M-BSSID Control Frame Integrity Using CIGTKs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communications systems face challenges in ensuring sufficient performance levels, including excessive latency, resource consumption, and insufficient data security during wireless data transmission between nodes.

Innovation Solution

Implementing a multiple basic service set identifier (M-BSSID) scheme with control frame integrity checks (CMICs) using control frame integrity group temporal keys (CIGTKs) to secure communications between access points and stations, minimizing latency and maximizing data throughput.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in M-BSSID schemes, then implementation is simpler, but security is insufficient against BSSID spoofing and unauthorized access

Engineering Contradiction:
Improvedata securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing cryptographic key relationships between the AP and multiple BSSIDs before actual communication occurs. The AP generates key pairs for each BSSID and pre-configures the verification mechanism, so that when control frames are exchanged, security verification can immediately occur without adding complex real-time authentication protocols. This resolves the contradiction by preparing security measures in advance, maintaining simplicity during operation while ensuring strong security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If separate CMICs are generated for each BSSID, then security is enhanced, but control frame overhead and processing complexity increase

Engineering Contradiction:
Improvecontrol frame securityVSAvoidcontrol frame processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a verification mechanism that works across all BSSIDs through a common cryptographic relationship. The AP generates key pairs where the public keys are associated with each BSSID, but the verification process uses a unified approach: STAs verify control frames by checking signatures against the AP's public key corresponding to their associated BSSID. This universal verification method provides security for each BSSID without requiring separate complex verification systems, thus resolving the contradiction between security and processing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive security verification is performed on all control frames, then data security is improved, but transmission latency increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcontrol frame verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies this principle by using cryptographic hash signatures that are computationally efficient to verify. Instead of using heavy cryptographic protocols for every control frame, the system uses lightweight signature verification based on pre-established key pairs. The verification process involves checking a cryptographic signature against a public key, which is computationally inexpensive compared to full authentication protocols. This allows comprehensive security verification on all control frames without significantly increasing latency, resolving the contradiction between security and time loss.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Productivity

If M-BSSID scheme is implemented without proper authentication, then resource utilization is optimized, but unauthorized access and spoofing become possible

Engineering Contradiction:
Improveresource utilizationVSAvoidBSSID spoofing vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies the intermediary principle by introducing cryptographic key pairs as mediators between the AP and STAs in the M-BSSID scheme. The public keys act as intermediaries that allow STAs to verify the authenticity of control frames without requiring complex real-time authentication. The verification process uses these cryptographic intermediaries to ensure that control frames genuinely originate from the AP, preventing BSSID spoofing while maintaining the efficient resource utilization benefits of M-BSSID. This resolves the contradiction by adding a lightweight verification layer that blocks harmful factors without sacrificing productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4645124A1Communications systems with control frame protection
Publication Date: 2025.11.05 APPLE INC
  • EP4645124A1 patent drawingFigure 1
  • EP4645124A1 patent drawingFigure 2
  • EP4645124A1 patent drawingFigure 3

AI summary

A communication system is provided in which access points (APs) communicate with stations (STAs). An AP may communicate with a STA according to a multiple basic service set identifier (M-BSSID) scheme. The AP may transmit an initial control frame (ICF) to STAs associated with different BSSIDs of the AP. The AP may integrity protect the ICF by generating one or more control message integrity checks (CMICs) and inserting the CMIC(s) into the ICF. The AP may generate a common CMIC shared across BSSIDs using a control frame integrity group temporal key (CIGTK) that is BSSID-specific or BSSID-independent. A BSSID-independent CIGTK may be a newly defined or may be a beacon integrity group temporal key (BIGTK). As another example, the AP may generate different CMICs in the ICF for each BSSID using different BSSID-specific CIGTKs for each BSSID.