M-BSSID Control Frame Integrity Checks for Low-Latency Wi-Fi

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ensuring sufficient performance in wireless communications systems, including minimizing latency, resource consumption, and enhancing data security, is challenging due to inadequate communication protocols between nodes in a communications network.

Innovation Solution

Implementing a multiple basic service set identifier (M-BSSID) scheme with control frame integrity checks (CMICs) using control frame integrity group temporal keys (CIGTKs) to secure communications between access points (APs) and stations (STAs), allowing for shared or BSSID-specific integrity checks to minimize latency and maximize throughput.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional communication protocols are used without control frame integrity checks, then latency is reduced and resource consumption is minimized, but data security and communication integrity are compromised

Engineering Contradiction:
Improvedata securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing control frame integrity check mechanisms (CMICs) using CIGTKs before actual data transmission occurs. The AP and STAs pre-share these cryptographic keys and establish the integrity verification framework in advance, allowing rapid verification without adding significant latency to the communication process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the integrity verification function into a separate, dedicated mechanism (CMIC) that operates independently from the main data transmission protocol. This extracted integrity check can be performed efficiently without interfering with the primary communication flow, thus maintaining low latency while ensuring security.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If control frame integrity checks are implemented for each BSSID separately, then data security is enhanced, but device complexity and resource consumption increase

Engineering Contradiction:
Improvecommunication integrityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a single CIGTK mechanism that can serve multiple BSSIDs simultaneously. The same integrity check framework and cryptographic key management approach can be applied across different BSSIDs, reducing the need for separate complex verification systems for each BSSID while maintaining security across all virtual networks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the integrity verification functionality into a unified control frame structure that can carry CMICs applicable to multiple BSSIDs. By combining the integrity check mechanism with the existing control frame protocol rather than implementing separate verification systems, the overall device complexity is reduced while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If control frame integrity checks are implemented, then data security is improved, but resource consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing integrity checks selectively on control frames rather than all communication data. Since control frames are critical for network management and coordination, verifying their integrity provides maximum security benefit with minimal resource overhead compared to verifying every data packet.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the verification parameter from comprehensive data frame checking to targeted control frame verification. This parameter change focuses computational resources on the most critical security needs (control plane integrity) while reducing overall energy consumption compared to exhaustive verification of all communication traffic.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If multiple BSSID-specific CMICs are generated and verified, then communication integrity is maximized, but productivity and throughput are reduced

Engineering Contradiction:
Improvecommunication integrityVSAvoiddata throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies universality by using a unified CIGTK-based CMIC mechanism that can verify integrity across multiple BSSIDs simultaneously. This universal approach eliminates the need for separate verification processes for each BSSID, reducing the cumulative overhead and preserving higher throughput while maintaining integrity across all virtual networks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple BSSID-specific integrity requirements into a single unified verification framework. By combining the verification process rather than executing separate checks for each BSSID, the system reduces processing overhead and maintains higher data throughput while ensuring integrity protection across all BSSIDs.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250350948A1Communications Systems with Control Frame Protection
Publication Date: 2025.11.13 APPLE INC
  • US20250350948A1 patent drawing
  • US20250350948A1 patent drawing
  • US20250350948A1 patent drawing

AI summary

A communication system is provided in which access points (APs) communicate with stations (STAs). An AP may communicate with a STA according to a multiple basic service set identifier (M-BSSID) scheme. The AP may transmit an initial control frame (ICF) to STAs associated with different BSSIDs of the AP. The AP may integrity protect the ICF by generating one or more control message integrity checks (CMICs) and inserting the CMIC(s) into the ICF. The AP may generate a common CMIC shared across BSSIDs using a control frame integrity group temporal key (CIGTK) that is BSSID-specific or BSSID-independent. A BSSID-independent CIGTK may be a newly defined or may be a beacon integrity group temporal key (BIGTK). As another example, the AP may generate different CMICs in the ICF for each BSSID using different BSSID-specific CIGTKs for each BSSID.