Method and apparatus for protecting a media access control (MAC) header of a mac protocol data unit (MPDU)
By adding an additional MIC field to the MPDU to protect vulnerable MAC header fields/bits, the method enhances the security of IEEE 802.11 wireless communications by detecting and preventing tampering attacks.
Patent Information
- Application Number
- PCT/US2024/060581
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-27
- Filing Date
- 2024-12-17
- Publication Date
- 2025-07-03
AI Technical Summary
Current IEEE 802.11 security protocols, such as CCMP and GCMP, do not adequately protect certain fields/bits of the MAC header in MPDUs, making them vulnerable to tampering attacks.
An additional MIC field is added to the MPDU to carry an additional authentication value, generated based on unprotected MAC header fields/bits, allowing for double message integrity checks to verify the integrity of these fields/bits.
Enhances security by detecting and preventing tampering of unprotected MAC header fields/bits, ensuring the integrity and reliability of wireless communications.
Smart Images

Figure US2024060581_03072025_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR PROTECTING A MEDIA ACCESS CONTROL (MAC) HEADER OF A MAC PROTOCOL DATA UNIT (MPDU)CROSS-REFERENCE TO RELATED APPLICATION
[0001] This application claims the benefit of U.S. Provisional Application No. 63 / 614,975 filed December 27, 2023, which is hereby incorporated by reference.TECHNICAL FIELD
[0002] The present disclosure generally relates to wireless communications, and more specifically, relates to protecting a media access control (MAC) header of a MAC protocol data unit (MPDU).BACKGROUND
[0003] Institute of Electrical and Electronics Engineers (IEEE) 802.11 is a set of standards for implementing wireless local area network communication in various frequencies, including but not limited to the 2.4 gigahertz (GHz), 5 GHz, 6 GHz, and 60 GHz bands. These standards define the protocols that enable Wi-Fi devices to communicate with each other. The IEEE 802.11 family of standards has evolved over time to accommodate higher data rates, improved security, and better performance in different environments. Some of the most widely used standards include 802.11a, 802.11b, 802.11g, 802.1 In, 802.1 lac, and 802.1 lax (also known as “Wi-Fi 6”). These standards specify the modulation techniques, channel bandwidths, and other technical aspects that facilitate interoperability between devices from various manufacturers. IEEE 802.11 has played an important role in the widespread adoption of wireless networking in homes, offices, and public spaces, enabling users to connect their devices to the internet and each other without the need for wired connections.
[0004] IEEE 802.1 Ibe, also known as “Wi-Fi 7”, is the next generation of the IEEE 802.11 family of standards for wireless local area networks. Currently under development, 802.1 Ibe aims to significantly improve upon the capabilities of its predecessor, 802.1 lax / Wi-Fi 6, by offering even higher data rates, lower latency, and increased reliability. The standard is expected to leverage advanced technologies such as multi-link operation (MLO), which allows devices to simultaneously use multiple frequency bands and channels for enhanced performance and reliability. Additionally, 802.1 Ibe will introduce 4096-QAM (Quadrature AmplitudeModulation), enabling higher data rates by encoding more bits per symbol. The standard will also feature improved medium access control (MAC) efficiency, enhanced power saving capabilities, and better support for high-density environments. With these advancements, 802.1 Ibe is expected to deliver theoretical maximum data rates of up to 46 gigabits per second (Gbps), making it suitable for bandwidth-intensive applications such as virtual and augmented reality, 8K video streaming, and high-performance gaming. The IEEE 802.1 Ibe standard is projected to be finalized by the end of 2024, paving the way for the next generation of Wi-Fi devices and networks.
[0005] Wireless networking standards define security protocols for encrypting and decrypting a MAC protocol data unit (MPDU) and performing an integrity check of the MPDU. Currently, there are two security protocols that are commonly used: (1) counter mode (CTR) with cipher block chaining message authentication code (CBC-MAC) protocol (CCMP) and (2) Galois / counter mode (GCM) protocol (GCMP). These security protocols encrypt the entire frame body field of data frames. Also, they use some fields of the MAC header and the frame body field to perform a message integrity check (MIC) for the data frame. However, some fi elds / bits of the MAC header are not involved in the encryption process or the MIC in either CCMP or GCMP. As a result, the receiver of the MPDU may not be able to detect when these fi elds / bits have been tampered with, creating a security vulnerability that can be exploited by attackers.BRIEF DESCRIPTION OF THE DRAWINGS
[0006] The disclosure will be more fully understood from the detailed description provided below and the accompanying drawings that depict various embodiments of the disclosure. However, these drawings should not be interpreted as limiting the disclosure to the specific embodiments shown; they are provided for explanation and understanding only.
[0007] Figure 1 illustrates an example of a wireless local area network (WLAN) with a basic service set (BSS) that includes multiple wireless devices, in accordance with some embodiments of the present disclosure.
[0008] Figure 2 is a schematic diagram of a wireless device, in accordance with some embodiments of the present disclosure.
[0009] Figure 3 A illustrates components of a wireless device configured to transmit data, in accordance with some embodiments of the present disclosure.
[0010] Figure 3B illustrates components of a wireless device configured to receive data, in accordance with some embodiments of the present disclosure.
[0011] Figure 4 illustrates interframe space (IFS) relationships, in accordance with some embodiments of the present disclosure.
[0012] Figure 5 illustrates a Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA)-based frame transmission procedure, in accordance with some embodiments of the present disclosure.
[0013] Figure 6 illustrates maximum physical layer (PHY) rates for Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards, in accordance with some embodiments of the present disclosure.
[0014] Figure 7 provides a detailed description of fields in Extremely High Throughput (EHT) Physical Protocol Data Unit (PPDU) frames, including their purposes and characteristics, in accordance with some embodiments of the present disclosure.
[0015] Figure 8 illustrates an example of multi-user (MU) transmission in Orthogonal Frequency -Division Multiple Access (OFDMA), in accordance with some embodiments of the present disclosure.
[0016] Figure 9 illustrates an example of an access point sending a trigger frame to multiple associated stations and receiving Uplink Orthogonal Frequency -Division Multiple Access Trigger-Based Physical Protocol Data Units (UL OFDMA TB PPDUs) in response, in accordance with some embodiments of the present disclosure.
[0017] Figure 10 is a diagram showing a format of a media access control protocol data unit (MPDU) with a non-encrypted frame body field, according to some embodiments.
[0018] Figure 11 is a diagram showing a format of an MPDU with an encrypted frame body field, according to some embodiments.
[0019] Figure 12 is a diagram showing a way to generate additional authentication data (AAD), according to some embodiments.
[0020] Figure 13 is a diagram showing a format of a frame control field, according to some embodiments.
[0021] Figure 14 is a diagram showing a format of a sequence control field, according to some embodiments.
[0022] Figure 15 is a diagram showing a format of a MPDU with an additional message integrity check (MIC) field, according to some embodiments.
[0023] Figure 16 is a diagram showing counter mode with cipher block chaining message authentication code protocol (CCMP) operations, according to some embodiments.
[0024] Figure 17 is a diagram showing Galois / counter mode protocol (GCMP) operations, according to some embodiments.
[0025] Figure 18 is a diagram showing the use of CCMP operations for data encryption and the use of idle GHASH computation resources to generate the additional authentication value, according to some embodiments.
[0026] Figure 19 is a diagram showing the use of GCMP operations for data encryption and the use of idle AES computation resources to generate the additional authentication value, according to some embodiments.
[0027] Figure 20 is a flow diagram of a method for protecting a MAC header of a MPDU, according to some embodiments.
[0028] Figure 21 is a flow diagram of a method for verifying an integrity of a MAC header of a MPDU, according to some embodiments.DETAILED DESCRIPTION
[0029] The present disclosure generally relates to wireless communications, and more specifically, relates to protecting a media access control (MAC) header of a MAC protocol data unit (MPDU).
[0030] Counter mode (CTR) with cipher block chaining message authentication code (CBC- MAC) protocol (CCMP) and Galois / counter mode (GCM) protocol (GCMP) are two commonly used security protocols for protecting MPDUs. In these security protocols, certain fields of the MAC header of the MPDU are used to generate an authentication value. This authentication value is then transmitted in a message integrity check (MIC) field that comes after the encrypted frame body field of the MPDU. A wireless device that receives the MPDU can verify the integrity of the MAC header using the authentication value. However, some fields / bits of the MAC header are not involved in the generation of the authentication value, which means that these fields / bits are unprotected and are vulnerable to tampering. Thus, there is a need for a way to protect the fields / bits of the MAC header that are not protected by conventional CCMP and GCMP methods.
[0031] Techniques are described herein for protecting additional fields / bits of the MAC header that are not protected by conventional CCMP and GCMP methods. According to some embodiments, an additional MIC field is added to a MPDU after the existing MIC field. An additional authentication value is generated based on some of the fields / bits of the MAC header that are not used for generating the existing authentication value. The additional authentication value is inserted in the additional MIC field. A wireless device that receives an MPDU with the additional MIC field may perform a double message integrity check using the authentication values included in the existing MIC field and the additional MIC field, respectively. The MACheader protection techniques described herein can be used to protect fields / bits of the MAC header that are not protected by the conventional CCMP and GCMP methods.
[0032] An embodiment is a method performed by a wireless device to protect a MAC header of a MPDU. The method includes encrypting a payload of the MPDU to generate an encrypted payload, generating first additional authentication data (AAD) based on concatenating a set of fields included in the MAC header and masking one or more bits included in the set of fields, generating a first authentication value based on the first AAD, generating second AAD based on one or more bits of the MAC header that do not contribute to the first AAD, generating a second authentication value based on the second AAD, and generating the MPDU, where the MPDU includes the MAC header, a security protocol header that carries information for decrypting the encrypted payload, a frame body field that carries the encrypted payload, a first message integrity check (MIC) field that carries the first authentication value, and a second MIC field that carries the second authentication value. The method further includes transmitting the MPDU.
[0033] An embodiment is a wireless device configured to protect a MAC header of a MPDU. The wireless device includes encryption circuitry operable to encrypt a payload of the MPDU to generate an encrypted payload, first authentication value generation circuitry operable to generate a first AAD based on concatenating a set of fields included in the MAC header and masking one or more bits included in the set of fields and generate a first authentication value based on the first AAD, second authentication value generation circuitry operable to generate second AAD based on one or more bits of the MAC header that do not contribute to the first AAD and generate a second authentication value based on the second AAD, MAC circuitry operable to generate the MPDU, wherein the MPDU includes the MAC header, a security protocol header that carries information for decrypting the encrypted payload, a frame body field that carries the encrypted payload, a first MIC field that carries the first authentication value, and a second MIC field that carries the second authentication value, and a wireless transmitter operable to transmit the MPDU.
[0034] An embodiment is a method performed by a wireless device to verify an integrity of a MAC header of a MPDU. The method includes receiving a MPDU, where the MPDU includes the MAC header, a security protocol header that carries information for decrypting an encrypted payload, a frame body field that carries the encrypted payload, a first MIC field that carries a first authentication value, and a second MIC field that carries a second authentication value. The method further includes decrypting the encrypted payload using the information for decrypting the encrypted payload to recover an unencrypted payload, verifying an integrity of afirst set of bits included in the MAC header using the first authentication value, verifying an integrity of a second set of bits included in the MAC header using the second authentication value, and accepting and processing the MAC header in response to successfully verifying the integrity of the first set of bits and the integrity of the second set of bits.
[0035] An embodiment is a wireless device configured to verify an integrity of a MAC header of a MPDU. The wireless device includes a wireless receiver operable to receive the MPDU, wherein the MPDU includes the MAC header, a security protocol header that carries information for decrypting an encrypted payload, a frame body field that carries the encrypted payload, a first MIC field that carries a first authentication value, and a second MIC field that carries a second authentication value, decryption circuitry operable to decrypt the encrypted payload using the information for decrypting the encrypted payload to recover an unencrypted payload, first authentication value verification circuitry operable to verify an integrity of a first set of bits included in the MAC header using the first authentication value, second authentication value verification circuitry operable to verify an integrity of a second set of bits included in the MAC header using the second authentication value, and MAC circuitry operable to accept and process the MAC header in response to the integrity of the first set of bits and the integrity of the second set of bits being successfully verified.
[0036] The MAC header protection techniques described herein may provide one or more advantages. The security protocols currently defined in the IEEE 802.11 wireless networking standards do not protect some fields / bits of the MAC header, which makes those fields / bits vulnerable to tampering / attacks. To address this problem, the MAC header protection techniques described herein add an additional MIC field to the MPDU that can be used to protect the fields / bits of the MAC header that are not protected by conventional security protocol methods (e.g., conventional CCMP and GCMP methods). While certain advantages are mentioned here, one of ordinary skill in the relevant art will appreciate that the techniques disclosed herein may have other advantages in view of the present disclosure.
[0037] For purposes of illustration, various embodiments are described herein in the context of wireless networks that are based on IEEE 802.11 standards and using terminology and concepts thereof. Those skilled in the art will appreciate that the embodiments disclosed herein can be modified / adapted for use in other types of wireless networks.
[0038] In the following detailed description, only certain embodiments of the present invention have been shown and described, simply by way of illustration. As those skilled in the art would realize, the described embodiments may be modified in different ways, all without departing from the spirit or scope of the present invention. Accordingly, the drawings anddescription are to be regarded as illustrative in nature and not restrictive. Like reference numerals designate like elements throughout the specification.
[0039] Figure 1 shows a wireless local area network (WLAN) 100 with a basic service set (BSS) 102 that includes a plurality of wireless devices 104 (sometimes referred to as WLAN devices 104). Each of the wireless devices 104 may include a medium access control (MAC) layer and a physical (PHY) layer according to an IEEE (Institute of Electrical and Electronics Engineers) standard 802.11, including one or more of the amendments(e.g., 802.1 la / b / g / n / p / ac / ax / bd / be). In one embodiment, the MAC layer of a wireless device 104 may initiate transmission of a frame to another wireless device 104 by passing a PHY- TXSTART. request (TXVECTOR) to the PHY layer. The TXVECTOR provides parameters for generating and / or transmitting a corresponding frame. Similarly, a PHY layer of a receiving wireless device may generate an RXVECTOR, which includes parameters of a received frame and is passed to a MAC layer for processing.
[0040] The plurality of wireless devices 104 may include a wireless device 104A that is an access point (sometimes referred to as an AP station or AP STA) and the other wireless devices 104B1-104B4 that are non-AP stations (sometimes referred to as non-AP STAs). Alternatively, all the plurality of wireless devices 104 may be non-AP STAs in an ad-hoc networking environment. In general, the AP STA (e.g., wireless device 104 A) and the non-AP STAs (e.g., wireless devices 104B1-104B4) may be collectively referred to as STAs. However, for ease of description, only the non-AP STAs may be referred to as STAs unless the context indicates otherwise. Although shown with four non-AP STAs (e.g., the wireless devices 104B1- IO4B4), the WLAN 100 may include any number of non-AP STAs (e.g., one or more wireless devices 104B).
[0041] Figure 2 illustrates a schematic block diagram of a wireless device 104, according to an embodiment. The wireless device 104 may be the wireless device 104 A (i.e., the AP of the WLAN 100) or any of the wireless devices 104B1-104B4 in Figure 1. The wireless device 104 includes a baseband processor 210, a radio frequency (RF) transceiver 240, an antenna unit 250, a storage device (e.g., memory device) 232, one or more input interfaces 234, and one or more output interfaces 236. The baseband processor 210, the storage device 232, the input interfaces 234, the output interfaces 236, and the RF transceiver 240 may communicate with each other via a bus 260.
[0042] The baseband processor 210 performs baseband signal processing and includes a MAC processor 212 and a PHY processor 222. The baseband processor 210 may utilize thememory 232, which may include a non-transitory computer / machine readable medium having software (e.g., computer / machine programing instructions) and data stored therein.
[0043] In an embodiment, the MAC processor 212 includes a MAC software processing unit 214 and a MAC hardware processing unit 216. The MAC software processing unit 214 may implement a first plurality of functions of the MAC layer by executing MAC software, which may be included in the software stored in the storage device 232. The MAC hardware processing unit 216 may implement a second plurality of functions of the MAC layer in specialpurpose hardware. However, the MAC processor 212 is not limited thereto. For example, the MAC processor 212 may be configured to perform the first and second plurality of functions entirely in software or entirely in hardware according to an implementation.
[0044] The PHY processor 222 includes a transmitting (TX) signal processing unit (SPU) 224 and a receiving (RX) SPU 226. The PHY processor 222 implements a plurality of functions of the PHY layer. These functions may be performed in software, hardware, or a combination thereof according to an implementation.
[0045] Functions performed by the transmitting SPU 224 may include one or more of Forward Error Correction (FEC) encoding, stream parsing into one or more spatial streams, diversity encoding of the spatial streams into a plurality of space-time streams, spatial mapping of the space-time streams to transmit chains, inverse Fourier Transform (iFT) computation, Cyclic Prefix (CP) insertion to create a Guard Interval (GI), and the like. Functions performed by the receiving SPU 226 may include inverses of the functions performed by the transmitting SPU 224, such as GI removal, Fourier Transform computation, and the like.
[0046] The RF transceiver 240 includes an RF transmitter 242 and an RF receiver 244. The RF transceiver 240 is configured to transmit first information received from the baseband processor 210 to the WLAN 100 (e.g., to another WLAN device 104 of the WLAN 100) and provide second information received from the WLAN 100 (e.g., from another WLAN device 104 of the WLAN 100) to the baseband processor 210.
[0047] The antenna unit 250 includes one or more antennas. When Multiple-Input Multiple- Output (MIMO) or Multi-User MIMO (MU-MIMO) is used, the antenna unit 250 may include a plurality of antennas. In an embodiment, the antennas in the antenna unit 250 may operate as a beam-formed antenna array. In an embodiment, the antennas in the antenna unit 250 may be directional antennas, which may be fixed or steerable.
[0048] The input interfaces 234 receive information from a user, and the output interfaces 236 output information to the user. The input interfaces 234 may include one or more of a keyboard,keypad, mouse, touchscreen, microphone, and the like. The output interfaces 236 may include one or more of a display device, touch screen, speaker, and the like.
[0049] As described herein, many functions of the WLAN device 104 may be implemented in either hardware or software. Which functions are implemented in software and which functions are implemented in hardware will vary according to constraints imposed on a design. The constraints may include one or more of design cost, manufacturing cost, time to market, power consumption, available semiconductor technology, etc.
[0050] As described herein, a wide variety of electronic devices, circuits, firmware, software, and combinations thereof may be used to implement the functions of the components of the WLAN device 104. Furthermore, the WLAN device 104 may include other components, such as application processors, storage interfaces, clock generator circuits, power supply circuits, and the like, which have been omitted in the interest of brevity.
[0051] Figure 3 A illustrates components of a WLAN device 104 configured to transmit data according to an embodiment, including a transmitting (Tx) SPU (TxSP) 324, an RF transmitter 342, and an antenna 352. In an embodiment, the TxSP 324, the RF transmitter 342, and the antenna 352 correspond to the transmitting SPU 224, the RF transmitter 242, and an antenna of the antenna unit 250 of Figure 2, respectively.
[0052] The TxSP 324 includes an encoder 300, an interleaver 302, a mapper 304, an inverse Fourier transformer (TFT) 306, and a guard interval (GI) inserter 308.
[0053] The encoder 300 receives and encodes input data. In an embodiment, the encoder 300 includes a forward error correction (FEC) encoder. The FEC encoder may include a binary convolution code (BCC) encoder followed by a puncturing device. The FEC encoder may include a low-density parity-check (LDPC) encoder.
[0054] The TxSP 324 may further include a scrambler for scrambling the input data before the encoding is performed by the encoder 300 to reduce the probability of long sequences of 0s or Is. When the encoder 300 performs the BCC encoding, the TxSP 324 may further include an encoder parser for demultiplexing the scrambled bits among a plurality of BCC encoders. If LDPC encoding is used in the encoder, the TxSP 324 may not use the encoder parser.
[0055] The interleaver 302 interleaves the bits of each stream output from the encoder 300 to change an order of bits therein. The interleaver 302 may apply the interleaving only when the encoder 300 performs BCC encoding and otherwise may output the stream output from the encoder 300 without changing the order of the bits therein.
[0056] The mapper 304 maps the sequence of bits output from the interleaver 302 to constellation points. If the encoder 300 performed LDPC encoding, the mapper 304 may also perform LDPC tone mapping in addition to constellation mapping.
[0057] When the TxSP 324 performs a MIMO or MU-MIMO transmission, the TxSP 324 may include a plurality of interleavers 302 and a plurality of mappers 304 according to a number of spatial streams (NSS) of the transmission. The TxSP 324 may further include a stream parser for dividing the output of the encoder 300 into blocks and may respectively send the blocks to different interleavers 302 or mappers 304. The TxSP 324 may further include a space-time block code (STBC) encoder for spreading the constellation points from the spatial streams into a number of space-time streams (NSTS) and a spatial mapper for mapping the space-time streams to transmit chains. The spatial mapper may use direct mapping, spatial expansion, or beamforming.
[0058] The IFT 306 converts a block of the constellation points output from the mapper 304 (or, when MIMO or MU-MIMO is performed, the spatial mapper) to a time domain block (i.e., a symbol) by using an inverse discrete Fourier transform (IDFT) or an inverse fast Fourier transform (IFFT). If the STBC encoder and the spatial mapper are used, the IFT 306 may be provided for each transmit chain.
[0059] When the TxSP 324 performs a MIMO or MU-MIMO transmission, the TxSP 324 may insert cyclic shift diversities (CSDs) to prevent unintentional beamforming. The TxSP 324 may perform the insertion of the CSD before or after the IFT 306. The CSD may be specified per transmit chain or may be specified per space-time stream. Alternatively, the CSD may be applied as a part of the spatial mapper.
[0060] When the TxSP 324 performs a MIMO or MU-MIMO transmission, some blocks before the spatial mapper may be provided for each user.
[0061] The GI inserter 308 prepends a GI to each symbol produced by the IFT 306. Each GI may include a Cyclic Prefix (CP) corresponding to a repeated portion of the end of the symbol that the GI precedes. The TxSP 324 may optionally perform windowing to smooth edges of each symbol after inserting the GI.
[0062] The RF transmitter 342 converts the symbols into an RF signal and transmits the RF signal via the antenna 352. When the TxSP 324 performs a MIMO or MU-MIMO transmission, the GI inserter 308 and the RF transmitter 342 may be provided for each transmit chain.
[0063] Figure 3B illustrates components of a WLAN device 104 configured to receive data according to an embodiment, including a Receiver (Rx) SPU (RxSP) 326, an RF receiver 344, and an antenna 354. In an embodiment, the RxSP 326, RF receiver 344, and antenna 354 maycorrespond to the receiving SPU 226, the RF receiver 244, and an antenna of the antenna unit 250 of Figure 2, respectively.
[0064] The RxSP 326 includes a GI remover 318, a Fourier transformer (FT) 316, a demapper 314, a deinterleaver 312, and a decoder 310.
[0065] The RF receiver 344 receives an RF signal via the antenna 354 and converts the RF signal into symbols. The GI remover 318 removes the GI from each of the symbols. When the received transmission is a MIMO or MU-MIMO transmission, the RF receiver 344 and the GI remover 318 may be provided for each receive chain.
[0066] The FT 316 converts each symbol (that is, each time domain block) into a frequency domain block of constellation points by using a discrete Fourier transform (DFT) or a fast Fourier transform (FFT). The FT 316 may be provided for each receive chain.
[0067] When the received transmission is the MIMO or MU-MIMO transmission, the RxSP 326 may include a spatial demapper for converting the respective outputs of the FTs 316 of the receiver chains to constellation points of a plurality of space-time streams, and an STBC decoder for despreading the constellation points from the space-time streams into one or more spatial streams.
[0068] The demapper 314 demaps the constellation points output from the FT 316 or the STBC decoder to bit streams. If the received transmission was encoded using LDPC encoding, the demapper 314 may further perform LDPC tone demapping before performing the constellation demapping.
[0069] The deinterleaver 312 deinterleaves the bits of each stream output from the demapper 314. The deinterleaver 312 may perform the deinterleaving only when the received transmission was encoded using BCC encoding, and otherwise may output the stream output by the demapper 314 without performing deinterleaving.
[0070] When the received transmission is the MIMO or MU-MIMO transmission, the RxSP 326 may use a plurality of demappers 314 and a plurality of deinterleavers 312 corresponding to the number of spatial streams of the transmission. In this case, the RxSP 326 may further include a stream deparser for combining the streams output from the deinterleavers 312.
[0071] The decoder 310 decodes the streams output from the deinterleaver 312 or the stream deparser. In an embodiment, the decoder 310 includes an FEC decoder. The FEC decoder may include a BCC decoder or an LDPC decoder.
[0072] The RxSP 326 may further include a descrambler for descrambling the decoded data. When the decoder 310 performs BCC decoding, the RxSP 326 may further include an encoderdeparser for multiplexing the data decoded by a plurality of BCC decoders. When the decoder 310 performs the LDPC decoding, the RxSP 326 may not use the encoder deparser.
[0073] Before making a transmission, wireless devices such as wireless device 104 will assess the availability of the wireless medium using Clear Channel Assessment (CCA). If the medium is occupied, CCA may determine that it is busy, while if the medium is available, CCA determines that it is idle.
[0074] The PHY entity for IEEE 802.11 is based on Orthogonal Frequency Division Multiplexing (OFDM) or Orthogonal Frequency Division Multiple Access (OFDMA). In either OFDM or OFDMA Physical (PHY) layers, a STA (e.g., a wireless device 104) is capable of transmitting and receiving Physical Layer (PHY) Protocol Data Units (PPDUs) (also referred to as PLCP (Physical Layer Convergence Procedure) Protocol Data Units) that are compliant with the mandatory PHY specifications. A PHY specification defines a set of Modulation and Coding Schemes (MCS) and a maximum number of spatial streams. Some PHY entities define downlink (DL) and uplink (UL) Multi-User (MU) transmissions having a maximum number of space-time streams (STS) per user and employing up to a predetermined total number of STSs. A PHY entity may provide support for 10 Megahertz (MHz), 20 MHz, 40 MHz, 80 MHz, 160 MHz, 240 MHz, and 320 MHz contiguous channel widths and support for an 80+80, 80+160 MHz, and 160+160 MHz non-contiguous channel width. Each channel includes a plurality of subcarriers, which may also be referred to as tones. A PHY entity may define signaling fields denoted as Legacy Signal (L-SIG), Signal A (SIG-A), and Signal B (SIG-B), and the like within a PPDU by which some necessary information about PHY Service Data Unit (PSDU) attributes are communicated. The descriptions below, for sake of completeness and brevity, refer to OFDM-based 802.11 technology. Unless otherwise indicated, a station refers to a non-AP STA.
[0075] Figure 4 illustrates Inter-Frame Space (IFS) relationships. In particular, Figure 4 illustrates a Short IFS (SIFS), a Point Coordination Function (PCF) IFS (PIFS), a Distributed Coordination Function (DCF) IFS (DIFS), and an Arbitration IFSs corresponding to an Access Category (AC) ‘i’ (AIFS[i]). Figure 4 also illustrates a slot time and a data frame is used for transmission of data forwarded to a higher layer. As shown, a WLAN device 104 transmits the data frame after performing backoff if a DIFS has elapsed during which the medium has been idle.
[0076] A management frame may be used for exchanging management information, which is not forwarded to the higher layer. Subtype frames of the management frame include a beacon frame, an association request / response frame, a probe request / response frame, and an authentication request / response frame.
[0077] A control frame may be used for controlling access to the medium. Subtype frames of the control frame include a request to send (RTS) frame, a clear to send (CTS) frame, and an acknowledgement (ACK) frame.
[0078] When the control frame is not a response frame of another frame, the WLAN device 104 transmits the control frame after performing backoff if a DIFS has elapsed during which the medium has been idle. When the control frame is the response frame of another frame, the WLAN device 104 transmits the control frame after a SIFS has elapsed without performing backoff or checking whether the medium is idle.
[0079] A WLAN device 104 that supports Quality of Service (QoS) functionality (that is, a QoS STA) may transmit the frame after performing backoff if an AIFS for an associated access category (AC) (i.e., AIFS[AC]) has elapsed. When transmitted by the QoS STA, any of the data frame, the management frame, and the control frame, which is not the response frame, may use the AIFS[AC] of the AC of the transmitted frame.
[0080] A WLAN device 104 may perform a backoff procedure when the WLAN device 104 that is ready to transfer a frame finds the medium busy. The backoff procedure includes determining a random backoff time composed of N backoff slots, where each backoff slot has a duration equal to a slot time and N being an integer number greater than or equal to zero. The backoff time may be determined according to a length of a Contention Window (CW). In an embodiment, the backoff time may be determined according to an AC of the frame. All backoff slots occur following a DIFS or Extended IFS (EIFS) period during which the medium is determined to be idle for the duration of the period.
[0081] When the WLAN device 104 detects no medium activity for the duration of a particular backoff slot, the backoff procedure shall decrement the backoff time by the slot time. When the WLAN device 104 determines that the medium is busy during a backoff slot, the backoff procedure is suspended until the medium is again determined to be idle for the duration of a DIFS or EIFS period. The WLAN device 104 may perform transmission or retransmission of the frame when the backoff timer reaches zero.
[0082] The backoff procedure operates so that when multiple WLAN devices 104 are deferring and execute the backoff procedure, each WLAN device 104 may select a backoff time using a random function and the WLAN device 104 that selects the smallest backoff time may win the contention, reducing the probability of a collision.
[0083] Figure 5 illustrates a Carrier Sense Multiple Access / Collision Avoidance (CSMA / CA) based frame transmission procedure for avoiding collision between frames in a channel according to an embodiment. Figure 5 shows a first station STA1 transmitting data, a secondstation STA2 receiving the data, and a third station STA3 that may be located in an area where a frame transmitted from the STA1 can be received, a frame transmitted from the second station STA2 can be received, or both can be received. The stations STA1, STA2, and STA3 may be WLAN devices 104 of Figure 1.
[0084] The station STA1 may determine whether the channel is busy by carrier sensing. The station STA1 may determine channel occupation / status based on an energy level in the channel or an autocorrelation of signals in the channel, or may determine the channel occupation by using a network allocation vector (NAV) timer.
[0085] After determining that the channel is not used by other devices (that is, that the channel is IDLE) during a DIFS (and performing backoff if required), the station STA1 may transmit a Request-To-Send (RTS) frame to the station STA2. Upon receiving the RTS frame, after a SIFS the station STA2 may transmit a Clear-To-Send (CTS) frame as a response to the RTS frame. If Dual-CTS is enabled and the station STA2 is an AP, the AP may send two CTS frames in response to the RTS frame (e.g., a first CTS frame in a non-High Throughput format and a second CTS frame in the HT format).
[0086] When the station STA3 receives the RTS frame, it may set a NAV timer of the station STA3 for a transmission duration of subsequently transmitted frames (for example, a duration of SIFS + CTS frame duration + SIFS + data frame duration + SIFS + ACK frame duration) using duration information included in the RTS frame. When the station STA3 receives the CTS frame, it may set the NAV timer of the station STA3 for a transmission duration of subsequently transmitted frames using duration information included in the CTS frame. Upon receiving a new frame before the NAV timer expires, the station STA3 may update the NAV timer of the station STA3 by using duration information included in the new frame. The station STA3 does not attempt to access the channel until the NAV timer expires.
[0087] When the station STA1 receives the CTS frame from the station STA2, it may transmit a data frame to the station STA2 after a SIFS period elapses from a time when the CTS frame has been completely received. Upon successfully receiving the data frame, the station STA2 may transmit an ACK frame as a response to the data frame after a SIFS period elapses.
[0088] When the NAV timer expires, the third station STA3 may determine whether the channel is busy using the carrier sensing. Upon determining that the channel is not used by other devices during a DIFS period after the NAV timer has expired, the station STA3 may attempt to access the channel after a contention window elapses according to a backoff process.
[0089] When Dual-CTS is enabled, a station that has obtained a transmission opportunity (TXOP) and that has no data to transmit may transmit a CF-End frame to cut short the TXOP.An AP receiving a CF-End frame having a Basic Service Set Identifier (BSSID) of the AP as a destination address may respond by transmitting two more CF-End frames: a first CF-End frame using Space Time Block Coding (STBC) and a second CF-End frame using non-STBC. A station receiving a CF-End frame resets its NAV timer to 0 at the end of the PPDU containing the CF-End frame. Figure 5 shows the station STA2 transmitting an ACK frame to acknowledge the successful reception of a frame by the recipient.
[0090] The IEEE 802.1 Ibn (Ultra High Reliability, UHR) working group has been established to address the growing demand for higher peak throughput and reliability in Wi-Fi. As shown in Figure 6, the peak PHY rate has significantly increased from IEEE 802.1 lb to IEEE 802.1 Ibe (Wi-Fi 7), with the latter focusing on further improving peak throughput. The UHR study group aims to enhance the tail of the latency distribution and jitter to support applications that require low latency, such as video-over- WLAN, gaming, AR, and VR. It is noted that various characteristics of UHR (e.g., max PHY rate, PHY rate enhancement, bandwidth / number of spatial streams, and operating bands) are still to be determined.
[0091] The focus of IEEE 802.1 Ibe is primarily on WLAN indoor and outdoor operation with stationary and pedestrian speeds in the 2.4, 5, and 6 GHz frequency bands. In addition to peak PHY rate, different candidate features are under discussion. These candidate features include (1) a 320MHz bandwidth and a more efficient utilization of a non-contiguous spectrum, (2) multi -band / multi-channel aggregation and operation, (3) 16 spatial streams and Multiple Input Multiple Output (MIMO) protocol enhancements, (4) multi-Access Point (AP) Coordination (e.g., coordinated and joint transmission), (5) an enhanced link adaptation and retransmission protocol (e.g., Hybrid Automatic Repeat Request (HARQ)), and (6) adaptation to regulatory rules specific to a 6 GHz spectrum.
[0092] The focus of IEEE 802.1 Ibn (UHR) is still under discussion, with candidate features including MLO enhancements (e.g., in terms of increased throughput / reliability and decreased latency), latency and reliability improvements (e.g., multi-AP coordination to support low latency traffic), bandwidth expansion (e.g., to 240, 480, 640 MHz), aggregated PPDU (A- PPDU), enhanced multi-link single-radio (eMLSR) extensions to AP, roaming improvements, and power-saving schemes for prolonging battery life.
[0093] Some features, such as increasing the bandwidth and the number of spatial streams, are solutions that have been proven to be effective in previous projects focused on increasing link throughput and on which feasibility demonstration is achievable.
[0094] With respect to operational bands (e.g., 2.4 / 5 / 6 GHz) for IEEE 802.1 Ibe, more than 1 GHz of additional unlicensed spectrum is likely to be available because the 6 GHz band (5.925- 7.125 GHz) is being considered for unlicensed use. This would allow APs and STAs to become tri-band devices. Larger than 160MHz data transmissions (e.g., 320 MHz or 640 MHz) could be considered to increase the maximum PHY rate. For example, 320 MHz or 160+160MHz data could be transmitted in the 6 GHz band. For example, 160+160 MHz data could be transmitted across the 5 and 6 GHz bands.
[0095] In the process of wireless communication, a transmitting station (STA) creates a Physical Layer Protocol Data Unit (PPDU) frame and sends it to a receiving STA. The receiving STA then receives, detects, and processes the PPDU.
[0096] The Extremely High Throughput (EHT) PPDU frame encompasses several components. It includes a legacy part, which comprises fields such as the Legacy Short Training Field (L-STF), Legacy Long Training Field (L-LTF), Legacy Signal Field (L-SIG), and Repeated Legacy Signal Field (RL-SIG). These fields are used to maintain compatibility with older Wi-Fi standards.
[0097] In addition to the legacy part, the EHT PPDU frame also contains the Universal Signal Field (U-SIG), EHT Signal Field (EHT-SIG), EHT Short Training Field (EHT-STF), and EHT Long Training Field (EHT-LTF). These fields are specific to the EHT standard and are used for various purposes, such as signaling, synchronization, and channel estimation.
[0098] Figure 7 provides a more detailed description of each field in the EHT PPDU frame, including their purposes and characteristics.
[0099] Regarding the Ultra High Reliability (UHR) PPDU, its frame structure is currently undefined and will be determined through further discussions within the relevant working group or study group. This indicates that the specifics of the UHR PPDU are still under development and will be finalized based on the outcomes of future deliberations.
[0100] The distributed nature of channel access networks, such as IEEE 802.11 WLANs, makes the carrier sense mechanism useful for ensuring collision-free operation. Each station (STA) uses its physical carrier sense to detect transmissions from other STAs. However, in certain situations, it may not be possible for a STA to detect every transmission. For instance, when one STA is located far away from another STA, it might perceive the medium as idle and start transmitting a frame, leading to collisions. To mitigate this hidden node problem, the network allocation vector (NAV) has been introduced.
[0101] As the IEEE 802.11 standard continues to evolve, it now includes scenarios where multiple users can simultaneously transmit or receive data within a basic service set (BSS), such as uplink (UL) and downlink (DL) multi-user (MU) transmissions in a cascaded manner. In these cases, the existing carrier sense and NAV mechanisms may not be sufficient, andmodifications or newly defined mechanisms may be required to facilitate efficient and collision- free operation.
[0102] For the purpose of this disclosure, MU transmission refers to situations where multiple frames are transmitted to or from multiple STAs simultaneously using different resources. Examples of these resources include different frequency resources in Orthogonal Frequency Division Multiple Access (OFDMA) transmission and different spatial streams in Multi-User Multiple Input Multiple Output (MU-MIMO) transmission. Consequently, downlink OFDMA (DL-OFDMA), downlink MU-MIMO (DL-MU-MIMO), uplink OFDMA (UL- OFDMA), uplink MU-MIMO (UL-MU-MIMO), and OFDMA with MU-MIMO are all considered examples of MU transmission.
[0103] Figure 8 illustrates an example of multi-user (MU) transmission in Orthogonal Frequency -Division Multiple Access (OFDMA), in accordance with some embodiments of the present disclosure.
[0104] In the IEEE 802.1 lax and 802.1 Ibe specifications, the trigger frame plays a useful role in facilitating uplink multi-user (MU) transmissions. The purpose of the trigger frame is to allocate resources and solicit one or more Trigger-based (TB) Physical Layer Protocol Data Unit (PPDU) transmissions from the associated stations (STAs).
[0105] The trigger frame contains information required by the responding STAs to send their Uplink TB PPDUs. This information includes the Trigger type, which specifies the type of TB PPDU expected, and the Uplink Length (UL Length), which indicates the duration of the uplink transmission.
[0106] Figure 9 illustrates an example scenario where an access point (AP) operating in an 80MHz bandwidth environment sends a Trigger frame to multiple associated STAs. Upon receiving the Trigger frame, the STAs respond by sending their respective Uplink Orthogonal Frequency Division Multiple Access (UL OFDMA) TB PPDUs, utilizing the allocated resources within the specified 80 MHz bandwidth.
[0107] After successfully receiving the UL OFDMA TB PPDUs, the AP acknowledges the STAs by sending an acknowledgement frame. This acknowledgement can be in the form of an 80MHz width multi-STA Block Acknowledgement (Block Ack) or a Block Acknowledgement with a Direct Feedback (DF) OFDMA method. The multi-STA Block Ack allows the AP to acknowledge multiple STAs simultaneously, while the Block Ack with DF OFDMA enables the AP to provide feedback to the STAs using the same OFDMA technique employed in the uplink transmission.
[0108] The trigger frame is a useful component in enabling efficient uplink MU transmissions in IEEE 802.1 lax and 802.1 Ibe networks, by allocating resources and coordinating the uplink transmissions from multiple STAs within the same bandwidth.
[0109] Wireless network systems can rely on retransmission of media access control (MAC) protocol data units (MPDUs) when the transmitter (TX) does not receive an acknowledgement from the receiver (RX) or MPDUs are not successfully decoded by the receiver. Using an automatic repeat request (ARQ) approach, the receiver discards the last failed MPDU before receiving the newly retransmitted MPDU. With requirements of enhanced reliability and reduced latency, the wireless network system can evolve toward a hybrid ARQ (HARQ) approach.
[0110] There are two methods of HARQ processing. In a first type of HARQ scheme, also referred to as chase combining (CC) HARQ (CC-HARQ) scheme, signals to be retransmitted are the same as the signals that previously failed because all subpackets to be retransmitted use the same puncturing pattern. The puncturing is needed to remove some of the parity bits after encoding using an error-correction code. The reason why the same puncturing pattern is used with CC-HARQ is to generate a coded data sequence with forward error correction (FEC) and to make the receiver use a maximum-ratio combining (MRC) to combine the received, retransmitted bits with the same bits from the previous transmission. For example, information sequences are transmitted in packets with a fixed length. At a receiver, error correction and detection are carried out over the whole packet. However, the ARQ scheme may be inefficient in the presence of burst errors. To solve this more efficiently, subpackets are used. In subpacket transmissions, only those subpackets that include errors need to be retransmitted.
[0111] Since the receiver uses both the current and the previously received subpackets for decoding data, the error probability in decoding decreases as the number of used subpackets increases. The decoding process passes a cyclic redundancy check (CRC) and ends when the entire packet is decoded without error or the maximum number of subpackets is reached. In particular, this scheme operates on a stop-and-wait protocol such that if the receiver can decode the packet, it sends an acknowledgement (ACK) to the transmitter. When the transmitter receives an ACK successfully, it terminates the HARQ transmission of the packet. If the receiver cannot decode the packet, it sends a negative acknowledgement (NAK) to the transmitter and the transmitter performs the retransmission process.
[0112] In a second type of HARQ scheme, also referred to as an incremental redundancy (IR) HARQ (IR-HARQ) scheme, different puncturing patterns are used for each subpacket such that the signal changes for each retransmitted subpacket in comparison to the originally transmittedsubpacket. IR-HARQ alternatively uses two puncturing patterns for odd numbered and even numbered transmissions, respectively. The redundancy scheme of IR-HARQ improves the log likelihood ratio (LLR) of parity bit(s) in order to combine information sent across different transmissions due to requests and lowers the code rate as the additional subpacket is used. This results in a lower error rate of the subpacket in comparison to CC-HARQ. The puncturing pattern used in IR-HARQ is indicated by a subpacket identity (SPID) indication. The SPID of the first subpacket may always be set to 0 and all the systematic bits and the punctured parity bits are transmitted in the first subpacket. Self-decoding is possible when the receiving signal- to-noise ratio (SNR) environment is good (i.e., a high SNR). In some embodiments, subpackets with corresponding SPIDs to be transmitted are in increasing order of SPID but can be exchanged / switched except for the first SPID.
[0113] AP coordination has been considered as a potential technology to improve WLAN system throughput in the IEEE 802.1 Ibe standard and is still being discussed in the IEEE 802.11bn (UHR) standard. To support various AP coordination schemes, such as coordinated beamforming, OFDMA, TDMA, spatial reuse, and joint transmission, a predefined mechanism for APs is necessary.
[0114] In the context of coordinated TDMA (C-TDMA), the AP that obtains a transmit opportunity (TXOP) is referred to as the sharing AP. This AP initiates the AP coordination schemes to determine the AP candidate set by sending a frame, such as a Beacon frame or probe response frame, which includes information about the AP coordination scheme capabilities. The AP that participates in the AP coordination schemes after receiving the frame from the sharing AP is called the shared AP. The sharing AP is also known as the master AP or coordinating AP, while the shared AP is referred to as the slave AP or coordinated AP.
[0115] The operation of various AP coordination schemes has been discussed in the IEEE 802.1 Ibe and UHR standards:
[0116] Coordinated Beamforming (C-BF): Multiple APs transmit on the same frequency resource by coordinating and forming spatial nulls, allowing for simultaneous transmission from multiple APs.
[0117] Coordinated OFDMA (C-OFDMA): APs transmit on orthogonal frequency resources by coordinating and splitting the spectrum, enabling more efficient spectrum utilization.
[0118] Joint Transmission (JTX): Multiple APs transmit jointly to a given user simultaneously by sharing data between the APs.
[0119] Coordinated Spatial Reuse (C-SR): Multiple APs or STAs adjust their transmit power to reduce interference between APs.
[0120] By implementing these AP coordination schemes, WLAN systems can improve their overall throughput and efficiency by leveraging the cooperation between multiple APs.
[0121] Counter mode with cipher block chaining message authentication code protocol (CCMP) and Galois / counter mode protocol (GCMP) are widely used security protocols for encrypting MPDUs. CCMP is based on the advanced encryption standard (AES) algorithm and the cipher block chaining message authentication code (CBC-MAC) technique. GCMP is also based on the AES algorithm but uses the Galois message authentication code (GMAC) technique. Both CCMP and GCMP have two variants, depending on the length of the encryption key: CCMP-128 and CCMP-256 use 128-bit and 256-bit keys, respectively, and GCMP-128 and GCMP -256 also use 128-bit and 256-bit keys, respectively.
[0122] Figure 10 is a diagram showing a format of a MPDU with a non-encrypted frame body field, according to some embodiments.
[0123] As shown in the diagram, the MPDU may include a MAC header 1010, a frame body field 1030, and a frame check sequence (FCS) field 1040. The MAC header 1010 may include a frame control field 1012 (2 bytes), a duration / ID field 1014 (2 bytes), an address 1 field 1016 (6 bytes), an address 2 field 1018 (0 or 6 bytes), an address 3 field 1020 (0 or 6 bytes), a sequence control field 1022 (0 or 2 bytes), an address 4 field 1024 (0 or 6 bytes), a quality of service (QoS) control field 1026 (0 or 2 bytes), and a high throughput (HT) control field 1028 (0 or 4 bytes). The frame control field 1012 may include general information about the MPDU such as its type and subtype. The duration / ID field 1014 may include information regarding the remaining time for consecutive frame exchanges or an association identifier (AID) depending on the type and subtype of the MPDU. The address fields (e.g., address 1 field 1016, address 2 field 1018, address 3 field 1020, and / or address 4 field 1024) may include the address of the transmitter and receiver of the MPDU, as well as any intermediate wireless devices that are involved in the transmission. The frame body field 1030 may carry the payload of the MPDU, which may vary depending on the type and subtype of the MPDU. The FCS field 1040 may carry a 32-bit cyclic redundancy check (CRC) value, which can be used to verify the integrity and validity of the MAC header 1010 and the frame body field 1030. In general, CRC provides simple data integrity, whereas MIC provides cryptographic integrity.
[0124] Figure 11 is a diagram showing a format of an MPDU with an encrypted frame body field, according to some embodiments.
[0125] As shown in the diagram, the MPDU may include a MAC header 1110, a CCMP / GCMP header 1140 (8 bytes), a (encrypted) frame body field 1150, a MIC field 1160 (8 or 16 bytes), and a FCS field 1170. The CCMP / GCMP header 1140 may include a packetnumber 0 (PNO) field 1112 (1 byte), a PN1 field 1114 (1 byte), a reserved (Rsvd) field 1116 (1 byte), a key ID octet field 1118 (1 byte), a PN2 field 1126 (1 byte), a PN3 field 1128 (1 byte), a PN4 field 1130 (1 byte), and a PN5 field 1132 (1 byte). The key ID octet field 1118 may include a reserved field 1120 (5 bits), an extended initialization vector (IV) field 1122 (1 bits), and a key ID field 1124 (2 bits).
[0126] Both CCMP and GCMP require additional information to be transmitted in the MPDU. The CCMP / GCMP header 1140 and the MIC field 1160 may be added to the MPDU to accommodate this additional information. The CCMP / GCMP header 1140 may carry information that is needed for decrypting the encrypted frame body field 1150 such as the packet number (PN) and the key ID. The extended initialization vector field 1122 may carry a bit that is fixed to 1. The MIC field 1160 may carry an authentication value for verifying the encryption and decryption processes.
[0127] Both CCMP and GCMP involve two operations to ensure the security and accuracy of the encryption and decryption processes. The first operation is to encrypt the data / payload that is to be included in the frame body field 1150 of the MPDU and then insert the encrypted data / payload in the frame body field 1150. The second operation is to generate an authentication value that can be used for verifying the encryption and decryption processes and to insert the authentication value in the MIC field 1160. The length of the authentication value may be eight (8) bytes for CCMP-128 and sixteen (16) bytes for CCMP-256, GCMP-128, and GCMP-256. The length of the MIC field 1160 may be variable and depend on the length of the authentication value.
[0128] Figure 12 is a diagram showing a way to generate additional authentication data (AAD), according to some embodiments.
[0129] Both CCMP and GCMP may generate an authentication value for a MPDU based on additional authentication data (AAD) for the MPDU. The AAD for an MPDU may be generated based on concatenating certain fields included in the MPDU and masking certain (sub)fields / bits included in the concatenated fields. The procedure for generating the AAD is the same for both CCMP and GCMP.
[0130] For example, as shown in the diagram, the AAD may be generated by concatenating a frame control (FC) field 1202 (2 bytes), an Al (address 1) field 1204 (6 bytes), an A2 (address 2) field 1206 (6 bytes), an A3 (address 3) field 1208 (6 bytes), a sequence control (SC) field 1210 (2 bytes), an A4 (address 4) field 1212 (0 or 6 bytes), and a QoS control (QC) field 1214 (0 or 2 bytes), in that order. It should be noted that not all MPDUs have an A4 field 1212 and QoS Control field 1214, and any fields that are absent from the MAC header are also excluded fromthe AAD. As such, the length of the AAD can vary depending on the presence or absence of such fields. The possible lengths of AAD are 22, 24, 28, or 30 bytes.
[0131] The Al (address 1) field 1204, A2 (address 2) field 1206, Address 3 (address 3) field 1208, and Address 4 (address 4) fields 1212 are used in the AAD without modification. However, the FC field 1202, SC field 1210, and QC field 1214 are modified by deleting / masking some fields / bits therein.
[0132] Figure 13 is a diagram showing a format of a frame control field, according to some embodiments.
[0133] The frame control (FC) field may include fields for carrying information regarding the format and function of the MPDU. As shown in the diagram, the frame control field may include a protocol version field 1302 (2 bits), a type field 1304 (2 bits), a subtype field 1306 (4 bits), a to distribution system (DS) field 1308 (1 bit), a from DS field 1310 (1 bit), a more fragments field 1312 (1 bits), a retry field 1314 (1 bits), a power management field 1316 (1 bits), a more data field 1318 (1 bits), a protected frame field 1320 (1 bits), and a plus high throughput control (+HTC) field 1322 (1 bits). The bit positions of the fields may be as shown in the diagram.
[0134] When generating AAD, some of these fields are modified by masking certain bits to 0. For example, bits 4, 5, and 6 of the subtype field 1306 in a data frame are masked to 0. Also, the retry field 1314, which indicates whether the MPDU is a retransmission, is masked to 0. Also, the power management field 1316, which indicates the power-saving mode of the transmitter, is masked to 0. Also, the more data field 1318, which indicates whether there are more MPDUs buffered for transmission, is masked to 0. Finally, the +HTC field 1322, which indicates the presence of a high throughput control (HTC) field, is masked to 0 in the case that a data frame has a QoS control field.
[0135] Figure 14 is a diagram showing a format of a sequence control field, according to some embodiments.
[0136] The sequence control (SC) field may includes fields for carrying information about the order and fragmentation of the MPDU. As shown in the diagram, the sequence control field may include a fragment number field 1402 (4 bits) and a sequence number field (12 bits). When generating AAD, the sequence number field 1404, which indicates the position of the MPDU in a sequence of MPDUs, is masked to 0. The bit positions of the fields may be as shown in the diagram.
[0137] The QoS control field includes fields for carrying information about the quality of service and the aggregation of the MPDU. When generating AAD, the masking rules applied tothe QoS control field may vary depending on whether the MPDU belongs to a non-directional multi-gigabit (non-DMG) basic service set (BSS) or a directional multi-gigabit (DMG) BSS. If the MPDU belongs to a non-DMG BSS and both the transmitter and the receiver have the signaling and payload protected (SPP) aggregated MAC service data unit (A-MSDU) capable field set to a value of 1, indicating that they support single MPDU protection for an A-MSDU, then all fields included in the QoS control field except the traffic identifier (TID) field and the A-MSDU present field are masked to 0. If the MPDU belongs to a non-DMG BSS and either the transmitter or the receiver does not have the SPP A-MSDU capable field set to a value of 1, then all fields included in the QoS control field except the TID field are masked to 0. If the MPDU belongs to a DMG BSS, then all fields included in the QoS control field except the TID field, the A-MSDU present field, and the A-MSDU type field are masked to 0.
[0138] According to the existing AAD generation rules, only some of the MAC header fields are included in the AAD and are used to generate the authentication value and certain fields / bits are masked in the AAD. Thus, the MAC header fields / bits that are excluded from the AAD or masked in the AAD do not meaningfully contribute to the encryption process or to generating the authentication value. As a result, a wireless device that receives and decrypts an MPDU using the conventional CCMP or GCMP methods cannot detect an attack that only modifies the MAC header fields / bits that are excluded from the AAD or masked in the AAD. To address this problem, techniques are described herein that allow the receiving wireless device to detect when MAC header fields / bits that are excluded from the AAD or masked in the AAD are modified. Embodiments achieve this by adding a new field to the MPDU to carry an additional authentication value that can be used to verify the integrity of the MAC header fields / bits that are excluded from the AAD or masked in the AAD. The new field may be referred to herein as an additional MIC field and be added to the MPDU in addition to the existing MIC field. Thus, the MPDU may include both the existing MIC field and the new / additional MIC field. The techniques may be used to detect when an attacker tampers with any of the MAC header fields / bits that are excluded from the AAD or masked in the AAD, and thus do not contribute to the encryption process or to generating the authentication value. The additional MIC field may thus provide additional MAC header protection for the MPDU.
[0139] For purposes of clarity, the currently existing MIC field may be referred to herein as the “original” MIC field and the new MIC field that is added to provide additional MAC header protection may be referred to herein as the “additional” MIC field. Similarly, the authentication value that is generated using conventional CCMP / GCMP methods and included in the original MIC field may be referred to herein as the “original” authentication value and the newauthentication value that is generated using the techniques described herein and included in the additional MIC field may be referred to as the “additional” authentication value.
[0140] Figure 15 is a diagram showing a format of a MPDU with an additional MIC field, according to some embodiments.
[0141] As shown in the diagram, the MPDU may include a MAC header 1510, a CCMP / GCMP header 1520, a (encrypted) frame body field 1550, a (original) MIC field 1560, an additional MIC field 1570, and a FCS field 1580. The CCMP / GCMP header 1520 may include a PN0 field 1522 (1 byte), a PN1 field 1524 (1 byte), a reserved field 1526 (1 byte), a key ID octet field 1528 (1 byte), a PN2 field 1530 (1 byte), a PN3 field 1532 (1 byte), a PN4 field 1534 (1 byte), and a PN5 field 1536 (1 byte). The key ID octet field 1528 may include a reserved field 1538 (4 bits), an additional MIC exists field 1540 (1 bit), an ext IV field 1542 (1 bits), and a key ID field 1544 (2 bits).
[0142] The additional MIC exists field 1540 may be used for indicating that the MPDU includes an additional MIC field 1570 to help differentiate the MPDU from a MPDU that is encrypted using conventional CCMP / GCMP methods and which does not include the additional MIC field 1570. The additional MIC exists field 1540 may occupy one of the reserved bits in the CCMP / GCMP header 1520. For example, as shown in the diagram, the additional MIC exists field 1540 may be included in the key ID octet field 1528 immediately before the ext IV field 1542. In an embodiment, the additional MIC exists field 1540 carries a single bit (which may be referred to herein as an “additional MIC exists bit”). The additional MIC exists bit being set to 1 may indicate that the additional MIC field 1570 is present in the MPDU, although the opposite convention can be used in some embodiments.
[0143] A wireless device that receives the MPDU may read the CCMP / GCMP header 1520, and if the additional MIC exists bit is set to a value of 0, it may infer that the MPDU is encrypted using conventional CCMP / GCMP methods (and thus the MPDU does not include the additional MIC field 1570). Thus, the receiving wireless device may expect that a frame body field will be followed by the original MIC field and the FCS field. Otherwise, if the additional MIC exists bit is set to a value of 1, the receiving wireless device may infer that the MPDU includes the additional MIC field 1570. Thus, the receiving wireless device may expect that the (encrypted) frame body field 1550 will be followed by the original MIC field 1560, the additional MIC field 1570, and the FCS field 1580. While a particular frame format is shown in the diagram, it should be appreciated that the frame format can be modified without departing from the spirit of the present disclosure (e.g., the additional MIC field 1570 and / or the additional MIC exists field 1540 can be located in different positions within the MPDU).
[0144] The original MIC field 1560 may function in the same way as before. It may carry the original authentication value generated by conventional CCMP / GCMP methods.
[0145] If the wireless device transmitting the MPDU wants to include the additional MIC field 1570 in the MPDU, it may generate an additional AAD based on the fields / bits of the MAC header that are excluded from the original AAD and / or masked in the original AAD, and generate an additional authentication value based on the additional AAD. The transmitting wireless device may then insert the additional authentication value in the additional MIC field 1570. The fields / bits that are excluded from the original AAD and masked in the original AAD may be considered as fields / bits that do not contribute to the AAD and may be referred to herein as such.
[0146] Broadcast / multicast integrity protocol (BIP) is a protocol defined in the IEEE 802.11 wireless networking standards . BIP does not encrypt the data in the group addressed management frame, but it provides a way to ensure its validity. To apply BIP to a group addressed management frame, a management MIC element is added to the end of the frame body field of the frame. Then, an integrity value is generated using one of the following algorithms: AES-128-CMAC (where CMAC stands for cipher-based message authentication code), AES-256-CMAC, AES-128-GMAC (where GMAC stands for Galois message authentication code), or AES-256-GMAC. These algorithms target the frame body field and are the same as the ones used for generating the authentication value in CCMP-128, CCMP-256, GCMP-128, and GCMP-256. The generated integrity value is inserted in the MIC field of the management MIC element.
[0147] BIP generates the authentication value without encryption of the frame body field. However, BIP does not provide MAC header protection because it targets the frame body field. Embodiments may generate an additional authentication value using a similar operations as BIP but targeting some or all of the fields / bits of the MAC header that are excluded from the original AAD or masked in the original AAD (and thus not involved in the encryption process in conventional CCMP / GCMP methods) instead of targeting the frame body. The additional authentication value may then be inserted in the additional MIC field.
[0148] CCMP and GCMP operate on 128-bit units of data. Therefore, the data included in the frame body field of the MPDU is divided into 128-bit data blocks and processed in units of data blocks. If the length of the final data block is less than 128 bits, it may be padded with zeroes to make it 128 bits. The data blocks of the frame body field may be denoted herein as M[z], where z is the block number. The first data block may be M[l] and the last data block may be M[ / / ].
[0149] Figure 16 is a diagram showing CCMP operations, according to some embodiments. The diagram shows operations for encrypting data blocks and generating an authentication value (denoted as “MIC” in the diagram). The various inputs and operations involved are further described herein below. In the diagram, the AES blocks represent AES operations and the crosshair symbols represents bitwise XOR operations.
[0150] CCMP may use AES operations for both encrypting the data in the frame body field and generating the authentication value for the MPDU. The encryption process may involve a counter that increases sequentially and is used as an input to the AES operations. This counter may be denoted as Tc[z], where z is the block number. Tc[z] may be an input to the AES operation, and the output of the AES operation may be bitwise XORed with M[z], the original data block. The result of this operation may be the encrypted data block, denoted as Cc[z].
[0151] Tc[z] may have a length of 16 bytes (128 bits) and may be divided into three parts: a 2-byte counter, a 13-byte nonce, and a 1-byte CTR flags. The counter may have a value of z. The nonce may include a 1-byte nonce flags, a 6-byte Address 2 field from the MAC Header, and a 6-byte PN from the CCMP header. The nonce flags may include a 4-bit MPDU priority value, a 1 -bit management frame indicator, a 1 -bit PV1 frame indicator, and 2 bits of zero. The CTR flags may have a fixed value of 1. The values of the nonce and CTR flags may be constant for each MPDU and not depend on z.
[0152] The generation of the authentication value may require additional AES operations before M[l] is input. An AES feedback operation may be performed sequentially with three sequence blocks as input. The three sequence blocks may be denoted as Bc[ / '], where j is 0, 1, and 2, respectively. Then, the AES feedback operation with M[z] as input may be performed sequentially. The authentication value (denoted as “MIC” in the diagram) may be generated by bitwise XORing the final result with the AES output of Tc[0].
[0153] Bc[ / '] may be determined by the following rule: Bc[0] may include a 2-byte message length, a 13-byte nonce, and a 1-byte CBC flags. The CBC flags may have a fixed value of 89 for CCMP-128 and a fixed value of 121 for CCMP -256. Bc[l] may include a 0 in the lowest byte, and the next byte may contain the length of AAD. The next 14 bytes may be filled with the lower 14 bytes of AAD. Bc[2] may include the remaining AAD excluding the lower 14 bytes, and the remaining bits may be padded with 0s.
[0154] Figure 17 is a diagram showing GCMP operations, according to some embodiments. The diagram shows operations for encrypting data blocks and generating an authentication value (denoted as “MIC” in the diagram). The various inputs and operations involved are further described herein below. In the diagram, the AES blocks represent AES operations, the GHASHblocks represent GHASH operations, and the crosshair symbols represents bitwise XOR operations.
[0155] GCMP may use AES operations for encrypting the data in the frame body field and use GHASH operations to generate the authentication value for the MPDU. The encryption process may involve a counter that increases sequentially and is used as an input to the AES operations. This counter may be denoted as To[i], where i is the block number. TG[Z] may be an input to the AES operation, and the output of the AES operation may be bitwise XORed with M[z], the original data block. The result of this operation may be the encrypted data block, denoted as CG[Z].
[0156] TG[Z] may have a length of 16 bytes (128 bits) and may be divided into two parts: a 4- byte counter and a 12-byte nonce. The counter may have the value of (z+1). The nonce may include a 6-byte Address 2 field from the MAC header and a 6-byte PN from the GCMP header. The nonce may be the same as the one used in CCMP and described above, except that it does not include the nonce flags.
[0157] The generation of the authentication value may require additional AES operations and GHASH operations before M[l] is input, and one more GHASH operation after M[ / / ] is input. The GHASH operation may require a hash key, denoted as H. To obtain H, an AES operation may performed on 128 bits of zeros. The hash key H may be used in all GHASH operations. The sequence blocks that are provided as inputs for the additional GHASH operations may be denoted as BG[ ], where j is 0, 1, and 2, respectively. A GHASH feedback operation may be performed sequentially with BG[0] and BG[1] as input before M[l] is input. Then, the GHASH feedback operation with CG[Z] as input may be performed sequentially. After generating CG[«], a GHASH feedback operation may be performed with BG[2] as input. The authentication value (denoted as “MIC” in the diagram) may be generated by bitwise XORing the final result with the AES output of TG[0].
[0158] BG[ / ] may be determined by the following rule: BG[0] may include the lower 16 bytes of AAD. BG[1] may include the remaining AAD excluding the lower 16 bytes, and the remaining bits may be padded with 0s. The lower 8 bytes of BG[2] include the length of the message and the upper 8 bytes of BG[2] may include the length of AAD.
[0159] In an embodiment, the additional authentication value is generated the same way the original authentication value is generated but using different AAD.
[0160] When encrypting the data block M[z], two sets of AES operations are needed for CCMP (one for encrypting data and one for generating the authentication value), and one set of AES operations and one set of GHASH operations are needed for GCMP (the AES operationsare used for encrypting data and the GHASH operations are used for generating the authentication value). Therefore, a wireless device that supports both CCMP and GCMP should be able to perform two AES operations and one GHASH operations in parallel between the input of M[z] and the input of M[z+1],
[0161] When using CCMP, one set of AES computation resources is dedicated to encrypting data and the other set of AES computation resources is dedicated to generating the authentication value. When using GCMP, one set of AES computation resources is dedicated to encrypting data and the set of GHASH computation resources is dedicated to generating the authentication value. This means that a wireless device that supports both CCMP and GCMP has idle computation resources that can perform GHASH operations during CCMP data encryption and has idle computation resources that can perform AES operations during GCMP data encryption. As will be described in additional detail herein, these idle computation resources can be leveraged to generate the additional authentication value, without requiring additional hardware or software components.
[0162] Figure 18 is a diagram showing the use of CCMP operations for data encryption and the use of idle GHASH computation resources to generate the additional authentication value, according to some embodiments. The diagram shows operations for encrypting data blocks, generating an original authentication value (denoted as “MIC” in the diagram), and generating an additional authentication value (denoted as “Additional MIC” in the diagram). The various inputs and operations involved are further described herein below. In the diagram, the AES blocks represent AES operations, the GHASH blocks represent GHASH operations, and the crosshair symbols represents bitwise XOR operations.
[0163] When encrypting an MPDU using CCMP methods, the additional authentication value (that is to be included in the additional MIC field of the MPDU) can be generated by performing GHASH operations in parallel with the AES operations (by leveraging the idle GHASH computation resources). In this case, the procedure for generating the additional authentication value may be similar to the procedure used in GCMP. However, since the data encryption is performed using CCMP, the encrypted data blocks Cc[z] may be used as the input to the GHASH operations instead of the encrypted data blocks CG[Z]. Also, to maintain consistency with GCMP, sequence blocks BG'[ / '] may used as the input to the additional GHASH operations. BG'[ / '] may have the same format as BG[ / '], except the AAD included in BG'[ / ] includes some or all of the fields / bits of the MAC header that did not contribute to the original AAD. The input to the final bitwise XOR operation may be the result of applying an AES operation to TG[0].While a particular way to generate the additional authentication value (“Additional MIC”) isshown in the diagram, one of ordinary skill in the art will appreciate that the additional authentication value can be generated in a different way than shown in the diagram.
[0164] Figure 19 is a diagram showing the use of GCMP operations for data encryption and the use of idle AES computation resources to generate the additional authentication value, according to some embodiments. The diagram shows operations for encrypting data blocks, generating an original authentication value (denoted as “MIC” in the diagram), and generating an additional authentication value (denoted as “Additional MIC” in the diagram). In the diagram, the AES blocks represent AES operations, the GHASH blocks represent GHASH operations, and the crosshair symbols represents bitwise XOR operations.
[0165] When encrypting an MPDU using GCMP, the additional authentication value (that is to be included in the additional MIC field of the MPDU) can be generated by performing AES operations in parallel with the AES and GHASH operations that are performed for encrypting data and generating the original authentication value (by leveraging the idle AES computation resources). In this case, the procedure for generating the additional authentication value may be similar to the procedure used in CCMP. For data encryption, the original data block M[z] may used as the input to the AES operations, as done in CCMP. Also, to maintain consistency with CCMP, the sequence blocks Bc'[z] may used as the input to the additional AES operations. Bc'[z] may have the same format as Bc[z], except the AAD included in Bc'[z] includes some or all of the fi elds / bits of the MAC header that did not contribute to the original AAD. The input to the final bitwise XOR operation may be the result of applying an AES operation to Tc[0].While a particular way to generate the additional authentication value (“Additional MIC”) is shown in the diagram, one of ordinary skill in the art will appreciate that the additional authentication value can be generated in a different way than shown in the diagram.
[0166] The security protocols defined in the current IEEE 802.11 wireless networking standards (e.g., CCMP and GCMP) do not protect some fi elds / bits of the MAC header, which makes them vulnerable to attacks (e.g., attackers can tamper with the unprotected fields / bits and there is no way to detect the tampering). To address this problem, MAC header protection techniques are described herein that add an additional MIC field to the MAC header that can be used for protecting the fi elds / bits of the MAC header that are not protected by the conventional security protocol methods. Furthermore, in some embodiments, the additional authentication value that is transmitted in the additional MIC field can be generated by leveraging computation resources that are available in existing wireless devices but are not being used (idle computation resources). This way, the additional authentication value for the additional MIC field can be generated without requiring additional hardware or software components.
[0167] Turning now to Figure 20, a method 2000 will be described for protecting a MAC header of a MPDU, in accordance with an example embodiment. The method 2000 may be performed by a wireless device (e.g., wireless device 104).
[0168] Additionally, although shown in a particular order, in some embodiments the operations of the method 2000 (and the other methods shown in the other figures) may be performed in a different order. For example, although the operations of the method 2000 are shown in a sequential order, some of the operations may be performed in partially or entirely overlapping time periods.
[0169] At operation 2005, the wireless device encrypts a payload of the MPDU to generate an encrypted payload.
[0170] At operation 2010, the wireless device generates first AAD based on concatenating a set of fields included in the MAC header and masking one or more bits included in the set of fields. In an embodiment, the set of fields includes a frame control field, a first address field, a second address field, a third address field, and a sequence control field (and possibly a fourth address field). In an embodiment, the one or more bits that are masked includes one or more of the following: one or more bits included in a subtype field included in the frame control field, a single bit corresponding to a retry field included in the frame control field, a single bit corresponding to a power management field included in the frame control field, a single bit corresponding to a more data field included in the frame control field, a single bit corresponding to a high throughput control field exists field included in the frame control field, and bits corresponding to a sequence number field included in the sequence control field. In an embodiment, the set of fields further includes a QoS control field, wherein the one or more bits that are masked further include one or more bits included in the QoS control field.
[0171] At operation 2015, the wireless device generates a first authentication value (e.g., an original authentication value) based on the first AAD.
[0172] At operation 2020, the wireless device generates second AAD based on one or more bits of the MAC header that do not contribute to the first AAD (e.g., bits that are excluded from the first AAD or masked in the AAD).
[0173] At operation 2025, the wireless device generates a second authentication value (e.g., an additional authentication value) based on the second AAD.
[0174] At operation 2030, the wireless device generates the MPDU, wherein the MPDU includes the MAC header, a security protocol header (e.g., a CCMP / GCMP header) that carries information for decrypting the encrypted payload, a frame body field that carries the encrypted payload, a first message integrity check (MIC) field (e.g., an original MIC field) that carries thefirst authentication value, and a second MIC field (e.g., an additional MIC field) that carries the second authentication value. In an embodiment, the security protocol header includes an additional MIC field exists field that carries a value indicating that the second MIC field exists in the MPDU. In an embodiment, the additional MIC field exists field is included in a key ID octet field included in the security protocol header.
[0175] In an embodiment, the payload is encrypted using CCMP. In such an embodiment, the first authentication value may be generated based on applying AES operations and the second authentication value may be generated based on applying GHASH operations.
[0176] In an embodiment, the payload is encrypted using GCMP. In such an embodiment, the first authentication value may be generated based on applying GHASH operations and the second authentication value may be generated based on applying AES operations.
[0177] At operation 2035, the wireless device transmits the MPDU.
[0178] An embodiment is a wireless device that is configured to perform method 2000. For example, the wireless device may include encryption circuitry operable to encrypt a payload of the MPDU to generate an encrypted payload, first authentication value generation circuitry operable to generate a first AAD based on concatenating a set of fields included in the MAC header and masking one or more bits included in the set of fields and generate a first authentication value based on the first AAD, second authentication value generation circuitry operable to generate second AAD based on one or more bits of the MAC header that do not contribute to the first AAD and generate a second authentication value based on the second AAD, MAC circuitry operable to generate the MPDU, wherein the MPDU includes the MAC header, a security protocol header that carries information for decrypting the encrypted payload, a frame body field that carries the encrypted payload, a first MIC field that carries the first authentication value, and a second MIC field that carries the second authentication value, and a wireless transmitter operable to transmit the MPDU.
[0179] Turning now to Figure 21, a method 2100 will be described for verifying an integrity of a MAC header of a MPDU, in accordance with an example embodiment. The method 2100 may be performed by a wireless device (e.g., wireless device 104).
[0180] At operation 2105, the wireless device receives the MPDU, wherein the MPDU includes the MAC header, a security protocol header (e.g., CCMP / GCMP header) that carries information for decrypting an encrypted payload, a frame body field that carries the encrypted payload, a first MIC field (e.g., an original MIC field) that carries a first authentication value (e.g., an original authentication value), and a second MIC field (e.g., an additional MIC field) that carries a second authentication value (e.g., an additional authentication value). In anembodiment, the wireless device determines that the MPDU includes the second MIC field based on a value carried in an additional MIC field exists field included in the security protocol header (e.g., based on the value of an additional MIC field exists bit).
[0181] At operation 2110, the wireless device decrypts the encrypted payload using the information for decrypting the encrypted payload to recover an unencrypted payload.
[0182] At operation 2115, the wireless device verifies an integrity of a first set of bits included in the MAC header using the first authentication value (e.g., using CCMP / GCMP verification methods or similar methods). The first set of bits may be a set of bits that contributed to the generation of the first authentication value.
[0183] At operation 2120, the wireless device determines whether the first set of bits are successfully verified. If the first set of bits are not successfully verified, then the method may proceed to operation 2125 at which the wireless device does not accept the MAC header. Otherwise, if the first set of bits are successfully verified, then the method may proceed to operation 2130.
[0184] At operation 2130, the wireless device verifies an integrity of a second set of bits included in the MAC header using the second authentication value (e.g., using CCMP / GCMP verification methods or similar methods). The second set of bits may be a set of bits that did not contribute to the generation of the first authentication value.
[0185] At operation 2135, the wireless device determines whether the second set of bits are successfully verified. If the second set of bits are not successfully verified, then the method may proceed to operation 2125 at which the wireless device does not accept the MAC header. Otherwise, if the second set of bits are successfully verified, then the method may proceed to operation 2140 at which the wireless device accepts the MAC header.
[0186] In an embodiment, the encrypted payload is decrypted using CCMP, wherein the integrity of the second set of bits is verified using GCMP. In an embodiment, the encrypted payload is decrypted using GCMP, wherein the integrity of the second set of bits is verified using CCMP.
[0187] An embodiment is a wireless device that is configured to perform method 2100. For example, the wireless device may include a wireless receiver operable to receive the MPDU, wherein the MPDU includes the MAC header, a security protocol header that carries information for decrypting an encrypted payload, a frame body field that carries the encrypted payload, a first MIC field that carries a first authentication value, and a second MIC field that carries a second authentication value, decryption circuitry operable to decrypt the encrypted payload using the information for decrypting the encrypted payload to recover an unencryptedpayload, first authentication value verification circuitry operable to verify an integrity of a first set of bits included in the MAC header using the first authentication value, second authentication value verification circuitry operable to verify an integrity of a second set of bits included in the MAC header using the second authentication value, and MAC circuitry operable to accept and process the MAC header in response to the integrity of the first set of bits and the integrity of the second set of bits being successfully verified.
[0188] Although many of the solutions and techniques provided herein have been described with reference to a WLAN system, it should be understood that these solutions and techniques are also applicable to other network environments, such as cellular telecommunication networks, wired networks, etc. In some embodiments, the solutions and techniques provided herein may be or may be embodied in an article of manufacture in which a non-transitory machine-readable medium (such as microelectronic memory) has stored thereon instructions which program one or more data processing components (generically referred to here as a “processor” or “processing unit”) to perform the operations described herein. In other embodiments, some of these operations might be performed by specific hardware components that contain hardwired logic (e.g., dedicated digital filter blocks and state machines). Those operations might alternatively be performed by any combination of programmed data processing components and fixed hardwired circuit components.
[0189] In some cases, an embodiment may be an apparatus (e.g., an AP STA, a non-AP STA, or another network or computing device) that includes one or more hardware and software logic structures for performing one or more of the operations described herein. For example, as described herein, an apparatus may include a memory unit, which stores instructions that may be executed by a hardware processor installed in the apparatus. The apparatus may also include one or more other hardware or software elements, including a network interface, a display device, etc.
[0190] Some portions of the preceding detailed descriptions have been presented in terms of algorithms and symbolic representations of operations on data bits within a computer memory. These algorithmic descriptions and representations are the ways used by those skilled in the data processing arts to most effectively convey the substance of their work to others skilled in the art. An algorithm is here, and generally, conceived to be a self-consi stent sequence of operations leading to a desired result. The operations are those requiring physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical or magnetic signals capable of being stored, combined, compared, and otherwise manipulated.It has proven convenient at times, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like.
[0191] It should be borne in mind, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities. The present disclosure can refer to the action and processes of a computer system, or similar electronic computing device, that manipulates and transforms data represented as physical (electronic) quantities within the computer system's registers and memories into other data similarly represented as physical quantities within the computer system memories or registers or other such information storage systems.
[0192] The present disclosure also relates to an apparatus for performing the operations herein. This apparatus can be specially constructed for the intended purposes, or it can include a general -purpose computer selectively activated or reconfigured by a computer program stored in the computer. For example, a computer system or other data processing system may carry out the computer-implemented methods described herein in response to its processor executing a computer program (e.g., a sequence of instructions) contained in a memory or other non- transitory machine-readable storage medium. Such a computer program can be stored in a computer readable storage medium, such as, but not limited to, any type of disk including floppy disks, optical disks, CD-ROMs, and magnetic-optical disks, read-only memories (ROMs), random access memories (RAMs), EPROMs, EEPROMs, magnetic or optical cards, or any type of media suitable for storing electronic instructions, each coupled to a computer system bus.
[0193] The algorithms and displays presented herein are not inherently related to any particular computer or other apparatus. Various general -purpose systems can be used with programs in accordance with the teachings herein, or it can prove convenient to construct a more specialized apparatus to perform the method. The structure for a variety of these systems will appear as set forth in the description below. In addition, the present disclosure is not described with reference to any particular programming language. It will be appreciated that a variety of programming languages can be used to implement the teachings of the disclosure as described herein.
[0194] The present disclosure can be provided as a computer program product, or software, that can include a machine-readable medium having stored thereon instructions, which can be used to program a computer system (or other electronic devices) to perform a process according to the present disclosure. A machine-readable medium includes any mechanism for storing information in a form readable by a machine (e.g., a computer). In some embodiments, a machine-readable (e.g., computer-readable) medium includes a machine (e.g., a computer)readable storage medium such as a read only memory (“ROM”), random access memory (“RAM”), magnetic disk storage media, optical storage media, flash memory components, etc.
[0195] In the foregoing specification, embodiments of the disclosure have been described with reference to specific example embodiments thereof. It will be evident that various modifications can be made thereto without departing from the broader spirit and scope of embodiments of the disclosure as set forth in the following claims. The specification and drawings are, accordingly, to be regarded in an illustrative sense rather than a restrictive sense.
Claims
CLAIMSWhat is claimed is:
1. A method performed by a wireless device to protect a media access control (MAC) header of a MAC protocol data unit (MPDU), the method comprising: encrypting a payload of the MPDU to generate an encrypted payload; generating first additional authentication data (AAD) based on concatenating a set of fields included in the MAC header and masking one or more bits included in the set of fields; generating a first authentication value based on the first AAD; generating second AAD based on one or more bits of the MAC header that do not contribute to the first AAD; generating a second authentication value based on the second AAD; generating the MPDU, wherein the MPDU includes the MAC header, a security protocol header that carries information for decrypting the encrypted payload, a frame body field that carries the encrypted payload, a first message integrity check (MIC) field that carries the first authentication value, and a second MIC field that carries the second authentication value; and transmitting the MPDU.
2. The method of claim 1, wherein the security protocol header includes an additional MIC field exists field that carries a value indicating that the second MIC field exists in the MPDU.
3. The method of claim 2, wherein the additional MIC field exists field is included in a key ID octet field included in the security protocol header.
4. The method of claim 1, wherein the set of fields includes a frame control field, a first address field, a second address field, a third address field, and a sequence control field.
5. The method of claim 4, wherein the one or more bits that are masked include one or more of the following: one or more bits included in a subtype field included in the frame control field, a single bit corresponding to a retry field included in the frame control field, a single bit corresponding to a power management field included in the frame control field, a single bit corresponding to a more data field included in the frame control field,a single bit corresponding to a high throughput control field exists field included in the frame control field, and bits corresponding to a sequence number field included in the sequence control field.
6. The method of claim 4, wherein the set of fields further includes a quality of service (QoS) control field, wherein the one or more bits that are masked further include one or more bits included in the QoS control field.
7. The method of claim 1, wherein the payload is encrypted using counter mode with cipher block changing message authentication code protocol (CCMP).
8. The method of claim 7, wherein the first authentication value is generated based on applying advanced encryption standard (AES) operations and the second authentication value is generated based on applying GHASH operations.
9. The method of claim 1, wherein the payload is encrypted using Galois counter mode protocol (GCMP).
10. The method of claim 9, wherein the first authentication value is generated based on applying GHASH operations and the second authentication value is generated based on applying advanced encryption standard (AES) operations.
11. A wireless device configured to protect a media access control (MAC) header of a MAC protocol data unit (MPDU), the wireless device comprising: encryption circuitry operable to encrypt a payload of the MPDU to generate an encrypted payload; first authentication value generation circuitry operable to generate a first additional authentication data (AAD) based on concatenating a set of fields included in the MAC header and masking one or more bits included in the set of fields and generate a first authentication value based on the first AAD; second authentication value generation circuitry operable to generate second AAD based on one or more bits of the MAC header that do not contribute to the first AAD and generate a second authentication value based on the second AAD; media access control (MAC) circuitry operable to generate the MPDU, wherein the MPDU includes the MAC header, a security protocol header that carries information for decrypting the encrypted payload, a frame body field that carries the encrypted payload, a first message integrity check (MIC) field that carries thefirst authentication value, and a second MIC field that carries the second authentication value; and a wireless transmitter operable to transmit the MPDU.
12. A method performed by a wireless device to verify an integrity of a media access control (MAC) header of a MAC protocol data unit (MPDU), the method comprising: receiving the MPDU, wherein the MPDU includes the MAC header, a security protocol header that carries information for decrypting an encrypted payload, a frame body field that carries the encrypted payload, a first message integrity check (MIC) field that carries a first authentication value, and a second MIC field that carries a second authentication value; decrypting the encrypted payload using the information for decrypting the encrypted payload to recover an unencrypted payload; verifying an integrity of a first set of bits included in the MAC header using the first authentication value; verifying an integrity of a second set of bits included in the MAC header using the second authentication value; and accepting the MAC header in response to successfully verifying the integrity of the first set of bits and the integrity of the second set of bits.
13. The method of claim 12, further comprising: determining that the MPDU includes the second MIC field based on a value carried in an additional MIC field exists field included in the security protocol header.
14. The method of claim 12, wherein the encrypted payload is decrypted using counter mode with cipher block changing message authentication code protocol (CCMP), wherein the integrity of the second set of bits is verified using Galois counter mode protocol (GCMP).
15. The method of claim 12, wherein the encrypted payload is decrypted using Galois counter mode protocol (GCMP), wherein the integrity of the second set of bits is verified using counter mode with cipher block changing message authentication code protocol (CCMP).
16. A wireless device configured to verify an integrity of a media access control (MAC) header of a MAC protocol data unit (MPDU), the wireless device comprising: a wireless receiver operable to receive the MPDU, wherein the MPDU includes the MAC header, a security protocol header that carries information for decryptingan encrypted payload, a frame body field that carries the encrypted payload, a first message integrity check (MIC) field that carries a first authentication value, and a second MIC field that carries a second authentication value; decryption circuitry operable to decrypt the encrypted payload using the information for decrypting the encrypted payload to recover an unencrypted payload; first authentication value verification circuitry operable to verify an integrity of a first set of bits included in the MAC header using the first authentication value; second authentication value verification circuitry operable to verify an integrity of a second set of bits included in the MAC header using the second authentication value; andMAC circuitry operable to accept the MAC header in response to the integrity of the first set of bits and the integrity of the second set of bits being successfully verified.
Citation Information
Patent Citations
Device power management transitions in wireless networks
US11812379B1
Long range WLAN data unit format
US20130044877A1
Communication apparatus and communication method for multi-AP joint transmission
US20220190880A1
Encrypting mac header fields for WLAN privacy enhancement
US20230232218A1
Data transmission method, communication apparatus, computer-readable storage medium, and chip
US20230413368A1