Method, equipment and device for communication and computer readable storage medium

By constructing a secure frame in IEEE 802.15.4z, random numbers are generated using identification information, round index and block index, the challenge of random number construction in range measurement is solved, and communication security and ranging accuracy are improved.

CN120499644AActive Publication Date: 2025-08-15HUAWEI TECH CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510939028.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-04-03
Publication Date
2025-08-15
Estimated Expiration
2043-04-03

AI Technical Summary

Technical Problem

In IEEE 802.15.4z, how to build a unique random number for ranging measurements to improve communication security is a challenge.

Method used

Generate a secure frame, sent in the time slot through a block-based time structure or a super-block time structure, and random numbers are constructed using identification information, round index and block index to protect communication, including slot index, packet number, round index and block index bit fields, reducing signaling overhead and ensuring the security of the frame.

Benefits of technology

Improve the security of communication and the accuracy of ranging measurement, simplify the negotiation process between the transmitter and the receiver, and enhance the security and reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120499644A_ABST
    Figure CN120499644A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a method, equipment and device for communication and a computer readable storage medium. In some embodiments, a first security frame may be generated to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a superblock-based time structure, where the block-based time structure or the superblock-based time structure includes a plurality of blocks, and where the block-based time structure includes a first block and a second block. Each block of the plurality of blocks comprises a plurality of rounds, each round of the plurality of rounds comprises a plurality of time slots, the first security frame is protected by a first random number, the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, and the block index is an index of the second round. The block index is an index of the first block. Accordingly, a secure operation may be performed, and it may be ensured that communication is secure.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The application number of the original application is 202380070073.5, and the original application date is April 3, 2023. The entire content of the original application is incorporated into this application by reference. Technical Field

[0002] Exemplary embodiments of the present invention generally relate to the field of telecommunications, and more particularly, to methods, devices, apparatuses, and computer-readable storage media for communications. Background Art

[0003] One of the main purposes of the enhancement is to improve the accuracy of ranging measurements in Institute of Electrical and Electronic Engineers (IEEE) 802.15.4z.A block-based time structure or a super-block-based time structure can be used for ranging.

[0004] In ranging, an authenticated encryption with associated data (AEAD) security operation is proposed. A key input for AEAD security operations is a unique random number (nonce). However, how to construct the nonce requires further research. Summary of the Invention

[0005] In general, exemplary embodiments of the present invention provide a solution for security frames in ultra-wideband.

[0006] In a first aspect, a method is provided, comprising: generating a first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, and each of the plurality of rounds includes a plurality of time slots, wherein the first security frame is protected by a first random number constructed based on identification information associated with the first security frame, a round index, and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block; and transmitting the first security frame. Therefore, a security operation can be performed and communication security can be guaranteed.

[0007] In some examples, the identification information includes a time slot index, which is an index of the time slot in which the first security frame is transmitted. Since the first security frame is transmitted in a specific time slot, the first random number can be used to protect the first security frame.

[0008] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the time slot index. In some examples, the first number is determined based on the number of time slots in each round, or the first number is a first predefined number. If the first number can be predefined, the agreement between the transmitter and the receiver can be simplified. If the first number is variable, there may be some remaining bits in the first random number, which can be used for other information.

[0009] In some examples, the identification information includes a first packet number (PN), and wherein the first PN is the packet number of the first security frame. Since the first PN is specific to the first security frame, the first random number can be used to protect the first security frame.

[0010] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0011] In some examples, the first random number includes: a second field having a second number of bits, carrying the round index; and a third field having a third number of bits, carrying the block index.

[0012] In some examples, the second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number. In some examples, the third number is a third predefined number.

[0013] In some examples, the sum of the first number, the second number, and the third number is equal to a predefined total number.

[0014] Therefore, the first random number can be constructed by including the identification information, the round index, and the block index. Therefore, the first random number can be used to protect the first security frame.

[0015] In some examples, the first random number includes a fourth field having a fourth number of bits, carrying a period index, where the period index is an index of a period including a plurality of blocks, wherein the first block is one of the plurality of blocks. Therefore, the period index can also be used to construct the first random number, and accordingly, the security key can be used for a longer period of time.

[0016] In some examples, the first random number includes a first block indicator that indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

[0017] In some examples, the first security frame includes the block index and the round index. Thus, the first security frame can include the block index and the round index so that the receiver can correctly construct the random number for deprotection.

[0018] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index. If the block index or round index is a default value, the block index or round index may not be sent, thereby reducing signaling overhead.

[0019] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure. Therefore, whether the frame is secure can be determined based on the security indicator.

[0020] In some examples, the method further includes: generating a second security frame to be transmitted, the second security frame being protected by a second random number constructed based on a second PN, wherein the second PN is a packet number of the second security frame; and transmitting the second security frame. Thus, the PN can be used to construct a random number for a frame that is not based on a block-based timing structure or a super-block-based timing structure.

[0021] In some examples, the second random number includes a field having a predefined number of octets, the field carrying the second PN.

[0022] In some examples, the second random number includes a second block indicator that indicates that the second security frame is sent outside the block-based timing structure or the super-block-based timing structure.

[0023] In some examples, the second security frame includes a PN field carrying the second PN.

[0024] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0025] In some examples, the second security frame includes a security payload, and wherein the security payload includes: a second block index presence indicator indicating whether the second block index is included; a second round index presence indicator indicating whether the second round index is included; and a second time slot index presence indicator indicating whether the second time slot index is included.

[0026] In some examples, if the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; if the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; if the second time slot index presence indicator indicates that the second time slot index is included, the security payload includes the time slot index.

[0027] In some examples, at least one of the second block index presence indicator, the second round index presence indicator, or the second slot index presence indicator indicates that the corresponding index is not included and implicitly indicates that the corresponding index is a default index.

[0028] In a second aspect, a method is provided, comprising: receiving a first security frame, the first security frame to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, and each of the multiple rounds includes multiple time slots; unprotecting the first security frame according to a first random number, wherein the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block.

[0029] In some examples, the identification information includes a time slot index, where the time slot index is an index of the time slot in which the first security frame is transmitted.

[0030] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the time slot index. In some examples, the first number is determined based on the number of the plurality of time slots in each round, or the first number is a first predefined number.

[0031] In some examples, the identification information includes a first packet number (PN), and wherein the first PN is the packet number of the first security frame. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0032] In some examples, the first random number includes: a second field having a second number of bits, carrying the round index; and a third field having a third number of bits, carrying the block index.

[0033] In some examples, the second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number. In some examples, the third number is a third predefined number.

[0034] In some examples, the sum of the first number, the second number, and the third number is equal to a predefined total number.

[0035] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

[0036] In some examples, the first random number includes a first block indicator that indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

[0037] In some examples, the first security frame includes the block index and carries the round index.

[0038] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0039] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0040] In some examples, the method further includes: receiving a second security frame, the second security frame not being sent according to the block-based time structure or the super-block-based time structure; and unprotecting the second security frame according to a second random number, the second random number being constructed based on a second PN, wherein the second PN is a packet number of the second security frame.

[0041] In some examples, the second random number includes a field having a predefined number of octets, the field carrying the second PN.

[0042] In some examples, the second random number includes a second block indicator that indicates that the second frame is transmitted outside the block-based timing structure or the super-block-based timing structure.

[0043] In some examples, the second security frame includes a PN field carrying the second PN.

[0044] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0045] In some examples, the second security frame includes a security payload, wherein unprotecting the second security frame includes unprotecting the security payload based on the second random number, and wherein the security payload includes: a second block index presence indicator indicating whether the second block index is included; a second round index presence indicator indicating whether the second round index is included; and a second time slot index presence indicator indicating whether the second time slot index is included.

[0046] In some examples, if the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; if the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; if the second time slot index presence indicator indicates that the second time slot index is included, the security payload includes the time slot index.

[0047] In some examples, the method further includes determining that the corresponding index is a default index based on a determination that at least one of the second block index presence indicator, the second round index presence indicator, or the second time slot index presence indicator indicates that the corresponding index is not included.

[0048] In a third aspect, a device is provided, including: a generation module for generating a first security frame, the first security frame to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, and each of the multiple rounds includes multiple time slots, wherein the first security frame is protected by a first random number, the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, and the block index is an index of the first block; a sending module for sending the first security frame.

[0049] The device may include various modules for implementing the method described in the first aspect, which are not listed one by one here for the sake of brevity.

[0050] In a fourth aspect, a device is provided, including: a receiving module for receiving a first security frame, the first security frame to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, and each of the multiple rounds includes multiple time slots; a deprotection module for deprotecting the first security frame according to a first random number, wherein the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block.

[0051] The device may include various modules for implementing the method described in the first aspect, which are not listed one by one here for the sake of brevity.

[0052] In a fifth aspect, a method is provided, comprising: generating a first security frame to be sent in a block-based time structure or a super-block-based time structure, wherein the first security frame is protected by a first random number constructed based on a first basic packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, and the first PN being a packet number of the first security frame; and sending the first security frame.

[0053] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0054] In some examples, the first random number includes: a first field having a first number of bits, carrying the first BPN; and a second field having a second number of bits, carrying the first PN.

[0055] In some examples, the first security frame includes a first PN field carrying the first PN.

[0056] In some examples, the first security frame indicates a first BPN.

[0057] In some examples, the first security frame includes a BPN presence field that carries a BPN presence indicator indicating whether a BPN field is included.

[0058] In some examples, if the BPN presence indicator indicates that the BPN field is included, the first security frame includes the BPN field carrying the first BPN.

[0059] In some examples, if the BPN presence indicator indicates that the BPN field is not included, the first security frame indicates that the first BPN is a default number.

[0060] In some examples, the method further includes storing the first BPN associated with a first communication direction between the initiator and the responder.

[0061] In some examples, the method further includes transmitting a second security frame including a second PN that is smaller than a PN included in a frame preceding the third security frame.

[0062] In some examples, the method further includes sending a third security frame including the second BPN.

[0063] In a sixth aspect, a method is provided, comprising: receiving a first security frame sent in a block-based time structure or a super-block-based time structure; and unprotecting the first security frame according to a first random number, wherein the first random number is constructed based on a first basic packet number (BPN) and a first packet number (PN), the first BPN is associated with an initiator and a responder, and the first PN is a packet number of the first security frame.

[0064] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0065] In some examples, the first random number includes: a first field having a first number of bits, carrying the first BPN; and a second field having a second number of bits, carrying the first PN.

[0066] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0067] In some examples, the first security frame includes a BPN presence field that carries a BPN presence indicator indicating whether a BPN field is included.

[0068] In some examples, if the BPN presence indicator indicates that the BPN field is included, the first security frame includes the BPN field carrying the first BPN.

[0069] In some examples, if the BPN presence indicator indicates that the BPN field is not included, the first security frame indicates that the first BPN is a default number.

[0070] In some examples, the method further includes storing the first BPN associated with a first communication direction between the initiator and the responder.

[0071] In some examples, the method further includes: receiving a second security frame including a second PN; and updating the first BPN by increasing by 1 based on a determination that the second PN is less than a PN included in a previous frame of the third security frame.

[0072] In some examples, the method further includes: receiving a third security frame including a second BPN; and replacing the first BPN with the second BPN.

[0073] In the seventh aspect, a device is provided, including: a generation module for generating a first security frame to be sent in a block-based time structure or a super-block-based time structure, wherein the first security frame is protected by a first random number constructed based on a first basic packet number (BPN) and a first packet number (PN); the first BPN is associated with an initiator and a responder, and the first PN is the packet number of the first security frame; and a sending module for sending the first security frame.

[0074] The device may include various modules for implementing the method of the fifth aspect, which are not listed one by one here for the sake of brevity.

[0075] In an eighth aspect, a device is provided, comprising: a receiving module for receiving a first security frame sent in a block-based time structure or a super-block-based time structure; and a deprotection module for deprotecting the first security frame according to a first random number, wherein the first random number is constructed based on a first basic packet number (BPN) and a first packet number (PN), the first BPN is associated with an initiator and a responder, and the first PN is the packet number of the first security frame.

[0076] The device may include various modules for implementing the method of the sixth aspect, which are not listed one by one here for the sake of brevity.

[0077] In a ninth aspect, a communication device is provided, comprising: a processor configured to execute, together with a transceiver, at least the method described in the first aspect, the second aspect, the fifth aspect, or the sixth aspect.

[0078] In a tenth aspect, a system is provided, comprising: the apparatus described in the third aspect and the apparatus described in the fourth aspect.

[0079] In the eleventh aspect, a system is provided, comprising: the device described in the seventh aspect and the device described in the eighth aspect.

[0080] In a twelfth aspect, a non-transitory computer-readable medium comprising program instructions is provided, wherein the program instructions are used to cause an apparatus to at least execute the method described in the first aspect, the second aspect, the fifth aspect or the sixth aspect.

[0081] In a thirteenth aspect, a computer program comprising instructions is provided, which, when executed by a device, causes the device to at least perform the method described in the first aspect, the second aspect, the fifth aspect or the sixth aspect.

[0082] It should be understood that the summary of the invention is not intended to identify the key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0083] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which:

[0084] Figure 1A A schematic diagram showing a block-based temporal structure;

[0085] Figure 1B A schematic diagram showing a superblock-based temporal structure;

[0086] Figure 1C shows a schematic diagram of an MMS ranging session;

[0087] Figure 1D A schematic diagram showing the format of a compressed PSDU;

[0088] Figure 1E A schematic diagram showing the format of a compressed header IE frame only;

[0089] Figure 1F A schematic diagram showing the format of a random number;

[0090] Figure 2A An exemplary communication system is shown in which some embodiments of the present invention may be implemented;

[0091] Figure 2B Another exemplary communication system is shown in which some embodiments of the present invention may be implemented;

[0092] Figure 3 shows a signaling diagram illustrating a communication process provided by some exemplary embodiments of the present invention;

[0093] Figure 4 A schematic diagram illustrating an exemplary NBA-MMS ranging session in a block-based time structure provided by some exemplary embodiments of the present invention is shown;

[0094] Figure 5 shows a signaling diagram illustrating the procedure of an exemplary MMS ranging session provided by some exemplary embodiments of the present invention;

[0095] Figure 6A A schematic diagram illustrating a format of a SOR frame provided by some exemplary embodiments of the present invention;

[0096] Figure 6B A schematic diagram illustrating a format of a random number for protecting a frame transmitted in an outer block structure provided by some exemplary embodiments of the present invention;

[0097] Figure 7A A schematic diagram illustrating a format of a POLL frame provided by some exemplary embodiments of the present invention;

[0098] Figure 7B A schematic diagram illustrating a format of a random number for protecting a frame within a block structure provided by some exemplary embodiments of the present invention;

[0099] Figure 7C An example of constructing a random number for protecting a compressed frame provided by some exemplary embodiments of the present invention is shown;

[0100] Figure 8 A schematic diagram illustrating another format of a random number for protecting a frame within a block structure provided by some exemplary embodiments of the present invention;

[0101] Figure 9 A schematic diagram illustrating a format of a secure SOR frame provided by some exemplary embodiments of the present invention is shown;

[0102] Figure 10A An exemplary conversation between an initiator and a responder 1 provided by some exemplary embodiments of the present invention is shown;

[0103] Figure 10B shows an exemplary conversation between an initiator and a responder 2 provided by some exemplary embodiments of the present invention;

[0104] Figure 11A A schematic diagram showing a time structure including a period provided by some exemplary embodiments of the present invention;

[0105] Figure 11B A schematic diagram illustrating a format of another secure SOR frame provided by some exemplary embodiments of the present invention;

[0106] Figure 11C A schematic diagram illustrating another format of a random number for protecting a frame within a block structure provided by some exemplary embodiments of the present invention;

[0107] Figure 12AA schematic diagram illustrating random number construction in a super-block-based time structure provided by some exemplary embodiments of the present invention is shown;

[0108] Figure 12B A schematic diagram illustrating random number construction in a super-block-based time structure provided by some exemplary embodiments of the present invention is shown;

[0109] Figure 13 A schematic diagram illustrating another exemplary MMS ranging session in a block-based time structure provided by some exemplary embodiments of the present invention is shown;

[0110] Figure 14 shows a signaling diagram illustrating a procedure of another exemplary MMS ranging session provided by some exemplary embodiments of the present invention;

[0111] Figure 15A A schematic diagram illustrating a format of a random number for protecting a frame provided by some exemplary embodiments of the present invention;

[0112] Figure 15B A schematic diagram illustrating another format of a random number for protecting a frame provided by some exemplary embodiments of the present invention;

[0113] Figure 16A A schematic diagram illustrating a format of a secure RPRT frame provided by some exemplary embodiments of the present invention is shown;

[0114] Figure 16B A schematic diagram illustrating a format of an ADV-POLL frame provided by some exemplary embodiments of the present invention;

[0115] Figure 17 illustrating exemplary conversations between an initiator and responders 1 and 2 provided by some exemplary embodiments of the present invention;

[0116] Figure 18 shows a signaling diagram illustrating a communication process provided by some exemplary embodiments of the present invention;

[0117] Figure 19 A schematic diagram illustrating an exemplary MMS ranging session provided by some exemplary embodiments of the present invention is shown;

[0118] Figure 20 shows a signaling diagram illustrating the procedure of an exemplary MMS ranging session provided by some exemplary embodiments of the present invention;

[0119] Figure 21A A schematic diagram illustrating the format of a security frame during the initialization and establishment phases provided by some exemplary embodiments of the present invention;

[0120] Figure 21BA schematic diagram illustrating a format of a security frame during a measurement period provided by some exemplary embodiments of the present invention;

[0121] Figure 21C A schematic diagram illustrating a format of a secure SOR frame provided by some exemplary embodiments of the present invention is shown;

[0122] Figure 21D A schematic diagram illustrating the format of a secure PRM-REQ or PRM-RESP frame provided by some exemplary embodiments of the present invention;

[0123] Figure 21E A schematic diagram illustrating a format of a random number provided by some exemplary embodiments of the present invention;

[0124] Figure 22A An exemplary downlink session from an initiator to a responder 1 provided by some exemplary embodiments of the present invention is shown;

[0125] Figure 22B An exemplary uplink session from responder 2 to initiator provided by some exemplary embodiments of the present invention is shown;

[0126] Figure 23 An exemplary block diagram of a communication device provided by some embodiments of the present invention is shown;

[0127] Figure 24 An exemplary block diagram of another communication device provided by some embodiments of the present invention is shown;

[0128] Figure 25 A schematic block diagram of an apparatus that can be used to implement some embodiments of the present invention is shown.

[0129] Throughout the drawings, the same or similar reference numerals refer to the same or similar elements. DETAILED DESCRIPTION

[0130] The principle of the present invention will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described merely for illustrative purposes and to help those skilled in the art understand and implement the present invention without limiting the scope of the present invention. The disclosure described herein can be implemented in a variety of ways except for the manner described below.

[0131] Ultra-wideband (UWB) technology has been used for indoor positioning and other location-based services, such as access control and asset location. In addition to dedicated devices and tags, UWB radios are becoming increasingly common in high-end smartphones. A working group is underway to enhance UWB technology.

[0132] UWB technology has been used in various scenarios such as device-free sensing, downlink time difference of arrival (DL-TDOA), long-distance ranging, etc. Multi-millisecond (MMS) ranging has been introduced to address long-distance ranging scenarios. The key idea behind MMS ranging is to distribute the UWB ranging frame into multiple segments, where each segment is sent within multiple milliseconds (ms), thereby overcoming the transmission energy limitation of 37nJ / ms. Narrowband assisted (NBA) MMS ranging can be regarded as an enhancement of MMS ranging, proposed by high-performance narrowband (NB) radio, which is used to provide time synchronization for UWB radio and for control signaling. In MMS ranging, the number of segments required for ranging depends on the range to be measured and the channel conditions, and can therefore be dynamically adjusted even in the same ranging session.

[0133] Figure 1A Schematic diagram of a block-based time structure 110 is shown. Figure 1A As shown, each block includes multiple rounds, and each round includes multiple time slots. The block-based time structure 110 can be used for a block-based ranging mode. The block-based mode can use a structured timeline, wherein the block-based time structure 110 is periodic by default. In some examples, a block can also be referred to as a ranging block, a round can also be referred to as a ranging round, and a time slot can also be referred to as a ranging slot.

[0134] A ranging round is a time period of sufficient duration to complete a complete range measurement cycle involving the set of ERDEVs participating in a ranging exchange. A ranging slot is a time period of sufficient duration to transmit at least one frame. Figure 1A As shown, the start of the frame can be aligned with the start of the time slot, or a transmission offset can be applied from the start of the time slot to the start of the frame.

[0135] The block-based time structure 110 may be predetermined and remain unchanged during the ranging session.It should be understood that the block-based time structure 110 may not be suitable for NBA-MMS ranging scenarios, where the round duration may vary dynamically.

[0136] Figure 1B Schematic diagram of a super-block based time structure 120 is shown. Figure 1B As shown, each superblock includes multiple blocks. Different blocks in a superblock can have different configurations, such as block duration, round duration, slot duration, number of rounds in a block, number of slots in a round, etc. For example, Figure 1BThe super block K in includes block 0, block 1 and block 2, where block 0 includes 2 rounds, block 1 includes 7 rounds, and block 2 includes 3 rounds.

[0137] In some examples, different blocks within a super-block can be used for different purposes. For example, block 0 can be used for DL-TDOA, block 1 can be used for ranging, and block 2 can be used for sensing. In other examples, different blocks within a super-block can be used for different scenarios within the same purpose. For example, blocks 0, 1, and 2 can all be used for NBA-MMS ranging, but block 1 can be used for one-to-one ranging in good channel conditions, block 0 can be used for one-to-many ranging, and block 2 can be used for one-to-one ranging in poor channel conditions, etc.

[0138] Figure 1C A schematic diagram of an MMS ranging session 130 is shown. The MMS ranging session 130 includes an initialization and setup phase 131 and one or more measurement cycles 132. The MMS ranging session 130 involves an initiator and a responder. It should be understood that the initiator may be a device that initiates a UWB exchange by sending a first message, and the responder may be a device that receives and responds to the first message from the initiator.

[0139] In some examples, frames are sent in the initialization channel during the initialization and setup phase 131, and frames are sent in the ranging channel during one or more measurement periods 132. In some examples, the same channel can be used, e.g., a well-known channel can be used, as both the initialization channel and the ranging channel.

[0140] During the initialization and establishment phase 131, the initiator and responder can negotiate the ranging configuration. Specifically, the initiator opportunistically sends advertisement poll (ADV-POLL) frames at a time and interval determined by it. If the responder intends to participate in a ranging session with the initiator, the responder can opportunistically listen for incoming ADV-POLL frames and respond with advertisement response (ADV-RESP) frames. Once the initiator receives the ADV-RESP frame, it sends a start of ranging (SOR) frame, which provides the time offset for the start of the first measurement cycle.

[0141] The measurement cycle, also known as the distance measurement cycle, consists of a control phase, a ranging phase, and an optional measurement reporting phase. The control phase (also known as the ranging control phase) begins at the beginning of the distance measurement cycle. The initiator begins the ranging control phase by sending a POLL frame to the responder at the beginning of the first ranging slot of the ranging round. Upon receiving the POLL frame, the responder successfully sends a RESP frame back to the initiator. The POLL and RESP frames enable the initiator and responder to achieve time and frequency synchronization. In some examples, other control information may also be included in the POLL frame.

[0142] During the ranging phase, the initiator and responder can exchange zero or more UWB ranging sequence fragments (RSFs) and optionally one or more UWB ranging integrity fragments (RIFs). The RSFs are used to perform ranging measurements, while the RIFs are used to check the integrity of the ranging measurements.

[0143] The measurement report phase may begin after the initiator or responder completes receiving all UWB segments from the ranging phase. During the measurement report phase, the initiator or responder may generate a ranging measurement report and send a ranging packet report (RPRT) frame carrying the measurement report to the peer device.

[0144] Frames in the control phase and frames in the ranging phase are sent using UWB for MMS ranging. Frames in the control phase are sent using NB, and frames in the ranging phase are sent using UWB for NBA-MMS ranging.

[0145] In order to provide more space for the information carried in the frame, compressed physical (PHY) service data unit (PSDU) is introduced. Figure 1D FIG1 is a schematic diagram showing the format of the compressed PSDU 140. The compressed PSDU 140 may be used for NB control frames. Figure 1D As shown, the compressed PSDU 140 includes an identifier (ID) field having 1 octet, an address field having 2 octets, a payload field having a variable length, and a cyclic redundancy check (CRC) field having 2 octets.

[0146] Similarly, compression of header-only information element (IE) frames is also introduced. Figure 1E FIG. 1 is a schematic diagram showing the format of a compressed header-only IE frame 150. The compressed header-only IE frame 150 may be used for broadcast traffic. Figure 1E As shown, the compressed header-only IE frame 150 includes a frame control field having 1 or 2 octets, an address field having 2 octets, a header IE message ID field having 1 octet, a payload field having a variable length, and a CRC field having 2 octets.

[0147] The compressed PSDU 140 or the compressed header-only IE frame 150 may be carried in an 802.15.4ab physical protocol data unit (PPDU). A conventional 802.15.4 frame carried in an 802.15.4ab physical protocol data unit (PPDU) may also be used for MMS ranging, and the frame may not carry the auxiliary security header field (and therefore, the frame counter field).

[0148] As mentioned above, AEAD security operations are proposed. AEAD security operations use an extension of counter mode encryption and cipher block chaining message authentication codes. In addition to the security key, the important input to each AEAD security operation is a unique random number. Figure 1F FIG1 is a schematic diagram showing the format of the random number 160. The random number 160 can be used in a time slotted channel hopping (TSCH) mode. Figure 1F As shown, the random number 160 includes a source address field having 8 octets, a frame counter field having 4 octets, and a random number security level field having 1 octet.

[0149] If AEAD security operations are applied to compressed PSDUs or compressed header-only IE frames, or 802.15.4 frames that do not carry a frame counter field, further investigation should be conducted into how the random number is constructed.

[0150] Embodiments of the present invention provide a solution for secure frames in ultra-wideband (UWB). In some embodiments, a secure frame can be generated based on a random number, where the random number is constructed based on identification information associated with the secure frame, a block index, and a round index associated with the round and block in which the first secure frame is transmitted. Therefore, secure operations can be performed and communications can be guaranteed secure. The principles and implementations of the present invention are described in detail below with reference to the accompanying drawings.

[0151] Figure 2A An exemplary communication system 200 in which some embodiments of the present invention may be implemented is shown. The communication system 200 includes a controller 210, a controlled 220-1, and a controlled 220-2, where the controlled 220-1 and 220-2 may be collectively or individually referred to as a controlled 220.

[0152] In the present invention, the controller 210 may be a device that controls a UWB session and defines session parameters, and the controlled device 220 may be a device that participates in the UWB session using the session parameters received from the controller 210 .

[0153] A UWB session may also be referred to as a UWB exchange. When participating in a UWB session, the controller 210 may be the initiator and the controlled entity 220 may be the responder, or the controlled entity 220 may be the initiator and the controller 210 may be the responder.

[0154] Figure 2B Another exemplary communication system 250 is shown in which some embodiments of the present invention may be implemented. Communication system 250 includes initiator 260, responder 270-1, and responder 270-2, where responders 270-1 and 270-2 may be collectively or individually referred to as responders 270.

[0155] In the present invention, initiator 260 may be a device that follows one or more instructions from a controller and may initiate a UWB exchange by sending a first message of the exchange to responder 270. Responder 270 may be a device that responds to the first message received from initiator 260 and participates in the UWB exchange.

[0156] In system 250, the link from initiator 260 to responder 270 is called a downlink (DL), while the link from responder 270 to initiator 260 is called an uplink (UL). In the downlink, initiator 260 is a transmitting (TX) device (or transmitter), and responder 270 is a receiving (RX) device (or receiver). In the uplink, responder 270 is a transmitting (TX) device (or transmitter), and initiator 260 is an RX device (or receiver).

[0157] It should be understood that the controller or the controlled entity can be initiator 260; similarly, the controlled entity or the controller can be responder 270. As a specific example, initiator 260 is controller 210, responder 270-1 is controlled entity 220-1, and responder 270-2 is controlled entity 220-2. However, it should be understood that this is for ease of explanation only and does not limit the scope of protection.

[0158] The device of the present invention, for example Figure 2A The controller 210 or the controller 220 or Figure 2B The initiator 260 or responder 270 in the embodiment can be implemented as a tag, a mobile device, a remote control key, a vehicle, a door lock, etc., wherein the mobile device can include but is not limited to a smartphone, a personal digital assistant (PDA), a laptop computer, a tablet computer, a wearable device, an Internet of Things (IoT) device, a vehicle to everything (V2X) device, etc.

[0159] It should be understood that Figure 2A and Figure 2B The number of devices and their connection relationships and types shown in the figure are for illustration only and do not represent any limitation. System 200 or 250 may include any suitable number of devices suitable for implementing embodiments of the present invention.

[0160] Further references Figure 3 , shows a signaling diagram illustrating a communication process 300 provided by some exemplary embodiments of the present invention. The process 300 may involve a transmitter 301 and a receiver 302. It should be understood that referring to Figure 2A , the transmitter 301 can be the controller 210 or the controlled 220, and the receiver 302 can be the controlled 220 or the controller 210. It should be understood that, see Figure 2B , the sender 301 can be the initiator 260 or the responder 270 , and the receiver 302 can be the responder 270 or the initiator 260 .

[0161] The transmitter 301 generates (310) a first security frame. The first security frame is to be transmitted in a time slot (e.g., a first time slot) in a first round, wherein the first round is in a first block. A block-based time structure or a super-block-based time structure may be employed, wherein each block includes multiple rounds and each round includes multiple time slots. In some examples, when a block-based time structure is employed, different blocks include the same number of rounds and different rounds include the same number of time slots. In other examples, when a super-block-based time structure is employed, different blocks may include the same number of rounds or different numbers of rounds and different numbers of rounds may include the same number of time slots or different numbers of time slots. The first security frame may be protected by a first random number, wherein the first random number is constructed based on identification information associated with the first security frame, a round index, and a block index, wherein the round index is an index of the first round and the block index is an index of the first block. In some embodiments, the transmitter 301 may construct the first random number and then generate the first security frame. In some examples, the identification information associated with the first security frame may include a time slot index or a first PN, which will be described in detail below.

[0162] In some exemplary embodiments, a first security frame may be transmitted during a measurement period. In some examples, the first random number is constructed based on a slot index, a round index, and a block index. For example, the identification information includes a slot index. The slot index is the index of the first slot in which the first security frame is transmitted, the round index is the index of the first round to which the first slot belongs, and the block index is the index of the first block to which the first round belongs.

[0163] The first random number may include a first field carrying a slot index, a second field carrying a round index, and a third field carrying a block index. The length of the first field may be equal to the first number, the length of the second field may be equal to the second number, and the length of the third field may be equal to the third number.

[0164] In some examples, the first number can be a first predefined number, such as 8 bits, 10 bits, or other values. In some examples, the first number can be determined by the position of the start bit and the position of the end bit. For example, the position of the start bit and the position of the end bit of the first field can be predefined. In some other examples, the first number can be associated with the length of the first round (e.g., the number of time slots in the first round). For example, the first number can be M bits, where M is an integer and can be determined by equation (1): in, is the upper limit function of the variable X, i.e., the smallest integer not less than (≥) X. The “round duration” in equation (1) refers to the time length of the first round. The “time slot duration” in equation (1) refers to the time length of the first time slot. is the number of time slots per round (denoted as “NumSlots”). For example, the position of the start bit of the first field may be predefined, and the position of the end bit of the first field may be determined according to M.

[0165] In some examples, the second number can be a second predefined number, such as 15 bits, 13 bits, or other values. In some examples, the second number can be determined by the position of the start bit and the position of the end bit. For example, the position of the start bit and the position of the end bit of the second field can be predefined. In some other examples, the second number can be associated with the length of the first block (e.g., the number of rounds in the first block). For example, the second number can be N bits, where n is an integer and can be determined by equation (2): Wherein, the “round duration” in equation (2) refers to the time length of the first round, the “block duration” in equation (2) refers to the time length of the first block, and the Refers to the number of rounds per block (expressed as "NumRounds"). For example, the position of the start bit of the second field can be the bit after the first field, and the position of the end bit of the second field can be determined according to N.

[0166] In some examples, the third number may be a third predefined number, such as 16 bits, 18 bits, or another value. In other examples, the third number may be determined based on at least one of the first number and the second number. For example, the sum of the first number, the second number, and the third number may equal the predefined total number, and thus the third number may be determined based on the predefined total number, the first number, and the second number. For example, the predefined total number may be 39 bits, 35 bits, or another value. Alternatively, the combination of the first field, the second field, and the third field may be considered a frame counter field, for example, having a length equal to the predefined total number.

[0167] In the first random number, the first field, the second field, and the third field may be consecutive. For example, the second field follows the first field, and the third field follows the second field. However, it should be understood that the present invention is not limited to this aspect. For example, there may be one or more reserved bits or one or more other fields between the first field and the second field. For example, the third field may be located before the first field. The present invention will not further enumerate these details.

[0168] In addition, the first random number may include a fourth field carrying a period index. The length of the fourth field may be equal to the fourth quantity. In the present invention, a new period may be defined, wherein a period includes one or more blocks. The period index is the index of the period that includes the first block. In some examples, the fourth quantity may be a fourth predefined quantity, such as 6 bits, 7 bits, 8 bits, or other values. In other examples, the fourth quantity may be determined based on at least one of the first quantity, the second quantity, and the third quantity. For example, the sum of the first quantity, the second quantity, the third quantity, and the fourth quantity may be equal to the predefined total quantity, and thus the fourth quantity may be determined based on the predefined total quantity, the first quantity, the second quantity, and the third quantity. Alternatively, the combination of the first field, the second field, the third field, and the fourth field may be considered a frame counter field, for example, having a length equal to the predefined total quantity.

[0169] The first random number includes a first block indicator, wherein the first block indicator may indicate that the first security frame is transmitted based on a block-based timing structure or a super-block-based timing structure. For example, the first random number may include a field carrying the first block indicator, such as a block indicator field. In some examples, the term "block-based timing structure or super-block-based timing structure" may be referred to as an "internal block structure." The term "internal block structure" may refer to a time period in which the block-based timing structure or super-block-based timing structure is known to both the transmitter 301 and the receiver 302. The length of the field carrying the first block indicator may be predefined, such as 1 bit, 2 bits, or another value. If the first block indicator is equal to the first value, it may indicate that the first security frame is in an internal block structure. For example, the first value may be 1 or 0. In some examples, the field carrying the first block indicator may be located at a predefined position of the first random number, such as at the end of the first random number.

[0170] The first random number includes a source address. For example, the first random number may include a field carrying the source address, such as a source address field. The length of the field carrying the source address may be predefined, such as 8 octets, 10 octets, or another value. The field carrying the source address may be located in a predefined position within the first random number, such as before the first random number. The source address may be an extended address of the device initiating the first security frame, i.e., the address of transmitter 301.

[0171] In some exemplary embodiments, a first security frame may be sent during the measurement period. As some examples, the first security frame may be any one of: secure POLL, secure RESP, or secure RPRT.

[0172] The first safety frame may include a first block index presence indicator and a first round index presence indicator. The first block index presence indicator may indicate whether a block index exists in the first safety frame. The first round index presence indicator may indicate whether a round index exists in the first safety frame. For example, the first block index presence indicator is equal to a first value to indicate that a block index exists in the first safety frame, or is equal to a second value to indicate that a block index does not exist in the first safety frame. For example, the first round index presence indicator is equal to a first value to indicate that a round index exists in the first safety frame, or is equal to a second value to indicate that a round index does not exist in the first safety frame. The first value is 1 and the second value is 0, or the first value is 0 and the second value is 1.

[0173] For example, the first security frame may include a first block index presence field carrying a first block index presence indicator and a first round index presence field carrying a first round index presence indicator. Alternatively, the first security frame may include a presence control field (having a predefined length, such as 1 octet), the presence control field including a first block index presence field and a first round index presence field. In some examples, the length of the first block index presence field may be 1 bit, 2 bits, or other values, and the length of the first round index presence field may be 1 bit, 2 bits, or other values.

[0174] The first security frame may include a block index. For example, if the first block index presence indicator indicates the presence of the block index, for example, the first block index presence indicator is equal to a first value. For example, the first security frame may include a first block index field carrying the block index. Alternatively, the length of the first block index field may be predefined, such as 2 octets, 15 bits, or another value. It should be understood that if the first block index presence indicator is equal to a second value, the first block index field is not included, i.e., the length of the first block index field is 0.

[0175] The first security frame may include a round index. For example, if the first round index presence indicator indicates the presence of a round index, for example, the first round index presence indicator is equal to a first value. For example, the first security frame may include a first block index field carrying a block index. Alternatively, the length of the first round index field may be predefined, such as 2 octets, 15 bits, or another value. It should be understood that if the first round index presence indicator is equal to a second value, the first round index field is not included, i.e., the length of the first round index field is 0.

[0176] Alternatively, the first security frame may include an open payload including a first block index present field, a first round index present field, a first block index field (if present), and a first round index field (if present).

[0177] The first security frame may include a first security indicator. For example, the first security frame may include a field carrying the first security indicator, such as a security indicator field. The first security indicator may indicate that the first security frame is secure. For example, the length of the field carrying the first security indicator may be predefined, such as 1 bit, 2 bits, or another value.

[0178] The first security frame may also include one or more of a field carrying an ID, a field carrying an address, a field carrying a security payload, and a field carrying a message integrity check (MIC). The security payload in the first security frame may be generated based on the first random number. In some examples, a security key may be used to generate the security payload in the first security frame.

[0179] The transmitter 301 transmits (320) a first security frame 322 to the receiver 302. The receiver 302 receives (324) the first security frame 322. The receiver 302 deprotects (330) the first security frame 322. Specifically, the receiver 302 deprotects the first security frame 322 using a random number constructed based on the round index and the block index.

[0180] It should be understood that the standards for constructing random numbers by the transmitter 301 and the receiver 302 should be consistent, that is, the random number constructed by the receiver 302 should be the same as the first random number constructed by the transmitter 301 for protecting the first security frame. If the random number constructed by the receiver 302 is different from the first random number constructed by the transmitter 301 for protecting the first security frame, deprotection of the first security frame will fail.

[0181] In some embodiments, the receiver 302 may construct a first random number and then deprotect the first security frame 322. The first random number constructed by the receiver 302 is similar to the random number described above (i.e., the random number constructed by the sender) and will not be described in detail for the sake of brevity.

[0182] As mentioned above, the first random number may include three fields, each carrying a time slot index, a round index, and a block index. In other examples, the first random number may include two fields, one of which carries one of the time slot index, the round index, and the block index, and the other carries a combination of the other two of the time slot index, the round index, and the block index. For example, one field of the first random number carries the time slot index, and the other field of the first random number carries a function of the round index and the block index. In some other examples, the first random number may include a field carrying a value (such as a frame counter (FC)), which is a function of the time slot index, the round index, and the block index. It should be understood that the first random number can also be determined based on the time slot index, the round index, and the block index in other ways, and the present invention is not limited to this aspect.

[0183] In addition, transmitter 301 may generate a second security frame. The second security frame will not be transmitted according to a block-based timing structure or a super-block-based timing structure; that is, the second security frame will be transmitted in a non-block-based timing structure or a non-super-block-based timing structure or other structure. In some examples, the term "non-block-based timing structure" or "non-block-based timing structure" or "non-super-block-based timing structure" or "non-super-block-based timing structure" may be referred to as an "external block structure." The term "external block structure" may refer to a period of time during which the block-based timing structure or the super-block-based timing structure is unknown to either transmitter 301 or receiver 302.

[0184] The second security frame may be protected by a second random number, wherein the second random number is constructed based on a second packet number (PN), and the second PN is the packet number of the second security frame. In some embodiments, the transmitter 301 may construct the second random number and then generate the second security frame.

[0185] In some examples, the second random number may include a field carrying the second PN. The length of the field carrying the second PN may be equal to a predefined number, such as 4 octets, 3 octets, or other values.

[0186] The second random number includes a field carrying a second block indicator, wherein the second block indicator may indicate that the second security frame is sent in an outer block structure. The length of the field carrying the second block indicator may be predefined, such as 1 bit, 2 bits, or another value. If the second block indicator is equal to the second value, it may indicate that the second security frame is in an outer block structure. For example, the second value may be different from the first value of the first block indicator indicating that the first security frame is in an inner block structure. For example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1. In some examples, the field carrying the second block indicator may be located at a predefined position of the second random number, such as at the end of the second random number.

[0187] The second random number includes a field containing a source address. The length of the field containing the source address can be predefined, such as 8 octets, 7 octets, or another value. The field containing the source address can be located at a predefined position within the second random number, such as before the second random number. The source address can be an extended address of the device initiating the second security frame, i.e., the address of transmitter 301.

[0188] In some exemplary embodiments, the second security frame may be sent during the initialization and setup phases. As some examples, the second security frame may be any one of a secure ADV-RESP or a secure SOR.

[0189] The second security frame may include a PN field carrying the second PN. The length of the PN field in the second security frame may be predefined, such as 4 octets, 3 octets, or other values.

[0190] The second security frame may include a field carrying a second security indicator. The second security indicator may indicate that the second security frame is secure. For example, the length of the field carrying the second security indicator may be predefined, such as 1 bit, 2 bits, or other values.

[0191] The second security frame may also include one or more of a field carrying an ID, a field carrying an address, a field carrying a security level, a field carrying a security payload, and a field carrying a MIC. The security payload in the second security frame may be generated based on the second random number. In some examples, a security key may be used to generate the security payload in the second security frame.

[0192] In some examples, the security payload may include a second block index presence field carrying a second block index presence indicator, a second round index presence field carrying a second round index presence indicator, and a second slot index presence field carrying a second slot index presence indicator. The second block index presence indicator may indicate whether the second block index field exists. The second round index presence indicator may indicate whether the second round index field exists. The second slot index presence indicator may indicate whether the second slot index field exists.

[0193] For example, the second block index presence indicator may be equal to a first value to indicate the presence of the second block index field in the security payload, or equal to a second value to indicate the absence of the second block index field in the security payload. For example, the second round index presence indicator may be equal to a first value to indicate the presence of the second round index field in the security payload, or equal to a second value to indicate the absence of the second round index field in the security payload. For example, the second slot index presence indicator may be equal to a first value to indicate the presence of the second slot index field in the security payload, or equal to a second value to indicate the absence of the second slot index field in the security payload. The first value may be 1 and the second value may be 0, or the first value may be 0 and the second value may be 1. Alternatively, the security payload may include a presence control field (having a predefined length, such as 1 octet) comprising a second block index presence field, a second round index presence field, and a second slot index presence field. In some examples, the second block index presence field may have a length of 1 bit, 2 bits, or another value, the second round index presence field may have a length of 1 bit, 2 bits, or another value, and the second slot index presence field may have a length of 1 bit, 2 bits, or another value.

[0194] The security payload may include a second block index field carrying a block index. For example, if a second block index presence indicator in the second block index presence field indicates the presence of a second block index field, e.g., if the second block index presence indicator is equal to a first value, then the second block index field carrying the block index is present. Alternatively, the length of the second block index field may be predefined, e.g., 2 octets, 15 bits, or another value. It should be understood that if the second block index presence indicator is equal to the second value, i.e., the length of the second block index field is 0, then the second block index field is not included.

[0195] The security payload may include a second-round index field carrying the round index. For example, if the second-round index presence indicator in the second-round index presence field indicates the presence of the second-round index field, e.g., if the second-round index presence indicator is equal to a first value, then the second-round index field carrying the round index is present. Alternatively, the length of the second-round index field may be predefined, such as 2 octets, 15 bits, or another value. It should be understood that if the second-round index presence indicator is equal to the second value, i.e., the length of the second-round index field is 0, then the second-round index field is not included.

[0196] The security payload may include a second slot index field carrying a slot index. For example, if a second slot index presence indicator in the second slot index presence field indicates the presence of the second slot index field, e.g., if the second slot index presence indicator is equal to a first value, then the second slot index field carrying the slot index is present. Alternatively, the length of the second slot index field may be predefined, e.g., 2 octets, 15 bits, or another value. It should be understood that if the second slot index presence indicator is equal to the second value, i.e., the length of the second slot index field is 0, then the second slot index field is not included.

[0197] The transmitter 301 sends a second security frame to the receiver 302. The receiver 302 receives the second security frame and removes protection from the second security frame. Specifically, the receiver 302 removes protection from the second security frame using a random number constructed according to the second PN.

[0198] As described above, the standards for constructing random numbers by the transmitter 301 and the receiver 302 should be consistent, that is, the random number constructed by the receiver 302 should be the same as the second random number constructed by the transmitter 301 for protecting the second security frame. If the random number constructed by the receiver 302 for deprotecting the second security frame is different from the random number constructed by the transmitter 301 for protecting the second security frame, deprotection of the second security frame will fail.

[0199] In some embodiments, the receiver 302 may construct a second random number and then deprotect the second security frame. The second random number constructed by the receiver 302 is similar to the random number described above (ie, the random number constructed by the sender) and will not be described in detail for the sake of brevity.

[0200] When receiver 302 deprotects the second security frame, receiver 302 may obtain information in the security payload of the second security frame. In some examples, if the second block index field, the second round index field, and the second time slot index field are included, the carried block index, round index, and time slot index may be obtained by receiver 302. In other examples, if at least one of the second block index field, the second round index field, and the second time slot index field is not included, receiver 302 may determine the corresponding index independently. For example, if the second block index field is not included in the security payload, receiver 302 may determine the block index as a default value, such as a block index of 0. Therefore, if the index is a default value (e.g., 0), it does not need to be included in the security payload, thereby saving signaling overhead.

[0201] According to some embodiments described above, different random numbers may be used to protect frames during the initialization and setup phases and during the measurement period. Specifically, the PN may be used to construct a random number for protecting frames sent in the "external block structure," and the slot index, round index, and block index may be used to construct a random number for protecting frames sent in the "internal block structure."

[0202] In some other exemplary embodiments, the first security frame generated by transmitter 301 at 310 may be sent during the initialization and setup phase or during a measurement period. Specifically, a block-based timing structure or a super-block-based timing structure may be established before or at the beginning of the initialization and setup phase. In this case, the frames sent during the initialization and setup phase are also in the block-based timing structure or the super-block-based timing structure.

[0203] The first random number used to protect the first security frame is constructed based on the block index, the round index, and the first PN. The round index is the index of the first round in which the first security frame is transmitted, and the block index is the index of the first block to which the first round belongs. The first PN is the packet number of the first security frame. That is, the first PN is used to uniquely identify the first security frame.

[0204] The first random number may include a first field carrying a first PN, a second field carrying a round index, and a third field carrying a block index. The length of the first field may be equal to the first number, the length of the second field may be equal to the second number, and the length of the third field may be equal to the third number.

[0205] In some examples, the first number can be a first predefined number, such as 8 bits, 7 bits, or other values. In some examples, the first number can be determined by the position of the start bit and the position of the end bit. For example, the position of the start bit and the position of the end bit of the first field can be predefined.

[0206] In some examples, the second number can be a second predefined number, such as 15 bits, 16 bits, or other values. In some examples, the second number can be determined by the position of the start bit and the position of the end bit. For example, the position of the start bit and the position of the end bit of the second field can be predefined. In some other examples, the second number can be associated with the length of the first block (e.g., the number of rounds in the first block). For example, the second number can be N bits, where N is an integer and can be determined by the above equation (2).

[0207] In some examples, the third number may be a third predefined number, such as 16 bits, 17 bits, or another value. In other examples, the third number may be determined based on at least one of the first number and the second number. For example, the sum of the first number, the second number, and the third number may equal a predefined total number, and thus the third number may be determined based on the predefined total number, the first number, and the second number. For example, the predefined total number may be 40 bits, 39 bits, or another value. Alternatively, the combination of the first field, the second field, and the third field may be considered a frame counter field, for example, having a length equal to the predefined total number.

[0208] In the first random number, the first field, the second field, and the third field may be consecutive. For example, the second field follows the first field, and the third field follows the second field. However, it should be understood that the present invention is not limited to this aspect. For example, there may be one or more reserved bits between the first field and the second field, and the third field may be located before the first field. The present invention will not further enumerate these details.

[0209] The first random number includes a field containing a source address. The length of the field containing the source address can be predefined, such as 8 octets, 7 octets, or another value. The field containing the source address can be located in a predefined position within the first random number, such as before the first random number. The source address can be an extended address of the device initiating the first security frame, i.e., the address of transmitter 301.

[0210] Similarly, transmitter 301 transmits (320) a first security frame 322 protected by a first random number constructed based on a first PN, a round index, and a block index. Receiver 302 may receive (324) the first security frame 322. Receiver 302 may deprotect (330) the first security frame 322. Specifically, receiver 302 may construct a first random number based on the first PN, the round index, and the block index, and deprotect the first security frame 322 using the first random number.

[0211] As described above, the first random number may include three fields, each carrying a first PN, a round index, and a block index. In other examples, the first random number may include two fields, one field carrying one of the first PN, the round index, and the block index, and the other field carrying a combination of the other two of the first PN, the round index, and the block index. For example, one field of the first random number carries the first PN, and another field of the first random number carries a function of the round index and the block index. In some other examples, the first random number may include a field carrying a value (e.g., a frame counter (FC)), the value of which is a function of the first PN, the round index, and the block index. It should be understood that the first random number may also be determined based on the first PN, the round index, and the block index in other ways, and the present invention is not limited in this respect.

[0212] According to some embodiments described above, where a block-based time structure or a super-block-based time structure can be established before or at the beginning of the initialization and establishment phase, PN, round index and block index can be used to construct a random number for protecting the frame.

[0213] Some of the above embodiments have described that the identification information associated with the first security frame may include a time slot index or a first PN. In some other examples, the identification information associated with the first security frame may include a time slot index and a first PN. In some other examples, the identification information associated with the first security frame may include a parameter or value specific to the first security frame (or unique). The present invention is not limited in this respect.

[0214] In the present invention, a secure frame is generated by protecting a compressed frame, where the compressed frame can be a compressed PSDU frame or a frame with a compressed header IE format as described above. Alternatively, a secure frame can be generated by protecting an 802.15.4 frame that does not carry a frame counter field. Security operations can be performed using cryptographic operations such as authentication or encryption.

[0215] Figure 4 FIG. 4 is a schematic diagram showing an exemplary MMS ranging session 400 in a block-based time structure provided by some exemplary embodiments of the present invention. Figure 4 As shown, an MMS ranging session 400 includes an initialization and setup phase 401 followed by one or more measurement cycles 402 .

[0216] During the initialization and establishment phase 401, the responder may not be aware of the block-based time structure, so the initialization and establishment phase 401 is considered to be an "external block structure." During one or more measurement periods 402, both the initiator and the responder participating in the MMS ranging session will be aware of the block-based time structure, so the one or more measurement periods 402 are considered to be an "internal block structure."

[0217] As shown at 410, during the initialization and setup phase 401, the PN is used to construct a random number. It should also be understood that the transmission duration of the frame during the initialization and setup phase 401 is not necessarily limited to 1 ms.

[0218] During one or more measurement cycles 402, a transmitter (initiator or responder) may only transmit a single frame in a time slot, so each frame is uniquely associated with a specific time slot. Therefore, the time slot index, round index, and block index can be used to construct a random number for protecting the frame sent in the time slot. Since the index is strictly increasing, it is guaranteed that the time slot index, round index, and block index used to construct the random number will not be repeated in the current block structure, so the frame does not need to carry any PN, as shown in 420.

[0219] Figure 5 A signaling diagram illustrating a process 500 of an exemplary MMS ranging session is shown, provided by some exemplary embodiments of the present invention.

[0220] The process 500 begins with the controller and the controlled performing a session establishment 510. During the session establishment 510, long-term session parameters such as the UWB channel number, preamble, default block structure (eg, number of blocks, block duration), etc. are negotiated. Figure 4 The long-term session parameters include default values for m and n, where m is associated with the number of slots in each round (e.g., NumSlots = m + 1, as Figure 4 As shown), and n is associated with the number of rounds in each block (e.g., NumRounds = n+1, as shown Figure 4 (as shown). Long-term parameters are not expected to change during an MMS ranging session. When security is enabled, the controller will also provide at least one security key to the controlled party to protect unicast frames (i.e., frames exchanged between the responder and the initiator). If security is also enabled for broadcast frames, a separate security key shared by all responders will also be provided. For NBA-MMS ranging sessions, narrowband-related parameters (e.g., NB channel number, etc.) can also be negotiated during session establishment 510.

[0221] Some other parameters, such as the number of MMS segments, reporting mode, etc., may be considered short-term parameters because they may be modified during the MMS ranging session. Session establishment 510 may be performed out-of-band, such as using a Bluetooth or Wi-Fi radio, or in-band, such as using a narrowband or UWB radio.

[0222] Additionally, the roles of initiator and responder are also assigned during session establishment 510. Figure 5In the specific example shown in , it is assumed that the controller assumes the role of initiator 260 and the controlled is assigned the role of responder 270. However, it should be understood that it is also possible that the controlled is assigned the role of initiator and the controller assumes the role of responder.

[0223] At 522, the initiator 260 opportunistically sends ADV-POLL frames at times and intervals determined by it, while the responder 270 can opportunistically listen for incoming ADV-POLL frames. At 524, if the responder 270 intends to participate in a ranging session with the initiator 260, the responder 270 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN that is used to construct a random number used to protect the ADV-RESP frame. Figure 5 As shown, a secure ADV-RESP frame may be sent from responder 270 to initiator 260 .

[0224] At 526, once the initiator 260 receives the ADV-RESP frame, it sends a SOR frame that provides the time offset for the start of the first distance measurement period. If security is enabled, the SOR frame carries a PN that is used to construct a random number for protecting the SOR frame. Figure 5 As shown, a secure SOR frame can be sent from the initiator 260 to the responder 270. It should be noted that the PN used for UL and the PN used for DL can be used separately, that is, the PN in the uplink (responder to initiator) and downlink (initiator to responder) directions can use different numbering spaces, and the PN is increased by 1 each time a frame carrying the PN is sent.

[0225] At 528, the initiator 260 sends a secure POLL frame to the responder 270 at the beginning of the first time slot of a round, where the beginning of the first time slot is indicated by the time offset in the SOR frame. The initiator 260 may also include other control information in the POLL frame of the responder 270. At 530, the responder 270 sends a secure RESP frame back to the initiator 260 if it successfully receives the secure POLL frame. The POLL frame and the RESP frame can synchronize the time and frequency of the initiator 260 and the responder 270.

[0226] During the ranging phase, the initiator 260 and the responder 270 may exchange zero or more UWB RSFs, and optionally one or more UWB RIFs. The RSFs are used to perform ranging measurements, while the RIFs are used to check the integrity of the ranging measurements. Figure 5 As shown at 532 and 534 in FIG.

[0227] After the initiator 260 or responder 270 completes receiving all UWB segments in the ranging phase, the reporting phase may begin. During the reporting phase, the initiator 260 or responder 270 may generate a ranging measurement report and send a secure RPRT frame carrying the measurement report to the peer device. Figure 5 As shown, at 536 , the initiator 260 sends the secure RPRT frame to the responder 270 , and at 538 , the responder 270 sends the secure RPRT frame to the initiator 260 .

[0228] The time slot index of the corresponding frame in which the corresponding frame is transmitted, the round index, and the block in which the time slot is located may be used to construct a random number for protecting the POLL frame, the RESP frame, and the RPRT frame.

[0229] The present invention shows some exemplary formats of frames and random numbers in conjunction with the accompanying drawings. However, it should be noted that the examples are given for illustrative purposes and do not impose any limitations on the present invention. For example, a frame or a random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may also be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying the information and the other field retained. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the fields may be arranged in another manner, such as in a different order. The present invention is not limited in this respect.

[0230] Figure 6A A schematic diagram illustrating the format of a SOR frame 610 provided by some exemplary embodiments of the present invention is shown. For example, the SOR frame 610 may be Figure 5 Although the SOR frame 610 is shown in a compressed PSDU format, the described process can work even if the frame is carried as a compressed header ID format or even as a traditional 802.15.4 frame.

[0231] like Figure 6A As shown, the SOR frame 610 includes a field 611 carrying an ID, a field 612 carrying a security indicator, a field 613 carrying an address, a field 614 carrying a PN, a field 615 carrying a security level, a field 616 carrying a security payload, and a field 617 carrying a MIC. When carried as a traditional 802.15.4 frame, the PN field 614 and the security level field 615 may be carried within the auxiliary security header field in the MHR.

[0232] Fields 611 to 615 can be considered as a compressed header (CHR) of the SOR frame 610, where fields 611 to 613 are mandatory and fields 614 to 615 are optional. For example, if the frame is not secure, field 614 may not be included. For example, if the security level is negotiated in advance, field 615 may be omitted.

[0233] Field 611 may indicate an identification of the SOR frame 610, for example, field 611 carries "0x22" indicating a SOR frame. Field 612 may indicate whether the frame is secure. In some examples, field 612 may be the most significant bit (MSB) of field 611, for example, carrying "1" or "0". For example, "1" indicates that the frame is secure, while "0" indicates that the frame is not secure. Figure 6A As shown, the total length of field 611 and field 612 may be 1 octet.

[0234] Field 614 may carry the packet number of the SOR frame 610. In some examples, the initiator 260 may maintain a separate numbering space for each responder 270 of the security compressed frame to ensure that the same random number is never reused with the same security key. For example, a first numbering space is associated with responder 270-1 and a second numbering space is associated with responder 270-2. Figure 6A As shown, field 614 may be 4 octets in length. Where the SOR frame is addressed to multiple responders, the PN may be the same for all responders and a separate security key negotiated for the broadcast transmission is used to protect or unprotect the SOR frame.

[0235] Field 615 may indicate the security level to be applied to the security operation on the frame. Alternatively, field 615 may be omitted if the security level is negotiated during session establishment 510 and is assumed to be fixed for the entire ranging session.

[0236] Field 616 is secure (ie, encrypted) when SOR frame 610 is encrypted, for example, when the security level is one of 5, 6, or 7. For example, field 616 carries a security payload.

[0237] Field 617 carries the MIC generated by the AEAD transformation process. The size of the MIC depends on the security level. For example, if the security level is 5 or 6, the length of field 617 is 4 octets or 8 octets, respectively. It is also possible that only a portion of the MIC (e.g., the least significant 16 bits) is carried in the MIC field, and the same 16 bits are used by the responder for integrity checking.

[0238] It should be understood that since the MIC can detect any error in the frame content, the CRC field is no longer needed, that is, the CRC field can be replaced by the MIC field.

[0239] It should be understood that Figure 6A The SOR frame 610 in may be considered a secure SOR frame. In other examples, if a non-secure SOR frame is used, the field 614 and the field 615 are not included, and the payload in the field 616 is a non-secure payload.

[0240] It should also be understood that although Figure 6A The format of the SOR frame is shown, but a similar format can be applied to the secure ADV-RESP, which will not be described here in detail.

[0241] Figure 6B A schematic diagram illustrates the format of a random number 620 for protecting frames sent in an external block structure, as provided by some exemplary embodiments of the present invention. For example, the random number 620 may be constructed by the initiator 260 to protect a SOR or to deprotect an ADV-RESP, or by the responder to protect an ADV-RESP or to deprotect a SOR. Alternatively, the random number 620 may be referred to as an external block-based random number.

[0242] like Figure 6B As shown, the random number 620 includes a frame 621 carrying a source address, a field 622 carrying a PN, a reserved field 623, a field 624 carrying a security level, and a field 615 carrying a block structure indicator.

[0243] Field 621 may indicate the extended address of the device that originates the frame. It is understood that during session establishment 510, the controller and the controlled device will exchange and store the extended address of the peer device.

[0244] Field 622 can be considered a frame counter field and can be set to a PN that is the same as the value of the PN field of the secure frame. For example, if the random number 620 is constructed by the initiator 260 to protect a SOR frame or by the responder 270 to deprotect a SOR frame, the PN in field 622 should be the same as the PN in field 614. Field 622 can be 4 octets in length.

[0245] Field 624 may indicate a security level, i.e., a random number security level. The security level may be an integer that is the same as the value of the security level field of the security frame. For example, if the random number 620 is constructed by the initiator 260 to protect a SOR frame, or by the responder 270 to deprotect a SOR frame, the security level in field 624 should be the same as the security level in field 615. However, as shown in the reference Figure 6AAs described, in the event that a security level is negotiated during session establishment 510 , field 615 may be omitted, in which case security level field 624 is set to the security level negotiated during session establishment 510 .

[0246] Field 625 may indicate a block structure indicator (or simply a block indicator). In some examples, field 625 may be the last bit of random number 620, for example, carrying a "1" or a "0." For example, a "1" indicates that the frame is in a block structure, and a "0" indicates that the frame is sent in an external block structure. Figure 6B As shown, the block structure indicator is 0 because the random number 620 is used in the initialization and setup phases.

[0247] It should be understood that the block structure indicator is used to ensure that the random numbers used to protect frames sent inside and outside the block structure are never reused. For example, in the case where a frame is sent or received outside the block structure, the block structure indicator can be set to "0".

[0248] Figure 7A A schematic diagram illustrating the format of a POLL frame 710 provided by some exemplary embodiments of the present invention is shown. For example, the POLL frame 710 may be Figure 5 The secure POLL frame sent at 528 in FIG.

[0249] like Figure 7A As shown, the POLL frame 710 includes a field 711 carrying an ID, a field 712 carrying a security indicator, a field 713 carrying an address, a field 714 serving as a presence control field, a field 715 carrying a block index, a field 716 carrying a round index, a field 717 carrying a security payload, and a field 718 carrying a MIC.

[0250] Fields 711 to 713 may be considered the CHR of the POLL frame 710. Field 711 may indicate the identity of the POLL frame 710. Field 712 may indicate whether the frame is secure. In some examples, field 712 may be the MSB of field 711, for example, carrying a "1" or a "0." For example, a "1" indicates that the frame is secure, while a "0" indicates that the frame is not secure. Figure 7A As shown, the total length of field 711 and field 712 may be 1 octet.

[0251] Fields 714 to 716 can be considered as the open payload of the POLL frame 710. Regardless of the security level, the open payload of the security frame can be authenticated but not encrypted. Field 714 includes a block index present field 7142 that carries a block index present indicator, a round index present field 7144 that carries a round index present indicator, and a reserved field 7146. Figure 7AAs shown, field 714 may be 1 octet in length.

[0252] In some examples, the block index presence indicator is equal to a first value (e.g., 1) to indicate the presence of field 715, and the round index presence indicator is equal to a first value (e.g., 1) to indicate the presence of field 716 in the open payload. For example, field 715 may be 2 octets long, and field 716 may be 2 octets long. In other examples, the block index presence indicator is equal to a second value (e.g., 0) to indicate the absence of field 715, i.e., the length of field 715 is 0. In other examples, the round index presence indicator is equal to a second value (e.g., 0) to indicate the absence of field 716, i.e., the length of field 716 is 0. For example, if the block index is the default value (e.g., 0), field 715 may be omitted. For example, if the round index is the default value (e.g., 0), field 716 may be omitted.

[0253] When POLL frame 710 is encrypted, for example, when the security level is one of 5, 6, or 7, field 717 is secure (i.e., encrypted). For example, field 717 carries a security payload. Field 718 carries a MIC generated by the AEAD transform process. The size of the MIC depends on the security level. For example, if the security level is 5 or 6, the length of field 718 is 4 octets or 8 octets, respectively.

[0254] Alternatively, the POLL frame 710 may include a field that carries a security level, which is similar to Figure 6A Field 615 in is similar.

[0255] It should be understood that Figure 7A The POLL frame 710 in can be considered as a secure POLL frame. The secure POLL frame 710 is sent in the first time slot in the round indicated by the SOR frame (eg, secure SOR frame 610) to synchronize the receiver of the secure POLL frame 710 (responder 270) with the block structure.

[0256] It should also be understood that although Figure 7A The format of the POLL frame is shown, but a similar format can be applied to secure RESP or secure RPRT, which will not be described in detail here.

[0257] Figure 7BA schematic diagram illustrates the format of a random number 720 for protecting frames within a block structure, as provided by some exemplary embodiments of the present invention. For example, the random number 720 may be constructed by the initiator 260 to protect a POLL, deprotect a secure RESP, protect an RPRT, or deprotect a secure RPRT, or by the responder to deprotect a secure POLL, protect an RESP, deprotect a secure RPRT, or protect an RPRT. Alternatively, the random number 720 may be referred to as an intra-block-based random number.

[0258] like Figure 7B As shown, the random number 720 includes a frame 721 carrying a source address, a field 722 carrying a slot index, a field 723 carrying a round index, a field 724 carrying a block index, and a field 725 carrying a block structure indicator.

[0259] Field 721 may indicate the extended address of the device that originates the frame. It is understood that during session establishment 510, the controller and the controlled device will exchange and store the extended address of the peer device.

[0260] Fields 722 to 724 can be considered as frame counter fields of the random number 720. Fields 722 to 724 can be set to the index of the time slot, round, and block in which the frame is transmitted (while protected) or received (while unprotected). Figure 7B As shown, each length of fields 722 to 724 is predefined, and the total number of lengths is 39 bits.

[0261] Field 725 may indicate a block structure indicator (or simply a block indicator). In some examples, field 725 may be the last bit of random number 720, for example, carrying a "1" or a "0." For example, a "1" indicates that the frame is in a block structure, and a "0" indicates that the frame is sent in an external block structure. Figure 7B As shown, since the random number 720 is used for measuring the period, the block structure indicator is 1.

[0262] Alternatively, the random number 720 may include a field that carries a security level, which is similar to Figure 6B Field 624 in is similar.

[0263] In some examples, field 724 can be split into two fields, one of which carries the block index and the other is reserved. In some examples, the order of fields 722 to 724 can be another way, such as Figure 7B Reverse order as shown.

[0264] It should be understood that the block structure indicator is used to ensure that the random numbers used to protect frames sent inside and outside the block structure are never reused. For example, in the case where a frame is sent or received in an external block structure, the block structure indicator can be set to "0".

[0265] Figure 7C An example 730 of constructing a random number for protecting a compressed frame provided by some exemplary embodiments of the present invention is shown. Figure 7C As shown, if the security frame is to be sent in slot 1 of round 1 of block 1 in a block-based timing structure, the random number may include a field 732 carrying slot index 1, a field 733 carrying round index 1, and a field carrying block index 1.

[0266] It should be understood that example 730 also applies to a responder that de-secures a frame, e.g., the secured frame is received in slot 1 of round 1 of block 1 in a block-based timing structure, and the random number is constructed in the same manner.

[0267] As reference Figures 7B to 7C As described above, the lengths of the fields carrying the slot index, round index, and block index can be set to fixed values, such as 8 bits, 15 bits, and 16 bits, respectively. In the present invention, there can be a single frame being transmitted in a time slot to ensure that the random number of the same security key is never repeated. In this case, a larger number of frame counter values may be required, and accordingly, the frame counter space may be quickly exhausted. Therefore, if the frame counter wraps around (i.e., rolls to 0), the security key needs to be changed to ensure that the random number of the same security key is never repeated.

[0268] Table 1 below shows the increment of the frame counter value based on the random number of the inner block (e.g., random number 720) when a security frame is transmitted or received in the first time slot of different rounds in three consecutive blocks. It can be seen that the frame counter value increases by 8,388,865 each time the block index is updated. For example, for a block structure with a block duration of 96 ms, the frame counter will wrap around in 6291 seconds = 104 minutes. Table 1

[0269] Figure 8 FIG2 is a diagram illustrating another format of a random number 800 for protecting a frame within a block structure provided by some exemplary embodiments of the present invention. Alternatively, the random number 820 may be referred to as an intra-block based random number.

[0270] like Figure 8As shown, the random number 800 includes a frame 821 carrying a source address, a field 822 carrying a time slot index, a field 823 carrying a round index, a field 824 carrying a block index, and a field 825 carrying a block structure indicator. It should be noted that the random number 800 and Figure 7B The random number 720 in FIG. 8 is similar, however, the lengths of fields 822 to 824 are not fixed values.

[0271] For example, the length of field 822 (i.e., the first bit number), the length of field 823 (i.e., the second bit number), and the length of field 824 (i.e., the third bit number) may be determined based on a block-based temporal structure. Figure 8 The values of M and N in may be determined according to equations (1) and (2), respectively. In some examples, the values of M and N may be indicated by initiator 260, for example, in SOR frame 610.

[0272] Alternatively, the random number 800 may include a field carrying a security level, which is similar to Figure 6B Alternatively, in some other examples, field 814 may be split into three fields, one field carrying the block index, one field carrying the security level, and one field reserved.

[0273] As a specific example, assuming that each block includes 16 rounds and each round includes 16 time slots, the number of time slots per round (NumSlots) = the number of rounds per block (NumRounds) = 16. Therefore, M = N = 4 bits. Table 2 below shows the increment of the frame counter value based on the intra-block random number (e.g., random number 800) when a security frame is transmitted or received in the first time slot of different rounds in three consecutive blocks. As can be seen, the frame counter value increases by 273 each time the block index is updated. For example, for a block structure with a block duration of 96 ms, the frame counter will wrap around in 3,435,974 minutes. Table 2

[0274] By comparing Table 2 with Table 1, it can be seen that the rapid increase of the frame counter value can be prevented if the random number 800 is used. Therefore, there is no need to update the security key so frequently.

[0275] Alternatively, by defining the value of the frame counter field (i.e., FC) as equation (3), Figure 8 The same effect can be achieved by constructing the frame counter (FC) field with a random number in , without dividing the frame counter field into slot index, round index, and block index fields (e.g., 822 to 824): FC=Block_Index×NumRounds×NumSlots+Round_Index×NumSlots+Slot_Index (3)

[0276] In equation (3), Block_index, Round_Index, and Slot_Index represent a block index, a round index, and a slot index, respectively.

[0277] Figure 8 The random numbers in can also have Figure 6B The random number has the same format as in the Frame Counter field, i.e., the frame counter field is 4 octets long and the random number includes the random number security level field.

[0278] Figure 9 FIG. 9 is a schematic diagram showing the format of a secure SOR frame 900 provided by some exemplary embodiments of the present invention. Figure 6A Similar to that described in , the secure SOR frame 900 includes a field 616 that carries a security payload.

[0279] Field 616 includes field 911 as a presence control field, field 912 carrying a time offset, field 913 carrying a block index, field 914 carrying a round index, and field 915 carrying a slot index. Field 911 may include field 9112 carrying a block index presence indicator, field 9114 carrying a round index presence indicator, field 9116 carrying a slot index presence indicator, and a reserved field 9118.

[0280] In the case where the controller is assigned to an existing block structure, the block index, round index, and slot index pointed to by the Time Offset field of the SOR frame may not start from zero. If the POLL frame sent at the time pointed to by the Time Offset field of the SOR frame does not carry the round and block indexes in the open payload (such as Figure 7A As shown, if the index is encrypted, the responder will not be able to deprotect the POLL frame because it will not be able to construct the random number. When indicating the first round allocated to the controller, in addition to the time offset of the block / round allocated in field 912, if the controller also includes the index of the block, round, and time slot pointed to by the time offset field 912, for example, in field 616 of the secure SOR frame 900. This will enable the first frame (e.g., POLL frame) sent in the block, round, and time slot pointed to by the time offset field 912 to be encrypted.

[0281] In some other examples, if any one of the block index presence indicator in field 9112, the round index presence indicator in field 9114, and the slot index presence indicator in field 9116 indicates that the corresponding index is not included, a default index (e.g., zero) can be applied.

[0282] Figure 10A An exemplary session 1010 between the initiator 260 and the responder 1 (eg, responder 270 - 1 ) provided by some exemplary embodiments of the present invention is shown. Figure 10B An exemplary conversation 1020 between initiator 260 and responder 2 (e.g., responder 270-2) according to some exemplary embodiments of the present invention is shown. In both examples, the number of rounds per block (NumRounds) = 16, and the number of slots per round (Numslots) = 16. This results in the number of bits of the round index (N) = the number of bits of the slot index (M) = 4. The frame counter field, used to construct the random number used to protect / deprotect each frame, is shown below the frame, e.g., "Random Number: FC = ..."

[0283] like Figure 10A As shown, the SOR frame sent to responder 1 can be as follows Figure 6A The secure SOR frame shown is shown, therefore, responder 1 will assume that the slot index, round index, and block index are all 0. Therefore, the first POLL frame (POLL 1) sent to responder 1 is sent in slot 0 (0x0) of round 0 of block 0, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the POLL 1 frame can be calculated as 0x0000. Similarly, the 128th RPRT frame (RPRT 128) is sent in slot 7 (0x7) of round 0 (0x0) of block 127 (0x7F), and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the RPRT 128 frame can be calculated as 0x7F07.

[0284] like Figure 10B As shown, the SOR frame sent to responder 2 can be as follows Figure 9As shown in the secure SOR frame, responder 2 will understand the existing block-based time structure and the indexes of time slots, rounds, and blocks by deprotecting the secure SOR frame, where the first POLL is expected, for example, "block index = 1, round index = 1, slot index = 0" shown at 1022. Therefore, the first POLL frame (POLL 1) sent to responder 2 is sent in time slot 0 of round 1 of block 1, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number for protecting / deprotecting the POLL 1 frame can be calculated as 0x0110. Similarly, the 129th RPRT frame (RPRT 129) is transmitted in time slot 15 (0xF) of round 1 (0x1) of block 128 (0x80), and the least significant two octets (in hexadecimal) of the frame counter field used to construct a random number for protecting / deprotecting the RPRT 128 frame can be calculated as 0x801F.

[0285] Assuming that the indexes of the block, round, and slot structures are always increasing and that the block structure never restarts within the same session between a pair of initiators and responders, an inner block random number, such as random number 720 or random number 800, is constructed. In the event that the block structure restarts two or more times between the same pair of initiators and responders, the inner block random number may be repeated if the same security key is used to protect the frames, which may violate security.

[0286] In some embodiments, the security key should be updated when the block structure is restarted, that is, a new security key should be used every time a new block structure is established between the same pair of initiator and responder.

[0287] In other embodiments, a cycle can be defined to avoid this situation, where a cycle consists of multiple blocks. This means that a layer of cycles can be added on top of blocks. Assuming the security key remains unchanged, the cycle index increases each time the block structure is restarted between the same initiator and responder pair. Figure 11A Schematic diagram of a time structure 1110 including a period provided by some exemplary embodiments of the present invention is shown. Figure 11A As shown, two cycles, cycle 0 and cycle 1, are shown.

[0288] If the period is newly defined, the index of the period in which the security frame is sent can also be used to construct the inner block random number. For example, the inner block random number can be constructed based on the slot index, round index, block index and period index.

[0289] Figure 11BFIG2 is a schematic diagram showing the format of another secure SOR frame 1120 provided by some exemplary embodiments of the present invention. Figure 9 Similar to that described in , the secure SOR frame 11200 includes a field 616 that carries a security payload.

[0290] Field 616 includes field 1121, which is a presence control field and includes field 1124 carrying a block index presence indicator, field 1125 carrying a round index presence indicator, field 1126 carrying a slot index presence indicator, field 1127 carrying a cycle index presence indicator, and a reserved field 1128.

[0291] Fields 1124 to 1126 can be used with Figure 9 Fields 9112 to 9116 in are similar and will not be described here. Figure 11B , assuming that fields 1124 to 1126 indicate that there is no block index field, round index field, or time slot index field, then Figure 11B There is no Figure 9 Fields corresponding to fields 913 to 915 in.

[0292] Field 1127 carries a period index presence indicator, which may indicate whether field 1123 is included. Figure 11B As shown, field 616 includes a field 1122 carrying a time offset and a field 1123 carrying a period index.

[0293] Alternatively, if the block index presence indicator in field 1124 is 1, a block index field carrying a block index may also be included. Figure 9 If the round index presence indicator in field 1125 is 1, a round index field carrying the round index may also be included, similar to field 913 in FIG. Figure 9 If the slot index presence indicator in field 1126 is 1, a slot index field carrying a round index may also be included, similar to field 914 in FIG. Figure 9 915 in . That is, the security payload 616 may include a presence control field (e.g., field 911 or 1121), a field carrying a time offset (e.g., field 912 or 1122), and may also include zero or more of the block index field, round index field, slot index field, and cycle index field, without any order restriction. For example, the field carrying a time offset (e.g., field 912 or 1122) may be located at the end of field 616, i.e., the last two octets.

[0294] In some examples, initiator 260 may use secure SOR frame 1120 to inform responder 270 of the cycle index each time a new block structure is started, in order to allow the responder to synchronize with the cycle index.

[0295] Figure 11C FIG2 is a diagram illustrating another format of a random number 1130 for protecting a frame within a block structure provided by some exemplary embodiments of the present invention. Alternatively, the random number 1130 may be referred to as an intra-block-based random number.

[0296] like Figure 11C As shown, the random number 1130 includes: a frame 1131 carrying a source address, a field 1132 carrying a time slot index, a field 1133 carrying a round index, a field 1134 carrying a block index, a field 1135 carrying a cycle index, and a field 1136 carrying a block structure indicator. It should be noted that the random number 1130 and Figure 8 The random number 800 in is similar, except that Figure 8 Field 824 in is split into Figure 11C For example, some of the MSBs of the block index field may be allocated to the cycle index, such as 6 bits allowing a maximum of 64 cycles.

[0297] Alternatively, the random number 1130 may include a field that carries a security level, which is similar to Figure 6B Alternatively, field 1135 may be split into two fields, one of which carries the period index and the other of which is reserved. In some examples, the order of fields 1132 to 1135 may be another way, such as Figure 11C Reverse order as shown.

[0298] According to the above combination Figures 4 to 9 In some embodiments described, some security frames may include a field carrying a PN, such as the SOR frame 610 or 900. Table 3 below lists some frames, some of which may need to include a PN, while others may not. Table 3

[0299] Specifically, frames sent outside of the block structure (e.g., ADV-POLL, ADV-RESP, SOR) include a PN field in the frame and use a random number based on the outer block (e.g., Figure 6B The random number 620 shown in FIG. 5 ) is used, while frames sent within the block structure (e.g., POLL, RESP, RPRT, PRM-RESP, PRM-REQ, ADV-HBS) do not include a PN field in the frame and use an inner block based random number (e.g., as shown in FIG. Figure 7B The random number 720 shown, or Figure 8 The random number shown is 800).

[0300] In some examples, the operation of protecting a frame may also be referred to as an AEAD transform, and the operation of deprotecting a secure frame may also be referred to as an inverse AEAD transform, but the present invention is not limited in this respect.

[0301] Although the above reference Figures 4 to 11C Some embodiments are described in relation to a block-based temporal structure, but it should be understood that they may also be related to a super-block-based temporal structure.

[0302] Figure 12A 1210 shows a schematic diagram of random number construction in a super-block time structure provided by some exemplary embodiments of the present invention. Figure 12A As shown, a superblock consists of three types of blocks: block 0 includes 2 rounds, each with 32 time slots, block 1 includes 8 rounds, each with 8 time slots, and block 2 includes 16 rounds, each with 16 time slots. If the frame is sent in time slot 0 of round 7 or block 4, the random number may include a field 1212 carrying "time slot index = 0", a field 1214 carrying "round index = 7", and a field 1216 carrying "block index = 4". Figure 12A The random number in may be an inner block random number based on random number 720, where the length of fields 1212 to 1216 is fixed.

[0303] Figure 12B Schematic diagram 1220 of random number construction in a super-block-based temporal structure provided by some exemplary embodiments of the present invention is shown. Figure 12A Similarly, a superblock consists of three types of blocks: block 0 includes 2 rounds, each with 32 time slots, block 1 includes 8 rounds, each with 8 time slots, and block 2 includes 16 rounds, each with 16 time slots. If the frame is sent in slot 0 of round 7 or block 4, the random number may include a field 1222 carrying "slot index = 0", a field 1224 carrying "round index = 7", and a field 1226 carrying "block index = 4".

[0304] Figure 12B The random number in may be an internal block random number based on random number 800, wherein the lengths of fields 1222 to 1226 are not fixed. Specifically, the maximum number of slots in a round (Max_NumSlots) = max(32, 8, 16) = 32, so M can be determined to be 5. Therefore, the length of field 1222 is 5 bits. Specifically, the maximum number of rounds in a block (Max_NumRounds) = max(2, 8, 16) = 16, so N can be determined to be 4. Therefore, the length of field 1224 is 4 bits.

[0305] Therefore, PN can be used to construct an outer block random number, and the time slot index, round index and block index (and optional cycle index) can be used to construct an inner block random number. The frames transmitted between the initiator and the responder can be protected accordingly, thereby ensuring the security of communication.

[0306] Alternatively, by defining the value of the frame counter field (i.e., FC) as equation (4), Figure 12A The same effect can be achieved by constructing the frame counter field with a random number in , without dividing the frame counter field into slot index, round index, and block index fields: FC=Block_Index×Max_NumRounds×Max_NumSlots+Round_Index×Max_NumSlots+Slot_Index (4)

[0307] In equation (4), Block_index, Round_Index, and Slot_Index represent the block index, round index, and slot index, respectively. In the case where the block index in the super block is expressed as a relative block index, the block index can be calculated according to equation (5): Block_Index=Hyper_Block_Index×NumBlocks+Relative_Block_Index (5)

[0308] In equation (5), Hyper_Block_Index is the index of the hyperblock, Relation_Block_Index is the relative block index, and NumBlocks is the number of blocks in the hyperblock.

[0309] Figure 13 A schematic diagram of another exemplary MMS ranging session 1300 in a block-based time structure provided by some exemplary embodiments of the present invention is shown. As shown in diagram 1300, the MMS ranging session 1300 includes an initialization and setup phase, followed by one or more measurement periods.

[0310] exist Figure 13 In this example, the block structure is assumed to exist during the initialization and setup phases. For example, the controller may create the block structure right at the beginning of the initialization and setup phases (i.e., even before or at the beginning). Thus, the initialization and setup phases and one or more measurement cycles are all within the block structure.

[0311] Since the synchronization between the initiator 260 and the responder 270 at the slot level may not be easy during the initialization and establishment phases, the slot index is not used to construct the random number, but a short PN (e.g., 1 octet long) may be used. In this case, the PN, round index, and block index may be used to construct the random number used to protect the frame, as shown in 1310. Due to the use of the round index, it is recommended that the initialization and establishment phases be completed within one round to prevent loss of synchronization due to changes in the round index. Figure 14 A signaling diagram illustrating a process 1400 of another exemplary MMS ranging session is shown, provided in accordance with some exemplary embodiments of the present invention.

[0312] Process 1400 begins with the controller and two controlled devices performing session establishment 1412 and session establishment 1414, respectively. During session establishment 1412 / 1414, long-term session parameters such as UWB channel number, preamble, block structure (e.g., number of blocks, block duration), etc. are negotiated. When security is enabled, the controller will also provide at least one security key to each controlled device to protect unicast frames (i.e., frames exchanged between the responder and the initiator). If security is also enabled for broadcast frames, a separate security key shared by all responders will also be provided. For NBA-MMS ranging sessions, narrowband-related parameters (e.g., NB channel number, number of MMS fragments, etc.) can also be negotiated during session establishment 1412 / 1414. Although Figure 13 While the same block structure is shown for the initialization and setup phase and the measurement period, different block structures may be used for the initialization and setup phase and the measurement period. In this case, a single security key may be negotiated for the initialization and setup phase and a different security key may be negotiated for the measurement period. In this case, the PN space may also be different for the initialization and setup phase and the measurement period. Furthermore, the block index of the block structure for the measurement period may start at zero at the time indicated by the time offset of the SOR frame.

[0313] Some other parameters, such as the number of MMS segments, reporting mode, etc., may be considered short-term parameters because they may be modified during the MMS ranging session. Session establishment 1412 / 1414 may be performed out-of-band, such as using a Bluetooth or Wi-Fi radio, or in-band, such as using a narrowband or UWB radio.

[0314] Additionally, the roles of initiator and responder are also assigned during session establishment 1412 / 1414. Figure 14 In the specific example shown in FIG, it is assumed that the controller plays the role of initiator 260 and the controlled are assigned the roles of responders 270-1 and 270-2. However, it should be understood that it is also possible for the controlled to be assigned the role of initiator and the controller to play the role of responder.

[0315] At 1416, the controller (initiator 260) initiates a block structure before sending the first ADV-POLL frame. For example, the initiator 260 may establish a block and round structure, for example, defining at least a block duration and a round duration. In some cases, a slot structure may also be defined. In this case, a slot index may be used instead of a PN for random number construction, both within and outside the block structure.

[0316] At 1422, initiator 260 opportunistically transmits ADV-POLL frames at times and intervals determined by it, while responders 270-1 and 270-2 can opportunistically listen for incoming ADV-POLL frames. To allow responders 270-1 and 270-2 to synchronize with the block structure, the ADV-POLL frame includes the index of the round and block in which the ADV-POLL frame is transmitted, as well as the duration of the current round. If a slot structure is also defined, the ADV-POLL frame also includes the slot index of the time slot in which the ADV-POLL frame is transmitted.

[0317] At 1424, if responder 270-1 intends to participate in a ranging session with initiator 260, responder 270-1 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN (e.g., PN_U1) that is used to construct a random number for protecting the ADV-RESP frame. Figure 14 As shown, a secure ADV-RESP frame may be sent from responder 270 - 1 to initiator 260 .

[0318] At 1426, if responder 270-2 intends to participate in a ranging session with initiator 260, responder 270-2 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN (e.g., PN_U2) that is used to construct a random number for protecting the ADV-RESP frame. Figure 14 As shown, a secure ADV-RESP frame may be sent from responder 270 - 2 to initiator 260 .

[0319] At 1428, once the initiator 260 receives the ADV-RESP frame, it sends a SOR frame that provides the time offset for the start of the first distance measurement period. The SOR frame can be sent in a broadcast manner so that both the responder 270-1 and the responder 270-2 can detect the frame. If security is enabled, the SOR frame carries a broadcast PN (e.g., PN_B), which is used to construct a random number for protecting the SOR frame. Figure 14As shown, a secure SOR frame can be sent from initiator 260 to responders 270-1 and 270-2. It should be noted that different numbering spaces can be used for PNs for unicast and broadcast frames. In this case, the time offset field in the SOR frame indicates the time when the first POLL frame was sent. Alternatively, the SOR frame may carry multiple time offset fields, one for each responder; or the initiator may send multiple unicast SOR frames, one for each responder; the time offset field indicates the exact time when the ranging measurement period for a specific responder begins.

[0320] At 1432, initiator 260 sends a broadcast POLL frame to responders 270-1 and 270-2 at the beginning of the first time slot of a round, where the beginning of the first time slot is indicated by the time offset in the SOR frame. Initiator 260 may also include other control information in the POLL frames of responders 270-1 and 270-2.

[0321] At 1434, the responder 270-1 sends a RESP frame back to the initiator 260 if it successfully receives the POLL frame. The POLL frame and the RESP frame may enable the initiator 260 and the responder 270-1 to achieve time and frequency synchronization.

[0322] During the ranging phase, the initiator 260 and the responder 270-1 may exchange zero or more UWB RSFs, and optionally one or more UWB RIFs. The RSFs are used to perform ranging measurements, while the RIFs are used to check the integrity of the ranging measurements. Figure 14 The exchanges between the initiator 260 and the responder 270 - 1 are shown at 1436 and 1438 in FIG.

[0323] After the initiator 260 or responder 270-1 completes receiving all UWB segments in the ranging phase, the reporting phase may begin. During the reporting phase, the initiator 260 or responder 270-1 may generate a ranging measurement report and send an RPRT frame carrying the measurement report to the peer device. Figure 14 As shown, at 1440 , the initiator 260 sends a secure RPRT frame to the responder 270 - 1 , and at 1442 , the responder 270 - 1 sends a secure RPRT frame to the initiator 260 .

[0324] The processes 1452 to 1462 between the initiator 260 and the responder 270 - 2 are similar to the processes 1432 to 1442 between the initiator 260 and the responder 270 - 1 , and thus are not described again herein.

[0325] like Figure 14As shown, each of all security frames carries an appropriate PN. The PN, together with the round and block indices, can be used to construct a random number for protecting POLL, RESP, and RPRT frames.

[0326] The present invention shows some exemplary formats of frames and random numbers in conjunction with the accompanying drawings. However, it should be noted that the examples are given for illustrative purposes and do not impose any limitations on the present invention. For example, a frame or a random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may also be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying the information and the other field retained. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the fields may be arranged in another manner, such as in a different order. The present invention is not limited in this respect.

[0327] Figure 15A FIG2 is a diagram illustrating a format of a random number 1510 for protecting a frame provided by some exemplary embodiments of the present invention. For example, the random number 1510 may be constructed by the initiator 260 or the responder 270 - 1 or 270 - 2.

[0328] like Figure 15A As shown, the random number 1510 includes a frame 1511 carrying a source address, a field 1512 carrying a PN, a field 1513 carrying a round index, and a field 1514 carrying a block index.

[0329] Field 1511 may indicate the extended address of the device originating the frame.Fields 1512 to 1514 may be considered as the frame counter random number 720.

[0330] Field 1512 carrying the PN may be 1 octet, or 8 bits, in length. The PN may also be referred to as a short PN. For example, the PN starts at 0 for each round and may not wrap around within a round. It should be understood that the maximum number of secure frames per round depends on the length of field 1512. For example, if field 1512 occupies 8 bits, the maximum number of secure frames per round is 256.

[0331] like Figure 15A As shown, the length of field 1513 is fixed, for example, 15 bits (8 to 22). In other examples, the length of the field carrying the round index may not be a fixed value. Figure 15BFIG1 is a schematic diagram showing another format of a random number 1520, which includes a frame 1521 carrying a source address, a field 1522 carrying a PN, a field 1523 carrying a round index, and a field 1524 carrying a block index. The length of field 1523 is N bits, where N can be determined by equation (2) above.

[0332] Alternatively, the random number 1510 or 1520 may include a field that carries a security level, which is similar to Figure 6B Alternatively, field 1514 or 1524 can be split into two fields, one of which carries the block index and the other of which is reserved. In some examples, the order of fields 1512 to 1514 or 1522 to 1524 can be another way, for example Figure 15A or Figure 15B Reverse order as shown.

[0333] Figure 16A A schematic diagram illustrating the format of a secure RPRT frame 1610 provided by some exemplary embodiments of the present invention is shown. For example, the secure RPRT frame 1610 may be Figure 14 Any of the frames sent at 1440, 1442, 1460 and 1462.

[0334] like Figure 16A As shown, secure RPRT frame 1610 includes a field 1611 carrying an ID, a field 1612 carrying a security indicator, a field 1613 carrying an address, a field 1614 carrying a PN, a field 1615 carrying a security payload, and a field 1616 carrying a MIC. Fields 1611 to 1614 can be considered the CHR of secure RPRT frame 1610. Although RPRT frame 1610 is shown in a compressed PSDU format, the described process can also work even if the frame is carried in a compressed header ID format or even as a traditional 802.15.4 frame.

[0335] Field 1611 may indicate an identification of a secure RPRT frame 1610. Field 1612 may indicate whether the frame is secure. In some examples, a field 1612 carrying a "1" indicates that the frame is secure. Figure 16A As shown, the total length of field 1611 and field 1612 can be 1 octet.

[0336] Field 1614 may carry the packet number of the secure RPRT frame 1610. Figure 14PN_U1 may be maintained for upstream transmissions from responder 270-1 to initiator 260, and PN_D1 may be maintained for downstream transmissions from initiator 260 to responder 270-1. PN_U2 may be maintained for upstream transmissions from responder 270-2 to initiator 260, and PN_D2 may be maintained for downstream transmissions from initiator 260 to responder 270-2. Figure 16A As shown, field 1614 may be 1 octet in length.

[0337] Field 1615 carries the security payload. Field 1616 carries the MIC generated by the AEAD transformation process. Field 1616 can be 4 octets or 8 octets in length.

[0338] Alternatively, the secure RPRT frame 1610 may include a field that carries the security level, which is similar to Figure 6A Field 615 in is similar.

[0339] Figure 16B FIG. 1 is a diagram showing the format of an ADV-POLL frame 1620 provided by some exemplary embodiments of the present invention. For example, the ADV-POLL frame 1620 may be Figure 14 The frame sent at 1422.

[0340] like Figure 16B As shown, ADV-POLL frame 1620 includes a field 1621 carrying an ID, a field 1622 carrying a security indicator, a field 1623 carrying an address, a field 1624 serving as a presence control field, a field 1625 carrying a block index, a field 1626 carrying a round index, a field 1627 carrying a round duration, a field 1628 carrying a payload, and a field 1629 carrying a CRC. Fields 1621-1623 can be considered as the CHR of ADV-POLL frame 1620, and fields 1624 to 1627 can be considered as the open payload of ADV-POLL frame 1620.

[0341] Field 1621 may indicate the identity of ADV-POLL frame 1620. Field 1622 may indicate whether ADV-POLL frame 1620 is secure. In some examples, field 1622 carrying "0" indicates that ADV-POLL frame 1620 is not secure. Figure 16B As shown, the total length of field 1621 and field 1622 can be 1 octet.

[0342] Field 1624 includes: a block index presence field 1681 carrying a block index presence indicator, a round index presence field 1682 carrying a round index presence indicator, a round duration presence field 1683 carrying a round duration presence indicator, and a reserved field 1684. Figure 16B As shown, field 1624 may be 1 octet in length.

[0343] In some examples, the block index presence indicator is equal to a first value (e.g., 1) to indicate the presence of the block index field 1625, the round index presence indicator is equal to a first value (e.g., 1) to indicate the presence of the round index field 1626, and the round duration presence indicator is equal to a first value (e.g., 1) to indicate the presence of the round duration field 1627. For example, each of fields 1625 through 1627 can be 2 octets in length.

[0344] Alternatively, the secure ADV-POLL frame 1620 may include a field that carries the security level, which is similar to Figure 6A Alternatively, the present invention does not limit the order of fields 1625 to 1627 and fields 1681 to 1683.

[0345] Since the ADV-POLL frame 1620 is sent at the beginning of a round and includes block structure information (e.g., block index, round index, round duration in fields 1625-1627), the initiator and one or more responders can synchronize to the block structure during the initialization and establishment phases.

[0346] Figure 17 FIG. 1 shows an exemplary conversation 1700 between the initiator 260, the responder 1 (eg, responder 270-1), and the responder 2 (eg, responder 270-2) provided by some exemplary embodiments of the present invention. Figure 15B The random number shown is 1520. As a specific example, assuming that each block includes 16 rounds, that is, NumRounds=16, it can be determined that N=4.

[0347] A downlink security frame from the initiator to responder 1 is shown at 1710, while a downlink security frame from the initiator to responder 2 is shown at 1720. The frame counter field, which is used to construct a random number for protecting / unprotecting each frame, is shown below the frame.

[0348] like Figure 17 As shown, the ADV-RESP frames from responder 1 and responder 2 are both secure frames sent in round 1 of block 6, and the PN field in both frames may be set to 0 (ie, as shown in FIG. Figure 17As shown, PN=0x00). The least significant 20 bits (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the ADV-RESP frame can be calculated as 0x06100. Although the FC of the two ADV-RESP frames is the same, this does not violate security because the source address field in the random number is different and the security keys used for responder 1 and responder 2 are different. Similarly, the 128th RPRT frame (RPRT 128) with the PN field set to 0xFF is sent to responder 1 in round 0 (0x0) of block 127 (0x7F), and the least significant 20 bits (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the RPRT 128 frame can be calculated as 0x7F0FF.

[0349] The potential wraparound of the PN field in the RPRT frame is also shown at 1712 in block 127. If the wraparound of the PN field occurs within the same round, this will cause the frame counter (0x7F000) to repeat (the same counter used for the POLL frame (POLL 128)) and cause the random number to be reused. However, as long as the maximum limit of 256 frames per round per device is adhered to, the frame counter will not repeat and this problem can be avoided.

[0350] Alternatively, by defining the value of the frame counter field (i.e., FC) as equation (6), Figure 15A or Figure 15B The same effect can be achieved by constructing the frame counter field of the random number in , without the need to divide the frame counter field into PN, round index and block index fields: FC=Block_Index×NumRounds×2 M +Round_Index×2 M +PN (6)

[0351] In equation (6), Block_index and Round_Index refer to the block index and the round index, respectively, and M = the number of bits used for the PN field.

[0352] According to the combination Figures 3 to 17 In some embodiments, the block index, round index, and time slot index / PN may be used to construct a random number, wherein the random number may be used to protect a frame or to deprotect a secure frame sent according to a block-based or super-block-based time structure, so that AEAD security operations may be applied and secure communication between the initiator and the responder may be guaranteed.

[0353] Further references Figure 18, shows a signaling diagram illustrating a communication process 1800 provided by some exemplary embodiments of the present invention. The process 1800 may involve a transmitter 1801 and a receiver 1802. It should be understood that referring to Figure 2A , the transmitter 1801 can be the controller 210 or the controlled 220, and the receiver 1802 can be the controlled 220 or the controller 210. It should be understood that, see Figure 2B , the sender 1801 can be the initiator 260 or the responder 270 , and the receiver 1802 can be the responder 270 or the initiator 260 .

[0354] The transmitter 1801 generates (1810) a first security frame. The first security frame may be protected by a first random number, wherein the first random number is constructed based on a first base packet number (BPN) and a first PN. In some embodiments, the transmitter 1801 may construct the first random number and then generate the first security frame.

[0355] The first BPN is associated with the initiator and responder. Specifically, the first BPN is associated with the communication direction from sender 1801 to receiver 1802. For example, if sender 1801 is initiator 260, the first BPN is the DL BPN; if sender 1801 is responder 270, the first BPN is the DL BPN. The first PN is the packet number of the first security frame.

[0356] The first random number includes a first field carrying a first BPN and a second field carrying a first PN. The length of the first field can be equal to the first number, for example, N1 bits. The length of the second field can be equal to the second number, for example, N2 bits. For example, the total number of the first number and the second number can be a predefined value, for example, 40 bits. The initial value of the first BPN can be stored locally in the transmitter 1801 and can be indicated to the receiver 1802 during session establishment and stored locally in the receiver. Alternatively, a default value (for example, 0) can be used as the initial value of the first BPN.

[0357] The first random number includes a source address. For example, the first random number may include a field carrying the source address, such as a source address field. The length of the field carrying the source address may be predefined, such as 8 octets, 7 octets, or other values.

[0358] In some exemplary embodiments, the first security frame will be sent during the initialization and setup phase or during a measurement period. In some examples, the first security frame may include the first BPN and the first PN. In other examples, the first security frame may include the first PN without the first BPN, in which case a locally stored first BPN may be used.

[0359] The first security frame may include a first security indicator. For example, the first security frame may include a field carrying the first security indicator, such as a security indicator field. The first security indicator may indicate whether the first security frame is secure. For example, the first security indicator may be "1" to indicate that the first security frame is secure. For example, the field carrying the first security indicator may be 1 bit long.

[0360] The first security frame includes a first PN field carrying a first PN. The length of the first PN field may be a predefined value, such as 1 octet.

[0361] The first security frame may include a BPN presence field that carries a BPN presence indicator. The BPN presence indicator may indicate whether the BPN field is included. For example, the BPN presence indicator is "1" to indicate that the BPN field is present. The first security frame may include a BPN field that carries a first BPN to allow the receiver to obtain a BPN for deprotecting the frame and subsequent security frames sent by the same initiator. In some examples, if the first BPN is equal to a default number (e.g., 0), the BPN presence indicator may be "0" to indicate that the BPN field is not included.

[0362] Transmitter 1801 transmits (1820) a first security frame 1822 to receiver 1802. Receiver 1802 receives (1824) first security frame 1822. Receiver 1802 deprotects (1830) first security frame 1822. Specifically, receiver 1802 deprotects first security frame 1822 using a random number constructed based on the first BPN and the first PN.

[0363] Specifically, if the first security frame 1822 includes a BPN field and a first PN field, the receiver 1802 can directly obtain the first BPN and the first PN. If the BPN field is not included, a default value (e.g., 0) can be used as the first BPN. The receiver 1802 can also construct a random number for deprotecting the first security frame 1822 based on the first BPN and the first PN. The receiver 1802 stores the first BPN locally.

[0364] The random number constructed by the receiver 1802 should be the same as the first random number used to protect the first security frame constructed by the sender 1801. The first random number constructed by the receiver 1802 is similar to the random number described above (i.e., the random number constructed by the sender) and will not be described in detail for the sake of brevity.

[0365] In some exemplary embodiments, transmitter 1801 may also transmit a second security frame to receiver 1802, where the second security frame includes the second PN but does not include the first BPN. Receiver 1802 may receive the second security frame and construct a second random number for deprotecting the second security frame based on the second PN and the locally stored first BPN. In some examples, if the second PN is less than the PN in the previous security frame, receiver 1802 may determine that the PN has wrapped and, therefore, should update the locally stored first BPN by incrementing it by 1.

[0366] In other exemplary embodiments, transmitter 1801 may further transmit a third security frame to receiver 1802, wherein the third security frame includes a second BPN and a third PN. Receiver 1802 may receive the third security frame. Because the second BPN is different from the locally stored first BPN, receiver 1802 may replace the first BPN with the second BPN. That is, the second BPN is locally stored instead of the first BPN. Receiver 1802 may also construct a third random number for deprotecting the third security frame based on the second BPN and the third PN.

[0367] In the present invention, a security frame is generated by protecting a compressed frame, wherein the compressed frame can be a compressed PSDU frame or a frame with a compressed header IE format as described above. The security operation can be performed by using cryptographic operations such as authentication or encryption.

[0368] Figure 19 A schematic diagram of an exemplary MMS ranging session 1900 provided by some exemplary embodiments of the present invention is shown. As shown in diagram 1900, the MMS ranging session 1900 includes an initialization and setup phase, followed by one or more measurement cycles, wherein the initialization and setup phase are outside the block structure, while the one or more measurement cycles are inside the block structure.

[0369] exist Figure 19 In the example, the PN and the locally stored BPN can be used to construct a random number for protecting the frame, whether outside or inside the block structure, as shown in 1910. Table 4 Responder ID DL BPN UL BPN 1 0x00000078 0x00000048 2 0x00000294 0x000000159 …… Table 5 Initiator ID DL BPN UL BPN 1 0x00000078 0x00000048 Table 6 Initiator ID DL BPN UL BPN 1 0x00000294 0x000000159

[0370] An example of a BPN stored locally at an initiator (e.g., initiator 26) is shown in Table 4, while examples of BPNs stored locally at responders (e.g., responders 270-1 and 270-2) are shown in Tables 5 and 6, respectively. The DL BPN is used for security frames sent by the initiator to one or more responders, while the UL BPN is used for security frames sent by one or more responders to the initiator.

[0371] Figure 20 A signaling diagram illustrating a process 2000 of an exemplary MMS ranging session is shown, provided by some exemplary embodiments of the present invention.

[0372] Similar to some embodiments described above, process 2000 begins with the controller and the controlled party performing session establishment 2010. During session establishment 2010, it is assumed that security keys and security levels will be exchanged, and long-term session parameters such as the UWB channel number, preamble, and block structure (e.g., number of blocks, block duration) will be negotiated. These long-term parameters are not expected to change during the MMS ranging session. When security is enabled, the controller will also provide each controlled party with at least one security key to protect unicast frames (i.e., frames exchanged between the responder and initiator). If security is also enabled for broadcast frames, a separate security key shared by all responders will also be provided. For NBA-MMS ranging sessions, narrowband-related parameters (e.g., NB channel number, number of MMS segments, etc.) may also be negotiated during session establishment 2010. Some other parameters, such as the number of MMS segments and reporting mode, may be considered short-term parameters because they may be modified during the MMS ranging session. Session establishment 2010 can be performed out-of-band, for example, using a Bluetooth or Wi-Fi radio, or in-band, for example, using a narrowband or UWB radio.

[0373] In addition, the roles of initiator and responder are also assigned during session establishment 2010. Figure 20 In the specific example shown in , it is assumed that the controller assumes the role of initiator 260 and the controlled is assigned the role of responder 270. However, it should be understood that it is also possible that the controlled is assigned the role of initiator and the controller assumes the role of responder.

[0374] At 2022 , the initiator 260 opportunistically sends ADV-POLL frames at times and intervals determined by the initiator 260, while the responder 270 may opportunistically listen for incoming ADV-POLL frames.

[0375] At 2024, if the responder 270 intends to participate in a ranging session with the initiator 260, the responder 270 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries the PN and BPN associated with the uplink transmission. The PN and BPN (UL) are used to construct a random number for protecting the ADV-RESP frame. Figure 20 As shown, a secure ADV-RESP frame may be sent from responder 270 to initiator 260 .

[0376] Once the initiator 260 has received the ADV-RESP frame, it stores the BPN(UL) locally. At 2026, the initiator 260 sends a SOR frame that provides the time offset for the start of the first distance measurement period. If security is enabled, the SOR frame carries the PN and the BPN associated with the downlink transmission. The PN and BPN(DL) are used to construct a random number for protecting the SOR frame. Figure 20 As shown, a secure SOR frame can be sent from initiator 260 to responder 270. Once responder 270 receives the SOR frame, it stores the BPN(DL) locally. It should be noted that the PNs in the upstream (responder to initiator) and downstream (initiator to responder) directions can use different numbering spaces.

[0377] At 2028, the initiator 260 sends a POLL frame to the responder 270 at the beginning of the first time slot of a round, where the beginning of the first time slot is indicated by the time offset in the SOR frame. The initiator 260 may also include other control information in the POLL frame of the responder 270. At 2030, the responder 270 sends a RESP frame back to the initiator 260 if it successfully receives the POLL frame. The POLL frame and the RESP frame can synchronize the time and frequency of the initiator 260 and the responder 270.

[0378] During the ranging phase, the initiator 260 and the responder 270 may exchange zero or more UWB RSFs, and optionally one or more UWB RIFs. The RSFs are used to perform ranging measurements, while the RIFs are used to check the integrity of the ranging measurements. Figure 20 As shown at 2032 and 2034 in FIG.

[0379] After the initiator 260 or responder 270 completes receiving all UWB segments in the ranging phase, the reporting phase may begin. During the reporting phase, the initiator 260 or responder 270 may generate a ranging measurement report and send an RPRT frame carrying the measurement report to the peer device. Figure 20As shown, at 2036 , the initiator 260 sends a secure RPRT frame to the responder 270 , and at 2038 , the responder 270 sends a secure RPRT frame to the initiator 260 .

[0380] Among them, each frame in the secure POLL frame, secure RESP frame and secure RPRT frame carries a PN. The carried PN and the locally stored BPN can be used to construct a random number for protecting / unprotecting the POLL, RESP and RPRT frames.

[0381] In addition, if Figure 20 As shown, PRM-RESP frames and PRM-REQ frames can be exchanged between the initiator 260 and the responder 270. The initiator 260 can send a secure PRM-RESP frame including a new BPN (i.e., New BPN(DL)). The responder 270 can send a secure PRM-REQ frame including a new BPN (i.e., New BPN(UL)). Thus, the locally stored BPN can be updated.

[0382] The present invention shows some exemplary formats of frames and random numbers in conjunction with the accompanying drawings. However, it should be noted that the examples are given for illustrative purposes and do not impose any limitations on the present invention. For example, a frame or a random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may also be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying the information and the other field retained. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the fields may be arranged in another manner, such as in a different order. The present invention is not limited in this respect.

[0383] Figure 21A A schematic diagram illustrating the format of a security frame 2110 during the initialization and establishment phases provided by some exemplary embodiments of the present invention is shown. For example, the security frame 2110 may be Figure 20 The secure ADV-RESP frame sent at 2024 or the secure SOR frame sent at 2026. The secure frame 2110 may be based on a compressed PSDU or may be based on a compressed header ID format or even on a legacy 802.15.4 frame format, in which case the security enable field in the frame control (FC) field is set to 1 to indicate that the auxiliary security header field is not present in the MHR.

[0384] like Figure 21AAs shown, the security frame 2110 includes a field 2111 carrying an ID, a field 2112 carrying a security indicator, a field 2113 carrying an address, a field 2114 serving as a presence control field (including a field 2114-1 carrying a BPN presence indicator and a reserved field 2114-2), a field 2115 carrying a PN, a field 2116 carrying a BPN, a field 2117 carrying a security payload, and a field 2118 carrying a MIC.

[0385] Field 2112 may indicate whether the frame is secure. In some examples, field 2112 may carry a "1" to indicate that the field is secure. In other examples, field 2112 may carry a "0" to indicate that the field is not secure, e.g., field 2115 may not be included.

[0386] Fields 2114 through 2116 may be considered the open payload of the secure frame 2110. The open payload may be authenticated but not encrypted because the BPN and PN are used by the receiver to construct a random number.

[0387] If security frame 2110 is a secure ADV-RESP frame, field 2116 may include the BPN associated with the uplink transmission, i.e., BPN_UL. If security frame 2110 is a secure SOR frame, field 2116 may include the BPN associated with the downlink transmission, i.e., BPN_DL. If the secure SOR frame is broadcast or multicast, multiple BPNs associated with multiple responders may be included in the open payload. In this case, the PN may also be extracted from the separate broadcast PN space.

[0388] In some examples, the security frame 2110 may include a field carrying a security level, for example, if a security level was not negotiated during session establishment 2010 .

[0389] Figure 21B A schematic diagram illustrating the format of a security frame 2120 during a measurement period provided by some exemplary embodiments of the present invention is shown. For example, the security frame 2120 may be Figure 20 The secure frame 2120 may be based on a compressed PSDU, a secure POLL frame sent at 2028, a secure RESP frame sent at 2030, or a secure RPRT frame sent at 2036 / 2038.

[0390] like Figure 21B As shown, the security frame 2120 includes a field 2121 carrying an ID, a field 2122 carrying a security indicator (e.g., Figure 21B ), a field 2122 carrying a “1” in the field, a field 2123 carrying an address, a field 2124 carrying a PN, a field 2125 carrying a security payload, and a field 2126 carrying a MIC.

[0391] In some examples, the security frame 2120 is similar to the secure RPRT frame 1610 described above and therefore will not be described in detail for the sake of brevity.

[0392] Figure 21C FIG2 is a schematic diagram illustrating a format of a secure SOR frame 2130 provided by some exemplary embodiments of the present invention. For example, the secure frame 2130 may be based on a frame having a compressed header IE format, that is, based on a compressed header IE format.

[0393] like Figure 21C As shown, the secure SOR frame 2130 includes a field 2131 carrying an FC, a field 2132 carrying an address, a field 2133 carrying an ID, a field 2134 carrying a security indicator (eg, Figure 21C The secure SOR frame 2130 includes a field 2134 containing a "1" in the frame control field, a field as a presence control field (including a field 2135-1 carrying a BPN presence indicator and a reserved field 2135-2), a field 2136 carrying a PN, a field 2137 carrying a payload, and a field 2138 carrying a MIC. It should be understood that since the BPN presence indicator in field 2135-1 is "0", there is no field carrying a BPN. The security enable field in the frame control (FC) field 2131 is set to 1 to indicate that the auxiliary security header field is not present in the MHR. In this case, the secure SOR frame 2130 does not include a BPN field, and the security level applied only involves authentication (i.e., the security level is any of 1, 2, or 3), so the payload in field 2137 is unsecured, but includes a field 2138 carrying a MIC.

[0394] It should be noted that in the case of a k-bit field carrying a PN, a maximum of 2 bits can be protected before the BPN needs to be incremented. k For example, if k = 8 bits, then for the same BPN, a maximum of 256 frames can be protected.

[0395] In some examples, when the PN of a security frame received from a transmitter is less than the PN of the previous security frame received from the same transmitter, the locally stored BPN should be increased by 1. In some other examples, the BPN can be explicitly updated during the measurement session. For example, the BPN can be updated using a secure PRM-REQ (for UL) or a secure PRM-RESP (for DL).

[0396] Figure 21DFIG2 is a diagram illustrating a format of a secure PRM-REQ or PRM-RESP frame 2140 provided by some exemplary embodiments of the present invention. The secure frame 2140 includes an SHR field 2141 , a PHR field 2142 , and a PHY payload field 2143 .

[0397] Field 2143 includes a field 2151 carrying an ID, a field 2152 carrying a security indicator (e.g., Figure 21D ), a field 2152 carrying a "1" in the field, a field 2153 carrying an address, a field 2154 as a presence control field (including a field 2154-1 carrying a BPN presence indicator and a reserved field 2154-2), a field 2155 carrying a PN, a field 2156 carrying a BPN, a field 2157 carrying a security payload, and a field 2158 carrying a MIC.

[0398] Fields 2154 through 2156 may be considered the open payload of the security frame 2140. The open payload may be authenticated but not encrypted because the BPN and PN are used by the receiver to construct a random number.

[0399] In some examples, field 2143 in security frame 2140 is similar to security frame 2110 described above, and therefore will not be described in detail for the sake of brevity.

[0400] Figure 21E A diagram illustrating a format of a random number 2150 provided by some exemplary embodiments of the present invention is shown. The random number 2150 may be used to protect a frame or to deprotect a secure frame, for example, during process 2000.

[0401] like Figure 21E As shown, the random number 2150 includes a frame 2151 carrying a source address, a field 2152 carrying a PN, and a field 2153 carrying a BPN. In some examples, fields 2152 to 2153 can be considered as a frame counter of the random number 2150. Figure 21E As shown, each length of fields 2152 to 2153 is predefined, and the total number of lengths is 40 bits.

[0402] Alternatively, random number 720 may include a field that carries the security level. Alternatively, field 2153 may be split into two fields, one of which carries the BPN and the other is reserved. Alternatively, field 2152 may be located after field 2153, i.e., the order of fields 2152 and 2153 may be reversed.

[0403] Figure 22AAn exemplary downlink session 2210 from an initiator to a responder 1 (e.g., responder 270-1) according to some exemplary embodiments of the present invention is shown. The value in the frame counter field (i.e., FC) is shown below the frame. This field is used to construct a random number used to protect / unprotect each frame.

[0404] like Figure 22A As shown, the SOR frame can be Figure 21A As shown in FIG1 , the secure SOR frame carries BPN=0x00 and PN=0x00. Therefore, the first POLL frame (POLL 1) is sent to responder 1 in round 0 of block 0 and carries a PN field set to 0x01, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number for protecting / unprotecting the POLL 1 frame can be calculated as 0x0001. Similarly, the 128th RPRT frame (RPRT 128) carrying PN=0xFF is sent in round 0 of block 127, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number for protecting / unprotecting the RPRT128 frame can be calculated as 0x00FF. As shown in FIG1 , the secure SOR frame carries BPN=0x00 and PN=0x00. Figure 22A As shown, the BPN associated with the downlink transmission from the initiator to responder 1 may be explicitly updated at 2212 by the initiator by sending a PRM-RESP 1 frame carrying a BPN field set to 0x01.

[0405] Figure 22B An exemplary uplink session 2220 from responder 2 (e.g., responder 270-2) to the initiator according to some exemplary embodiments of the present invention is shown. The value in the frame counter field (i.e., FC) is shown below the frame. This field is used to construct a random number used to protect / unprotect each frame.

[0406] like Figure 22BAs shown, the ADV-RESP frame may be a secure frame carried by responder 2 and carries BPN=0x07 and PN=0x01. Thus, the first RESP frame (RESP 1) is sent by responder 2 in round 1 of block 20 and carries a PN field set to 0x02, and the least significant two octets (in hexadecimal) of the frame counter field used to construct a random number for protecting / deprotecting the RESP 1 frame can be calculated as 0x0702. Similarly, the 128th RPRT frame (RPRT 128) carrying PN=0xFF is sent by responder 2 in round n of block 227, and the least significant two octets (in hexadecimal) of the frame counter field used to construct a random number for protecting / deprotecting the RPRT 128 frame can be calculated as 0x07FF. As shown Figure 22B As shown, the BPN associated with the upstream transmission from responder 2 to the initiator may be explicitly updated at 2222 by responder 2 by sending a PRM-REQ 1 frame carrying a BPN field set to 0x08.

[0407] Alternatively, by defining the value of the frame counter field (i.e., FC) as equation (7), Figure 21E The same effect can be achieved by constructing the frame counter field with a random number in , without dividing the frame counter field into PN and BPN fields: FC = PN || BPN (7)

[0408] In equation (7), “||” indicates a cascade operation.

[0409] According to the reference Figures 18 to 22B In some embodiments, the BPN and PN can be used to construct a random number, wherein the random number can be used to protect a frame or to deprotect a frame regardless of whether the secure frame is sent according to a block-based timing structure or a super-block-based timing structure, thereby, AEAD security operations can be applied and secure communication between the initiator and the responder can be guaranteed.

[0410] Figure 23 FIG2 shows an exemplary block diagram of a communication device 2300 provided by some embodiments of the present invention. The device 2300 may be implemented at a transmitter, such as a Figure 3 The transmitter 301 or Figure 18 The transmitter 1801 in FIG. 1 may be implemented as a chip or chip system within the transmitter. Figure 23 As shown, the device includes a generating module 2310 and a sending module 2320.

[0411] It should be understood that the module may be referred to as a unit or a means, and the present invention is not limited in this regard.

[0412] In some exemplary embodiments, the generation module 2310 may be configured to generate a first security frame, the first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, and each of the plurality of rounds includes a plurality of time slots, wherein the first security frame is protected by a first random number, the first random number being constructed based on identification information associated with the first security frame, a round index, and a block index, the round index being an index of the first round, and the block index being an index of the first block. The sending module 2320 may be configured to transmit the first security frame.

[0413] In some examples, the identification information includes a time slot index, which is an index of a time slot in which the first security frame is sent. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the time slot index.

[0414] In some examples, the first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

[0415] In some examples, the identification information includes a first packet number (PN), and wherein the first PN is the packet number of the first security frame. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN.

[0416] In some examples, the first number is a first predefined number.

[0417] In some examples, the first random number includes: a second field having a second number of bits, carrying the round index; and a third field having a third number of bits, carrying the block index.

[0418] In some examples, the second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number. In some examples, the third number is a third predefined number.

[0419] In some examples, the sum of the first number, the second number, and the third number is equal to a predefined total number.

[0420] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

[0421] In some examples, the first random number includes a first block indicator that indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

[0422] In some examples, the first security frame includes the block index and the round index. In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0423] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0424] In some examples, the generation module 2310 may also be configured to generate a second security frame to be transmitted, wherein the second security frame is protected by a second random number constructed based on a second PN, wherein the second PN is a packet number of the second security frame. The transmission module 2320 may also be configured to transmit the second security frame.

[0425] In some examples, the second random number includes a field having a predefined number of octets, the field carrying the second PN.

[0426] In some examples, the second random number includes a second block indicator that indicates that the second security frame is sent outside the block-based timing structure or the super-block-based timing structure.

[0427] In some examples, the second security frame includes a PN field carrying the second PN.

[0428] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0429] In some examples, the second security frame includes a security payload, and wherein the security payload includes: a second block index presence indicator indicating whether the second block index is included; a second round index presence indicator indicating whether the second round index is included; and a second time slot index presence indicator indicating whether the second time slot index is included.

[0430] In some examples, if the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; if the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; if the second time slot index presence indicator indicates that the second time slot index is included, the security payload includes the time slot index.

[0431] In some examples, at least one of the second block index presence indicator, the second round index presence indicator, or the second slot index presence indicator indicates that the corresponding index is not included and implicitly indicates that the corresponding index is a default index.

[0432] The device 2300 can be used in reference Figures 3 to 17 Some embodiments are implemented at the described transmitter.

[0433] In some other exemplary embodiments, the generating module 2310 may be configured to generate a first security frame to be transmitted in a block-based timing structure or a super-block-based timing structure, wherein the first security frame is protected by a first random number constructed based on a first base packet number (BPN) and a first packet number (PN), wherein the first BPN is associated with an initiator and a responder, and the first PN is a packet number of the first security frame. The transmitting module 2320 may be configured to transmit the first security frame.

[0434] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0435] In some examples, the first random number includes: a first field having a first number of bits, carrying the first BPN; and a second field having a second number of bits, carrying the first PN.

[0436] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0437] In some examples, the first security frame includes a BPN presence field that carries a BPN presence indicator indicating whether a BPN field is included.

[0438] In some examples, if the BPN presence indicator indicates that the BPN field is included, the first security frame includes the BPN field carrying the first BPN.

[0439] In some examples, if the BPN presence indicator indicates that the BPN field is not included, the first security frame indicates that the first BPN is a default number.

[0440] In some examples, the apparatus 2300 may further include a storage module for storing a first BPN associated with a first communication direction between the initiator and the responder.

[0441] In some examples, the sending module 2320 may be configured to send a second security frame including a second PN that is smaller than a PN included in a frame preceding the third security frame.

[0442] In some examples, the sending module 2320 may be used to send a third security frame including the second BPN.

[0443] The device 2300 can be used in reference Figures 18 to 22B Some embodiments are implemented at the described transmitter.

[0444] Figure 24 FIG2 shows an exemplary block diagram of a communication device 2400 provided by some embodiments of the present invention. The device 2400 may be implemented at a receiver, such as a receiver. Figure 3 Receiver 302 or Figure 18 The receiver 1802 in FIG. 1 may be implemented as a chip or chip system within the receiver. Figure 24 As shown, the device includes a receiving module 2410 and a protection release module 2420.

[0445] It should be understood that the module may be referred to as a unit or a means, and the present invention is not limited in this regard.

[0446] In some exemplary embodiments, the receiving module 2410 may be used to receive a first security frame, which is sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds; each of the multiple rounds includes multiple time slots; the deprotection module 2420 may be used to deprotect the first security frame according to a first random number, wherein the first random number is constructed based on identification information, a round index and a block index associated with the first security frame, wherein the round index is an index of the first round, and the block index is an index of the first block.

[0447] In some examples, the identification information includes a time slot index, which is an index of a time slot in which the first security frame is sent. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the time slot index.

[0448] In some examples, the first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

[0449] In some examples, the identification information includes a first packet number (PN), and wherein the first PN is the packet number of the first security frame.

[0450] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0451] In some examples, the first random number includes: a second field having a second number of bits, carrying the round index; and a third field having a third number of bits, carrying the block index.

[0452] In some examples, the second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number. In some examples, the third number is a third predefined number.

[0453] In some examples, the sum of the first number, the second number, and the third number is equal to a predefined total number.

[0454] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

[0455] In some examples, the first random number includes a first block indicator that indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

[0456] In some examples, the first security frame includes the block index and carries the round index.

[0457] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0458] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0459] In some examples, the receiving module 2410 may be further configured to receive a second security frame, the second security frame not being transmitted according to the block-based timing structure or the super-block-based timing structure. The deprotection module 2420 may be further configured to deprotect the second security frame according to a second random number constructed according to a second PN, where the second PN is a packet number of the second security frame.

[0460] In some examples, the second random number includes a field having a predefined number of octets, the field carrying the second PN.

[0461] In some examples, the second random number includes a second block indicator that indicates that the second frame is transmitted outside the block-based timing structure or the super-block-based timing structure.

[0462] In some examples, the second security frame includes a PN field carrying the second PN.

[0463] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0464] In some examples, the second security frame includes a security payload, wherein unprotecting the second security frame includes unprotecting the security payload based on the second random number, and wherein the security payload includes: a second block index presence indicator indicating whether the second block index is included; a second round index presence indicator indicating whether the second round index is included; and a second time slot index presence indicator indicating whether the second time slot index is included.

[0465] In some examples, if the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; if the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; if the second time slot index presence indicator indicates that the second time slot index is included, the security payload includes the time slot index.

[0466] In some examples, the deprotection module 2420 can be used to: determine that the corresponding index is a default index based on a determination that the corresponding index is not included based on at least one indicator among the second block index existence indicator, the second round index existence indicator, or the second time slot index existence indicator.

[0467] The device 2400 can be used in reference Figures 3 to 17 Some embodiments are implemented at a described receiver.

[0468] In some other exemplary embodiments, the receiving module 2410 may be configured to receive a first security frame, the first security frame being transmitted in a block-based timing structure or a super-block-based timing structure, and the de-protection module 2420 may be configured to de-protect the first security frame according to a first random number, wherein the first random number is constructed based on a first base packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, and the first PN being a packet number of the first security frame.

[0469] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0470] In some examples, the first random number includes: a first field having a first number of bits, carrying the first BPN; and a second field having a second number of bits, carrying the first PN.

[0471] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0472] In some examples, the first security frame includes a BPN presence field that carries a BPN presence indicator indicating whether a BPN field is included.

[0473] In some examples, if the BPN presence indicator indicates that the BPN field is included, the first security frame includes the BPN field carrying the first BPN.

[0474] In some examples, if the BPN presence indicator indicates that the BPN field is not included, the first security frame indicates that the first BPN is a default number.

[0475] In some examples, the apparatus 2400 may further include a storage module for storing a first BPN associated with a first communication direction between the initiator and the responder.

[0476] In some examples, the receiving module 2410 may also be configured to receive a second security frame including a second PN. The apparatus 2400 may also include an updating module configured to update the locally stored first BPN by increasing it by 1 if the second PN is less than the PN included in the previous frame of the third security frame.

[0477] In some examples, the receiving module 2410 may be further configured to receive a third security frame including the second BPN. The apparatus 2400 may further include an updating module configured to replace the first BPN with the second BPN.

[0478] The device 2400 can be used in reference Figures 18 to 22B Some embodiments are implemented at a described receiver.

[0479] Figure 25 1 shows a schematic block diagram of a device 2500 that can be used to implement some embodiments of the present invention. The device 250 can be considered as Figure 2A The controller 210 and the controlled 220 shown, or as Figure 2BAnother exemplary implementation (eg, portion) of an initiator 260 and a responder 270 is shown.

[0480] As shown in the figure, the device 2500 includes a processor 2510, a memory 2520 coupled to the processor 2510, a suitable transmitter (TX) and receiver (RX) 2540 coupled to the processor 2510, and a communication interface coupled to the TX / RX 2540. The memory 2510 stores at least a portion of the program 2530. The TX / RX 2540 is used for bidirectional communication. The TX / RX 2540 has at least one antenna to facilitate communication, but in practice, the access node mentioned in the present invention may have several antennas. The communication interface can represent any interface required for communication with other network elements, such as an X2 interface for bidirectional communication between eNBs, an S1 interface for communication between a mobility management entity (MME) / serving gateway (S-GW) and an eNB, a Un interface for communication between an eNB and a relay node (RN), or a Uu interface for communication between an eNB and a terminal device.

[0481] Assume that program 2530 includes program instructions that, when executed by associated processor 2510, enable device 2500 to operate in accordance with embodiments of the present invention, as described herein with reference to Figures 3 to 24 The embodiments herein may be implemented by computer software executable by the processor 2510 of the device 2500, or by hardware, or by a combination of software and hardware. The processor 2510 may be used to implement various embodiments of the present invention. Furthermore, the combination of the processor 2510 and the memory 2520 may form a processing device 2550 for implementing various embodiments of the present invention.

[0482] Memory 2520 can be of any type suitable for the local technology network and can be implemented using any suitable data storage technology, such as non-transitory computer-readable storage media, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory (as non-limiting examples). Although only one memory 2520 is shown in device 2500, there may be several physically distinct memory modules in device 2500. Processor 2510 can be of any type suitable for the local technology network and can include one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture (as non-limiting examples). Device 2500 can have multiple processors, such as application-specific integrated circuit chips that are time-slave to a clock synchronized with a main processor.

[0483] The present invention provides a device, comprising: a processor; and a memory storing computer program code; the memory and the computer program code are used to enable the device to execute the method implemented at the transmitter or receiver through the processor.

[0484] The present invention provides a computer-readable medium having instructions stored thereon. When the instructions are executed by a processor of a device, the device is caused to execute the method implemented at a transmitter or a receiver as described above.

[0485] In general, various embodiments of the present invention can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects can be implemented in hardware, while other aspects can be implemented in firmware or software, which can be executed by a controller, microprocessor, or other computing device. Although various aspects of embodiments of the present invention are shown and described as block diagrams, flow charts, or using some other graphical representations, it should be understood that the blocks, devices, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuits or logic, general-purpose hardware or a controller or other computing device (as non-limiting examples), or some combination thereof.

[0486] The present invention also provides at least one computer program product tangibly stored on a non-transitory computer readable storage medium. The computer program product includes computer executable instructions, such as instructions included in a program module, that are executed in a device on a target real or virtual processor to perform the operations described above with reference to Figures 3 to 24The process or method described. Typically, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types. In various embodiments, the functionality of program modules can be combined or split between program modules as needed. The machine-executable instructions of program modules can be executed on a local device or distributed devices. In distributed devices, program modules can be located in local storage media and remote storage media.

[0487] The program code for implementing the method of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart or block diagram are implemented. The program code can be executed entirely on a single machine, partially on a machine as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0488] The program code described above may be embodied on a machine-readable medium, which may be any tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination thereof. More specific examples of machine-readable storage media would include an electrical connection having one or more wires, a portable computer floppy disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0489] In addition, although operations are described in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequence, or that all operations shown be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the invention, but rather as descriptions of features unique to a particular embodiment. In the context of a separate embodiment, certain features described in the present invention may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable subcombination.

[0490] Although the invention has been described in language specific to structural features or methodological acts, it should be understood that the invention defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. A method, characterized in that include: generating a first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, and each of the plurality of rounds includes a plurality of time slots, wherein the first security frame is protected by a first random number constructed based on identification information associated with the first security frame, a round index, and a block index, the round index being an index of the first round, and the block index being an index of the first block; Send the first security frame.

2. The method according to claim 1, characterized in that The identification information includes a time slot index, where the time slot index is an index of the time slot in which the first security frame is transmitted.

3. The method according to claim 2, characterized in that The first random number includes a first field having a first number of bits, the first field carrying the time slot index.

4. The method according to claim 3, characterized in that The first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

5. The method according to claim 1, wherein The identification information includes a first packet number PN, and wherein the first PN is a packet number of the first security frame.

6. The method according to claim 5, characterized in that The first random number includes a first field having a first number of bits, the first field carrying the first PN.

7. The method according to claim 6, characterized in that The first number is a first predefined number.

8. The method according to any one of claims 1 to 7, characterized in that The first random number includes: a second field having a second number of bits carrying the round index; A third field having a third number of bits carries the block index.

9. The method according to claim 8, characterized in that The second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number.

10. The method according to claim 8 or 9, characterized in that The third number is a third predefined number.

11. The method according to any one of claims 8 to 10, characterized in that The sum of the first quantity, the second quantity, and the third quantity is equal to a predefined total quantity.

12. The method according to any one of claims 1 to 11, characterized in that The first random number includes: A fourth field having a fourth number of bits carries a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

13. The method according to any one of claims 1 to 12, characterized in that The first random number includes a first block indicator, and the first block indicator indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

14. The method according to any one of claims 1 to 13, characterized in that The first security frame includes the block index and the round index.

15. The method according to claim 14, characterized in that The first security frame includes: A first block index existence indicator, indicating the existence of the first block index, The first round index existence indicator indicates the existence of the first round index.

16. The method according to any one of claims 1 to 15, characterized in that The first security frame includes a first security indicator to indicate that the first security frame is secure.

17. The method according to any one of claims 1 to 16, characterized in that Also includes: generating a second security frame to be sent, wherein the second security frame is protected by a second random number constructed based on a second PN, wherein the second PN is a packet number of the second security frame; The second security frame is sent.

18. The method according to claim 17, characterized in that The second random number includes a field having a predefined number of octets, the field carrying the second PN.

19. The method according to claim 17 or 18, characterized in that The second random number includes a second block indicator indicating that the second security frame is transmitted outside the block-based timing structure or the super-block-based timing structure.

20. A device, characterized in that include: a generating module, configured to generate a first security frame, the first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, and each of the plurality of rounds includes a plurality of time slots, wherein the first security frame is protected by a first random number, the first random number being constructed based on identification information associated with the first security frame, a round index, and a block index, the round index being an index of the first round, and the block index being an index of the first block; A sending module is used to send the first security frame.

21. The device according to claim 20, characterized in that The identification information includes a time slot index, where the time slot index is an index of the time slot in which the first security frame is transmitted.

22. The device according to claim 21, characterized in that The first random number includes a first field having a first number of bits, the first field carrying the time slot index.

23. The device according to claim 22, characterized in that The first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

24. The device according to claim 20, characterized in that The identification information includes a first packet number PN, and wherein the first PN is a packet number of the first security frame.

25. The device according to claim 24, characterized in that The first random number includes a first field having a first number of bits, the first field carrying the first PN.

26. The device according to claim 25, characterized in that The first number is a first predefined number.

27. The device according to claim 25, characterized in that The second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number.

28. The device according to claim 25 or 27, characterized in that The third number is a third predefined number.

29. A computer-readable medium, characterized in that The computer-readable medium stores instructions, which, when executed by a processor of a device, cause the device to perform the method according to any one of claims 1 to 19.

30. A computer instruction product, characterized in that The computer instruction product stores computer-executable instructions, which, when executed by a processor of a device, cause the device to perform the method according to any one of claims 1 to 19.

Citation Information

Patent Citations

  • Processing module and associated method

    CN108075994A

  • Electronic device for ranging by using ultra wide band and method of operating same

    CN114599993A

  • Security frames in uwband

    CN119968873A

  • System and method for establishing secure communications between devices in distributed wireless networks

    US20060126847A1

  • Methods and architectures for secure ranging

    US20200336303A1