDU can be protected.
[0021]
[0042] The teachings herein may be incorporated into (e.g., implemented within or performed by) various wired or wireless devices (e.g., nodes). In some aspects, a wireless node implemented in accordance with the teachings herein may include an access point (AP) or an access terminal (AT).
[0022]
[0043] An AP may include, be implemented as, or be known as a Node B (NB), radio network controller (RNC), evolved Node B (eNB), base station controller (BSC), base transceiver station (BTS), base station (BS), transceiver function (TF), wireless router, wireless transceiver, basic service set (BSS), extended service set (ESS), radio base station (RBS), integrated access and backhaul (IAB) node (e.g., IAB donor node, IAB parent node, and IAB child node), or some other terminology.
[0023]
[0044] An AT may include, be implemented as, or be known as a subscriber station, subscriber unit, mobile station, remote station, remote terminal, user terminal, user agent, user device, user equipment (UE), user station, or some other terminology. In some implementations, an AT may include a mobile phone, cordless phone, Session Initiation Protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless connectivity, station (STA), or any other suitable processing device connected to a wireless modem (such as an augmented reality (AR) / virtual reality (VR) console and headset). Accordingly, one or more aspects taught herein may be incorporated within a telephone (e.g., a cell phone or smartphone), a computer (e.g., a laptop), a portable communication device, a portable computing device (e.g., a personal digital assistant), an entertainment device (e.g., a music or video device, or satellite radio), a global positioning system device, or any other suitable device configured to communicate over a wireless or wired medium. In some aspects, a node is a wireless node. Such a wireless node may provide, for example, connectivity for or to a network (e.g., a wide area network such as the Internet, or a cellular network) over a wired or wireless communications link.
[0024]
[0045] 1 shows a block diagram of an exemplary wireless communication network 100. According to some aspects, the wireless communication network 100 may be an example of a wireless local area network (WLAN), such as a Wi-Fi network (and hereinafter referred to as WLAN 100). For example, the WLAN 100 may be a network implementing at least one of the IEEE 802.11 family of wireless communication protocol standards (such as those defined by the IEEE 802.11-2020 specification or its supplements, including, but not limited to, 802.11ay, 802.11ax, 802.11az, 802.11ba, 802.11bd, 802.11be, 802.11bf, and 802.11 supplements associated with Wi-Fi 8). The WLAN 100 may include a number of wireless communication devices, such as a wireless AP 102 and a number of wireless STAs 104. Although only one AP 102 is shown in FIG. 1 , the WLAN network 100 can also include multiple APs 102. The AP 102 shown in FIG. 1 can represent a wide variety of types of APs, including, but not limited to, enterprise-level APs, single-frequency APs, dual-band APs, standalone APs, software APs (soft APs), and multi-link APs. The coverage area and capacity of cellular networks (such as LTE and 5G NR) can be further improved by small cells supported by APs serving as miniature base stations. Furthermore, private cellular networks can also be set up through wireless area networks using small cells.
[0025]
[0046] Each of the STAs 104 may also be referred to as a mobile station (MS), mobile device, mobile handset, wireless handset, access terminal (AT), user equipment (UE), subscriber station (SS), or subscriber unit, among other examples. The STAs 104 may represent a variety of devices, such as mobile phones, personal digital assistants (PDAs), other handheld devices, netbooks, notebook computers, tablet computers, laptops, Chromebooks, extended reality (XR) headsets, wearable devices, display devices (e.g., TVs (including smart TVs), computer monitors, navigation systems, among others), music or other audio or stereo devices, remote control devices (“remotes”), printers, kitchen appliances (including smart refrigerators) or other home appliances, key fobs (e.g., for passive keyless entry and start (PKES) systems), Internet of Things (IoT) devices, and vehicles, among other examples. The various STAs 104 in the network can communicate with one another via the APs 102.
[0026]
[0047] A single AP 102 and the set of associated STAs 104 managed by the corresponding AP 102 may be referred to as a basic service set (BSS). Figure 1 also shows an example coverage area 108 of the AP 102, which may represent the basic service area (BSA) of the WLAN 100. The BSS may be identified or indicated to users by a service set identifier (SSID) and to other devices by a basic service set identifier (BSSID), which may be the medium access control (MAC) address of the AP 102. The AP 102 may periodically broadcast a beacon frame ("beacon") containing the BSSID to allow any STAs 104 within wireless range of the AP 102 to "associate" or re-associate with the AP 102 to establish or maintain a corresponding communication link 106 (hereinafter also referred to as a "Wi-Fi link") with the AP 102. For example, the beacon may include an identification or indication of the primary channel being used by the corresponding AP 102, as well as timing synchronization functionality for establishing or maintaining timing synchronization with the AP 102. The AP 102 may provide various STAs 104 within the WLAN with access to external networks via corresponding communication links 106.
[0027]
[0048] To establish a communication link 106 with an AP 102, each of the STAs 104 is configured to perform passive or active scanning operations (“scans”) on frequency channels within one or more frequency bands (e.g., the 2.4 GHz, 5 GHz, 6 GHz, or 60 GHz bands). To perform passive scanning, the STAs 104 listen for beacons transmitted by the corresponding AP 102 at periodic time intervals (measured in time units (TUs), where one TU may equal 1024 microseconds (μs)) referred to as target beacon transmission times (TBTTs). To perform active scanning, the STAs 104 generate and transmit probe requests sequentially on each channel to be scanned and listen for probe responses from the AP 102. Each STA 104 can identify, determine, confirm, or select an AP 102 for association according to scan information obtained through passive or active scanning, and can perform authentication and association operations to establish a communication link 106 with the selected AP 102. Upon completing the association operation, the AP 102 assigns an association identifier (AID) to the STA 104, and the AP 102 uses the AID to track the STA 104.
[0028]
[0049] As a result of the increasing ubiquity of wireless networks, a STA 104 may have the opportunity to select one of many BSSs within range of the STA or to select from multiple APs 102 that together form an extended service set (ESS) that includes multiple connected BSSs. An extended network station associated with a WLAN 100 may be connected to a wired or wireless distribution system that may allow multiple APs 102 to be connected in such an ESS. Thus, a STA 104 may be covered by more than one AP 102 and may associate with different APs 102 at different times for different transmissions. Furthermore, after associating with an AP 102, the STA 104 may also periodically scan its surroundings to find a more suitable AP 102 to associate with. For example, a STA 104 that is moving relative to its associated AP 102 may perform a “roaming” scan to find another AP 102 with more desirable network characteristics, such as a stronger received signal strength indicator (RSSI) or reduced traffic load.
[0029]
[0050] In some cases, the STAs 104 may form a network without the AP 102 or any other device other than the STAs 104 themselves. One example of such a network is an ad hoc network (or wireless ad hoc network). An ad hoc network may alternatively be referred to as a mesh network or a peer-to-peer (P2P) network. In some cases, the ad hoc network may be implemented within a larger wireless network, such as a WLAN 100. In such an example, the STAs 104 may be able to communicate with each other through the AP 102 using the communication link 106, but the STAs 104 may also communicate with each other directly via a direct wireless communication link 110. Furthermore, two STAs 104 may communicate via the direct wireless communication link 110 regardless of whether both STAs 104 are associated with and served by the same AP 102. In such an ad hoc system, one or more of the STAs 104 may assume the role played by the AP 102 in a BSS. Such a STA 104 may be referred to as a group owner (GO) and may coordinate transmissions within the ad hoc network. Examples of direct wireless communication links 110 include Wi-Fi Direct connections, connections established by using Wi-Fi Tunneled Direct Link Setup (TDLS) links, and other P2P group connections.
[0030]
[0051] The AP 102 and the STAs 104 may function and communicate (via corresponding communication links 106) in accordance with one or more of the IEEE 802.11 family of wireless communication protocol standards. These standards define WLAN radio protocols and baseband protocols for the PHY and MAC layers. The AP 102 and the STAs 104 transmit and receive wireless communications between each other in the form of PHY protocol data units (PPDUs) (hereinafter also referred to as “Wi-Fi communications” or “wireless packets”). The AP 102 and the STAs 104 in the WLAN 100 may transmit PPDUs over unlicensed spectrum, which may be a portion of the spectrum that includes frequency bands traditionally used by Wi-Fi technology, such as the 2.4 GHz band, the 5 GHz band, the 60 GHz band, the 3.6 GHz band, and the 900 MHz band. Some embodiments of the AP 102 and the STAs 104 described herein may also communicate in other frequency bands, such as the 5.9 GHz band and the 6 GHz band, which may support both licensed and unlicensed communications. The AP 102 and the STAs 104 may also communicate over other frequency bands, such as shared licensed frequency bands, in which multiple operators may have licenses to operate in the same or overlapping frequency bands.
[0031]
[0052] Each frequency band may include multiple subbands or frequency channels. For example, PPDUs conforming to the IEEE 802.11n, 802.11ac, 802.11ax, and 802.11be supplemental standards may be transmitted over the 2.4 GHz, 5 GHz, or 6 GHz bands, each of which is divided into multiple 20 MHz channels. Therefore, these PPDUs are transmitted over physical channels with a minimum bandwidth of 20 MHz, although larger channels can be formed through channel bonding. For example, by bonding multiple 20 MHz channels together, PPDUs may be transmitted over physical channels with bandwidths of 40 MHz, 80 MHz, 160 MHz, or 320 MHz.
[0032]
[0053] Each PPDU is a composite structure in the form of a PHY service data unit (PSDU) that includes a PHY preamble and a payload. Information provided in the preamble can be used by a receiving device to decode the subsequent data in the PSDU. When a PPDU is transmitted over a bonded channel, the preamble field can be replicated and transmitted on each of multiple component channels. The PHY preamble can include both a legacy portion (or "legacy preamble") and a non-legacy portion (or "non-legacy preamble"). The legacy preamble can be used for packet detection, automatic gain control, and channel estimation, among other applications. The legacy preamble can also generally be used to maintain compatibility with legacy devices. The format, coding, and information provided in the non-legacy portion of the preamble are associated with the particular IEEE 802.11 protocol that will be used to transmit the payload.
[0033]
[0054] The AP 102 and the STAs 104 can support multi-user (MU) communications, i.e., simultaneous transmissions from one device to each of multiple devices (e.g., multiple simultaneous downlink (DL) communications from the AP 102 to corresponding STAs 104), or simultaneous transmissions from multiple devices to a single device (e.g., multiple simultaneous uplink (UL) transmissions from corresponding STAs 104 to the AP 102). To support MU transmissions, the AP 102 and the STAs 104 can utilize multi-user multiple-input, multiple-output (MU-MIMO) technology and multi-user orthogonal frequency division multiple access (MU-OFDMA) technology.
[0034]
[0055] In a MU-OFDMA system, the available frequency spectrum of a wireless channel may be divided into multiple resource units (RUs), each containing multiple frequency subcarriers (also referred to as "tones"). Different RUs may be assigned or allocated by the AP 102 to different STAs 104 at a particular time. The size and distribution of these RUs may be referred to as the RU allocation. In some embodiments, RUs may be assigned at 2 MHz intervals; therefore, the smallest RU may contain 26 tones, consisting of 24 data tones and 2 pilot tones. Consequently, in a 20 MHz channel, a maximum of 9 RUs (e.g., a 2 MHz, 26-tone RU) may be assigned (since some tones are reserved for other purposes). Similarly, in a 160 MHz channel, a maximum of 74 RUs may be assigned. Larger RUs with 52, 106, 242, 484, and 996 tones may also be assigned. Adjacent RUs may be separated by a null subcarrier (such as a DC subcarrier), for example, to reduce interference between adjacent RUs, to reduce DC offset in the receiver, and to avoid leakage of the transmit center frequency.
[0035]
[0056] For UL MU transmissions, the AP 102 may transmit trigger frames to initiate and synchronize UL MU-OFDMA or UL MU-MIMO transmissions from multiple STAs 104 to the AP 102. Such trigger frames may therefore enable multiple STAs 104 to transmit UL traffic to the AP 102 simultaneously in time. The trigger frames may address one or more STAs 104 via corresponding association identifiers (AIDs) and may allocate each AID (and therefore each STA 104) one or more RUs that it can use to transmit UL traffic to the AP 102. The AP may also designate one or more random access (RA) RUs for which unscheduled STAs 104 may contend.
[0036]
[0057] 2A illustrates, in block form, a trigger frame 200 according to aspects of the present disclosure. As shown, the trigger frame 200 may include a frame control field, a duration field, a receiver address (RA) field, a transmitter address (TA) field, a common information field, a user information list, padding, and a frame check sequence (FCS) field.
[0037]
[0058] 2B illustrates a set of trigger-based communications 250 in accordance with aspects of the present disclosure. As illustrated, an AP (such as the AP 102 described above with reference to FIG. 1) may transmit a trigger frame 252, which may be one embodiment of the trigger frame 200 described above with reference to FIG. 2A. Upon receiving the trigger frame 252, one or more UEs (such as the UE 104 described above with reference to FIG. 1) may transmit UL frames 254 in response to the trigger frame 252. In response to the UL frames 254, the AP may transmit a multi-station block acknowledgment (M-BA) frame 256 to the UEs. The M-BA frame may indicate successful reception of one or more of the UL frames 254, but may also indicate that one or more other UL frames 254 were not received by the AP.
[0038]
[0059] FIG. 3A illustrates an exemplary control message integrity check (MIC) field (CMF) 300 according to aspects of the present disclosure. The exemplary CMF 300 includes a security key ID field 302 containing two octets, an integrity group temporal key (IGTK) packet number or an integrity pairwise temporal key (IPTK) packet number 304 containing six octets, and a message integrity check (MIC) field 306 (also referred to herein as a message integrity code field) containing eight or sixteen octets. Note that the exemplary CMF 300 has a structure similar to a management MIC information element (IE) that may be used to protect beacon frames. However, the present disclosure is not limited to the structure illustrated in FIG. 3A and includes CMFs having other structures. For example, the IDs described herein may be carried in a field smaller than two octets or as bits contained within other fields of the frame. In another example, a complete packet number (PN) described herein may be split into a partial packet number (PPN) and a base packet number, and the PN field of a CMF described herein may carry the PPN instead of the complete packet number. A wireless node described herein may occasionally (e.g., periodically, in response to a request or in response to a trigger event) swap its base packet number and store the base packet number for use (e.g., in computing, transmitting, or validating received packets). In yet another example, a wireless node described herein may include only a portion of a MIC in a packet (e.g., in a CMF within the packet). A wireless node described herein may transmit four octets of the MIC (e.g., the least significant four octets of the MIC), and a node receiving a packet including the four octets of the MIC may compare those four octets with the corresponding four octets of an integrity check computed based at least on a security key and other portions of the packet.
[0039]
[0060] 3B illustrates an example CMF 350 according to aspects of the present disclosure. The example CMF 350 includes a MIC control field 352, a PN field 354, and a MIC field 356. As illustrated, the MIC control field 352 may include two octets, which may include one or more bits carrying a key ID and / or other bits indicating the combined length of the MIC control and PN fields. The PN field 354 may include two octets and may carry a PPN, which may be, for example, the least significant two octets of a packet number. The MIC field 356 may include four octets that carry a portion of the MIC for the packet (e.g., the least significant four octets).
[0040]
[0061] FIG. 4 illustrates an exemplary secure trigger frame 400 according to aspects of the present disclosure. As shown, the secure trigger frame 400 may include a CMF 402 after a user information list and padding 404 after the CMF. Alternatively, the CMF may be included within the padding of the secure trigger frame 400. The MIC of the CMF may be calculated over all or a portion of the fields of the MAC header (e.g., duration, TA, RA, etc.), the trigger frame body, including the common information field, the user information list field, the security key corresponding to the ID field, and the PN field. UHR STAs associated with the AP and unassociated UHR STAs with access to the IGTK can verify the trigger frame. If the STAs are unable to verify the trigger frame because the calculated MIC does not match the MIC in the trigger frame, the STAs discard the trigger frame and avoid generating a trigger-based (TB) PPDU, resulting in power savings. Other STAs that are not UHR STAs, such as HE STAs or EHT STAs, may ignore the CMF 402 while processing the remainder of the trigger frame 400. While the illustrated CMF 402 is similar to the CMF 300 shown in Figure 3A, this disclosure is not so limited and the CMF in the secure trigger frame may have other structures, such as the structure of the exemplary CMF 350 shown in Figure 3B.
[0041]
[0062] 5 illustrates an embodiment 500 of incorporating a CMF 510 (which may be an embodiment of CMF 300 or 350, described above with reference to FIGS. 3A and 3B ) within a user information list field 501 of a trigger frame, such as trigger frame 400 (described above with reference to FIG. 4 ), in accordance with aspects of the present disclosure. Three user information list fields 501 a, 501 b, and 501 e are shown, with each user information list field including five octets. Each of the five octets of the user information list fields includes an association ID field 502 including 12 bits, a first field 504 including 4 bits, and a second field 506 including 24 bits. As shown, the bits of CMF 510 may be contained within first fields 504a, 504b, 504c, etc. and second fields 506a, 506b, 506c, etc. of user information list fields, including association ID fields 502a, 502b, 502c, etc., set to a reserved value, such as 2023. If the MIC contains 8 octets, a CMF having the structure of CMF 300 may be contained within five user information list fields of 5 octets each. If the MIC contains 16 octets, a CMF having the structure of CMF 300 may be contained within seven user information list fields of 5 octets each.
[0042]
[0063] In aspects of the present disclosure, one or more reserved values of the association ID may indicate the presence of a MIC within a field of the secure trigger frame.
[0043]
[0064] According to aspects of the present disclosure, the CMF may be included in the padding field of the trigger frame after a sequence of 16 ones in the first two octets of the padding, which is used to signal to the receiver that the padding has begun. The CMF may also be included in the next 8, 16, 24, or another number of octets of the padding field, and the additional bits after the CMF may be considered padding.
[0044]
[0065] According to aspects of the present disclosure, a bit in the trigger frame, such as a protected bit in the frame control field, may be used to indicate the presence of a CMF in the trigger frame.
[0045]
[0066] In aspects of the present disclosure, a bit in the trigger frame, such as a bit in a padding field, may indicate the length (e.g., 16 octets or 24 octets) of the CMF present in the trigger frame.
[0046]
[0067] According to aspects of the present disclosure, verifying the PN in the CMF may be an alternative to checking the FCS of the frame, so that the UHR STA may verify the frame based on the CMF and begin processing the frame before the UHR checks the FCS.
[0047]
[0068] FIG. 6 illustrates an exemplary secure null data packet (NDP) announcement frame 600 according to aspects of the present disclosure. As shown, the secure NDP announcement frame 600 may include a CMF 602 after the STA information list and padding 604 after the CMF. Alternatively, the CMF may be included within the padding of the secure NDP announcement frame 600. The MIC of the CMF may be calculated over the NDP announcement frame body, including the sounding dialog token, the STA information list field, the security key ID field, and the PN field. UHR STAs associated with the AP can validate the secure NDP announcement frame 600. If the calculated MIC does not match the MIC in the trigger frame, the STA discards the NDP announcement frame. Other STAs that are not UHR STAs, such as HE STAs or EHT STAs, may process the remainder of the NDP announcement frame 600 while ignoring the CMF 602. The illustrated CMF 602 is similar to the CMF 300 shown in FIG. 3A, but the present disclosure is not so limited, and the CMF in the secure NDP announcement frame may have other structures, such as the structure of the exemplary CMF 350 shown in FIG. 3B.
[0048]
[0069] 7 illustrates an embodiment 700 incorporating a CMF 710 (which may be an embodiment of CMF 300 or 350, described above with reference to FIGS. 3A and 3B ) within an STA Information List field 701 of an NDP announcement frame, such as NDP announcement frame 600 (described above with reference to FIG. 6 ), in accordance with aspects of the present disclosure. Two STA Information List fields 701 a and 701 g are shown, with each STA Information List field including four octets. Each of the four octets of the STA Information List field includes an association ID field 702 including 11 bits, a first field 704 including 16 bits, a disambiguation field 706 including one bit, and a second field 708 including four bits. As shown, the bits of the CMF 710 may be contained in first fields 704a, 704b, 704c, etc., and second fields 708a, 708b, 708c, etc., of STA Information List fields 701a, 701b, 701c, etc., including Association ID fields 702a, 702b, 702c, etc., set to a reserved value, such as 2023. If the MIC contains 8 octets, a CMF having the structure of the CMF 300 may be contained in seven STA Information List fields of 4 octets each. If the MIC contains 16 octets, a CMF having the structure of the CMF 300 may be contained in ten STA Information List fields of 4 octets each.
[0049]
[0070] In aspects of the present disclosure, one or more reserved values of the association ID may indicate the presence of a MIC in a field of the secure NDP announcement frame.
[0050]
[0071] According to aspects of the present disclosure, a CMF may be included in the padding field of a secure NDP announcement frame after a sequence of 16 ones in the first two octets of the padding, which is used to signal to the receiver that the padding has begun. The CMF may also be included in the next eight or sixteen octets of the padding field, and the additional bits after the CMF may be considered padding.
[0051]
[0072] FIG. 8 illustrates an exemplary secure M-BA frame 800 according to aspects of the present disclosure. As illustrated, the secure M-BA frame 800 may include a CMF 802 in the block acknowledgement information list and padding 804 after the CMF 802. Alternatively, the CMF 802 may be included within the padding of the secure M-BA frame 800. The MIC of the CMF may be calculated over the M-BA frame body, including the BA control field and the preceding Per AID traffic identifier (TID) information field. UHR STAs associated with the AP can validate the secure M-BA frame. If the STAs are unable to validate the secure M-BA frame because the calculated MIC does not match the MIC in the trigger frame, the STAs discard the secure M-BA frame to avoid losing packets that were indicated as being acknowledged by the invalid secure M-BA frame. Other STAs that are not UHR STAs, such as HE STAs or EHT STAs, may ignore the CMF 802 while processing the remainder of the secure M-BA frame 800. The structure of the illustrated CMF 802 may be similar to the structure of one of the CMFs 300 or 350 shown in Figures 3A and 3B, or may be a different structure.
[0052]
[0073] 9 illustrates an embodiment 900 incorporating a CMF 930 (which may be an embodiment of CMF 300 or 350, described above with reference to FIGS. 3A and 3B ) within a Per AID TID information field 902 of a secure M-BA frame, such as secure M-BA frame 800 (described above with reference to FIG. 8 ), in accordance with aspects of the present disclosure. Two Per AID TID information fields 902 a and 902 n are shown, where the Per AID TID information field 902 n configured to carry the CMF 930 may include 18-36 octets, including an AID TID information field 910 including 2 octets, a Block ACK Start Sequence Control field 920 including 0 or 2 octets, and a CMF 930 including 16 or 32 octets. As shown, the AID TID information field 910 may include an AID field 912 that includes 11 bits and may be set to a reserved value, such as 2023, to indicate the presence of a CMF in the Per AID TID information field 902n. A CMF 930 having the structure of CMF 300 may include 16 octets if the MIC includes 8 octets, and a CMF 930 having the structure of CMF 300 may include 32 octets if the MIC includes 16 octets. The FN subfield of the Block ACK Start Sequence Control field 920 may indicate the length of the CMF field.
[0053]
[0074] In aspects of the present disclosure, one or more reserved values of the Association ID may indicate the presence of a CMF in the Per AID TID information field of the secure M-BA frame.
[0054]
[0075] According to aspects of the present disclosure, the CMF may be included within a secure compressed block acknowledgment (C-BA) frame in a manner similar to that described with respect to the secure M-BA frame.
[0055]
[0076] FIG. 10 illustrates an exemplary secure multiple traffic identifier (multi-TID) block acknowledgment request (BAR) frame 1000 in accordance with aspects of the present disclosure. As shown, the secure multi-TID BAR frame 1000 includes a CMF 1002 after the last useful BAR information list and may include padding after the CMF 1002. Alternatively, the CMF may be included within the padding of the secure multi-TID BAR frame 1000. The MIC of the CMF may be calculated over the secure multi-TID BAR frame body, including the BAR control field, BAR information field, security key ID field, and PN field. UHR STAs associated with the AP can validate the secure multi-TID BAR frame. If the STAs are unable to validate the secure multi-TID BAR frame because the calculated MIC does not match the MIC in the secure multi-TID BAR frame, the STAs discard the secure multi-TID BAR frame. Other STAs that are not UHR STAs, such as HE STAs or EHT STAs, may ignore the CMF 1002 while processing the remainder of the secure multi-TID BAR frame 1000. As shown, the CMF 1002 may be included in the BAR information field, with the leading bit of the Per TID information field (typically within a set of 12 bits considered reserved) set to indicate the presence of a CMF. The CMF 1002 bits may be included in the Block ACK Start Sequence Control field and other fields of the BAR information field. A sequence of ones may be used to indicate padding after the CMF. While the illustrated CMF 1002 is similar to the CMF 300 shown in FIG. 3A, this disclosure is not so limited, and the CMF in the secure multi-TID BAR frame may have other structures, such as the structure of the exemplary CMF 350 shown in FIG. 3B.
[0056]
[0077] 11 illustrates an example MPDU 1100 according to certain aspects of the present disclosure. Additional control fields (e.g., high efficiency (HE) control fields) may be added to the MAC header of the MPDU 1100 to provide specific control information.
[0057]
[0078] FIG. 12 illustrates an exemplary algorithm 1200 for encrypting data of an MPDU. As shown in the exemplary algorithm 1200, the MAC header 1208 is not encrypted in a Galois / counter mode (GCM) encryption block, so that the unencrypted MAC header is transmitted along with the encrypted data. In the exemplary algorithm 1200, portions of some fields in the MAC header of the MPDU 1100 are protected from tampering by being included in the MPDU's additional authentication data (AAD). If an attacker attempts to tamper with portions of the fields included in the AAD of a transmitted MPDU, or while transmitting a repetition of the MPDU (e.g., an attack frame), the receiver can detect these changes and reject (e.g., discard) the attack frame. Some bits of the frame control (FC) field of the exemplary MPDU 1100 are not protected by the AAD. The AAD does not protect the three least significant bits of the Subtype subfield of the FC field (i.e., bits 4, 5, and 6 of the FC field), the Retry subfield (i.e., bit 11 of the FC field), the Power Management subfield (i.e., bit 12 of the FC field), and the Additional Data subfield (i.e., bit 13 of the FC field). Furthermore, the AAD does not protect the +HTC subfield (i.e., bit 15 of the FC field) in data frames that include a QoS Control field. The AAD also does not protect the Sequence Number subfield of the Sequence Control (SC) field (i.e., bits 4 through 15). The AAD also does not protect the QoS Control field, except for the TID subfield within the QoS Control field. Furthermore, the AAD does not protect the Duration / ID field and the HT Control field.
[0058]
[0079] Because certain algorithms do not encrypt some header fields of an MPDU, those header fields may be used to track the activity of a node (e.g., of a STA or of an AP). For example, a STA's participation in a video call over a Wi-Fi network may be trackable, and other activity by the same STA may also be linked to the STA. Therefore, it is desirable to develop methods and apparatus for encrypting one or more subfields and fields of the MAC header of an MPDU. Such encryption may improve user privacy for users of the node.
[0059]
[0080] 13 illustrates an exemplary algorithm 1300 for encrypting and protecting MAC header fields for individually addressed QoS data frames or management frames ((M)MPDUs). As shown in exemplary algorithm 1300, an encryption key (TK′) 1302, a key ID for the encryption key 1304 (Key ID′), and a packet number (PN′) 1306 for a MAC header 1308 are provided to a header protection block 1310. The encryption key (TK′) 1302, PN′ 1306, and Key ID′ 1304 provided to header protection block 1310 may not be the same as the encryption key (TK) 1322, PN 1326, and Key ID 1324 used by a GCM encryption block 1330 to determine the MIC used to encrypt and protect the data in the MPDU. The encryption key 1302 is used to encrypt one or more portions of the MAC header, a MIC is calculated for the MAC header, and an indication of the PN' 1306, an indication of the Key ID' 1304, and an indication of the HDR MIC are placed by the header protection block 1310 in the header protection field (see Figure 15) of the individually addressed QoS data frame or management frame ((M)MPDU).
[0060]
[0081] FIG. 14 illustrates an example algorithm 1400 for encrypting and protecting MAC header fields for a QoS Null frame, a retry QoS data frame, or a retry management frame ((M)MPDU). Items of the example algorithm 1400 discussed above with reference to FIG. 13 will not be further described. Because a QoS Null frame does not contain data, the GCM encryption block 1330 (shown in FIG. 13) for that type of frame is not present in the example algorithm 1400. Because a retry QoS data frame or a retry (M)MPDU carries the same encrypted data as the original QoS data frame or original (M)MPDU, respectively (i.e., it is the original QoS data frame or original (M)MPDU that is being retried / retransmitted; note that the retry subfield of the FC field is not protected by AAD, as discussed above), the GCM encryption block is also not present for those types of frames in the example algorithm 1400. As described above with reference to FIG. 13, an indication of PN' 1306, an indication of Key ID' 1304, and an indication of HDR MIC are placed in the header protection field (see FIG. 15) of the QoS Null frame, retry QoS data frame, or retry (M) MPDU by the header protection block 1310.
[0061]
[0082] FIG. 15 illustrates one embodiment incorporating a header protection (HDR PRO) field 1502 within an MPDU 1500. As shown, the HDR PRO field 1502 may be included before or after the MPDU's Galois / counter mode protocol (GCMP) header 1504. The HDR PRO field may include an indication of a packet number (PN) associated with the MAC header, which may be a shortened version of the PN associated with the MAC header. The HDR PRO may also include an indication of the key ID of the key used to encrypt the encrypted portion of the MAC header. The HDR PRO may also include an indication of the MIC for the MAC header, which may be a shortened version of the MIC calculated for the MAC header.
[0062]
[0083] Because group address frames may be received by legacy STAs that are not capable of decrypting encrypted MAC headers, it may be desirable to protect the MAC headers of group address frames without encrypting them.
[0063]
[0084] In aspects of the present disclosure, the MAC header of the group address frame may be unencrypted and protected by a follow-up frame. A transmitter (e.g., a STA or an AP) transmitting a group address frame may transmit the group address frame according to conventionally known techniques and then transmit a follow-up frame one SIFS later than the group address frame. The transmitter may include an indication of the PN, key ID, and MIC for the header of the group address frame in the follow-up frame. Legacy STAs that are not capable of decrypting the follow-up frame ignore the follow-up frame. An STA that is an embodiment of the present disclosure may receive the follow-up frame and verify the preceding group address frame using the PN, key ID, and MIC indicated in the follow-up frame.
[0064]
[0085] 16 is an example call flow 1600 illustrating communication between an AP 1602, a UHR STA 1604a, a non-UHR STA 1604b, and an attacker device 1650. At 1610, the AP 1602 transmits a frame including a security key ID, a PN, and an IC. At 1612, the UHR STA 1604a validates the frame by comparing the PN with an expected PN for the frame and by comparing the IC received with the frame with another IC calculated for the frame based at least on the security key indicated by the ID. At 1620, the UHR STA 1604a accepts the validated frame and acts in accordance with the validated frame. At 1614, the non-UHR STA 1604b accepts the frame without validating it and acts in accordance with the frame. At 1616, the attacker device 1650 receives the frame and, in some cases, records or analyzes the frame. At 1652, the attacker device 1650 transmits an attack frame (such as a replay of frame 1610 or a defective block acknowledgment frame). At 1654, the UHR STA 1604a fails to validate the attack frame, and at 1660, the UHR STA 1604a discards the unvalidated attack frame. Similarly, at 1656, the AP 1602 fails to validate the attack frame, and at 1662, the AP 1602 discards the unvalidated attack frame. At 1658, the non-UHR STA 1604b accepts the attack frame (without validating it) and acts in accordance with the attack frame.
[0065]
[0086] FIG. 17 shows a flowchart illustrating an example process 1700 executable in a wireless transmitter to support frame security in accordance with certain aspects of the present disclosure. The operations of process 1700 may be implemented by a wireless AP or UE, or a component of a wireless AP or UE, as described herein. For example, process 1700 may be performed by a wireless communication device, such as wireless communication device 2000 described with reference to FIG. 20, operating as or within a wireless AP or UE. In some embodiments, process 1700 may be performed by a wireless AP, such as one of the APs 102 described with reference to FIG. 1. In some embodiments, process 1700 may be performed by a wireless STA, such as one of the STAs 104 described with reference to FIG. 1.
[0066]
[0087] In some embodiments, at block 1702, the wireless transmitter generates a frame including a security key identifier (ID), a packet number (PN), and an integrity check, the integrity check based on one or more portions of the frame, and the generating includes calculating the integrity check based at least on the security key.
[0067]
[0088] At block 1704, the wireless transmitter outputs the frame for transmission.
[0068]
[0089] FIG. 18 shows a flowchart illustrating an example process 1800 executable in a wireless receiver to support frame security in accordance with certain aspects of the present disclosure. The operations of process 1800 may be implemented by a wireless STA or AP, or a component of a wireless STA or AP, as described herein. For example, process 1800 may be performed by a wireless communication device, such as wireless communication device 2100 described with reference to FIG. 21, operating as or within a wireless STA or AP. In some embodiments, process 1800 may be performed by a wireless STA, such as one of the STAs 104 described with reference to FIG. 1. In some embodiments, process 1800 may be performed by a wireless AP, such as one of the APs 102 described with reference to FIG. 1.
[0069]
[0090] In some embodiments, at block 1802, a wireless receiver obtains a frame including a security key identifier (ID), a packet number (PN), and an integrity check.
[0070]
[0091] At block 1804, the wireless receiver verifies the validity of the frame based on a comparison of the integrity check with another integrity check that is based on at least the security key and one or more portions of the frame.
[0071]
[0092] 19 illustrates a block diagram of an AP 102 and two wireless STAs 104m and 104x in a MIMO / MLO system, such as wireless communication network 100, in accordance with certain aspects of the present disclosure. In certain aspects, the AP 102 and / or the wireless STAs 104m and 104x may implement various techniques to ensure the security of frames, particularly frames that include control information.
[0072]
[0093] AP102 is N apThe wireless STA104m is equipped with N antennas 1924a to 1924ap. sta,m Equipped with antennas 1952ma~1952mu, the Wireless STA104x can sta,x The AP 102 is equipped with antennas 1952xa through 1952xu. The AP 102 is a transmitting entity for the DL and a receiving entity for the UL. Each wireless STA 104 is a transmitting entity for the UL and a receiving entity for the DL. As used herein, a "transmitting entity" is an independently operating apparatus or device capable of transmitting data over a wireless channel, and a "receiving entity" is an independently operating apparatus or device capable of receiving data over a wireless channel. The term communication generally refers to transmitting, receiving, or both. In the following description, the subscript "DL" refers to downlink, the subscript "UL" refers to uplink, and the subscript "DL" refers to uplink. UL N wireless STAs are selected for simultaneous transmission on the uplink, DL wireless STAs are selected for simultaneous transmission on the downlink, and N UL is N DL It may or may not be equal to N UL and N DL may be a static value or may change for each scheduling interval. Beam-steering, beam-forming, or some other spatial processing technique may be used at the access point and the wireless station.
[0073]
[0094] On the UL, at each wireless STA 104 selected for UL transmission, a transmit (TX) data processor 1988 receives traffic data from a data source 1986 and control data from controller 1980. The TX data processor 1988 processes (e.g., encodes, interleaves, and modulates) the traffic data for the wireless station based on a coding and modulation scheme associated with the rate selected for the wireless STA and provides a data symbol stream. A TX spatial processor 1990 performs spatial processing on the data symbol stream and provides N sta,m N for antennas sta,m Each transceiver (TMTR) 1954 receives and processes (e.g., converts to analog, amplifies, filters, and frequency upconverts) a corresponding transmit symbol stream to generate an uplink signal. sta,m 1954 transceivers, N sta,m N for transmitting from antennas 1952 to AP 102 sta,m A memory 1982 may store data and program codes for user terminal 104 and may interface with controller 1980.
[0074]
[0095] N UL wireless STAs may be scheduled for simultaneous transmission on the uplink, each performing spatial processing on its data symbol stream and transmitting its set of transmit symbol streams to the AP 102 on the UL.
[0075]
[0096] In AP102, N ap All N antennas 1924a to 1924ap are transmitting on the UL. ULUL signals from N wireless STAs. Each antenna 1924 provides a received signal to a corresponding transceiver (RCVR) 1922. Each transceiver 1922 performs processing complementary to that performed by transceiver 1954 and provides a received symbol stream. A receive (RX) spatial processor 1940 processes N ap N transceivers from 1922 ap Receiver spatial processing is performed on the N received symbol streams, UL 1942 provides recovered UL data symbol streams. The receiver spatial processing is performed in accordance with channel correlation matrix inversion (CCMI), minimum mean square error (MMSE), soft interference cancellation (SIC), or some other technique. Each recovered UL data symbol stream is an estimate of the data symbol stream transmitted by the corresponding wireless station. An RX data processor 1942 processes (e.g., demodulates, deinterleaves, and decodes) each recovered uplink data symbol stream in accordance with the rate used for that stream to obtain decoded data. The decoded data for each such wireless STA may be provided to a data sink 1944 (e.g., corresponding to data sink 1972 of UT 104) for storage and / or to controller 1930 for further processing.
[0076]
[0097] On the DL, at the AP 102, a TX data processor 1910 processes N data packets scheduled for downlink transmission. DL19. The TX data processor 1910 receives traffic data for the N wireless stations from a data source 1908, control data from a controller 1930, and possibly other data from a scheduler 1934. Various types of data may be transmitted on different transport channels. The TX data processor 1910 processes (e.g., encodes, interleaves, and modulates) the traffic data for each wireless station based on a rate selected for the wireless station. The TX data processor 1910 processes (e.g., encodes, interleaves, and modulates) the traffic data for the N wireless stations based on a rate selected for the wireless station. DL For wireless stations, N DL TX spatial processor 1920 provides N DL data symbol streams. DL performing spatial processing (such as precoding or beamforming, as described in this disclosure) on the DL data symbol streams to obtain N ap N for antennas ap Each transceiver 1922 receives and processes a corresponding transmit symbol stream to generate a DL signal. ap The transceivers 1922 are ap N antennas 1924 for transmitting to wireless STAs ap A memory 1932 may store data and program codes for the access point 102 and may interface with the controller 1930.
[0077]
[0098] At each wireless STA 104, N sta,m The antennas 1952 receive N signals from the access point 102. ap Each transceiver 1954 processes the received signal from an associated antenna 1952 and provides a received symbol stream. An RX spatial processor 1960 processes the N DL signals. sta,m N transceivers from 1954 sta,mA RX data processor 1970 performs receiver spatial processing on the received symbol streams to provide recovered DL data symbol streams for the wireless station. The receiver spatial processing is performed in accordance with CCMI, MMSE, or some other technique. An RX data processor 1970 processes (e.g., demodulates, deinterleaves, and decodes) the recovered DL data symbol streams to obtain decoded data for the wireless station.
[0078]
[0099] At each wireless STA 104, a channel estimator 1978 estimates the DL channel response and provides a DL channel estimate, which may include a channel gain estimate, an SNR estimate, a noise variance, etc. Similarly, a channel estimator 1928 estimates the UL channel response and provides a UL channel estimate. The controller 1980 at each wireless STA typically calculates the downlink channel response matrix H for the wireless station. dn,m The controller 1930 derives a spatial filter matrix for the wireless station based on the effective UL channel response matrix H up,eff derives a spatial filter matrix for the AP based on ( ). Controller 1980 of each wireless STA may send feedback information (e.g., downlink and / or uplink eigenvectors, eigenvalues, SNR estimates, etc.) to the AP. Controllers 1930 and 1980 also control the operation of various processing units in AP 102 and wireless STA 104, respectively.
[0079] Exemplary Devices
[0100] FIG. 20 illustrates a communications device 2000 that may include various components (e.g., corresponding to means-plus-function components) operable, configured, or adapted to perform operations related to the techniques disclosed herein, such as those illustrated in FIG. 17 .
[0080]
[0101] The communications device 2000 includes a processing system 2002 coupled to a transceiver 2008 (e.g., a transmitter or receiver). The transceiver 2008 is configured to transmit and receive signals to and from the communications device 2000 via an antenna 2010, such as various signals as described herein. The processing system 2002 may be configured to perform processing functions of the communications device 2000, including processing signals received by the communications device 2000 or signals to be transmitted.
[0081]
[0102] The processing system 2002 includes a processor 2004 coupled to a computer-readable medium / memory 2012 via a bus 2006. In particular aspects, the computer-readable medium / memory 2012 is configured to store instructions (e.g., computer-executable code) that, when executed by the processor 2004, cause the processor 2004 to perform the operations illustrated in FIG. 17 or other operations for implementing the various techniques discussed herein.
[0082]
[0103] In certain aspects, computer readable medium / memory 2012 stores code 2014 (such as an example of a means) for generating, code 2015 (such as an example of a means) for calculating, code 2016 (such as an example of a means) for outputting, code 2017 (such as an example of a means), code 2018 (such as an example of a means), code 2019 (such as an example of a means) for including, code 2020, code 2021 for determining, and code 2022 for encrypting.
[0083]
[0104] In certain aspects, the processor 2004 has circuitry configured to implement code stored in the computer-readable medium / memory 2012. The processor 2004 includes a circuit 2032 for generating (e.g., an embodiment of a means), a circuit 2033 for calculating (e.g., an embodiment of a means), a circuit 2034 for outputting (e.g., an embodiment of a means), a circuit 2035 for arranging (e.g., an embodiment of a means), a circuit 2036 for setting (e.g., an embodiment of a means), a circuit 2037 for including (e.g., an embodiment of a means), a circuit 2038 for obtaining (e.g., an embodiment of a means), a circuit 2039 for determining (e.g., an embodiment of a means), and a circuit 2040 for encrypting (e.g., an embodiment of a means).
[0084]
[0105] The transceiver 2008 may provide a means for receiving information, such as packets, user data, or control information associated with various information channels (e.g., control channel, data channel, etc.). The information may be passed to other components of the device 2000. The transceiver 2008 may be an embodiment of aspects of the transceiver 1954 described with reference to FIG. 19 . The antenna 2010 may correspond to a single antenna or a set of antennas. The transceiver 2008 may provide a means for transmitting signals generated by other components of the device 2000.
[0085]
[0106] In some cases, a device may have an interface (means for outputting) for outputting frames for transmission, rather than actually transmitting the frames. For example, a processor may output frames to a radio frequency (RF) front end for transmission via a bus interface. Similarly, a device may have an interface (means for acquiring) for acquiring frames received from another device, rather than actually receiving the frames. For example, a processor may acquire (or receive) frames from a receiving RF front end via a bus interface. In some cases, the interface for outputting frames for transmission and the interface for acquiring frames (sometimes referred to herein as a first interface and a second interface) may be the same interface.
[0086]
[0107] The generating means, calculating means, arranging means, setting means, including means, determining means, and / or encrypting means may include any of the various processors and / or memories shown in Figure 19 or Figure 20. The obtaining means and / or outputting means may include any of the various processors, memories, and / or transceivers shown in Figure 19 or Figure 20.
[0087]
[0108] FIG. 21 illustrates a communications device 2100 that may include various components (e.g., corresponding to means-plus-function components) operable, configured, or adapted to perform operations related to the techniques disclosed herein, such as those illustrated in FIG. 18 .
[0088]
[0109] The communications device 2100 includes a processing system 2102 coupled to a transceiver 2108 (e.g., a transmitter or receiver). The transceiver 2108 is configured to transmit and receive signals to and from the communications device 2100 via an antenna 2110, such as various signals as described herein. The processing system 2102 may be configured to perform processing functions of the communications device 2100, including processing signals received by the communications device 2100 or signals to be transmitted.
[0089]
[0110] The processing system 2102 includes a processor 2104 coupled to a computer-readable medium / memory 2112 via a bus 2106. In particular aspects, the computer-readable medium / memory 2112 is configured to store instructions (e.g., computer-executable code) that, when executed by the processor 2104, cause the processor 2104 to perform the operations illustrated in FIG. 18 or other operations for implementing the various techniques discussed herein.
[0090]
[0111] In certain aspects, computer readable medium / memory 2112 stores code 2114 (such as an example of a means) for obtaining, code 2115 (such as an example of a means) for responding, code 2116 (such as an example of a means) for discarding, code 2117 (such as an example of a means), code 2118 (such as an example of a means), code 2119 (such as an example of a means), code 2120 for verifying, code 2121 for decoding, and code 2122 for outputting.
[0091]
[0112] In certain aspects, processor 2104 has circuitry configured to implement code stored on computer-readable medium / memory 2112. Processor 2104 includes circuitry 2132 for obtaining (e.g., an embodiment of a means), circuitry 2133 for responding (e.g., an embodiment of a means), circuitry 2134 for discarding (e.g., an embodiment of a means), circuitry 2135 for operating (e.g., an embodiment of a means), circuitry 2136 for calculating (e.g., an embodiment of a means), circuitry 2137 for requesting (e.g., an embodiment of a means), circuitry 2138 for verifying (e.g., an embodiment of a means), circuitry 2139 for decoding (e.g., an embodiment of a means), and circuitry 2140 for outputting (e.g., an embodiment of a means).
[0092]
[0113] The transceiver 2108 may provide a means for receiving information, such as packets, user data, or control information associated with various information channels (e.g., control channel, data channel), which may be passed to other components of the device 2100. The transceiver 2108 may be an embodiment of aspects of the transceiver 1954 described with reference to FIG. 19 . The antenna 2110 may correspond to a single antenna or a set of antennas. The transceiver 2108 may provide a means for transmitting signals generated by other components of the device 2100.
[0093]
[0114] In some cases, a device may have an interface (means for outputting) for outputting frames for transmission rather than actually transmitting the frames. For example, a processor may output frames to a radio frequency (RF) front end for transmission via a bus interface. Similarly, a device may have an interface (means for acquiring) for acquiring frames received from another device rather than actually receiving the frames. For example, a processor may acquire (or receive) frames from a receiving RF front end via a bus interface. A device acquiring a frame may acquire values of various fields of the frame as part of the acquisition, or additionally or alternatively, the device may acquire the frame and then acquire the values of various fields of the frame in a subsequent step, such as a decoding step. In some cases, the interface for outputting frames for transmission and the interface for acquiring frames (sometimes referred to herein as a first interface and a second interface) may be the same interface.
[0094]
[0115] The means for responding, the means for discarding, the means for operating, the means for calculating, the means for requesting, the means for verifying, and / or the means for decrypting may include any of the various processors and / or memories shown in Figure 19 or Figure 21. The means for obtaining and / or the means for outputting may include any of the various processors, memories, and / or transceivers shown in Figure 19 or Figure 21.
[0095] Example clauses
[0116] The following numbered clauses describe example implementations.
[0096]
[0117] Clause 1: A method for wireless communication in a wireless node, comprising: generating a frame including a security key identifier (ID), a packet number (PN), and an integrity check, wherein the integrity check is based on one or more portions of the frame, and wherein the generating includes calculating the integrity check based at least on the security key; and outputting the frame for transmission.
[0097]
[0118] Clause 2: The method of clause 1, wherein the PN includes at least one of an Integrity Group Transient Key (IGTK) packet number or an Integrity Pairwise Transient Key (IPTK) packet number.
[0098]
[0119] Clause 3: The method of clause 1, wherein the PN includes only a portion of a complete packet number for the frame, and another portion of the complete packet number is stored locally, and the method further includes updating the stored portion of the complete packet number based on an exchange of secure management frames.
[0099]
[0120] Clause 4: The method of clause 3, wherein the complete packet number includes a global timestamp maintained by a wireless node or access point (AP) that is an intended recipient of the frame, and if the global timestamp is maintained by the AP, the method further includes obtaining one or more protected beacon frames indicating the global timestamp, and if the global timestamp is maintained by the wireless node, the method further includes outputting one or more protected beacon frames indicating the global timestamp for transmission.
[0100]
[0121] Clause 5: The method of any of clauses 1-4, wherein the security key comprises at least one of an integrity group transient key (IGTK), a pairwise transient key (PTK), or a controlled integrity transient key (CIGTK).
[0101]
[0122] Clause 6: Any of clauses 1 to 5, wherein the frame includes a trigger frame including a user information list, and the method further includes placing the ID, PN, and integrity check after the user information list in the trigger frame.
[0102]
[0123] Clause 7: Any of clauses 1 to 5, wherein the frame includes a trigger frame, the trigger frame includes a user information list including a user information field, and the method further includes placing the ID, PN, and integrity check within a subset of the user information field.
[0103]
[0124] Clause 8: The method of clause 7, wherein each of the user information fields of the subset includes an association identifier (AID) field, and the method further includes setting the AID field of each user information field in the subset to a reserved value indicating the presence of an integrity check.
[0104]
[0125] Clause 9: The method of clause 7, wherein the integrity check is carried over 8 octets or 16 octets, and the subset consists of 5 user information fields if the integrity check is carried over 8 octets, and 7 user information fields if the integrity check is carried over 16 octets.
[0105]
[0126] Clause 10: The integrity check is a portion of a complete integrity check for the frame, or the complete integrity check includes an integrity check and a portion of the complete integrity check that is known by another wireless node that is an intended recipient of the frame. Any of the methods in clauses 1 to 9, which is at least one of the following:
[0106]
[0127] Clause 11: Any of clauses 1 to 10, wherein the frame includes a null data packet (NDP) announcement frame including a station (STA) information field, and the method further includes placing an ID, PN, and integrity check after the STA information field in the NDP announcement frame.
[0107]
[0128] Clause 12: Any of clauses 1 to 11, wherein the frame comprises a null data packet (NDP) announcement frame including a station (STA) information field, and the method further comprises placing the ID, PN, and integrity check within a subset of the STA information field.
[0108]
[0129] Clause 13: The method of clause 12, wherein each STA information field includes an association identifier (AID) field, and the method further includes setting the AID field of each STA information field in the subset to a reserved value indicating the presence of an integrity check.
[0109]
[0130] Clause 14: The method of clause 12, wherein the integrity check is carried over 8 octets or 16 octets, and the subset consists of 7 STA information fields if the integrity check is carried over 8 octets, and 10 STA information fields if the integrity check is carried over 16 octets.
[0110]
[0131] Clause 15: The method of any of clauses 1-14, wherein the frame comprises a multi-station block acknowledgment (M-BA) frame including an association identifier (AID) traffic identifier (TID) information field, and the method further comprises placing the ID, PN, and integrity check within a subset of the AID TID information field.
[0111]
[0132] Clause 16: The method of clause 15, wherein each of the subset AID TID information fields includes an AID field, and the method further includes setting the AID field of each AID TID information field of the subset to a reserved value indicating the presence of an integrity check.
[0112]
[0133] Clause 17: The method of clause 15, further comprising including padding in the frame after the subset, the amount of padding being based on the number of symbols between the subset and the end of the frame.
[0113]
[0134] Clause 18: The method of clause 17, further comprising obtaining an indication of a required period between the subset and an end of the frame, and determining the number of symbols based on the required period.
[0114]
[0135] Clause 19: Any of clauses 1 to 18, wherein the frame comprises a block acknowledgement request (BAR) frame including a BAR information field, and the method further comprises placing the ID, PN, and integrity check within a subset of the BAR information field.
[0115]
[0136] Clause 20: The method of clause 19, wherein the BAR frame comprises a multiple traffic identifier (multi-TID) BAR frame or a compressed BAR frame.
[0116]
[0137] Clause 21: The method of clause 19, wherein each of the subset of BAR information fields includes a Per Traffic Identifier (TID) information field, the method further including setting a leading bit of each Per TID information field.
[0117]
[0138] Clause 22: The method of any of clauses 1 to 21, wherein the integrity check includes a message integrity code (MIC).
[0118]
[0139] Clause 23: The method of any of clauses 1 to 22, wherein generating the frame includes encrypting one or more bits included in a Medium Access Control (MAC) header of the frame, and outputting the frame includes outputting the MAC header including the encrypted one or more bits.
[0119]
[0140] Clause 24: The method of clause 23, wherein the PN is at least one of a first PN associated with a MAC Protocol Data Unit (MPDU) of the frame, or encrypting one or more bits is based on a second PN associated with the MAC header and a second security key.
[0120]
[0141] Clause 25: The method of clause 24, wherein the frame further includes a header protection field, the header protection field including an indication of the second PN, an identification of the second security key, and another integrity check based on the MAC header.
[0121]
[0142] Clause 26: The method of any of clauses 23-25, further comprising obtaining an indication that another wireless node supports MAC header encryption, wherein the MAC header indicates a receiver address (RA) of the other wireless node.
[0122]
[0143] Clause 27: The method of any of clauses 23-26, further comprising outputting, for transmission, an indication that the wireless node supports MAC header encryption.
[0123]
[0144] Clause 28: A method for wireless communication in a wireless node, comprising: obtaining a frame including a security key identifier (ID), a packet number (PN), and an integrity check; and verifying the validity of the frame based on a comparison of the integrity check with another integrity check, wherein the other integrity check is based on at least the security key and one or more portions of the frame.
[0124]
[0145] Clause 29: The method of clause 28, further comprising responding to the frame based on verifying the validity of the frame.
[0125]
[0146] Clause 30: The method of clause 28 or 29, wherein the PN includes only a portion of the complete packet number for the frame, and another portion of the complete packet number is stored locally, and the method further includes updating the stored portion of the complete packet number based on an exchange of secure management frames.
[0126]
[0147] Clause 31: The method of clause 30, wherein the complete packet number includes a global timestamp maintained by the wireless node or access point (AP), and if the global timestamp is maintained by the AP, the method further includes obtaining the global timestamp from one or more protected beacon frames, and if the global timestamp is maintained by the wireless node, the method further includes outputting one or more protected beacon frames indicating the global timestamp for transmission.
[0127]
[0148] Clause 32: The method of any of clauses 28-31, wherein the security key comprises at least one of an integrity group transient key (IGTK), a pairwise transient key (PTK), or a controlled integrity transient key (CIGTK).
[0128]
[0149] Clause 33: The method of any of clauses 28-32, further comprising discarding the frame if the PN does not match an expected PN for the frame.
[0129]
[0150] Clause 34: The method of any of clauses 28-33, further comprising calculating another integrity check.
[0130]
[0151] Clause 35: The method of any of clauses 28-34, wherein the PN includes at least one of an Integrity Group Transient Key (IGTK) packet number or an Integrity Pairwise Transient Key (IPTK) packet number.
[0131]
[0152] Clause 36: The method of any of clauses 28 to 35, wherein the frame includes a trigger frame, the trigger frame including a user information list, and an ID, a PN, and an integrity check after the user information list in the trigger frame.
[0132]
[0153] Clause 37: Any of the methods of clauses 28 to 36, wherein the frame includes a trigger frame, the trigger frame including a user information list including a user information field, and an ID, a PN, and an integrity check in a subset of the user information field.
[0133]
[0154] Clause 38: The method of clause 37, wherein each of the subset of user information fields includes an association identifier (AID) field having a reserved value associated with an integrity check, and the method further includes obtaining the ID, PN, and integrity check from the subset of user information fields.
[0134]
[0155] Clause 39: The method of clause 37, wherein the integrity check is carried over 8 octets or 16 octets, and wherein the subset consists of 5 user information fields if the integrity check is carried over 8 octets, and 7 user information fields if the integrity check is carried over 16 octets.
[0135]
[0156] Clause 40: The method of any of clauses 28 to 39, wherein the integrity check is part of a full integrity check for the frame, and another part of the full integrity check is known by the wireless node.
[0136]
[0157] Clause 41: Any of the methods of clauses 28-40, wherein the frame comprises a null data packet (NDP) announcement frame including a station (STA) information field and an ID, PN, and integrity check after the STA information field.
[0137]
[0158] Clause 42: Any of clauses 28 to 41, wherein the frame includes a null data packet (NDP) announcement frame including a station (STA) information field and an ID, PN, and integrity check in a subset of the STA information field, and the method further includes obtaining the ID, PN, and integrity check from the subset STA information field.
[0138]
[0159] Clause 43: The method of clause 42, wherein each STA information field of the subset includes an association identifier (AID) field having a reserved value associated with an integrity check, and the method further includes obtaining the ID, PN, and integrity check from the STA information fields of the subset.
[0139]
[0160] Clause 44: The method of clause 42, wherein the integrity check is carried over 8 octets or 16 octets, and the subset consists of 7 STA information fields if the integrity check is carried over 8 octets, and 10 STA information fields if the integrity check is carried over 16 octets.
[0140]
[0161] Clause 45: The method of any of clauses 28-44, wherein the frame includes a multi-station block acknowledgement (M-BA) frame including an association identifier (AID) traffic identifier (TID) information field and an ID, PN, and integrity check in a subset of the AID TID information field, and the method further includes obtaining the ID, PN, and integrity check from the subset AID TID information field.
[0141]
[0162] Clause 46: The method of clause 45, wherein each of the subset of AID TID information fields includes an AID field having a reserved value associated with an integrity check.
[0142]
[0163] Clause 47: The method of clause 45, wherein the frame includes padding after the subset, the amount of padding being based on the number of symbols between the subset and the end of the frame.
[0143]
[0164] Clause 48: The method of clause 47, wherein the number of symbols is based on a period between the subset and an end of the frame, the method further comprising requesting the period between the subset and an end of the frame.
[0144]
[0165] Clause 49: Any of clauses 28 to 48, wherein the frame includes a block acknowledgement request (BAR) frame including a BAR information field and an ID, PN, and integrity check in a subset of the BAR information field, and the method further includes obtaining the ID, PN, and integrity check from the subset of BAR information fields.
[0145]
[0166] Clause 50: The method of clause 49, wherein the BAR frame comprises a multiple traffic identifier (multi-TID) BAR frame or a compressed BAR frame.
[0146]
[0167] Clause 51: The method of clause 49, wherein each of the subset of BAR information fields includes a Per Traffic Identifier (TID) information field having a leading bit set.
[0147]
[0168] Clause 52: The method of any of clauses 28 to 51, wherein the integrity check includes a message integrity code (MIC).
[0148]
[0169] Clause 53: Any of the methods of clauses 28 to 52, wherein verifying the validity of the frame includes decoding one or more bits contained within a Medium Access Control (MAC) header of the frame, and verifying the validity of the frame includes verifying the validity of the MAC header based on the decoded one or more bits.
[0149]
[0170] Clause 54: The PN is a first PN associated with a MAC Protocol Data Unit (MPDU) of the frame, or decoding one or more bits is based on a second PN associated with a MAC header and a second security key. The method of clause 53 is at least one of the following.
[0150]
[0171] Clause 55: The method of clause 54, wherein the frame further includes a header protection field, the header protection field including an indication of the second PN, an identification of the second security key, and another integrity check based on the MAC header.
[0151]
[0172] Clause 56: The method of any of clauses 53-55, further comprising outputting, for transmission, an indication that the wireless node supports MAC header encryption.
[0152]
[0173] Clause 57: The method of any of clauses 53-56, further comprising obtaining an indication that another wireless node supports MAC header encryption, wherein the MAC header indicates a receiver address (RA) of the other wireless node.
[0153]
[0174] Clause 58: An apparatus comprising a memory containing executable instructions and a processor, the processor configured to execute the executable instructions to cause the apparatus to perform a method according to any one of clauses 1 to 57.
[0154]
[0175] Clause 59: Apparatus comprising means for carrying out a method according to any one of clauses 1 to 57.
[0155]
[0176] Clause 60: A non-transitory computer-readable medium comprising executable instructions that, when executed by a processor of the device, cause the device to perform a method according to any one of clauses 1 to 57.
[0156]
[0177] Clause 61: A computer program product, embodied on a computer-readable storage medium, comprising code for performing a method according to any one of clauses 1 to 57.
[0157]
[0178] Aspect 62: A wireless node comprising at least one transceiver, a memory containing instructions, and one or more processors, wherein the one or more processors are configured to execute the instructions to cause the wireless node to generate a frame comprising a security key identifier (ID), a packet number (PN), and an integrity check, and to transmit the frame via the at least one transceiver, wherein the integrity check is based on one or more portions of the frame, and wherein the generating includes calculating the integrity check based at least on the security key.
[0158]
[0179] Aspect 63: A wireless node comprising at least one transceiver, a memory containing instructions, and one or more processors, wherein the one or more processors are configured to execute the instructions to cause the wireless node to receive, via the at least one transceiver, a frame including a security key identifier (ID), a packet number (PN), and an integrity check, and to verify the validity of the frame based on a comparison of the integrity check with another integrity check, wherein the other integrity check is based on at least the security key and one or more portions of the frame.
[0159]
[0180] As used herein, the terms "determine" or "determining" encompass a wide variety of actions, and thus "determining" can include calculating, computing, processing, deriving, investigating, looking up (such as by looking up in a table, database, or another data structure), inferring, ascertaining, measuring, etc. "Determining" can also include receiving (such as receiving information), accessing (such as accessing data stored in a memory), transmitting (such as sending information), etc. "Determining" can also include resolving, selecting, obtaining, choosing, establishing, and other such similar actions.
[0160]
[0181] As used herein, a phrase referring to "at least one of" a list of items refers to any combination of those items, including single members. By way of example, "at least one of a, b, or c" is intended to encompass a, b, c, ab, ac, bc, and abc. As used herein, "or" is intended to be interpreted in an inclusive sense unless expressly indicated otherwise. For example, "a or b" can include a only, b only, or a and b in combination.
[0161]
[0182] As used herein, "based on" is intended to be interpreted in an inclusive sense unless expressly indicated otherwise. For example, "based on" may be used interchangeably with "based at least in part on," "associated with," or "according to," unless expressly indicated otherwise. Specifically, unless the phrase refers to "based only on 'a'" or a contextual equivalent, "based on 'a'" or "based at least in part on 'a'" may refer to only "a," whatever that may be, or to "a" in combination with one or more other factors, conditions, or information.
[0162]
[0183] As used herein, "processor," "at least one processor," or "one or more processors" generally refers to a single processor configured to perform one or more operations, or to multiple processors configured to collectively perform one or more operations. In the case of multiple processors, performance of one or more operations may be divided among different processors, although a single processor may perform multiple operations, or multiple processors may collectively perform a single operation. Similarly, "memory," "at least one memory," or "one or more memories" generally refers to a single memory configured to store data and / or instructions, or to multiple memories configured collectively to store data and / or instructions.
[0163]
[0184] The various illustrative components, logic, logic blocks, modules, circuits, operations, and algorithmic processes described in connection with the embodiments disclosed herein may be implemented as electronic hardware, firmware, software, or combinations of hardware, firmware, or software, including the structures disclosed herein and structural equivalents thereof. The interchangeability of hardware, firmware, and software has been described generally in terms of functionality and is illustrated in the various illustrative components, blocks, modules, circuits, and processes described above. Whether such functionality is implemented in hardware, firmware, or software depends on the particular application and design constraints imposed on the overall system.
[0164]
[0185] Various modifications to the embodiments described in this disclosure will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other embodiments without departing from the scope of the disclosure. Thus, the scope of the claims is not intended to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with this disclosure, the principles and novel features disclosed herein.
[0165]
[0186] Moreover, various features that are described herein in the context of separate embodiments can also be implemented in combination in a single implementation. Conversely, various features that are described in the context of a single implementation can also be implemented in multiple embodiments separately or in any suitable subcombination. Thus, while features may be described above as working in a particular combination, and may even be initially claimed as such, one or more features from a claimed combination can, in some cases, be deleted from the combination, and the claimed combination may also be directed to a subcombination or a variation of the subcombination.
[0166]
[0187] Similarly, although operations are shown in a particular order in the figures, this should not be understood as requiring that such operations be performed in the particular order shown, or sequential order, or that all of the shown operations be performed, to achieve desirable results. Furthermore, the figures may generally depict one or more exemplary processes in the form of a flowchart or flow diagram. However, these generally depicted exemplary processes may incorporate other operations not shown. For example, one or more additional operations may be performed before, after, simultaneously with, or between any of the depicted operations. In some situations, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system components in the above-described embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems may generally be integrated together in a single software product or packaged within multiple software products.
Claims
1. 1. An apparatus for wireless communication, comprising: at least one memory containing instructions; one or more processors; wherein the one or more processors execute the instructions to cause the device to: generating a frame including a security key identifier (ID), a packet number (PN), and an integrity check; outputting the frame for transmission; It is structured as follows: the integrity check is based on one or more portions of the frame; said generating including calculating said integrity check based at least on said security key; Device.
2. the PN includes at least one of an Integrity Group Transient Key (IGTK) packet number or an Integrity Pairwise Transient Key (IPTK) packet number; The security key comprises at least one of an IGTK, a Pairwise Transient Key (PTK), or a Controlled Integrity Transient Key (CIGTK), or the PN includes only a portion of a complete packet number for the frame, another portion of the complete packet number being stored locally, and the one or more processors are configured to execute the instructions to cause the device to update the stored portion of the complete packet number based on an exchange of secure management frames. The device of claim 1 , wherein the at least one of
3. the frame includes a trigger frame, the trigger frame includes a user information list including a user information field; The one or more processors execute the instructions to cause the device to: configured to place the ID, the PN, and the integrity check after the user information list in the trigger frame or within a subset of the user information field.
10. The apparatus of claim 1.
4. each of the user information fields of the subset includes an association identifier (AID) field; The one or more processors execute the instructions to cause the device to: disposing the ID, the PN, and the integrity check within the subset of the user information fields; causing the AID field of each user information field in the subset to be set to a reserved value indicating the presence of the integrity check; It is configured as follows:
4. The apparatus of claim 3.
5. the frame comprises a null data packet (NDP) announcement frame including a station (STA) information field; The one or more processors execute the instructions to cause the device to: The ID, the PN, and the integrity check after the STA information field in the NDP announcement frame, or In the subset of the STA information field, configured to be placed on one of the 10. The apparatus of claim 1.
6. Each STA information field includes an association identifier (AID) field; The one or more processors execute the instructions to cause the device to: disposing the ID, the PN, and the integrity check within the subset of the STA information fields; causing the AID field of each STA information field in the subset to be set to a reserved value indicating the presence of the integrity check; It is configured as follows:
6. The apparatus of claim 5.
7. the frame comprises a multi-station block acknowledgment (M-BA) frame including an association identifier (AID) traffic identifier (TID) information field; The one or more processors execute the instructions to cause the device to: configured to place the ID, the PN, and the integrity check within a subset of the AID TID information field; 10. The apparatus of claim 1.
8. each of the AID TID information fields of the subset includes an AID field; The one or more processors execute the instructions to cause the device to: configured to cause the AID field of each AID TID information field of the subset to be set to a reserved value indicating the presence of the integrity check.
8. The apparatus of claim 7.
9. The one or more processors execute the instructions, and the device further comprises: configured to include padding in the frame after the subset, the amount of padding being based on the number of symbols between the subset and the end of the frame; 8. The apparatus of claim 7.
10. The one or more processors execute the instructions, and the device further comprises: obtaining an indication of a required period between the subset and the end of the frame; determining the number of symbols based on the requested period; It is configured as follows:
10. The apparatus of claim 9.
11. the frame comprises a block acknowledgement request (BAR) frame including a BAR information field; The one or more processors execute the instructions to cause the device to: configured to place the ID, the PN, and the integrity check within a subset of the BAR information fields; 10. The apparatus of claim 1.
12. each of the BAR information fields of the subset includes a Per Traffic Identifier (TID) information field; The one or more processors execute the instructions to cause the device to: configured to set the first bit of each Per TID information field; 12. The apparatus of claim 11.
13. The one or more processors are configured to cause the device to generate the frame, 2. The apparatus of claim 1, wherein the one or more processors are configured to cause the apparatus to output the frame, the one or more processors being configured to cause the apparatus to output the MAC header including the encrypted one or more bits.
14. the PN is a first PN associated with a MAC Protocol Data Unit (MPDU) of the frame; or wherein the one or more processors configured to cause the device to encrypt the one or more bits includes the one or more processors configured to cause the device to encrypt the one or more bits based on a second PN associated with the MAC header and a second security key.
14. The device of claim 13, wherein at least one of
15. wherein the one or more processors configured to cause the device to encrypt the one or more bits includes the one or more processors configured to cause the device to encrypt the one or more bits based on the second PN associated with the MAC header and the second security key; The frame further includes a header protection field, the header protection field comprising: an indication of the second PN; and an ID of the second security key; and another integrity check based on the MAC header; Including, 15. The apparatus of claim 14.
16. The apparatus of claim 1 , further comprising at least one transceiver configured to transmit the frame, the apparatus being configured as a wireless node.
17. 1. An apparatus for wireless communication, comprising: at least one memory containing instructions; one or more processors; wherein the one or more processors execute the instructions to cause the device to: capturing a frame containing a security key identifier (ID), a packet number (PN), and an integrity check; verifying the validity of the frame based on a comparison of the integrity check with another integrity check; wherein the further integrity check is based on at least the security key and one or more portions of the frame. Device.
18. the PN includes only a portion of the complete packet number for the frame; Another portion of the complete packet number is stored locally; The one or more processors execute the instructions to cause the device to: configured to update the stored portion of the complete packet number based on an exchange of secure management frames.
18. The apparatus of claim 17.
19. The security key comprises at least one of an integrity group transient key (IGTK), a pairwise transient key (PTK), or a controlled integrity transient key (CIGTK); or the PN includes at least one of an IGTK packet number or an Integrity Pairwise Temporal Key (IPTK) packet number; 18. The device of claim 17, wherein at least one of
20. the frame comprises a null data packet (NDP) announcement frame including a station (STA) information field, the ID, the PN, and the integrity check; The ID, the PN, and the integrity check after the STA information field, or In the subset of the STA information field placed in The one or more processors execute the instructions to cause the device to: configured to obtain the ID, the PN, and the integrity check from the NDP announcement frame; 18. The apparatus of claim 17.
21. the frame comprises a multi-station block acknowledgment (M-BA) frame including an association identifier (AID) traffic identifier (TID) information field, and the ID, the PN, and the integrity check within a subset of the AID TID information field; The one or more processors execute the instructions to cause the device to: obtaining the ID, the PN, and the integrity check from the AID TID information field of the subset; It is configured as follows:
18. The apparatus of claim 17.
22. each of the AID TID information fields of the subset includes an AID field having a reserved value associated with the integrity check; 22. The apparatus of claim 21.
23. the frame includes padding after the subset; the amount of padding is based on the number of symbols between the subset and the end of the frame; 22. The apparatus of claim 21.
24. the number of symbols is based on a period between the subset and the end of the frame; The one or more processors execute the instructions, and the device further comprises: configured to request the period between the subset and the end of the frame.
24. The apparatus of claim 23.
25. the frame comprises a block acknowledgement request (BAR) frame including a BAR information field and the ID, the PN, and the integrity check in a subset of the BAR information field; The one or more processors execute the instructions to cause the device to: configured to derive the ID, the PN, and the integrity check from the BAR information fields of the subset.
18. The apparatus of claim 17.
26. The one or more processors are configured to cause the device to verify the validity of the frame.
20. The apparatus of claim 17, wherein the one or more processors are configured to cause the apparatus to verify the validity of the frame, the one or more processors being configured to cause the apparatus to verify the validity of the MAC header based on the decoded one or more bits.
27. the PN is a first PN associated with a MAC Protocol Data Unit (MPDU) of the frame; or wherein the one or more processors configured to cause the device to decode the one or more bits includes the one or more processors configured to cause the device to decode the one or more bits based on a second PN associated with the MAC header and a second security key.
27. The device of claim 26, wherein at least one of
28. wherein the one or more processors configured to cause the device to decode the one or more bits comprises the one or more processors configured to cause the device to decode the one or more bits based on the second PN associated with the MAC header and the second security key; The frame further includes a header protection field, the header protection field comprising: an indication of the second PN; and an ID of the second security key; and another integrity check based on the MAC header; Including, 28. The apparatus of claim 27.
29. 20. The apparatus of claim 17, further comprising at least one transceiver configured to receive the frame, the apparatus being configured as a wireless node.
30. 1. A method for wireless communication in a wireless node, comprising: Obtaining a frame, including a security key identifier (ID), a packet number (PN), and an integrity check; verifying the validity of the frame based on a comparison of the integrity check with another integrity check; wherein the further integrity check is based on at least the security key and one or more portions of the frame. method.