Secure control frames in wireless communications

WO2025151279A3PCT designated stage Publication Date: 2025-10-23QUALCOMM INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/US2024/061433
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-11
Filing Date
2024-12-20
Publication Date
2025-10-23

AI Technical Summary

Technical Problem

Wireless communication networks are vulnerable to attacks targeting control frames, leading to denial of service, power drain, and inefficiencies in radio frequency resource usage due to malicious interference.

Method used

Implementing a control message integrity check (CMF) field in control frames that includes a security key identifier and a truncated integrity check, allowing verification of frame validity by comparing computed and transmitted integrity checks, and using group or pairwise temporal keys for encryption based on the number of associated stations.

Benefits of technology

Enhances security and efficiency by reducing power consumption and radio resource wastage, enabling effective verification of control frames and managing security keys for multiple stations, thus preventing unauthorized access and ensuring reliable communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024061433_23102025_PF_FP_ABST
    Figure US2024061433_23102025_PF_FP_ABST
Patent Text Reader

Abstract

This disclosure provides methods, components, devices and systems for secure control frames in wireless communications. Some aspects more specifically relate to security for control frames based on one or more fields included in the control frames. In some examples, a frame is transmitted with a control message integrity check (MIC) field (CMF) that includes an identifier of a security key, at least a portion of a packet number (PN), and at least a portion of an integrity check computed based on one or more portions of the frame including the control information and the security key. The CMF may be transmitted is separate parts, such as a first portion of the CMF that includes the identifier of the security key and at least the portion of the PN, and a second portion of the CMF that includes at least a truncated portion of the integrity check.
Need to check novelty before this filing date? Find Prior Art

Description

SECURE CONTROL FRAMES IN WIRELESS COMMUNICATIONSCROSS REFERENCE

[0001] The present Application for Patent claims priority to Indian Patent Application No. 202441002125 by ASTERJADH1 et al., entitled “SECURE CONTROL FRAMES IN WIRELESS COMMUNICATIONS,” filed Januaiy 11, 2024, which is assigned to the assignee hereof and expressly incorporated by reference herein.TECHNICAL FIELD

[0002] This disclosure relates generally to wireless communication and, more specifically, to security for control frames in wireless communications.DESCRIPTION OF THE RELATED TECHNOLOGY

[0003] A wireless local area network (WLAN) may be formed by one or more wireless access points (APs) that provide a shared wireless communication medium for use by multiple client devices also referred to as wireless stations (STAs). The basic building block of a WLAN conforming to the Institute of Electrical and Electronics Engineers (IEEE) 802.11 family of standards is a Basic Service Set (BSS), which is managed by an AP. Each BSS is identified by a Basic Service Set Identifier (BSSID) that is advertised by the AP. An AP periodically broadcasts beacon frames to enable any STAs within wireless range of the AP to establish or maintain a communication link with the WLAN.

[0004] In some WLANs, APs and STAs may engage in reliable, such as ultra-high reliability (UHR), communications. The UHR communications may rely on transmissions of control information for many purposes, such as for example acknowledgments, network allocation vector (NAV) setting, sounding, triggering, and cross link control signaling, among others. In some settings, a malicious actor may attack a wireless communication by targeting the frames containing control information. Such attacks can lead to denial of service, power drain at UEs, decrease of reliability of the communications, and wastage of radio frequency resources.SUMMARY

[0005] The systems, methods, and devices of this disclosure each have several innovative aspects, no single one of which is solely responsible for the desirable attributes disclosed herein.

[0006] One innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications by an apparatus. The method may include obtaining a control frame including a first portion of a control message integrity check field (CMF) and a second portion of the CMF, the first portion of the CMF including an identifier (ID) of a security key and the second portion of the CMF including a truncated first integrity check and verifying a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, where the second integrity check is based on at least the security' key, a partial packet number (PN) associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.

[0007] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include a processing system that includes processor circuitry and memory circuitry that stores code. The processing system may be configured to cause the apparatus to obtain a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated first integrity check and verify a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, where the second integrity check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame, and the second integrity' check is truncated corresponding to the truncated first integrity check.

[0008] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include means for obtaining a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a securitykey and the second portion of the CMF including a truncated first integrity check and means for verifying a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, where the second integrity check is based on at least the security key. a partial PN associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.

[0009] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communications. The code may include instructions executable by one or more processors to obtain a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated first integrity check and verify a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, where the second integrity check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.

[0010] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the CMF includes the partial PN and the partial PN included in the CMF may be combined with a base PN associated with the control frame to obtain a full PN associated with the control frame, where the second integrity check may be based on the full PN.

[0011] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the second integnty check may be truncated to include a subset of bits of an authentication code output that may be based on at least the security key, the partial PN, and the one or more portions of the control frame.

[0012] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the first portion of the CMF includes the partial PN. In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, the first portion of the CMF may be provided at a first deterministic location within a control information portion of the control frame that maybe located prior to one or more fields that may be protected by the truncated first integrity check, and the second portion of the CMF may be provided at a second deterministic location within the control information portion of the control frame that may be located subsequent to the one or more fields that may be protected by the truncated first integrity check.

[0013] In some examples of the method, apparatuses, and n on-transitory computer- readable medium described herein, a quantity of padding bits subsequent to the second portion of the CMF may be a fixed value that may be advertised via one or more management frames, or may be a value that may be signaled prior to the first portion of the CMF.

[0014] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications by an apparatus. The method may include obtaining a frame including a CMF including an association identity (AID), an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame and verifying a validity of the frame, based on a comparison of the first integrity’ check and a second integrity check, where the second integrity check is based on at least the security key and the PN indication associated with the AID.

[0015] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include a processing system that includes processor circuitry and memory circuitry that stores code. The processing system may be configured to cause the apparatus to obtain a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame and verify a validity of the frame, based on a comparison of the first integrity check and a second integrity check, where the second integrity check is based on at least the security key and the PN indication associated with the AID.

[0016] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include means for obtaining a frame including a CMF including an AID, an ID of asecurity key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame and means for verifying a validity of the frame, based on a comparison of the first integrity check and a second integrity check, where the second integrity check is based on at least the security key and the PN indication associated with the AID.

[0017] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communications. The code may include instructions executable by one or more processors to obtain a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame and verity’ a validity of the frame, based on a comparison of the first integrity check and a second integrity check, where the second integrity check is based on at least the security key and the PN indication associated with the AID.

[0018] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the AID may be provided in one or more medium access control (MAC) protocol data units (MPDUs) with secure MAC headers that solicit protected control frames.

[0019] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the one or more frames that solicit protected control frames include an indication that protected control frames are requested.

[0020] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications by an apparatus. The method may include obtaining an indication that one of a group temporal key (GTK) mode or a pairwise temporal key (PTK) mode is configured for control frame security, generating a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode, and outputting the control frame for transmission.

[0021] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus mayinclude a processing system that includes processor circuitry and memory circuitry that stores code. The processing system may be configured to cause the apparatus to obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security’, generate a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode, and output the control frame for transmission.

[0022] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include means for obtaining an indication that one of a GTK mode or a PTK mode is configured for control frame security, means for generating a control frame including a CMF including a security' key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode, and means for outputting the control frame for transmission.

[0023] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communications. The code may include instructions executable by one or more processors to obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security, generate a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, yvhere the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode, and output the control frame for transmission.

[0024] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the control frame may be a group control frame or an individual control frame, and where group control frames may be secured yvith the GTK in accordance yvith the GTK mode or the PTK mode, and individual control frames may be secured with the PTK in accordance with the PTK mode or the GTK in accordance with the GTK mode.

[0025] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the indication that one of the GTK mode or the PTKmode may be configured for control frame security may be a dynamic indication that provides for dynamic switching between the GTK mode and the PTK mode.

[0026] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications by an apparatus. The method may include obtaining a control frame including a CMF and a set of multiple padding bits prior to an end-of-frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame and decoding the control frame in accordance with the quantity of the set of multiple padding bits.

[0027] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include a processing system that includes processor circuitry and memory circuitry that stores code. The processing system may be configured to cause the apparatus to obtain a control frame including a CMF and a set of multiple padding bits prior to an end-of- frame field, where a quantity' of the set of multiple padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame and decode the control frame in accordance with the quantity of the set of multiple padding bits.

[0028] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include means for obtaining a control frame including a CMF and a set of multiple padding bits prior to an end-of-frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and. when the control frame is a secure control frame, a type of security associated with the control frame and means for decoding the control frame in accordance with the quantity of the set of multiple padding bits.

[0029] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communications. The code may include instructions executable by one or more processors to obtain a control frame including a CMF and a set of multiplepadding bits prior to an end-of-frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame and decode the control frame in accordance with the quantity of the set of multiple padding bits.

[0030] In some examples of the method, apparatuses, and n on-transitory computer- readable medium described herein, unsecured control frames include a first quantity of padding bits that is smaller than a second quantity of padding bits associated with secured control frames.

[0031] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the secured control frames that are unencrypted include the second quantity of padding bits, and where the second quantity of padding bits is smaller than a third quantity of padding bits associated with encrypted secured control frames.

[0032] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications by an apparatus. The method may include generating a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated integrity check, where the truncated integrity check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame and outputting the control frame for transmission.

[0033] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include a processing system that includes processor circuitry and memon' circuitry that stores code. The processing system may be configured to cause the apparatus to generate a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated integrity check, where the truncated integrity check is based on at least the security key, a partial PN associated with the controlframe, and one or more portions of the control frame and output the control frame for transmission.

[0034] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include means for generating a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated integrity check, where the truncated integrity check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame and means for outputting the control frame for transmission.

[0035] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communications. The code may include instructions executable by one or more processors to generate a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated integrity check, where the truncated integrity' check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame and output the control frame for transmission.

[0036] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the CMF includes the partial PN and the partial PN included in the CMF may be combined with a base PN associated with the control frame to provide a full PN associated with the control frame, where the truncated integrity check includes a subset of bits of a full integrity check based on the full PN.

[0037] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the first portion of the CMF includes the partial PN. In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, the first portion of the CMF may be provided at a first deterministic location within a control information portion of the control frame that may be located prior to one or more fields that may be protected by the truncated integrity' check, and the second portion of the CMF may be provided at a second deterministiclocation within the control information portion of the control frame that may be located subsequent to the one or more fields that may be protected by the truncated integrity check.

[0038] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, a quantity of padding bits subsequent to the second portion of the CMF may be a fixed value that is advertised via one or more management frames, or may be a value that is signaled prior to the first portion of the CMF.

[0039] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications by an apparatus. The method may include generating a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame, and where the first integrity check is based on at least the security key and the PN indication associated with the AID and outputting the frame for transmission.

[0040] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include a processing system that includes processor circuitry and memory circuitry that stores code. The processing system may be configured to cause the apparatus to generate a frame including a CMF including an AID, an ID of a security key. a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame, and where the first integrity check is based on at least the security key and the PN indication associated with the AID and output the frame for transmission.

[0041] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include means for generating a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame, and where the first integrity check is based on at least the security key and the PN indication associated with the AID and means for outputting the frame for transmission.

[0042] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communications. The code may include instructions executable by one or more processors to generate a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame, and where the first integrity check is based on at least the security key and the PN indication associated with the AID and output the frame for transmission.

[0043] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the AID may be provided in one or more MPDUs with secure MAC headers that solicit protected control frames.

[0044] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the one or more frames that solicit protected control frames include an indication that protected control frames are requested.

[0045] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications by an apparatus. The method may include obtaining an indication that one of a GTK mode or a PTK mode is configured for control frame security, generating a control frame including a CMF including a security’ key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode, and outputting the control frame for transmission.

[0046] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include a processing system that includes processor circuitry and memory’ circuitry that stores code. The processing system may be configured to cause the apparatus to obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security', generate a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode, and output the control frame for transmission.

[0047] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include means for obtaining an indication that one of a GTK mode or a PTK mode is configured for control frame security’, means for generating a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode, and means for outputting the control frame for transmission.

[0048] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communications. The code may include instructions executable by one or more processors to obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security, generate a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode, and output the control frame for transmission.

[0049] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the control frame may be a group control frame or an individual control frame, and where group control frames are secured with the GTK in accordance with the GTK mode or the PTK mode, and individual control frames are secured with the PTK in accordance with the PTK mode or the GTK in accordance with the GTK mode.

[0050] In some examples of the method, apparatuses, and non-transitory computer- readable medium described herein, the indication that one of the GTK mode or the PTK mode is configured for the control frame security may be a dynamic indication that provides for dynamic switching between the GTK mode and the PTK mode.

[0051] Another innovative aspect of the subject matter described in this disclosure can be implemented in a method for wireless communications by an apparatus. The method may include generating a control frame including a CMF and a set of multiple padding bits prior to an end-of-frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and, whenthe control frame is a secure control frame, a type of security associated with the control frame and outputting the control frame for transmission.

[0052] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include a processing system that includes processor circuitry and memory circuitry that stores code. The processing system may be configured to cause the apparatus to generate a control frame including a CMF and a set of multiple padding bits prior to an end-of-frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and. when the control frame is a secure control frame, a type of security associated with the control frame and output the control frame for transmission.

[0053] Another innovative aspect of the subject matter described in this disclosure can be implemented in an apparatus for wireless communications. The apparatus may include means for generating a control frame including a CMF and a set of multiple padding bits prior to an end-of-frame field, where a quantify of the set of multiple padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame and means for outputting the control frame for transmission.

[0054] Another innovative aspect of the subject matter described in this disclosure can be implemented in a non-transitory computer-readable medium storing code for wireless communications. The code may include instructions executable by one or more processors to generate a control frame including a CMF and a set of multiple padding bits prior to an end-of-frame field, where a quantify of the set of multiple padding bits is based on whether the control frame is a secure control frame and. when the control frame is a secure control frame, a type of security associated with the control frame and output the control frame for transmission.

[0055] Details of one or more implementations of the subject matter described in this disclosure are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages will become apparent from the description, the drawings and the claims. Note that the relative dimensions of the following figures may not be draw n to scale.BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 shows a pictorial diagram of an example wireless communication network.

[0057] Figure 2 shows an example protocol data unit (PDU) usable for communications between a wireless access point (AP) and one or more wireless stations (STAs).

[0058] Figure 3 shows an example physical layer (PHY) protocol data unit (PPDU) usable for communications between a wireless AP and one or more wireless STAs.

[0059] Figure 4 shows a hierarchical format of an example PPDU usable for communications between a wireless AP and one or more wireless STAs.

[0060] Figure 5 shows an example signaling diagram that supports secure control frames in wireless communications.

[0061] Figure 6 shows an example of a control message integrity check field (CMF) that supports secure control frames in wireless communications.

[0062] Figure 7 shows example CMF locations that support secure control frames in wireless communications.

[0063] Figure 8 shows an example of a secure control frame padding that supports secure control frames in wireless communications.

[0064] Figure 9 shows an example of a process flow that supports secure control frames in wireless communications.

[0065] Figure 10 shows an example of a process flow that supports secure control frames in wireless communications.

[0066] Figure 11 shows a block diagram of an example wireless communication device that supports secure control frames in wireless communications.

[0067] Figure 12 shows a block diagram of an example wireless communication device that supports secure control frames in wireless communications.

[0068] Figures 13-20 show flowcharts illustrating example processes performable by or at an apparatus that supports secure control frames in wireless communications.

[0069] Like reference numbers and designations in the various drawings indicate like elements.DETAILED DESCRIPTION

[0070] The following description is directed to some particular examples for the purposes of describing innovative aspects of this disclosure. However, a person having ordinary skill in the art will readily recognize that the teachings herein can be applied in a multitude of different ways. Some or all of the described examples may be implemented in any device, system or network that is capable of transmitting and receiving radio frequency (RF) signals according to one or more of the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards, the IEEE 802.15 standards, the Bluetooth® standards as defined by the Bluetooth Special Interest Group (SIG), or the Long Term Evolution (LTE), 3G, 4G, 5G (New Radio (NR)) or 6G standards promulgated by the 3rd Generation Partnership Project (3GPP), among others.

[0071] The described examples can be implemented in any suitable device, component, system or network that is capable of transmitting and receiving RF signals according to one or more of the following technologies or techniques: code division multiple access (CDMA), time division multiple access (TDMA). orthogonal frequency division multiplexing (OFDM), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), spatial division multiple access (SDMA), rate-splitting multiple access (RSMA), multi-user shared access (MUSA), single-user (SU) multiple-input multiple-output (MIMO) and multi-user (MU)-MIMO (MU-MIMO). The described examples also can be implemented using other wireless communication protocols or RF signals suitable for use in one or more of a wireless personal area network (WPAN), a wireless local area network (WLAN), a wireless wide area network (WWAN), a wireless metropolitan area network (WMAN), a nonterrestrial network (NTN), or an internet of things (IOT) network.

[0072] Various aspects relate generally to securing frames between an access point (AP) and station (STA), such as frames including control information. In some examples, a frame is transmitted with a control message integrity check (MIC) field (CMF) that includes an identifier (ID) of a security key, at least a portion of a packet number (PN), and at least a portion of an integrity check computed based on one ormore portions of the frame including the control information and the security key. In some examples, the CMF may be transmitted is separate parts, such as a first portion and a second portion. The first portion of the CMF and the second portion of the CMF may include different subsets of the ID of the security key, the portion of the PN. and at least a truncated portion of the integrity check. For example, the first portion of the CMF may include the ID of the security key and at least the portion of the PN, and a second portion of the CMF may include at least a truncated portion of the integrity check. The first portion of the CMF may be transmitted relatively early in the frame, such as pnor to one or more fields that are to be protected, and the second portion of the CMF may be transmitted after one or more fields that are to be protected. In some examples, a partial PN may be transmitted in the first portion of the CMF, which may be combined with a base PN to generate a full PN that is used for integrity check, encryption, or both. Additionally, or alternatively, an association identifier (AID) may be used instead of a medium access control (MAC) address to associate one or more security keys for each STA.

[0073] In some examples, additionally, or alternatively, an amount of padding provided in control frames may be based on whether a frame is protected and, if the frame is protected, whether protection is provided using an integrity check, encryption, or both. In some examples, the security key may be a group temporal key (GTK) or a pairwise temporal key (PTK). Such security- keys may be shared between an AP and authenticated STAs during or after authentication. In some implementations, a GTK or PTK may be selected for encrypting a frame based on a quantity of STAs that are being served by an AP, and switching between the PTK and GTK may be dynamic. A receiver receiving such a frame can verify the frame by computing an integrity check for the frame using the security key identified by the ID included in the frame and comparing the computed integrity check with the integrity check included in the frame. In addition, a receiver receiving such a frame can verify that the frame is not a replay of a frame the receiver has already received by checking that the PN of the frame is the expected PN, such as the next PN in sequence.

[0074] Particular aspects of the subject matter described in this disclosure can be implemented to realize one or more of the following potential advantages. In some examples, by verifying a control frame, a UE can avoid wasting power and radiofrequency resources when the UE receives an invalid control frame from an attacker. In addition, the described techniques can be used to efficiently verify a control frame, allowing devices to efficiently respond to the control frames, as opposed to some techniques in which large portions of a frame may be encrypted, which can cause a device to spend a substantial amount of time and processing resources decrypting those portions of the frame. Further, by providing information of the CMF in separate parts, the described techniques may allow for the CMF to be provided in accordance with existing frame structures in which the PN and the ID of the security key may be part of a security header while the integrity check is provided later in the frame. By providing a partial PN, overhead within the CMF (such as within the first portion of the CMF) may be reduced, and by providing a truncated integrity check, overhead within the CMF (such as within the second portion of the CMF) may be reduced. Further, in examples in which an AID may be used instead of a MAC address to associate one or more security keys for each STA, such techniques may provide for reduced memory usage relative to implementations in which the MAC address may be stored along with the one or more security keys for each STA.

[0075] Additionally, in examples that provide for switching between GTKs and PTKs, such techniques may be used to efficiently manage tracking of security keys of multiple STAs at an AP, where if a quantity of STAs served by an AP is less than a first amount separate PTKs for each STA may be maintained, and otherwise a GTK may be associated with multiple STAs which may allow for more efficient processing at the AP. Further, in examples in which an amount of padding is based on whether a frame is protected and, if the frame is protected, whether protection is provided using an integrity check, encryption, or both, sufficient processing time may be provided for processing of the control frame while reducing overhead in cases in which less processing time is used, such as cases in which no protection is provided for a frame or in which an unencrypted frame uses an integrity check, which use less processing time than encrypted frames.

[0076] Figure 1 shows a pictorial diagram of an example wireless communication network 100. According to some aspects, the wireless communication network 100 can be an example of a wireless local area network (WLAN) such as a Wi-Fi network. For example, the wireless communication network 100 can be a network implementing atleast one of the IEEE 802.11 family of wireless communication protocol standards (such as defined by the IEEE 802. 11-2020 specification or amendments thereof including, but not limited to, 802.11ay, 802.11ax, 802.11az, 802.11ba, 802.11bc, 802. 1 Ibd, 802. 1 Ibe, 802. 1 Ibf. and 802. 1 Ibn). In some other examples, the wireless communication network 100 can be an example of a cellular radio access network (RAN), such as a 5G or 6G RAN that implements one or more cellular protocols such as those specified in one or more 3GPP standards. In some other examples, the wireless communication network 100 can include a WLAN that functions in an interoperable or converged manner with one or more cellular RANs to provide greater or enhanced network coverage to wireless communication devices within the wireless communication network 100 or to enable such devices to connect to a cellular network’s core, such as to access the network management capabilities and functionality offered by the cellular network core. In some other examples, the wireless communication network 100 can include a WLAN that functions in an interoperable or converged manner with one or more personal area networks, such as a network implementing Bluetooth or other wireless technologies, to provide greater or enhanced network coverage or to provide or enable other capabilities, functionality, applications or services.

[0077] The wireless communication network 100 may include numerous wireless communication devices including at least one wireless AP 102 and any number of wireless STAs 104. While only one AP 102 is shown in Figure 1, the wireless communication network 100 can include multiple APs 102. The AP 102 can be or represent various different types of network entities including, but not limited to, a home networking AP, an enterprise-level AP, a single-frequency AP, a dual-band simultaneous (DBS) AP, a tri-band simultaneous (TBS) AP, a standalone AP, a non- standalone AP, a software-enabled AP (soft AP), and a multi-link AP (also referred to as an AP multi-link device (MLD)), as well as cellular (such as 3GPP, 4G LTE, 5G or 6G) base stations or other cellular network nodes such as a Node B, an evolved Node B (eNB), a gNB, a transmission reception point (TRP) or another ty pe of device or equipment included in a radio access network (RAN), including Open-RAN (O-RAN) network entities, such as a central unit (CU), a distributed unit (DU) or a radio unit (RU).

[0078] Each of the STAs 104 also may be referred to as a mobile station (MS), a mobile device, a mobile handset, a wireless handset, an access terminal (AT), a user equipment (UE), a subscriber station (SS), or a subscriber unit, among other examples. The STAs 104 may represent various devices such as mobile phones, other handheld or wearable communication devices, netbooks, notebook computers, tablet computers, laptops, Chromebooks, augmented reality (AR), virtual reality (VR), mixed reality (MR) or extended reality (XR) wireless headsets or other peripheral devices, wireless earbuds, other wearable devices, display devices (for example, TVs, computer monitors or video gaming consoles), video game controllers, navigation systems, music or other audio or stereo devices, remote control devices, printers, kitchen appliances (including smart refrigerators) or other household appliances, key fobs (for example, for passive keyless entry and start (PKES) systems), Internet of Things (loT) devices, and vehicles, among other examples.

[0079] A single AP 102 and an associated set of STAs 104 may be referred to as a basic service set (BSS), which is managed by the respective AP 102. Figure 1 additionally shows an example coverage area 108 of the AP 102, which may represent a basic service area (BSA) of the wireless communication network 100. The BSS may be identified by STAs 104 and other devices by a service set identifier (SSID), as well as a basic service set identifier (BSSID), which may be a medium access control (MAC) address of the AP 102. The AP 102 may periodically broadcast beacon frames ("beacons") including the BSSID to enable any STAs 104 within wireless range of the AP 102 to "‘associate” or re-associate with the AP 102 to establish a respective communication link 106 (hereinafter also referred to as a “Wi-Fi link”), or to maintain a communication link 106, with the AP 102. For example, the beacons can include an identification or indication of a primary channel used by the respective AP 102 as well as a timing synchronization function (TSF) for establishing or maintaining timing synchronization with the AP 102. The AP 102 may provide access to external networks to various STAs 104 in the wireless communication network 100 via respective communication links 106.

[0080] To establish a communication link 106 with an AP 102, each of the STAs 104 is configured to perform passive or active scanning operations (“scans”) on frequency channels in one or more frequency bands (for example, the 2.4 GHz. 5 GHz,6 GHz, 45 GHz, or 60 GHz bands). To perform passive scanning, a ST A 104 listens for beacons, which are transmitted by respective APs 102 at periodic time intervals referred to as target beacon transmission times (TBTTs). To perform active scanning, a STA 104 generates and sequentially transmits probe requests on each channel to be scanned and listens for probe responses from APs 102. Each STA 104 may identify, determine, ascertain, or select an AP 102 with which to associate in accordance with the scanning information obtained through the passive or active scans, and to perform authentication and association operations to establish a communication link 106 with the selected AP 102. The selected AP 102 assigns an AID to the STA 104 at the culmination of the association operations, which the AP 102 uses to track the STA 104.

[0081] As a result of the increasing ubiquity of wireless networks, a STA 104 may have the opportunity to select one of many BSSs within range of the STA 104 or to select among multiple APs 102 that together form an extended service set (ESS) including multiple connected BSSs. For example, the wireless communication network 100 may be connected to a wired or wireless distribution system that may enable multiple APs 102 to be connected in such an ESS. As such, a STA 104 can be covered by more than one AP 102 and can associate with different APs 102 at different times for different transmissions. Additionally, after association with an AP 102, a STA 104 also may periodically scan its surroundings to find a more suitable AP 102 with which to associate. For example, a STA 104 that is moving relative to its associated AP 102 may perform a ‘‘roaming’' scan to find another AP 102 having more desirable network characteristics such as a greater received signal strength indicator (RS SI) or a reduced traffic load.

[0082] In some examples, STAs 104 may form networks without APs 102 or other equipment other than the STAs 104 themselves. One example of such a network is an ad hoc network (or wireless ad hoc network). Ad hoc networks may alternatively be referred to as mesh networks or peer-to-peer (P2P) networks. In some examples, ad hoc networks may be implemented within a larger network such as the wireless communication network 100. In such examples, while the STAs 104 may be capable of communicating with each other through the AP 102 using communication links 106, STAs 104 also can communicate directly with each other via direct wireless communication links 110. Additionally, two STAs 104 may communicate via a directwireless communication link 1 10 regardless of whether both STAs 104 are associated with and served by the same AP 102. In such an ad hoc system, one or more of the STAs 104 may assume the role fdled by the AP 102 in a BSS. Such a STA 104 may be referred to as a group owner (GO) and may coordinate transmissions within the ad hoc network. Examples of direct wireless communication links 110 include Wi-Fi Direct connections, connections established by using a Wi-Fi Tunneled Direct Link Setup (TDLS) link, and other P2P group connections.

[0083] In some networks, the AP 102 or the STAs 104, or both, may support applications associated with high throughput or low-latency requirements, or may provide lossless audio to one or more other devices. For example, the AP 102 or the STAs 104 may support applications and use cases associated with ultra-low-latency (ULL), such as ULL gaming, or streaming lossless audio and video to one or more personal audio devices (such as peripheral devices) or AR / VR / MR / XR headset devices. In scenarios in which a user uses two or more peripheral devices, the AP 102 or the STAs 104 may support an extended personal audio network enabling communication with the two or more peripheral devices. Additionally, the AP 102 and STAs 104 may support additional ULL applications such as cloud-based applications (such as VR cloud gaming) that have ULL and high throughput requirements.

[0084] As indicated above, in some implementations, the AP 102 and the STAs 104 may function and communicate (via the respective communication links 106) according to one or more of the IEEE 802. 11 family of wireless communication protocol standards. These standards define the WLAN radio and baseband protocols for the physical (PHY) and MAC layers. The AP 102 and STAs 104 transmit and receive wireless communications (hereinafter also referred to as “Wi-Fi communications” or "w ireless packets”) to and from one another in the form of PHY protocol data units (PPDUs).

[0085] Each PPDU is a composite structure that includes a PHY preamble and a pay load that is in the form of a PHY service data unit (PSDU). The information provided in the preamble may be used by a receiving device to decode the subsequent data in the PSDU. In instances in which a PPDU is transmitted over a bonded or wideband channel, the preamble fields may be duplicated and transmitted in each of multiple component channels. The PHY preamble may include both a legacy portion(or '‘legacy preamble”) and a non-legacy portion (or “non-legacy preamble”). The legacy preamble may be used for packet detection, automatic gain control and channel estimation, among other uses. The legacy preamble also may generally be used to maintain compatibility with legacy devices. The format of, coding of, and information provided in the non-legacy portion of the preamble is associated with the particular IEEE 802. 11 wireless communication protocol to be used to transmit the payload.

[0086] The APs 102 and STAs 104 in the wireless communication network 100 may transmit PPDUs over an unlicensed spectrum, which may be a portion of spectrum that includes frequency bands traditionally used by Wi-Fi technology, such as the 2.4 GHz. 5 GHz, 6 GHz, 45 GHz, and 60 GHz bands. Some examples of the APs 102 and STAs 104 described herein also may communicate in other frequency bands that may support licensed or unlicensed communications. For example, the APs 102 or STAs 104, or both, also may be capable of communicating over licensed operating bands, where multiple operators may have respective licenses to operate in the same or overlapping frequency ranges. Such licensed operating bands may map to or be associated with frequency range designations of FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), FR4 (52.6 GHz - 114.25 GHz), and FR5 (114.25 GHz - 300 GHz).

[0087] Each of the frequency bands may include multiple sub-bands and frequencychannels (also referred to as subchannels). The terms “channel” and “subchannel” may be used interchangeably herein, as each may refer to a portion of frequency spectrum within a frequency band (for example, a 20 MHz, 40 MHz, 80 MHz, or 160 MHz portion of frequency spectrum) via which communication between two or more wireless communication devices can occur. For example, PPDUs conforming to the IEEE 802.11n, 802.11ac, 802.11ax, 802.11be and 802.11bn standard amendments may be transmitted over one or more of the 2.4 GHz, 5 GHz, or 6 GHz bands, each of which is divided into multiple 20 MHz channels. As such, these PPDUs are transmitted over a physical channel having a minimum bandwidth of 20 MHz, but larger channels can be formed through channel bonding. For example, PPDUs may be transmitted over physical channels having bandwidths of 40 MHz, 80 MHz, 160 MHz, 240 MHz, 320 MHz, 480 MHz, or 640 MHz by bonding together multiple 20 MHz channels.

[0088] An AP 102 may determine or select an operating or operational bandwidth for the STAs 104 in its BSS and select a range of channels within a band to provide that operating bandwidth. For example, the AP 102 may select sixteen 20 MHz channels that collectively span an operating bandwidth of 320 MHz. Within the operating bandwidth, the AP 102 may typically select a single primary 20 MHz channel on which the AP 102 and the STAs 104 in its BSS monitor for contention-based access schemes. In some examples, the AP 102 or the STAs 104 may be capable of monitoring only a single primary 20 MHz channel for packet detection (for example, for detecting preambles of PPDUs). Conventionally, any transmission by an AP 102 or a STA 104 within a BSS must involve transmission on the primary 20 MHz channel. As such, in conventional systems, the transmitting device must contend on and win a transmission opportunity (TXOP) on the primary channel to transmit anything at all. However, some APs 102 and STAs 104 supporting ultra-high reliability (UHR) communications or communication according to the IEEE 802.11 bn standard amendment can be configured to operate, monitor, contend and communicate using multiple primary 20 MHz channels. Such monitoring of multiple primary 20 MHz channels may be sequential such that responsive to determining, ascertaining or detecting that a first primary 20 MHz channel is not available, a wireless communication device may switch to monitoring and contending using a second primary 20 MHz channel.

[0089] Additionally, or alternatively, a wireless communication device may be configured to monitor multiple primary720 MHz channels in parallel. In some examples, a first primary 20 MHz channel may be referred to as a main primary (M- Pnmary) channel and one or more additional, second primary channels may each be referred to as an opportunistic primary7(O-Primary) channel. For example, if a wireless communication device measures, identifies, ascertains, detects, or otherwise determines that the M-Primary channel is busy or occupied (such as due to an overlapping BSS (OBSS) transmission), the wireless communication device may switch to monitoring and contending on an O-Primary channel. In some examples, the M-Primary channel may be used for beaconing and serving legacy client devices and an O-Primary7channel may be specifically used by non-legacy (for example, UHR- or IEEE 802.11bn- compatible) devices for opportunistic access to spectrum that may be otherwise underutilized.

[0090] Figure 2 shows an example protocol data unit (PDU) 200 usable for wireless communication between a wireless AP and one or more wireless STAs. For example, the AP and STAs may be examples of the AP 102 and the STAs 104 described with reference to Figure 1. The PDU 200 can be configured as a PPDU. As shown, the PDU 200 includes a PHY preamble 202 and a PHY payload 204. For example, the preamble 202 may include a legacy portion that itself includes a legacy short training field (L- STF) 206, which may consist of two symbols, a legacy long training field (L-LTF) 208, which may consist of two symbols, and a legacy signal field (L-SIG) 210, which may consist of two symbols. The legacy portion of the preamble 202 may be configured according to the IEEE 802. 1 la wireless communication protocol standard. The preamble 202 also may include a non-legacy portion including one or more non-legacy fields 212, for example, conforming to one or more of the IEEE 802. 11 family of wireless communication protocol standards.

[0091] The L-STF 206 generally enables a receiving device (such as an AP 102 or a STA 104) to perform coarse timing and frequency tracking and automatic gain control (AGC). The L-LTF 208 generally enables the receiving device to perform fine timing and frequency tracking and also to perform an initial estimate of the wireless channel. The L-SIG 210 generally enables the receiving device to determine (for example, obtain, select, identify, detect, ascertain, calculate, or compute) a duration of the PDU and to use the determined duration to avoid transmitting on top of the PDU. The legacy portion of the preamble, including the L-STF 206, the L-LTF 208 and the L-SIG 210, may be modulated according to a binary phase shift keying (BPSK) modulation scheme. The payload 204 may be modulated according to a BPSK modulation scheme, a quadrature BPSK (Q-BPSK) modulation scheme, a quadrature amplitude modulation (QAM) modulation scheme, or another appropriate modulation scheme. The payload 204 may include a PSDU including a data field (DATA) 214 that, in turn, may carry higher layer data, for example, in the form of MAC protocol data units (MPDUs) or an aggregated MPDU (A-MPDU).

[0092] Figure 3 shows an example physical layer (PHY) protocol data unit (PPDU) 350 usable for communications between a wireless AP and one or more wireless STAs. For example, the AP and STAs may be examples of the AP 102 and the STAs 104 described with reference to Figure 1. As shown, the PPDU 350 includes a PHYpreamble, that includes a legacy portion 352 and a non-legacy portion 354, and a payload 356 that includes a data field 374. The legacy portion 352 of the preamble includes an L-STF 358, an L-LTF 360, and an L-SIG 362. The non-legacy portion 354 of the preamble includes a repetition of L-SIG (RL-SIG) 364 and multiple wireless communication protocol version-dependent signal fields after RL-SIG 364. For example, the non-legacy portion 354 may include a universal signal field (referred to herein as “U-SIG 366’") and an EHT signal field (referred to herein as “EHT-SIG 368”). The presence of RL-SIG 364 and U-SIG 366 may indicate to EHT- or later version- compliant ST As 104 that the PPDU 350 is an EHT PPDU or a PPDU conforming to any later (post-EHT) version of a new wireless communication protocol conforming to a future IEEE 802.11 wireless communication protocol standard. One or both of U-SIG 366 and EHT-SIG 368 may be structured as, and cany' version-dependent information for. other wireless communication protocol versions associated with amendments to the IEEE family of standards beyond EHT. For example, U-SIG 366 may be used by a receiving device (such as an AP 102 or a STA 104) to interpret bits in one or more of EHT-SIG 368 or the data field 374. Like L-STF 358, L-LTF 360, and L-SIG 362, the information in U-SIG 366 and EHT-SIG 368 may be duplicated and transmitted in each of the component 20 MHz channels in instances involving the use of a bonded channel.

[0093] The non-legacy portion 354 further includes an additional short training field (referred to herein as “EHT-STF 370,” although it may be structured as, and carry version-dependent information for, other wireless communication protocol versions beyond EHT) and one or more additional long training fields (referred to herein as “EHT-LTFs 372,” although they may be structured as, and carry version-dependent information for, other wireless communication protocol versions beyond EHT). EHT- STF 370 may be used for timing and frequency tracking and AGC, and EHT-LTF 372 may be used for more refined channel estimation.

[0094] EHT-SIG 368 may be used by an AP 102 to identify and inform one or multiple STAs 104 that the AP 102 has scheduled uplink (UL) or downlink (DL) resources for them. EHT-SIG 368 may be decoded by each compatible STA 104 served by the AP 102. EHT-SIG 368 may generally be used by the receiving device to interpret bits in the data field 374. For example, EHT-SIG 368 may include resource unit (RU) allocation information, spatial stream configuration information, and per-user(for example, STA-specific) signaling information. Each EHT-SIG 368 may include a common field and at least one user-specific field. In the context of OFDMA, the common field can indicate RU distributions to multiple STAs 104, indicate the RU assignments in the frequency domain, indicate which RUs are allocated for MU-MIMO transmissions and which RUs correspond to OFDMA transmissions, and the number of users in allocations, among other examples. The user-specific fields are assigned to particular STAs 104 and carry STA-specific scheduling information such as userspecific MCS values and user-specific RU allocation information. Such information enables the respective STAs 104 to identify and decode corresponding RUs in the associated data field 374.

[0095] Figure 4 shows a hierarchical format of an example PPDU usable for communications between a wireless AP and one or more wireless STAs. For example, the AP and STAs may be examples of the AP 102 and the STAs 104 described with reference to Figure 1. As described, each PPDU 400 includes a PHY preamble 402 and a PSDU 404. Each PSDU 404 may represent (or “carry”) one or more MAC protocol data units (MPDUs) 416. For example, each PSDU 404 may cany an aggregated MPDU (A-MPDU) 406 that includes an aggregation of multiple A-MPDU subframes 408. Each A-MPDU subframe 408 may include an MPDU frame 410 that includes a MAC delimiter 412 and a MAC header 414 prior to the accompanying MPDU 416, which includes the data portion (“payload” or “frame body”) of the MPDU frame 410. Each MPDU frame 410 also may include a frame check sequence (FCS) field 418 for error detection (for example, the FCS field 418 may include a cyclic redundancy check (CRC)) and padding bits 420. The MPDU 416 may carry one or more MAC service data units (MSDUs) 430. For example, the MPDU 416 may carry an aggregated MSDU (A-MSDU) 422 including multiple A-MSDU subframes 424. Each A-MSDU subframe 424 may be associated with an MSDU frame 426 and may contain a corresponding MSDU 430 preceded by a subframe header 428 and, in some examples, followed by padding bits 432.

[0096] Referring back to the MPDU frame 410, the MAC delimiter 412 may serve as a marker of the start of the associated MPDU 416 and indicate the length of the associated MPDU 416. The MAC header 414 may include multiple fields containing information that defines or indicates characteristics or attributes of data encapsulatedwithin the frame body. The MAC header 414 includes a duration field indicating a duration extending from the end of the PPDU until at least the end of an acknowledgement (ACK) or Block ACK (BA) of the PPDU that is to be transmitted by the receiving wireless communication device. The use of the duration field serves to reserve the wireless medium for the indicated duration and enables the receiving device to establish its network allocation vector (NAV). The MAC header 414 also includes one or more fields indicating addresses for the data encapsulated within the frame body. For example, the MAC header 414 may include a combination of a source address, a transmitter address, a receiver address or a destination address. The MAC header 414 may further include a frame control field containing control information. The frame control field may specify a frame type, for example, a data frame, a control frame, or a management frame.

[0097] In some wireless communication systems, wireless communication between an AP 102 and an associated STA 104 can be secured. For example, either an AP 102 or a STA 104 may establish a security key for securing wireless communication between itself and the other device and may encry pt the contents of the data and management frames using the security key. In some examples, the control frame and fields within the MAC header of the data or management frames, or both, also may be secured either via encryption or via an integrity check (for example, by generating a MIC for one or more relevant fields.

[0098] Figure 5 shows an example signaling diagram 500 that supports secure control frames in wireless communications between a first wireless device, such as a wireless AP, and one or more second wireless devices, such as one or more wireless STAs. The signaling diagram 500 may implement or be implemented to realize one or more aspects of the wireless communication network 100. For example, the signaling diagram 500 illustrates communications 505 between an AP 510 and one or more STAs, such as a STA 515-a and a STA 515-b, which may be examples of corresponding devices illustrated by and described with reference to Figure 1. In some implementations, the communications 505 may be an example of one or more types of communications between the AP 510 and the STAs 515-a and 515-b, which may include one or more control frames 520.

[0099] In some implementations, a first wireless device, such as the AP 510, may communicate with a second wireless device, such as the STA 515-a, and one of the AP 510 or the STA 515-a may transmit a control frame 520. The control frame 520 may be any of multiple different types of control frames, such as a trigger frame, a ready -to- send frame, a request-to-send (RTS) frame, a block acknowledgment request (BAR) frame, a block acknowledgment (BA) frame, or the like. In some implementations, wireless devices may transmit a control frame 520 in response to an initiating control frame (such as in a trigger-based PPDU format), or the like. In some implementations, a wireless device may transmit a control response frame (CRF). such as a BA frame (which may be a CRF sent in response to a soliciting frame that is not a control frame) to another wireless device indicating feedback for data. In some examples, a soliciting frame may be an RTS frame, a trigger frame (and any variants of the trigger frame), a BAR frame, or the like.

[0100] In the example of Figure 5. the control frame 520 may include a frame control field 525 (two octets in this example), a duration or identification field 530 (two octets in this example), a receiver address (RA) field 535 (six octets in this example), a transmitter address (TA) field 540 (six octets in this example), one or more control information fields 545 (such as a common information field, a user information list, CMF, and padding, which may have a variable length), and a frame check sequence (FCS) field 550 (four octets in this example). In some implementations, these fields may include one or more subfields. In some implementations, a CMF may be provided in the control information fields 545, which may include two or more portions of the CMF such as a first portion of the CMF 555 and a second portion of the CMF 560. In some examples, a padding field 565 may be provided prior to the FCS field 550. The first portion of the CMF 555, in some examples, may be provided relatively early within the one or more control information fields 545. For example, a secure trigger frame may include the first portion of the CMF 555 after a common information field. The second portion of the CMF 560, in some examples, may be provided later within the one or more control information fields 545 such as subsequent to a user information list and prior to padding bits in padding field 565. Alternatively, the second portion of the CMF 560 may be included in the padding bits in the padding field 565.

[0101] In some examples, the second portion of the CMF 560 may include an integrity check that may be calculated over all or part of the fields of the MAC header (such as the duration or identification field 530, the RA field 535, and the TA field 540), the control information fields 545 (such as a common information field, user information list fields, a security key indication, and a PN). In some implementations, the STAs 515-a and 515-b and the AP 510 that have access to the security keys may verify the control frame 520 by computing an integrity check value based on received fields of the control frame 520 and comparing the computed integrity check to the integrity check value provided in the second portion of the CMF 560. If the STAs 515-a and 515-b or the AP 510 are unable to verify the control frame 520 because the computed integrity check does not match the integrity' check provided in the control frame 520, the STAs 515-a and 515-b or the AP 510 may discard the control frame 520. Other STAs that are capable of performing security checks (such as non-UHR STAs. such as high efficiency (HE) or extremely high throughput (EHT) STAs), may ignore the first portion of the CMF 555 and the second portion of the CMF 560 while processing the remainder of the control frame 520.

[0102] In some implementations, the control frame 520 may contain variable amounts of data or information to support communicating control information in addition to other information (such as information related to a TXOP). The control frame may be sent as a single MP DU, such as an initial frame of a TXOP or during the TXOP. In some implementations, the control frame 520 may solicit a response with control feedback, which may be indicated by a bit in the control frame 520 or a reserved value of a TXOP sharing mode. For example, a bit value of ‘ 1 ’ in the control frame 520 (such as a multi-user RTS (MU-RTS)) may indicate that the control frame 520 is soliciting a responsive frame (such as a Multi-STA BlockAck (M-BA) frame or a clear- to-send (CTS) frame with control feedback or a trigger frame variant with control feedback). In some examples, the control frame 520 may contain only control feedback in which no response (such as a CTS, a trigger-based PPDU, or the like) is requested.

[0103] Figure 6 shows an example of a CMF 600 usable for communications between wireless devices, such as a wireless AP and one or more wireless STAs. The example CMF 600 may include a security key ID field 610 that includes a first number of octets (such as two octets) or a packet number 615 (such as an integrity grouptemporal key packet number (IPN) or a beacon integrity group temporal key packet number (BIPN)) that includes a second number of octets (such as 6 octets) in a first portion of the CMF 620. The example CMF 600 also may include a second portion of the CMF 630 that includes a MIC value 625 that includes a third number of octets (such as eight or sixteen octets). It may be noted that the example CMF 600 has a structure similar to a management MIC information element (IE) that may be used to protect beacon frames. However, the present disclosure is not limited to the structure illustrated in Figure 6 and includes CMFs having other structures.

[0104] For example, the ID described herein may be conveyed in fields smaller than two octets, or as bits that are included in other fields of a frame. In another example, the complete PN described herein may be split into a partial PN and a base PN, and the PN field of the CMFs described herein may convey the partial PN instead of the complete PN. The wireless devices described herein may exchange the base PN occasionally (such as, regularly, in response to a request, or in response to a triggering event) and store the base PN for use (such as in calculations, transmissions, or verifying received packets). In yet another example, the wireless devices described herein may include only a portion of a MIC in the second portion of the CMF 630 (such as a truncated integrity check).

[0105] In some examples, the truncated integrity check may be a truncated portion of a Galois message authentication code (GMAC) output (such as the 28 or 32 least significant bits of the GMAC output or the 56 or 62 least significant bits of the GMAC Output), which may reduce the MIC value 625 to four octets or eight octets, and thereby reduce overhead relative to transmission of the full GMAC output. A receiving device may compare the truncated integrity check to the corresponding four octets or eight octets of an integrity check calculated at the receiving device based at least on the security key and other portions of the packet. In such examples, one or more portions of the CMF 605 may be provided in a user information field of a trigger frame is that is five octets long, although the same approach may be used for other control frames as well.

[0106] Figure 7 shows example CMF locations 700 that supports secure control frames in wireless communications between wireless devices, such as a wireless AP and one or more wireless STAs. In this example, a control frame 705, similarly as discussedabove, may include a frame control field 710, a duration or identification field 715, an RA field 720, a TA field 725, one or more control information fields 730, and an FCS field 735. The control information field 730 may include multiple fields including an optional first control information subfield 740-a, a second control information subfield 740-b, a first portion of a CMF 745, a second portion of the CMF 750, and a padding field 755. As discussed with reference to Figure 5, the locations of the first portion of the CMF 745 and the second portion of the CMF 750 may be provided within the control information at different areas.

[0107] In the example of Figure 7. the first portion of the CMF 745 may be placed relatively early in the control information field 730. For example, the first portion of the CMF 745 may be placed prior to one or more fields that are to be protected, although in some frames the first portion of the CMF 745 may be located after one or more control information fields due to defined formats of the frames. For example, in a trigger frame, a common information field may be located at the beginning of the control information, and in such cases the first portion of the CMF 745 may be located subsequent to the common information field. Placing the first portion of the CMF 745 relatively early in the control information may allow for early determination of location at the receiving device, depending on the control frame. For example, if the control frame 705 is a protected trigger frame, the first portion of the CMF 745 may be CMF1 immediately after the common information field, or if the control frame includes a special user information field, the first portion of the CMF 745 may be placed immediately after the special user information field. In some examples, if the protected control frame 705 is a BAR or BA frame, the first portion of the CMF 745 may be placed immediately after the BAR or BA control information.

[0108] In the example of Figure 7, the second portion of the CMF 750 may be located subsequent to one or more fields that are protected in the protected control frame 705. In some examples, the second portion of the CMF 750 may be located immediately prior to the padding field 755 (such as if the second portion of the CMF 750 is included as a user information field). In some other examples, the second portion of the CMF 750 may be included as part of the padding field 755. For example, the padding field 755 may include an initial set of bits having a defined value (such as thefirst 12 bits set to all ones), and the second portion of the CMF 750 may be located subsequent to such an initial set of bits.

[0109] In some examples, a receiving device may be able to make a relatively early determination on the location of the first portion of the CMF 745 and the second portion of the CMF 750. In some examples, the location of the second portion of the CMF 750 may be indicated in or prior to the first portion of the CMF 745. In some examples, a padding duration after the second portion of the CMF 750 remains the same (or slowly changes) and is advertised via a management frame (such as in a UHR operation element); or can be signaled in or prior to the first portion of the CMF 745. Such locations of the CMF may allow for decoding of the control frames at receiving devices that do not support security of such frames by preserving the control frame structure, in which the PN and encr ption key ID may be part of a security header and MIC may be at the end of the control information field 730.

[0110] Further, in some examples, an AID of a STA at an AP may be associated with encryption keys and PNs. In some implementations, various computations may be based on MAC addresses (such as nonce computations, additional authenticated data (AAD), and the like). At the STA side, using the MAC address may not consume significant memory’ or processing resources because the STA may be associated with only one AP and fetching the key (such as the PTK) for that MAC address may be relatively efficient, with a relatively small amount of memory’ usage (only one MAC address (of the AP), only one PTK and PN). However, at the AP side, due to potentially many STAs being associated with the AP, and fetching the keys (such as PTKs) for each STA, having associations with the MAC address and PTKs, PNs, of each STA may consume a significant amount of memory and processing resources. This applies to both receiving and transmitting at the AP, and especially to short interframe space (SIFS) generated control frames.[OHl] In some examples, the AID of the STA may be used for these steps instead of the MAC address. In such a manner, the AP may use the AID instead of the MAC addresses to fetch relevant data, and due to the AID having fewer bits, 12 bits as opposed to 48 bits, memory and processing resources at the AP are conserved. In some examples, to provide support for use of the AID, the AID may be carried in protected control frames. Providing the AID may be supported for trigger frames and M-BA(downlink) frames. In some examples, one or more fields of other types of frames may be modified to provide AID. For example, uplink M-BA frames, compressed BlockAck (C-BA) frames, multi-traffic identifiers (TID) BAR frames, and compressed BAR (C- BAR) frames may be modified to provide an AID indication. For frames soliciting protected control frames, in some examples, an AID field may be provided as part of MPDUs with secure MAC headers. In some examples, MPDUs that solicit protected control frames may only be carried in UHR PPDUs in which the PHY header of UHR PPDUs is expected to contain the transmitter ID in the U-SIG / SIG-A. Further, an indication of the AID may not be needed for all frames but only for frames that are generated by non-AP STAs, and that solicit protected responses, and in some examples the soliciting frame can contain a bit that indicates solicitation of protected control frames.

[0112] When performing encry ption on protected control frames, as discussed herein, a PTK or GTK may be used. For example, GTK may be used for group addressed control frames, and PTK may be used for individual control frames to provide additional security. However, use of PTKs by an AP may consume significant amounts of processing resources if a relatively large number of STAs are being served. In some examples, PTKs may be used for secure control frames in cases in which a limited quantity of STAs are actively communicating with the AP, and GTKs may be used when a quantity of STAs exceeds a threshold. For example, an AP may use PTKs for communications with STAs when 10 or fewer STAs are present, and may use GTKs for communications when more than 10 STAs are communicating. In some examples, the AP may determine whether all protected control frames are secured with a GTK (that is, both group and individual control frames are secured with GTK), or whether all protected group control frames are secured with a GTK while individual control frames are secured with a PTK. In some examples, the AP may dynamically switch between the two modes, and when the AP switches from one mode to the other, signaling may be provided (such as in a UHR operation element) to the STAs using protected control frames that a swi tch in PTK and GTK has occurred. In some examples, the AP may continue to use PTK for some STAs when the number of STAs exceed the threshold and use GTK for other STAs. For example, if nine STAs are communicating with anAP using a PTK mode, additional ST As may be indicated to use the GTK mode such that the AP may manage only 10 total encry ption keys.

[0113] Figure 8 shows an example of a secure control frame padding 800 that supports secure control frames in wireless communications. In some implementations these control frames may contain padding, prior to or after an FCS, which may give the receiver additional time to process the decry ption and integrity checks of protected control frames. The padding field may be a variable field that contains bits of information that are part of the PPDU carrying the control frame but that do not contain useful information for the receiver (which may instead provide the receiver with extra time to process the information, prepare a responsive message, adapt one or more subsequent frame exchanges to account for updated parameters indicated by the control feedback, or any combination thereof).

[0114] In some implementations, an amount of padding for frames (such as control frames) that solicit control frames may be based on whether the soliciting frame solicits a secured control frame or not, and, if a secured control frame is solicited, a type of protection used for the secured control frame. For example, first frames soliciting unsecured control frames may include a first quantity7of padding bits (such as one OFDM symbol of padding) that is smaller than a second quantity of padding bits (such as two OFDM symbols of padding) included within second frames soliciting secured control frames. In other words, if no secure control frames are solicited, a soliciting frame may include one OFDM symbol of padding. Else, two OFDM symbols may be included within the soliciting PPDU.

[0115] In the example of Figure 8. a control frame 805 may include a first portion of a CMF 810, a control information field 815. a second portion of the CMF 820, a padding field 825, and an FCS field 830. In this example, the padding field 825 for a non-secured control frame 835 may include a first quantity7of padding bits 840 (such as a quantity7of bits corresponding to one OFDM symbol). The padding field 825 for a non-encrypted MIC-only secured control frame 845 may include a second quantity of padding bits 850 (such as a quantity of bits corresponding to two OFDM symbols) that is greater than the first quantity of padding bits 840. The padding field 825 for an encrypted and MIC secured control frame 855 may include a third quantity of padding bits 860 (such as a quantity7of bits corresponding to three OFDM symbols) that isgreater than the second quantity of padding bits 850. The pre-end-of-frame padding for secure control frames may account for the extra amount of time the receiving device needs to obtain the PN, PTK / GTK, and perform security' procedure (such as MIC verification and decryption).

[0116] Figure 9 shows an example of a process flow 900 that supports secure control frames in wireless communications between a first wireless device (such as an AP) and a second wireless device (such as a STA). The process flow 900 may implement, or be implemented by, one or more aspects of the wireless communications system that uses secure control frames as described with reference to Figures 1-8. For example, the process flow 900 illustrates communications between a first wireless device 905 and a second wireless device 910, which may be examples of APs or STAs described with reference to Figures 1-8. The process flow 900 may support secure control frames and may be performed between any quantity of wireless devices.

[0117] In the following description of the process flow 900, the operations may be performed (such as reported or provided) in a different order than the order shown, or the operations performed by the example devices may be performed in different orders or at different times. For example, specific operations also may be left out of the process flow 900, or other operations may be added to the process flow 900. Further, although some operations or signaling may be shown to occur at different times for discussion purposes, these operations may actually occur at the same time. It should be noted that while the illustrated example refers to an AP communicating with one or more STAs, the sequence may support other device configurations, such as a STA indicating control feedback to one or more APs. a STA indicating control feedback to one or more other STAs, a first wireless device communicating with a second wireless device, or any combination of devices with different functionalities.

[0118] At 915, the first wireless device 905 and the second wireless device 910 may schedule an initial frame. The initial frame may be a data message. In some implementations, scheduling the initial frame may include communicating a control frame. For example, the first wireless device 905 and the second wireless device 910 may communicate one or more control frames (such as a BA frame) subsequent to the initial frame.

[0119] At 920, the first wireless device 905 may receive the initial frame from the second wireless device 910. In some implementations, the initial frame may be a data frame scheduled by the first wireless device 905 and the second wireless device 910.

[0120] At 925, the first wireless device 905 may transmit a first control frame in response to receiving the data message. In some implementations, the first control frame may be a first BA control frame and may be secured in accordance with techniques discussed herein. The first BA control frame may include, for example, a CMF to be used for verification of the first BA control frame.

[0121] At 930, the second wireless device 910 may verify frame validity of the first control frame. In some implementations, the second wireless device 910 may generate an integrity check on one or more fields of the first control frame and compare at least a portion of the generated integrity check to a corresponding MIC (or portion of a MIC) provided in a CMF within the first control frame. If the compared integrity checks match, the first control frame is further processed, and otherwise the first control frame is discarded.

[0122] At 935, the first wireless device 905 may receive a second control frame from the second wireless device 910. In some implementations, the second control frame may be the second BA control frame. The second control frame may include second control information (such as second BA control information) based on the first control feedback field indicating the request (soliciting a response). In some implementations, the second control frame may be secured in accordance with techniques discussed herein. The second BA control frame may include, for example, a CMF to be used for verification of the second BA control frame.

[0123] At 940, the first wireless device 905 may verify frame validity of the second control frame. In some implementations, the first wireless device 905 may generate an integrity check on one or more fields of the second control frame and compare at least a portion of the generated integrity check to a corresponding MIC (or portion of a MIC) provided in a CMF within the second control frame. If the compared integrity checks match, the second control frame may be further processed, and otherwise the second control frame may be discarded.

[0124] Figure 10 shows an example of a process flow 1000 that supports secure control frames in wireless communications between a first wireless device and a second wireless device. The process flow 1000 may implement, or be implemented by, one or more aspects of the wireless communications system that uses secure control frames as described with reference to Figures 1-8. For example, the process flow 1000 illustrates communications between a first wireless device 1005 and a second wireless device 1010, which may be examples of APs or STAs described with reference to Figures 1-8. The process flow WOO may support secure control frames and may be performed between any quantity of wireless devices.

[0125] In the following description of the process flow 1000, the operations may be performed (such as reported or provided) in a different order than the order shown, or the operations performed by the example devices may be performed in different orders or at different times. For example, specific operations also may be left out of the process flow 1000. or other operations may be added to the process flow 1000. Further, although some operations or signaling may be shown to occur at different times for discussion purposes, these operations may actually occur at the same time. It should be noted that while the illustrated example refers to an AP communicating with one or more STAs, the sequence may support other device configurations, such as a STA indicating control feedback to one or more APs, a STA indicating control feedback to one or more other STAs, a first wireless device communicating with a second wireless device, or any combination of devices with different functionalities.

[0126] At 1015, the first wireless device 1005 may transmit, to the second wireless device 1010, a first control frame. In some implementations, the first control frame may be a trigger frame, and may be secured in accordance with techniques discussed herein. The first control frame may include, for example, a CMF to be used for verification of the first control frame.

[0127] At 1020, the second wireless device 1010 may verify frame validity of the first control frame. In some implementations, the second wireless device 1010 may generate an integrity check on one or more fields of the first control frame and compare at least a portion of the generated integrity check to a corresponding MIC (or portion of a MIC) provided in a CMF within the first control frame. If the compared integritychecks match, the first control frame may be further processed, and otherwise the first control frame may be discarded.

[0128] At 1025, the first wireless device 1005 may receive, from the second wireless device 1010, a second control frame, such as a response frame responsive to the first control frame. The second control frame may be generated in accordance with a request for the first wireless device 1005 to respond with the second control frame indicating whether the first control frame was successfully received. Alternatively, the second control frame may not be transmitted if the first control frame does not solicit a response for the second wireless device 1010. In some implementations, the second control frame may be secured in accordance with techniques discussed herein. The second control frame may include, for example, a CMF to be used for verification of the first control frame.

[0129] At 1030, the first wireless device 1005 may verify frame validity' of the second control frame. In some implementations, the first wireless device 1005 may generate an integrity check on one or more fields of the second control frame and compare at least a portion of the generated integrity check to a corresponding MIC (or portion of a MIC) provided in a CMF within the second control frame. If the compared integrity checks match, the second control frame may be further processed, and otherwise the second control frame may be discarded.

[0130] At 1035, the first w ireless device 1005 may transmit, to the second wireless device 1010, a data frame based on receiving the response frame.

[0131] Figure 11 shows a block diagram of an example wireless communication device 1100 that supports secure control frames in wireless communications. In some examples, the wireless communication device 1100 is configured to perform the processes 1300, 1400, 1600, 1700, 1800, and 2000 described with reference to Figures 13, 14, 16, 17, 18, and 20, respectively. The wireless communication device 1100 may include one or more chips, SoCs, chipsets, packages, components or devices that individually or collectively constitute or include a processing system. The processing system may interface with other components of the wireless communication device 1100, and may generally process information (such as inputs or signals) received from such other components and output information (such as outputs or signals) to such othercomponents. Tn some aspects, an example chip may include a processing system, a first interface to output or transmit information and a second interface to receive or obtain information. For example, the first interface may refer to an interface between the processing system of the chip and a transmission component, such that the wireless communication device 1100 may transmit the information output from the chip. In such an example, the second interface may refer to an interface between the processing system of the chip and a reception component, such that the wireless communication device 1100 may receive information that is passed to the processing system. In some such examples, the first interface also may obtain information, such as from the transmission component, and the second interface also may output information, such as to the reception component.

[0132] The processing system of the wireless communication device 1100 includes processor (or “processing”) circuitry in the form of one or multiple processors, microprocessors, processing units (such as central processing units (CPUs), graphics processing units (GPUs), neural processing units (NPUs) (also referred to as neural network processors or deep learning processors (DLPs)), or digital signal processors (DSPs)), processing blocks, application-specific integrated circuits (ASIC), programmable logic devices (PLDs) (such as field programmable gate arrays (FPGAs)), or other discrete gate or transistor logic or circuitry (all of which may be generally referred to herein individually as “processors” or collectively as “the processor” or “the processor circuitry”). One or more of the processors may be individually or collectively configurable or configured to perform various functions or operations described herein.

[0133] The processing system may further include memory circuitry in the form of one or more memory devices, memory blocks, memory elements or other discrete gate or transistor logic or circuitry, each of which may include tangible storage media such as random-access memory (RAM) or read-only memory (ROM), or combinations thereof (all of which may be generally referred to herein individually as “memories” or collectively as “the memory” or “the memory circuitry”). One or more of the memories may be coupled with one or more of the processors and may individually or collectively store processor-executable code that, when executed by one or more of the processors, may configure one or more of the processors to perform various functions or operations described herein. Additionally, or alternatively, in some examples, one or more of theprocessors may be preconfigured to perform various functions or operations described herein without requiring configuration by software. The processing system may further include or be coupled with one or more modems (such as a Wi-Fi (for example, IEEE compliant) modem or a cellular (for example, 3 GPP 4G LTE. 5G or 6G compliant) modem). In some implementations, one or more processors of the processing system include or implement one or more of the modems. The processing system may further include or be coupled with multiple radios (collectively “the radio”), multiple RF chains or multiple transceivers, each of which may in turn be coupled with one or more of multiple antennas. In some implementations, one or more processors of the processing system include or implement one or more of the radios, RF chains or transceivers.

[0134] In some examples, the wireless communication device 1100 can be configurable or configured for use in an AP, such as the AP 102 described with reference to Figure 1. In some other examples, the wireless communication device 1100 can be an AP that includes such a processing system and other components including multiple antennas. The wireless communication device 1100 is capable of transmitting and receiving wireless communications in the form of, for example, wireless packets. For example, the wireless communication device 1100 can be configurable or configured to transmit and receive packets in the form of physical layer PPDUs and MPDUs conforming to one or more of the IEEE 802. 11 family of wireless communication protocol standards. In some other examples, the wireless communication device 1100 can be configurable or configured to transmit and receive signals and communications conforming to one or more 3GPP specifications including those for 5GNR or 6G. In some examples, the wireless communication device 1100 also includes or can be coupled with one or more application processors which may be further coupled with one or more other memories. In some examples, the wireless communication device 1100 further includes at least one external network interface coupled with the processing system that enables communication with a core network or backhaul network that enables the wireless communication device 1100 to gain access to external networks including the Internet.

[0135] The wireless communication device 1100 includes an CMF component 1125. a validation component 1130, and a frame manager 1135. Portions of one or more of the CMF component 1125, the validation component 1130, and the framemanager 1135 may be implemented at least in part in hardware or firmware. For example, one or more of the CMF component 1125, the validation component 1130, and the frame manager 1135 may be implemented at least in part by at least a processor or a modem. In some examples, portions of one or more of the CMF component 1125, the validation component 1130, and the frame manager 1135 may be implemented at least in part by a processor and software in the form of processor-executable code stored in memory.

[0136] The wireless communication device 1100 may support wireless communications in accordance with examples as disclosed herein. The CMF component 1125 is configurable or configured to obtain a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and a partial PN, and the second portion of the CMF including a truncated first integrity check. The validation component 1130 is configurable or configured to verify a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, where the second integrity check is based on at least the security' key, the partial PN, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.

[0137] In some examples, the partial PN included in the CMF is combined with a base PN associated with the control frame to obtain a full PN associated with the control frame, and where the second integrity check is based on the full PN. In some examples, a quantify of bits in the partial PN is based on a frame type of the control frame.

[0138] In some examples, the second integrity check is truncated to include a subset of bits of an authentication code output that is based on at least the security key, the partial PN, and the one or more portions of the control frame. In some examples, the validity' of each of multiple different types on control frames is verified based on partial PNs and truncated first integrity checks.

[0139] In some examples, the first portion of the CMF is provided at a first deterministic location within a control information portion of the control frame that is located prior to one or more fields that are protected by the truncated first integrity check, and the second portion of the CMF is provided at a second deterministic locationwithin the control information portion of the control frame that is located subsequent to the one or more fields that are protected by the truncated first integrity check.

[0140] In some examples, the first portion of the CMF is placed before or after one or more information fields within the control information portion based on a frame type of the control frame. In some examples, the second portion of the CMF is included as a user information field within the control information portion that is located prior to a set of multiple padding bits located at an end of the control information portion, or the second portion of the CMF is included within the set of multiple padding bits. In some examples, the second portion of the CMF is included within the control information portion at a location that is specified with or prior to the first portion of the CMF. In some examples, a quantity of padding bits subsequent to the second portion of the CMF is a fixed value that is advertised via one or more management frames, or is a value that is signaled prior to the first portion of the CMF.

[0141] Additionally, or alternatively, the wireless communication device 1100 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1125 is configurable or configured to obtain a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame. In some examples, the validation component 1130 is configurable or configured to verify a validity of the frame, based on a comparison of the first integrity check and a second integrity check, where the second integrity check is based on at least the security key and the PN indication associated with the AID.

[0142] In some examples, the frame is a trigger frame, a block acknowledgment frame, or block acknowledgment request frame. In some examples, the AID is provided in one or more MPDUs with secure MAC headers that solicit protected control frames.

[0143] In some examples, the MPDUs that solicit protected control frames are carried in UHR PPDUs. In some examples, the AID is provided in one or more frames that are generated by non-access point stations that solicit protected control frames. In some examples, the one or more frames that solicit protected control frames include an indication that protected control frames are requested.

[0144] Additionally, or alternatively, the wireless communication device 1 100 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1125 is configurable or configured to obtain a control frame including a CMF and a set of multiple padding bits prior to an end-of- frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame. In some examples, the validation component 1130 is configurable or configured to decode the control frame in accordance with the quantity of the set of multiple padding bits.

[0145] In some examples, the validation component 1130 is configurable or configured to verily a validity of the control frame, based on a comparison of a first integrity7check included in the CMF and a second integrity7check, where the second integrity check is based on at least a security key indicated in the CMF. a PN indicated in the CMF, and one or more portions of the control frame. In some examples, unsecured control frames include a first quantity of padding bits that is smaller than a second quantity' of padding bits associated with secured control frames. In some examples, the secured control frames that are unencrypted include the second quantity of padding bits, and where the second quantity7of padding bits is smaller than a third quantity of padding bits associated with encrypted secured control frames.

[0146] Additionally, or alternatively, the wireless communication device 1100 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1125 is configurable or configured to generate a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and a partial PN associated with the control frame, and the second portion of the CMF including a truncated integrity7check, where the truncated integrity7check is based on at least the security key, the partial PN, and one or more portions of the control frame. The frame manager 1135 is configurable or configured to output the control frame for transmission.

[0147] In some examples, the partial PN included in the CMF is combined with a base PN associated with the control frame to provide a full PN associated with the control frame, and where the truncated integrity check includes a subset of bits of a fullintegrity check based on the full PN. In some examples, a quantity of bits in the partial PN is based on a frame type of the control frame.

[0148] In some examples, the truncated integrity check includes a subset of bits of an authentication code output that is based on at least the security key, the partial PN, and the one or more portions of the control frame. In some examples, a validity of each of multiple different types on control frames is verified based on partial PNs and truncated first integrity checks. In some examples, the first portion of the CMF is provided at a first deterministic location within a control information portion of the control frame that is located prior to one or more fields that are protected by the truncated integrity check, and the second portion of the CMF is provided at a second deterministic location within the control information portion of the control frame that is located subsequent to the one or more fields that are protected by the truncated integrity' check.

[0149] In some examples, the first portion of the CMF is placed before or after one or more information fields within the control information portion based on a frame ty pe of the control frame. In some examples, the second portion of the CMF is included as a user information field within the control information portion that is located prior to a set of multiple padding bits located at an end of the control information portion, or the second portion of the CMF is included within the set of multiple padding bits. In some examples, the second portion of the CMF is included within the control information portion at a location that is specified with or prior to the first portion of the CMF. In some examples, a quantity of padding bits subsequent to the second portion of the CMF is a fixed value that is advertised via one or more management frames, or is a value that is signaled prior to the first portion of the CMF.

[0150] Additionally, or alternatively, the wireless communication device 1100 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1125 is configurable or configured to generate a frame including a CMF including an AID. an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame, and where the first integrity check is based on at least the security key and the PN indication associated with the AID. In some examples, the frame manager 1135 is configurable or configured to output the frame for transmission.

[0151] In some examples, the frame is a trigger frame, a block acknowledgment frame, or block acknowledgment request frame. In some examples, the AID is provided in one or more MPDUs with secure MAC headers that solicit protected control frames. In some examples, the MPDUs that solicit protected control frames are earned in UHR PPDUs. In some examples, the AID is provided in one or more frames that are generated by non-access point stations that solicit protected control frames. In some examples, the one or more frames that solicit protected control frames include an indication that protected control frames are requested.

[0152] Additionally, or alternatively, the wireless communication device 1100 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1125 is configurable or configured to generate a control frame including a CMF and a set of multiple padding bits prior to an end-of- frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame. In some examples, the frame manager 1135 is configurable or configured to output the control frame for transmission.

[0153] In some examples, the CMF field includes an integrity check based on at least a security key indicated in the CMF, a PN indicated in the CMF, and one or more portions of the control frame. In some examples, unsecured control frames include a first quantity of padding bits that is smaller than a second quantity of padding bits associated with secured control frames. In some examples, the secured control frames that are unencrypted include the second quantity of padding bits, and where the second quantity of padding bits is smaller than a third quantity of padding bits associated with encrypted secured control frames.

[0154] Figure 12 shows a block diagram of an example wireless communication device 1200 that supports secure control frames in wireless communications. In some examples, the wireless communication device 1200 is configured to perform the processes 1300, 1400, 1500, 1600, 1700, 1800, 1900, and 2000 described with reference to Figures 13, 14, 15, 16, 17, 18, 19, and 20, respectively. The wireless communication device 1200 may include one or more chips, SoCs, chipsets, packages, components or devices that individually or collectively constitute or include a processing system. Theprocessing system may interface with other components of the wireless communication device 1200, and may generally process information (such as inputs or signals) received from such other components and output information (such as outputs or signals) to such other components. In some aspects, an example chip may include a processing system, a first interface to output or transmit information and a second interface to receive or obtain information. For example, the first interface may refer to an interface between the processing system of the chip and a transmission component, such that the wireless communication device 1200 may transmit the information output from the chip. In such an example, the second interface may refer to an interface between the processing system of the chip and a reception component, such that the wireless communication device 1200 may receive information that is passed to the processing system. In some such examples, the first interface also may obtain information, such as from the transmission component, and the second interface also may output information, such as to the reception component.

[0155] The processing system of the wireless communication device 1200 includes processor (or “processing”) circuitry in the form of one or multiple processors, microprocessors, processing units (such as CPUs, GPUs, NPUs (also referred to as neural network processors or DLPs), or DSPs), processing blocks, ASIC. PLDs (such as FPGAs), or other discrete gate or transistor logic or circuitry (all of which may be generally referred to herein individually as “processors” or collectively as “the processor” or “the processor circuitry”). One or more of the processors may be individually or collectively configurable or configured to perform various functions or operations described herein.

[0156] The processing system may further include memory circuitry in the form of one or more memory devices, memory blocks, memory elements or other discrete gate or transistor logic or circuitry', each of which may include tangible storage media such as RAM or ROM, or combinations thereof (all of which may be generally referred to herein individually as “memories” or collectively as “the memory” or “the memory circuitry”). One or more of the memories may be coupled with one or more of the processors and may individually or collectively store processor-executable code that, when executed by one or more of the processors, may configure one or more of the processors to perform various functions or operations described herein. Additionally, oralternatively, in some examples, one or more of the processors may be preconfigured to perform various functions or operations described herein without requiring configuration by software. The processing system may further include or be coupled with one or more modems (such as a Wi-Fi (for example, IEEE compliant) modem or a cellular (for example, 3GPP 4G LTE, 5G or 6G compliant) modem). In some implementations, one or more processors of the processing system include or implement one or more of the modems. The processing system may further include or be coupled with multiple radios (collectively “the radio'’), multiple RF chains or multiple transceivers, each of which may in turn be coupled with one or more of multiple antennas. In some implementations, one or more processors of the processing system include or implement one or more of the radios, RF chains or transceivers.

[0157] In some examples, the wireless communication device 1200 can be configurable or configured for use in a STA, such as the STA 104 described with reference to Figure 1. In some other examples, the wireless communication device 1200 can be a STA that includes such a processing system and other components including multiple antennas. The wireless communication device 1200 is capable of transmitting and receiving wireless communications in the form of, for example, wireless packets. For example, the wireless communication device 1200 can be configurable or configured to transmit and receive packets in the form of physical layer PPDUs and MPDUs conforming to one or more of the IEEE 802.11 family of wireless communication protocol standards. In some other examples, the wireless communication device 1200 can be configurable or configured to transmit and receive signals and communications conforming to one or more 3GPP specifications including those for 5GNR or 6G. In some examples, the wireless communication device 1200 also includes or can be coupled with one or more application processors which may be further coupled with one or more other memories. In some examples, the wireless communication device 1200 further includes a user interface (UI) (such as a touchscreen or keypad) and a display, which may be integrated with the UI to form a touchscreen display that is coupled with the processing system. In some examples, the wireless communication device 1200 may further include one or more sensors such as, for example, one or more inertial sensors, accelerometers, temperature sensors, pressure sensors, or altitude sensors, that are coupled with the processing system.

[0158] The wireless communication device 1200 includes an CMF component 1225, a validation component 1230, and a frame manager 1235. Portions of one or more of the CMF component 1225, the validation component 1230, and the frame manager 1235 may be implemented at least in part in hardware or firmware. For example, one or more of the CMF component 1225, the validation component 1230, and the frame manager 1235 may be implemented at least in part by at least a processor or a modem. In some examples, portions of one or more of the CMF component 1225, the validation component 1230, and the frame manager 1235 may be implemented at least in part by a processor and software in the form of processor-executable code stored in memory.

[0159] The wireless communication device 1200 may support wireless communications in accordance with examples as disclosed herein. The CMF component 1225 is configurable or configured to obtain a control frame including a first portion of a CMF and a second portion of the CMF. the first portion of the CMF including an ID of a security key and a partial PN, and the second portion of the CMF including a truncated first integrity check. The validation component 1230 is configurable or configured to verify a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, where the second integrity check is based on at least the security key, the partial PN, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.

[0160] In some examples, the partial PN included in the CMF is combined with a base PN associated with the control frame to obtain a full PN associated with the control frame, and where the second integrity check is based on the full PN. In some examples, a quantity of bits in the partial PN is based on a frame type of the control frame.

[0161] In some examples, the second integrity check is truncated to include a subset of bits of an authentication code output that is based on at least the security key, the partial PN, and the one or more portions of the control frame. In some examples, the validity of each of multiple different types on control frames is verified based on partial PNs and truncated first integrity checks.

[0162] In some examples, the first portion of the CMF is provided at a first deterministic location within a control information portion of the control frame that is located prior to one or more fields that are protected by the truncated first integrity check, and the second portion of the CMF is provided at a second deterministic location within the control information portion of the control frame that is located subsequent to the one or more fields that are protected by the truncated first integrity check.

[0163] In some examples, the first portion of the CMF is placed before or after one or more information fields within the control information portion based on a frame type of the control frame. In some examples, the second portion of the CMF is included as a user information field within the control information portion that is located prior to a set of multiple padding bits located at an end of the control information portion, or the second portion of the CMF is included within the set of multiple padding bits. In some examples, the second portion of the CMF is included within the control information portion at a location that is specified with or prior to the first portion of the CMF.

[0164] In some examples, a quantity of padding bits subsequent to the second portion of the CMF is a fixed value that is advertised via one or more management frames, or is a value that is signaled prior to the first portion of the CMF.

[0165] Additionally, or alternatively, the wireless communication device 1200 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1225 is configurable or configured to obtain a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame. In some examples, the validation component 1230 is configurable or configured to verify a validity of the frame, based on a comparison of the first integrity check and a second integrity check, where the second integrity check is based on at least the security' key and the PN indication associated wi th the AID.

[0166] In some examples, the frame is a trigger frame, a block acknowledgment frame, or block acknowledgment request frame. In some examples, the AID is provided in one or more MPDUs with secure MAC headers that solicit protected control frames. In some examples, the MPDUs that solicit protected control frames are carried in UHR PPDUs. In some examples, the AID is provided in one or more frames that aregenerated by non-access point stations that solicit protected control frames. In some examples, the one or more frames that solicit protected control frames include an indication that protected control frames are requested.

[0167] Additionally, or alternatively, the wireless communication device 1200 may support wireless communications in accordance with examples as disclosed herein. In some examples, the validation component 1230 is configurable or configured to obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security. In some examples, the CMF component 1225 is configurable or configured to generate a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode. In some examples, the CMF component 1225 is configurable or configured to output the control frame for transmission.

[0168] In some examples, the control frame is a group control frame or an individual control frame, and where group control frames are secured with the GTK in accordance with the GTK mode or the PTK mode, and individual control frames are secured with the PTK in accordance with the PTK mode or the GTK in accordance with the GTK mode. In some examples, the indication that one of the GTK mode or the PTK mode is configured for the control frame security is a dynamic indication that provides for dynamic switching between the GTK mode and the PTK mode. In some examples, the indication that one of the GTK mode or the PTK mode is configured for the control frame security is obtained from a UHR operation element.

[0169] Additionally, or alternatively, the wireless communication device 1200 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1225 is configurable or configured to obtain a control frame including a CMF and a set of multiple padding bits prior to an end-of- frame field, where a quantity of the set of multiple padding bits is based on w hether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame. In some examples, the validation component 1230 is configurable or configured to decode the control frame in accordance with the quantity of the set of multiple padding bits.

[0170] In some examples, the validation component 1230 is configurable or configured to verify a validity of the control frame, based on a comparison of a first integrity check included in the CMF and a second integrity check, where the second integrity check is based on at least a security key indicated in the CMF. a PN indicated in the CMF, and one or more portions of the control frame. In some examples, unsecured control frames include a first quantity’ of padding bits that is smaller than a second quantity of padding bits associated with secured control frames. In some examples, the secured control frames that are unencrypted include the second quantity of padding bits, and where the second quantity of padding bits is smaller than a third quantity of padding bits associated with encrypted secured control frames.

[0171] Additionally, or alternatively, the wireless communication device 1200 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1225 is configurable or configured to generate a control frame including a first portion of a CMF and a second portion of the CMF. the first portion of the CMF including an ID of a security key and a partial PN associated with the control frame, and the second portion of the CMF including a truncated integrity check, where the truncated integrity check is based on at least the security key, the partial PN, and one or more portions of the control frame. The frame manager 1235 is configurable or configured to output the control frame for transmission.

[0172] In some examples, the partial PN included in the CMF is combined with a base PN associated with the control frame to provide a full PN associated with the control frame, and where the truncated integrity check includes a subset of bits of a full integrity check based on the full PN. In some examples, a quantity of bits in the partial PN is based on a frame type of the control frame. In some examples, the truncated integrity check includes a subset of bits of an authentication code output that is based on at least the security key, the partial PN, and the one or more portions of the control frame. In some examples, a validity of each of multiple different types on control frames is verified based on partial PNs and truncated first integrity checks. In some examples, the first portion of the CMF is provided at a first deterministic location within a control information portion of the control frame that is located prior to one or more fields that are protected by the truncated integrity check, and the second portion of the CMF is provided at a second deterministic location within the control informationportion of the control frame that is located subsequent to the one or more fields that are protected by the truncated integrity check.

[0173] In some examples, the first portion of the CMF is placed before or after one or more information fields within the control information portion based on a frame type of the control frame. In some examples, the second portion of the CMF is included as a user information field within the control information portion that is located prior to a set of multiple padding bits located at an end of the control information portion, or the second portion of the CMF is included within the set of multiple padding bits. In some examples, the second portion of the CMF is included within the control information portion at a location that is specified with or prior to the first portion of the CMF.

[0174] In some examples, a quantity of padding bits subsequent to the second portion of the CMF is a fixed value that is advertised via one or more management frames, or is a value that is signaled prior to the first portion of the CMF.

[0175] Additionally, or alternatively, the wireless communication device 1200 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1225 is configurable or configured to generate a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame, and where the first integrity check is based on at least the security key and the PN indication associated with the AID. In some examples, the frame manager 1235 is configurable or configured to output the frame for transmission.

[0176] In some examples, the frame is a trigger frame, a block acknowledgment frame, or block acknowledgment request frame. In some examples, the AID is provided in one or more MPDUs with secure MAC headers that solicit protected control frames. In some examples, the MPDUs that solicit protected control frames are earned in UHR PPDUs. In some examples, the AID is provided in one or more frames that are generated by non-access point stations that solicit protected control frames. In some examples, the one or more frames that solicit protected control frames include an indication that protected control frames are requested.

[0177] Additionally, or alternatively, the wireless communication device 1200 may support wireless communications in accordance with examples as disclosed herein. Insome examples, the validation component 1230 is configurable or configured to obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security. In some examples, the CMF component 1225 is configurable or configured to generate a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode. In some examples, the frame manager 1235 is configurable or configured to output the control frame for transmission.

[0178] In some examples, the control frame is a group control frame or an individual control frame, and where group control frames are secured with the GTK in accordance with the GTK mode or the PTK mode, and individual control frames are secured with the PTK in accordance with the PTK mode or the GTK in accordance with the GTK mode. In some examples, the indication that one of the GTK mode or the PTK mode is configured for the control frame security is a dynamic indication that provides for dynamic switching between the GTK mode and the PTK mode. In some examples, the indication that one of the GTK mode or the PTK mode is configured for the control frame security is obtained from a UHR operation element.

[0179] Additionally, or alternatively, the wireless communication device 1200 may support wireless communications in accordance with examples as disclosed herein. In some examples, the CMF component 1225 is configurable or configured to generate a control frame including a CMF and a set of multiple padding bits prior to an end-of- frame field, where a quantity of the set of multiple padding bits is based on w hether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame. In some examples, the frame manager 1235 is configurable or configured to output the control frame for transmission.

[0180] In some examples, the CMF field includes an integrity check based on at least a security key indicated in the CMF, a PN indicated in the CMF, and one or more portions of the control frame. In some examples, unsecured control frames include a first quantity of padding bits that is smaller than a second quantity of padding bits associated with secured control frames. In some examples, the secured control frames that are unencrypted include the second quantity of padding bits, and where the secondquantity of padding bits is smaller than a third quantity of padding bits associated with encry pted secured control frames.

[0181] Figure 13 shows a flowchart illustrating an example process 1300 performable by or at an apparatus that supports secure control frames in wireless communications. The operations of the process 1300 may be implemented by an apparatus or its components as described herein. For example, the process 1300 may be performed by a wireless communication device, such as the wireless communication device 1100 described with reference to Figure 11, operating as or within a wireless AP or a wireless STA. In some examples, the process 1300 may be performed by a wireless AP or a wireless STA, such as one of the APs 102 or the STAs 104 described with reference to Figure 1.

[0182] In some examples, in block 1305, the apparatus may obtain a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated first integrity check. The operations of block 1305 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1305 may be performed by an CMF component 1125 or an CMF component 1225 as described with reference to Figures 11 and 12.

[0183] In some examples, in block 1310, the apparatus may verify a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, where the second integrity check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check. The operations of block 1310 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1310 may be performed by a validation component 1130 or a validation component 1230 as described with reference to Figures 11 and 12.

[0184] Figure 14 shows a flowchart illustrating an example process 1400 performable by or at an apparatus that supports secure control frames in wireless communications. The operations of the process 1400 may be implemented by an apparatus or its components as described herein. For example, the process 1400 may beperformed by a wireless communication device, such as the wireless communication device 1100 described with reference to Figure 11, operating as or within a wireless AP or a wireless STA. In some examples, the process 1400 may be performed by a wireless AP or a wireless STA, such as one of the APs 102 or the STAs 104 described with reference to Figure 1.

[0185] In some examples, in block 1405, the apparatus may obtain a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity' check, where the AID is different than a medium access control address associated with the frame. The operations of block 1405 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1405 may be performed by an CMF component 1125 or an CMF component 1225 as described with reference to Figures 11 and 12.

[0186] In some examples, in block 1410, the apparatus may verity' a validity of the frame, based on a comparison of the first integrity check and a second integrity check, where the second integrity check is based on at least the security key and the PN indication associated with the AID. The operations of block 1410 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1410 may be performed by a validation component 1130 or a validation component 1230 as described with reference to Figures 11 and 12.

[0187] Figure 15 shows a flowchart illustrating an example process 1500 performable by or at an apparatus that supports secure control frames in wireless communications. The operations of the process 1500 may be implemented by an apparatus or its components as described herein. For example, the process 1500 may be performed by a wireless communication device, such as the wireless communication device 1200 described with reference to Figure 12, operating as or within a wireless STA. In some examples, the process 1500 may be performed by a wireless STA, such as one of the STAs 104 described with reference to Figure 1.

[0188] In some examples, in block 1505, the apparatus may obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security. The operations of block 1505 may be performed in accordance with examples as disclosedherein. Tn some implementations, aspects of the operations of block 1505 may be performed by a validation component 1230 as described with reference to Figure 12.

[0189] In some examples, in block 1510, the apparatus may generate a control frame including a CMF including a security key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode. The operations of block 1510 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1510 may be performed by an CMF component 1225 as described with reference to Figure 12.

[0190] In some examples, in block 1515, the apparatus may output the control frame for transmission. The operations of block 1515 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1515 may be performed by an CMF component 1225 as described with reference to Figure 12.

[0191] Figure 16 shows a flowchart illustrating an example process 1600 performable by or at an apparatus that supports secure control frames in wireless communications. The operations of the process 1600 may be implemented by an apparatus or its components as described herein. For example, the process 1600 may be performed by a wireless communication device, such as the wireless communication device 1100 described with reference to Figure 11, operating as or within a wireless AP or a wireless STA. In some examples, the process 1600 may be performed by a wireless AP or a wireless STA, such as one of the APs 102 or the STAs 104 described with reference to Figure 1.

[0192] In some examples, in block 1605, the apparatus may obtain a control frame including a CMF and a set of multiple padding bits prior to an end-of-frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame. The operations of block 1605 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1605 may be performed by an CMF component 1125 or an CMF component 1225 as described with reference to Figures 11 and 12.

[0193] In some examples, in block 1610, the apparatus may decode the control frame in accordance with the quantity of the set of multiple padding bits. The operations of block 1610 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1610 may be performed by a validation component 1130 or a validation component 1230 as described with reference to Figures 11 and 12.

[0194] Figure 17 shows a flowchart illustrating an example process 1700 performable by or at an apparatus that supports secure control frames in wireless communications. The operations of the process 1700 may be implemented by an apparatus or its components as described herein. For example, the process 1700 may be performed by a wireless communication device, such as the wireless communication device 1100 described with reference to Figure 11, operating as or within a wireless AP or a wireless STA. In some examples, the process 1700 may be performed by a wireless AP or a wireless STA, such as one of the APs 102 or the STAs 104 described with reference to Figure 1.

[0195] In some examples, in block 1705, the apparatus may generate a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated integrity check, where the truncated integrity check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame. The operations of block 1705 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1705 may be performed by an CMF component 1125 or an CMF component 1225 as described with reference to Figures 11 and 12.

[0196] In some examples, in block 1710, the apparatus may output the control frame for transmission. The operations of block 1710 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1710 may be performed by a frame manager 1135 or a frame manager 1235 as described with reference to Figures 11 and 12.

[0197] Figure 18 shows a flowchart illustrating an example process 1800 performable by or at an apparatus that supports secure control frames in wirelesscommunications. The operations of the process 1800 may be implemented by an apparatus or its components as described herein. For example, the process 1800 may be performed by a wireless communication device, such as the wireless communication device 1100 described with reference to Figure 11, operating as or within a wireless AP or a wireless STA. In some examples, the process 1800 may be performed by a wireless AP or a wireless STA, such as one of the APs 102 or the STAs 104 described with reference to Figure 1.

[0198] In some examples, in block 1805, the apparatus may generate a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame, and where the first integrity check is based on at least the security key and the PN indication associated with the AID. The operations of block 1805 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1805 may be performed by an CMF component 1 125 or an CMF component 1225 as described with reference to Figures 11 and 12.

[0199] In some examples, in block 1810, the apparatus may output the frame for transmission. The operations of block 1810 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1810 may be performed by a frame manager 1135 or a frame manager 1235 as described with reference to Figures 11 and 12.

[0200] Figure 19 shows a flowchart illustrating an example process 1900 performable by or at an apparatus that supports secure control frames in wireless communications. The operations of the process 1900 may be implemented by an apparatus or its components as described herein. For example, the process 1900 may be performed by a wireless communication device, such as the wireless communication device 1200 described with reference to Figure 12, operating as or within a wireless STA. In some examples, the process 1900 may be performed by a wireless STA, such as one of the STAs 104 described with reference to Figure 1.

[0201] In some examples, in block 1905, the apparatus may obtain an indication that one of a GTK mode or a PTK mode is configured for control frame security. Theoperations of block 1905 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1905 may be performed by a validation component 1230 as described with reference to Figure 12.

[0202] In some examples, in block 1910, the apparatus may generate a control frame including a CMF including a security key ID. a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode. The operations of block 1910 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1910 may be performed by an CMF component 1225 as described with reference to Figure 12.

[0203] In some examples, in block 1915, the apparatus may output the control frame for transmission. The operations of block 1915 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 1915 may be performed by a frame manager 1235 as described with reference to Figure 12.

[0204] Figure 20 shows a flowchart illustrating an example process 2000 performable by or at an apparatus that supports secure control frames in wireless communications. The operations of the process 2000 may be implemented by an apparatus or its components as described herein. For example, the process 2000 may be performed by a wireless communication device, such as the wireless communication device 1100 described with reference to Figure 11, operating as or within a wireless AP or a wireless STA. In some examples, the process 2000 may be performed by a wireless AP or a wireless STA, such as one of the APs 102 or the STAs 104 described with reference to Figure 1.

[0205] In some examples, in block 2005, the apparatus may generate a control frame including a CMF and a set of multiple padding bits prior to an end-of-frame field, where a quantity of the set of multiple padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a type of security associated with the control frame. The operations of block 2005 may be performed in accordance with examples as disclosed herein. In some implementations.aspects of the operations of block 2005 may be performed by an CMF component 1125 or an CMF component 1225 as described with reference to Figures 11 and 12.

[0206] In some examples, in block 2010, the apparatus may output the control frame for transmission. The operations of block 2010 may be performed in accordance with examples as disclosed herein. In some implementations, aspects of the operations of block 2010 may be performed by a frame manager 1135 or a frame manager 1235 as described with reference to Figures 11 and 12.

[0207] Implementation examples are described in the following numbered clauses:

[0208] Clause 1 : A method for wireless communications, including: obtaining a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of the CMF including a truncated first integrity check; and verifying a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, where the second integrity check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame, and the second integrity’ check is truncated corresponding to the truncated first integrity check.

[0209] Clause 2: The method of clause 1, where the CMF includes the partial PN, where the partial PN included in the CMF is combined with a base PN associated with the control frame to obtain a full PN associated with the control frame, and where the second integrity check is based on the full PN.

[0210] Clause 3: The method of any of clauses 1-2, where a quantity of bits in the partial PN is based on a frame type of the control frame.

[0211] Clause 4: The method of any of clauses 1-3, where the second integritycheck is truncated to include a subset of bits of an authentication code output that is based on at least the security key, the partial PN, and the one or more portions of the control frame.

[0212] Clause 5: The method of any of clauses 1-4, where the validity of each of multiple different types on control frames is verified based on partial PNs and truncated first integrity checks.

[0213] Clause 6: The method of any of clauses 1-5, where the first portion of the CMF includes the partial PN; and where the first portion of the CMF is provided at a first deterministic location within a control information portion of the control frame that is located prior to one or more fields that are protected by the truncated first integrity check, and the second portion of the CMF is provided at a second deterministic location within the control information portion of the control frame that is located subsequent to the one or more fields that are protected by the truncated first integrity check.

[0214] Clause 7 : The method of clause 6, where the first portion of the CMF is placed before or after one or more information fields within the control information portion based on a frame type of the control frame.

[0215] Clause 8: The method of any of clauses 6-7, where the second portion of the CMF is included as a user information field within the control information portion that is located prior to a plurality of padding bits located at an end of the control information portion, or the second portion of the CMF is included within the plurality of padding bits.

[0216] Clause 9: The method of any of clauses 6-8, where the second portion of the CMF is included within the control information portion at a location that is specified with or prior to the first portion of the CMF.

[0217] Clause 10: The method of any of clauses 6-9, where a quantity of padding bits subsequent to the second portion of the CMF is a fixed value that is advertised via one or more management frames, or is a value that is signaled prior to the first portion of the CMF.

[0218] Clause 11: A method for wireless communications, including: obtaining a frame including a CMF including an AID, an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame; and verifying a validity of the frame, based on a comparison of the first integrity check and a second integrity check, where the second integrity check is based on at least the security' key and the PN indication associated with the AID.

[0219] Clause 12: The method of clause 1 1 , where the frame is a trigger frame, a block acknowledgment frame, or block acknowledgment request frame.

[0220] Clause 13: The method of any of clauses 11-12, where the AID is provided in one or more MPDUs with secure MAC headers that solicit protected control frames.

[0221] Clause 14: The method of clause 13, where the MPDUs that solicit protected control frames are carried in UHR PPDUs.

[0222] Clause 15: The method of any of clauses 1 1-14, where the AID is provided in one or more frames that are generated by non-access point stations that solicit protected control frames.

[0223] Clause 16: The method of clause 15, where the one or more frames that solicit protected control frames include an indication that protected control frames are requested.

[0224] Clause 17: A method for wireless communications, including: obtaining an indication that one of a GTK mode or a PTK mode is configured for control frame security; generating a control frame including a CMF including a security' key ID, a PN indication, and a first integrity check, where the first integrity check is computed based on a GTK or a PTK in accordance w ith the indication of the GTK mode or the PTK mode; and outputting the control frame for transmission.

[0225] Clause 18: The method of clause 17, where the control frame is a group control frame or an individual control frame, and where group control frames are secured with the GTK in accordance with the GTK mode or the PTK mode, and individual control frames are secured with the PTK in accordance with the PTK mode or the GTK in accordance w ith the GTK mode.

[0226] Clause 19: The method of any of clauses 17-18, where the indication that one of the GTK mode or the PTK mode is configured for the control frame security is a dynamic indication that provides for dynamic switching between the GTK mode and the PTK mode.

[0227] Clause 20: The method of clause 19, where the indication that one of the GTK mode or the PTK mode is configured for the control frame security is obtained from a UHR operation element.

[0228] Clause 21 : A method for wireless communications, including: obtaining a control frame including a CMF and a plurality of padding bits prior to an end-of-frame field, where a quantity of the plurality of padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a ty pe of security- associated with the control frame; and decoding the control frame in accordance with the quantity' of the plurality’ of padding bits.

[0229] Clause 22: The method of clause 21, further including: outputting a frame soliciting the control frame, where the frame includes a second plurality of padding bits, and where a quantity of the second plurality of padding bits is based on whether the control frame solicited by the frame is the secure control frame and, when the control frame is the secure control frame, the type of security associated with the control frame.

[0230] Clause 23: The method of clause 22, where first frames soliciting unsecured control frames include a first quantity of padding bits that is smaller than a second quantity of padding bits included within second frames soliciting secured control frames.

[0231] Clause 24: The method of clause 21-23, further including: verifying a validity' of the control frame, based on a comparison of a first integrity check included in the CMF and a second integrity check, where the second integrity' check is based on at least a security key indicated in the CMF, a PN indicated in the CMF, and one or more portions of the control frame.

[0232] Clause 25: The method of any of clauses 21-24, where unsecured control frames include a first quantity of padding bits that is smaller than a second quantity' of padding bits associated with secured control frames.

[0233] Clause 26: The method of clause 25, where the secured control frames that are unencrypted include the second quantity of padding bits, and where the second quantity of padding bits is smaller than a third quantity of padding bits associated with encry pted secured control frames.

[0234] Clause 27: A method for wireless communications, including: generating a control frame including a first portion of a CMF and a second portion of the CMF, the first portion of the CMF including an ID of a security key and the second portion of theCMF including a truncated integrity check, where the truncated integrity check is based on at least the security key, a partial PN associated with the control frame, and one or more portions of the control frame; and outputting the control frame for transmission.

[0235] Clause 28: The method of clause 27, where the CMF includes the partial PN, where the partial PN included in the CMF is combined with a base PN associated with the control frame to provide a full PN associated with the control frame, and where the truncated integrity check includes a subset of bits of a full integrity check based on the full PN.

[0236] Clause 29: The method of any of clauses 27-28, where a quantity of bits in the partial PN is based on a frame type of the control frame.

[0237] Clause 30: The method of any of clauses 27-29. where the truncated integrity check includes a subset of bits of an authentication code output that is based on at least the security key, the partial PN, and the one or more portions of the control frame.

[0238] Clause 31 : The method of any of clauses 27-30, where a validity of each of multiple different types on control frames is verified based on partial PNs and truncated first integrity checks.

[0239] Clause 32: The method of any of clauses 27-31, where the first portion of the CMF includes the partial PN; and where the first portion of the CMF is provided at a first deterministic location within a control information portion of the control frame that is located prior to one or more fields that are protected by the truncated integrity check, and the second portion of the CMF is provided at a second deterministic location within the control information portion of the control frame that is located subsequent to the one or more fields that are protected by the truncated integrity check.

[0240] Clause 33: The method of clause 32, where the first portion of the CMF is placed before or after one or more information fields within the control information portion based on a frame type of the control frame.

[0241] Clause 34: The method of any of clauses 32-33, where the second portion of the CMF is included as a user information field within the control information portion that is located prior to a plurality of padding bits located at an end of the controlinformation portion, or the second portion of the CMF is included within the plurality of padding bits.

[0242] Clause 35: The method of any of clauses 32-34, where the second portion of the CMF is included within the control information portion at a location that is specified with or prior to the first portion of the CMF.

[0243] Clause 36: The method of any of clauses 32-35, where a quantity of padding bits subsequent to the second portion of the CMF is a fixed value that is advertised via one or more management frames, or is a value that is signaled prior to the first portion of the CMF.

[0244] Clause 37: A method for wireless communications, including: generating a frame including a CMF including an AID. an ID of a security key, a PN indication, and a first integrity check, where the AID is different than a medium access control address associated with the frame, and where the first integrity check is based on at least the security key and the PN indication associated with the AID; and outputting the frame for transmission.

[0245] Clause 38: The method of clause 37. where the frame is a trigger frame, a block acknowledgment frame, or block acknowledgment request frame.

[0246] Clause 39: The method of any of clauses 37-38, where the AID is provided in one or more MPDUs with secure MAC headers that solicit protected control frames.

[0247] Clause 40: The method of clause 39, where the MPDUs that solicit protected control frames are carried in UHR PPDUs.

[0248] Clause 41: The method of any of clauses 37-40. where the AID is provided in one or more frames that are generated by non-access point stations that solicit protected control frames.

[0249] Clause 42: The method of clause 41, where the one or more frames that solicit protected control frames include an indication that protected control frames are requested.

[0250] Clause 43: A method for wireless communications, including: obtaining an indication that one of a GTK mode or a PTK mode is configured for control framesecurity; generating a control frame including a CMF including a security' key ID, a PN indication, and a first integrity' check, where the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode; and outputting the control frame for transmission.

[0251] Clause 44: The method of clause 43. where the control frame is a group control frame or an individual control frame, and where group control frames are secured with the GTK in accordance with the GTK mode or the PTK mode, and individual control frames are secured with the PTK in accordance with the PTK mode or the GTK in accordance with the GTK mode.

[0252] Clause 45: The method of any of clauses 43-44. where the indication that one of the GTK mode or the PTK mode is configured for the control frame security is a dynamic indication that provides for dynamic switching between the GTK mode and the PTK mode.

[0253] Clause 46: The method of clause 45, where the indication that one of the GTK mode or the PTK mode is configured for the control frame security is obtained from a UHR operation element.

[0254] Clause 47: A method for wireless communications, including: generating a control frame including a CMF and a plurality of padding bits prior to an end-of-frame field, where a quantity of the plurality of padding bits is based on whether the control frame is a secure control frame and, when the control frame is a secure control frame, a ty pe of security- associated with the control frame; and outputting the control frame for transmission.

[0255] Clause 48: The method of clause 47, further including: obtaining a frame soliciting the control frame, where the frame includes a second plurality of padding bits, and where a quantity of the second plurality of padding bits is based on whether the control frame solicited by the frame is the secure control frame and, when the control frame is the secure control frame, the type of security associated with the control frame.

[0256] Clause 49: The method of clause 48, where first frames soliciting unsecured control frames include a first quantity of padding bits that is smaller than a secondquantity of padding bits included within second frames soliciting secured control frames.

[0257] Clause 50: The method of clause 47-49, where the CMF field includes an integrity check based on at least a security key indicated in the CMF, a PN indicated in the CMF. and one or more portions of the control frame.

[0258] Clause 51 : The method of any of clauses 47-50, where unsecured control frames include a first quantity of padding bits that is smaller than a second quantity of padding bits associated with secured control frames.

[0259] Clause 52: The method of clause 51, where the secured control frames that are unencry pted include the second quantity of padding bits, and where the second quantity of padding bits is smaller than a third quantity of padding bits associated with encrypted secured control frames.

[0260] Clause 53: An apparatus for wireless communications, including a processing system that includes processor circuitry' and memory' circuitry that stores code, the processing system configured to cause the apparatus to perform a method of any of clauses 1-10.

[0261] Clause 54: An apparatus for wireless communications, including one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to perform a method of any of clauses 1-10.

[0262] Clause 55: An apparatus for wireless communications, including at least one means for performing a method of any of clauses 1-10.

[0263] Clause 56: A non-transitory computer-readable medium storing code for wireless communications, the code including instructions executable by one or more processors to perform a method of any of clauses 1-10.

[0264] Clause 57: An apparatus for wireless communications, including a processing system that includes processor circuitry and memory’ circuitry that stores code, the processing system configured to cause the apparatus to perform a method of any of clauses 11-16.

[0265] Clause 58: An apparatus for wireless communications, including one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to perform a method of any of clauses 11-16.

[0266] Clause 59: An apparatus for wireless communications, including at least one means for performing a method of any of clauses 11-16.

[0267] Clause 60: A non-transitory computer-readable medium storing code for wireless communications, the code including instructions executable by one or more processors to perform a method of any of clauses 11-16.

[0268] Clause 61 : An apparatus for wireless communications, including a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to perform a method of any of clauses 17-20.

[0269] Clause 62: An apparatus for wireless communications, including one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to perform a method of any of clauses 17-20.

[0270] Clause 63: An apparatus for wireless communications, including at least one means for performing a method of any of clauses 17-20.

[0271] Clause 64: A non-transitory computer-readable medium storing code for wireless communications, the code including instructions executable by one or more processors to perform a method of any of clauses 17-20.

[0272] Clause 65: An apparatus for wireless communications, including a processing system that includes processor circuitry and memory' circuitry' that stores code, the processing system configured to cause the apparatus to perform a method of any of clauses 21-26.

[0273] Clause 66: An apparatus for wireless communications, including one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to perform a method of any of clauses 21-26.

[0274] Clause 67: An apparatus for wireless communications, including at least one means for performing a method of any of clauses 21-26.

[0275] Clause 68: A non-transitory computer-readable medium storing code for wireless communications, the code including instructions executable by one or more processors to perform a method of any of clauses 21-26.

[0276] Clause 69: An apparatus for wireless communications, including a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to perform a method of any of clauses 27-36.

[0277] Clause 70: An apparatus for wireless communications, including one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to perform a method of any of clauses 27-36.

[0278] Clause 71: An apparatus for wireless communications, including at least one means for performing a method of any of clauses 27-36.

[0279] Clause 72: A non-transitory computer-readable medium storing code for wireless communications, the code including instructions executable by one or more processors to perform a method of any of clauses 27-36.

[0280] Clause 73: An apparatus for wireless communications, including a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to perform a method of any of clauses 37-42.

[0281] Clause 74: An apparatus for wireless communications, including one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to perform a method of any of clauses 37-42.

[0282] Clause 75: An apparatus for wireless communications, including at least one means for performing a method of any of clauses 37-42.

[0283] Clause 76: A non-transitory computer-readable medium storing code for wireless communications, the code including instructions executable by one or more processors to perform a method of any of clauses 37-42.

[0284] Clause 77: An apparatus for wireless communications, including a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to perform a method of any of clauses 43-46.

[0285] Clause 78: An apparatus for wireless communications, including one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to perform a method of any of clauses 43-46.

[0286] Clause 79: An apparatus for wireless communications, including at least one means for performing a method of any of clauses 43-46.

[0287] Clause 80: A non-transitory' computer-readable medium storing code for wireless communications, the code including instructions executable by one or more processors to perform a method of any of clauses 43-46.

[0288] Clause 81 : An apparatus for wireless communications, including a processing system that includes processor circuitry and memory' circuitry' that stores code, the processing system configured to cause the apparatus to perform a method of any of clauses 47-52.

[0289] Clause 82: An apparatus for wireless communications, including one or more memories storing processor-executable code, and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to perform a method of any of clauses 47-52.

[0290] Clause 83: An apparatus for wireless communications, including at least one means for performing a method of any of clauses 47-52.

[0291] Clause 84: A non-transitory computer-readable medium storing code for wireless communications, the code including instructions executable by one or more processors to perform a method of any of clauses 47-52.

[0292] As used herein, the term “determine” or “determining” encompasses a wide variety of actions and, therefore, “determining” can include calculating, computing, processing, deriving, estimating, investigating, looking up (such as via looking up in a table, a database, or another data structure), inferring, ascertaining, or measuring. among other possibilities. Also, “determining” can include receiving (such as receiving information), accessing (such as accessing data stored in memory) or transmitting (such as transmitting information), among other possibilities. Additionally, “determining” can include resolving, selecting, obtaining, choosing, establishing and other such similar actions.

[0293] As used herein, a phrase referring to “at least one of’ or “one or more of’ a list of items refers to any combination of those items, including single members. As an example, “at least one of: a, b, or c” is intended to cover: a, b, c, a-b, a-c, b-c, and a-b-c. As used herein, “or” is intended to be interpreted in the inclusive sense, unless otherwise explicitly indicated. For example, “a or b” may include a only, b only, or a combination of a and b. Furthermore, as used herein, a phrase referring to “a” or “an” element refers to one or more of such elements acting individually or collectively to perform the recited function(s). Additionally, a “set” refers to one or more items, and a “subset” refers to less than a whole set, but non-empty.

[0294] As used herein, “based on” is intended to be interpreted in the inclusive sense, unless otherwise explicitly indicated. For example, “based on” may be used interchangeably with “based at least in part on,” “associated with,” “in association with,” or “in accordance with” unless otherwise explicitly indicated. Specifically, unless a phrase refers to “based on only ‘a,’” or the equivalent in context, whatever it is that is “based on 'a,’” or “based at least in part on ‘a,’” may be based on “a” alone or based on a combination of “a” and one or more other factors, conditions, or information.

[0295] The various illustrative components, logic, logical blocks, modules, circuits, operations, and algorithm processes described in connection with the examples disclosed herein may be implemented as electronic hardware, firmware, software, or combinations of hardware, firmware, or software, including the structures disclosed in this specification and the structural equivalents thereof. The interchangeability of hardware, firmware and software has been described generally, in terms of functionality, and illustrated in the various illustrative components, blocks, modules,circuits and processes described above. Whether such functionality is implemented in hardware, firmware or software depends upon the particular application and design constraints imposed on the overall system.

[0296] Various modifications to the examples described in this disclosure may be readily apparent to persons having ordinary skill in the art, and the generic principles defined herein may be applied to other examples without departing from the spirit or scope of this disclosure. Thus, the claims are not intended to be limited to the examples shown herein, but are to be accorded the widest scope consistent with this disclosure, the principles and the novel features disclosed herein.

[0297] Additionally, various features that are described in this specification in the context of separate examples also can be implemented in combination in a single implementation. Conversely, various features that are described in the context of a single implementation also can be implemented in multiple examples separately or in any suitable subcombination. As such, although features may be described above as acting in particular combinations, and even initially claimed as such, one or more features from a claimed combination can in some cases be excised from the combination, and the claimed combination may be directed to a subcombination or variation of a subcombination.

[0298] Similarly, while operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. Further, the drawings may schematically depict one or more example processes in the form of a flowchart or flow diagram. However, other operations that are not depicted can be incorporated in the example processes that are schematically illustrated. For example, one or more additional operations can be performed before, after, simultaneously, or between any of the illustrated operations. In some circumstances, multitasking and parallel processing may be advantageous. Moreover, the separation of various system components in the examples described above should not be understood as requiring such separation in all examples, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.

Claims

CLAIMSWhat is claimed is:

1. An apparatus, comprising: a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to: obtain a control frame comprising a first portion of a control message integrity check field (CMF) and a second portion of the CMF, the first portion of the CMF comprising an identifier (ID) of a security key and the second portion of the CMF comprising a truncated first integrity check; and verity a validity of the control frame, based on a comparison of the truncated first integrity check and a second integrity check, wherein the second integrity check is based on at least the security key, a partial packet number (PN) associated with the control frame, and one or more portions of the control frame, and the second integrity check is truncated corresponding to the truncated first integrity check.

2. The apparatus of claim 1, wherein the CMF includes the partial PN, wherein the partial PN included in the CMF is combined with a base PN associated with the control frame to obtain a full PN associated with the control frame, and wherein the second integrity check is based on the full PN.

3. The apparatus of claim 1. wherein a quantity of bits in the partial PN is based on a frame type of the control frame.

4. The apparatus of claim 1, wherein the second integrity check is truncated to include a subset of bits of an authentication code output that is based on at least the security key, the partial PN, and the one or more portions of the control frame.

5. The apparatus of claim 1, wherein: the validity of each of multiple different types on control frames is verified based on partial PNs and truncated first integrity checks.

6. The apparatus of claim 1, wherein: the first portion of the CMF includes the partial PN; andthe first portion of the CMF is provided at a first deterministic location within a control information portion of the control frame that is located prior to one or more fields that are protected by the truncated first integrity check, and the second portion of the CMF is provided at a second deterministic location within the control information portion of the control frame that is located subsequent to the one or more fields that are protected by the truncated first integrity check.

7. The apparatus of claim 6. wherein the first portion of the CMF is placed before or after one or more information fields within the control information portion based on a frame type of the control frame.

8. The apparatus of claim 6, wherein the second portion of the CMF is included as a user information field within the control information portion that is located prior to a plurality of padding bits located at an end of the control information portion, or the second portion of the CMF is included w ithin the plurality' of padding bits.

9. The apparatus of claim 6, wherein the second portion of the CMF is included within the control information portion at a location that is specified with or prior to the first portion of the CMF.

10. The apparatus of claim 6, wherein a quantity of padding bits subsequent to the second portion of the CMF is a fixed value that is advertised via one or more management frames, or is a value that is signaled prior to the first portion of the CMF.

11. An apparatus, comprising: a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to: obtain a control frame comprising a control message integrity check field (CMF) and a plurality of padding bits prior to an end-of-frame field, wherein a quantity7of the plurality7of padding bits is based on whether the control frame is a secure control frame and, when the control frame is the secure control frame, a type of security associated with the control frame; anddecode the control frame in accordance with the quantity of the plurality of padding bits.

12. The apparatus of claim 11, wherein the processing system is further configured to cause the apparatus to: output a frame soliciting the control frame, wherein the frame includes a second plurality of padding bits, and wherein a quantity of the second plurality of padding bits is based on whether the control frame solicited by the frame is the secure control frame and, when the control frame is the secure control frame, the type of security associated with the control frame.

13. The apparatus of claim 12, wherein first frames soliciting unsecured control frames include a first quantity of padding bits that is smaller than a second quantity of padding bits included within second frames soliciting secured control frames.

14. The apparatus of claim 11, wherein the processing system is further configured to cause the apparatus to: verity' a validity' of the control frame, based on a comparison of a first integrity check included in the CMF and a second integrity check, wherein the second integrity check is based on at least a security key indicated in the CMF. a packet number indicated in the CMF, and one or more portions of the control frame.

15. The apparatus of claim 11, wherein unsecured control frames include a first quantity of padding bits that is smaller than a second quantity of padding bits associated with secured control frames.

16. The apparatus of claim 15, wherein the secured control frames that are unencrypted include the second quantity of padding bits, and wherein the second quantity of padding bits is smaller than a third quantity of padding bits associated with encrypted secured control frames.

17. An apparatus, comprising: a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to:obtain an indication that one of a group temporal key (GTK) mode or a pairwise temporal key (PTK) mode is configured for control frame security; generate a control frame comprising a control message integrity check field (CMF) comprising a security key identifier (ID), a packet number (PN) indication, and a first integrity check, wherein the first integrity check is computed based on a GTK or a PTK in accordance with the indication of the GTK mode or the PTK mode; and output the control frame for transmission.

18. The apparatus of claim 17, wherein the control frame is a group control frame or an individual control frame, and wherein group control frames are secured with the GTK in accordance with the GTK mode or the PTK mode, and individual control frames are secured with the PTK in accordance with the PTK mode or the GTK in accordance with the GTK mode.

19. The apparatus of claim 17, wherein the indication that one of the GTK mode or the PTK mode is configured for the control frame security is a dynamic indication that provides for dynamic switching between the GTK mode and the PTK mode.

20. The apparatus of claim 19, wherein the indication that one of the GTK mode or the PTK mode is configured for the control frame security is obtained from an ultra-high reliability (UHR) operation element.

21. An apparatus, comprising: a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to: generate a control frame comprising a first portion of a control message integrity check field (CMF) and a second portion of the CMF. the first portion of the CMF comprising an identifier (ID) of a security key and the second portion of the CMF comprising a truncated integrity check, wherein the truncated integrity check is based on at least the security key, and a partialpacket number (PN) associated with the control frame, and one or more portions of the control frame; and output the control frame for transmission.

22. The apparatus of claim 21, wherein the CMF includes the partial PN, wherein the partial PN included in the CMF is combined with a base PN associated with the control frame to provide a full PN associated with the control frame, and wherein the truncated integrity check includes a subset of bits of a full integrity check based on the full PN.

23. The apparatus of claim 21, wherein a quantity7of bits in the partial PN is based on a frame type of the control frame.

24. The apparatus of claim 21, wherein the truncated integrity check includes a subset of bits of an authentication code output that is based on at least the security key, the partial PN, and the one or more portions of the control frame.

25. The apparatus of claim 21, wherein: a validity of each of multiple different types on control frames is verified based on partial PNs and truncated first integrity checks.

26. The apparatus of claim 21, wherein: the first portion of the CMF includes the partial PN; and the first portion of the CMF is provided at a first deterministic location within a control information portion of the control frame that is located prior to one or more fields that are protected by the truncated integrity check, and the second portion of the CMF is provided at a second deterministic location within the control information portion of the control frame that is located subsequent to the one or more fields that are protected by the truncated integrity check.

27. The apparatus of claim 26, wherein the first portion of the CMF is placed before or after one or more information fields within the control information portion based on a frame type of the control frame.

28. The apparatus of claim 26, wherein the second portion of the CMF is included as a user information field within the control information portion thatis located prior to a plurality of padding bits located at an end of the control information portion, or the second portion of the CMF is included within the plurality of padding bits.

29. The apparatus of claim 26, wherein the second portion of the CMF is included within the control information portion at a location that is specified with or prior to the first portion of the CMF.

30. The apparatus of claim 26, wherein a quantity of padding bits subsequent to the second portion of the CMF is a fixed value that is advertised via one or more management frames, or is a value that is signaled prior to the first portion of the CMF.

Citation Information

Patent Citations

  • Wake-up radio frame formats and device communications

    US20190007904A1

  • Enhanced beacon frames in wireless communications

    US20190200278A1

  • Addressing for wake-up radio (WUR) frames in WUR device communications

    US20190268847A1

  • Encrypted and Compressed Data Transmission with Padding

    US20200169382A1

  • Enhanced security for multi-link wireless operations

    US20210050999A1